Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 301–375

794 questions total · 11pages · All types, answers revealed

Page 4

Page 5 of 11

Page 6
301
MCQhard

An organization uses Microsoft 365 Copilot and wants to ensure that AI-generated content is automatically labeled with a sensitivity label. What should they configure?

A.Microsoft Defender for Cloud Apps session policies
B.Microsoft Intune app protection policies
C.Conditional Access policies in Microsoft Entra ID
D.Microsoft Purview auto-labeling policies
AnswerD

Microsoft Purview auto-labeling policies apply sensitivity labels automatically to content matching defined conditions, including AI-generated content produced by Microsoft 365 Copilot. This satisfies the requirement to label Copilot output without relying on manual user action.

Why this answer

Microsoft Purview auto-labeling policies automatically apply sensitivity labels to content based on conditions such as sensitive information types or trainable classifiers. This ensures that AI-generated content, like that from Microsoft 365 Copilot, is labeled according to organizational policy without manual intervention. Auto-labeling can be configured to label content at rest or in transit.

Exam trap

MS-900 often tests the difference between labeling and access control, and candidates may confuse auto-labeling with Conditional Access or DLP, picking a policy type that does not apply labels.

How to eliminate wrong answers

Option A is wrong because Defender for Cloud Apps session policies are used for conditional access and session control for cloud apps, not for automatically applying sensitivity labels to content. Option B is wrong because Intune app protection policies protect corporate data on mobile devices, but they do not apply sensitivity labels to content. Option C is wrong because Conditional Access policies control access to resources based on conditions, but they do not label content.

302
MCQmedium

A compliance administrator needs to automatically protect sensitive data by applying a 'Confidential' label that encrypts documents and restricts access to a specific user group. The label must be applied when a document containing a credit card number is saved in SharePoint. Which Microsoft Purview feature should be configured?

A.Retention labels
B.Sensitivity labels with auto-labeling
C.Data Loss Prevention (DLP) policies
D.Data classification service
AnswerB

Sensitivity labels with auto-labeling can be configured with policies that automatically detect sensitive data, such as credit card numbers, in SharePoint documents and apply encryption and access controls. These labels are integrated with Microsoft Purview Information Protection, so once applied, the document is encrypted at rest and permissions are enforced wherever the file is used. This makes it the correct answer, because it both classifies and actively protects content without manual intervention.

Why this answer

Sensitivity labels with auto-labeling are the correct choice because they allow you to automatically apply a 'Confidential' label that encrypts documents and restricts access based on sensitive content (e.g., credit card numbers) when documents are saved in SharePoint. This feature uses conditions like sensitive information types to trigger label application, ensuring data protection at rest and in use.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP policies only block or alert on data sharing, not apply labels or encryption, which is the core requirement for protecting data at rest.

How to eliminate wrong answers

Option A is wrong because retention labels are designed to manage data lifecycle (retention and deletion) and do not provide encryption or access restrictions. Option C is wrong because Data Loss Prevention (DLP) policies detect and prevent sharing of sensitive data but do not apply labels or encrypt documents; they enforce rules on data in motion. Option D is wrong because the data classification service identifies and classifies data but does not automatically apply labels or enforce protection actions like encryption.

303
MCQmedium

A company's IT team needs to provide employees with a single place to access all their Microsoft 365 applications, recent documents, and personalized content from any device. Which Microsoft 365 component should they promote as the primary entry point?

A.Microsoft 365 admin center
B.Microsoft SharePoint Online
C.Microsoft 365 Copilot
D.Microsoft 365 home page (office.com)
AnswerD

The Microsoft 365 home page at office.com is the personalized portal that gives users a single launchpad for all their Microsoft 365 apps, recent and shared documents, and recommended content. It works from any device through a browser and adapts to the user's activity, making it the appropriate primary entry point for employees.

Why this answer

The Microsoft 365 home page at office.com is designed as the personalized, cross-device launchpad that aggregates all Microsoft 365 apps, recent documents, and recommended content for each user. The admin center is for administrators, Copilot is an AI assistant within apps, and SharePoint Online is a collaboration and content platform, so none of them serves as the unified end-user portal.

Exam trap

The trap here is equating the administrative management portal with the end-user productivity portal, leading to selection of the Microsoft 365 admin center instead of the personalized office.com experience.

304
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to avoid license waste when employees change roles. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Microsoft Forms
D.License assignments against current user requirements
AnswerD

Assigning licences against current user requirements directly prevents waste when roles change, since Microsoft Entra ID group-based licensing removes or swaps licences automatically as group membership shifts. This satisfies the stem's constraint of avoiding licence waste during role transitions, rather than relying on manual reassignment that leaves unused licences paid for.

Why this answer

The core principle of avoiding license waste when employees change roles is to ensure that license assignments are aligned with current user requirements. Microsoft 365 licensing is user-based, and when a user's role changes, their assigned license should be updated or reassigned to reflect their new responsibilities, preventing unused or inappropriate licenses from being consumed.

Exam trap

The trap here is that candidates may confuse specific Microsoft 365 service features (like Whiteboard, Stream, or Forms) with the administrative licensing concept, but the question explicitly asks for the licensing, admin, or support concept most relevant to avoiding waste, which is license assignment management.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration tool for visual brainstorming and has no direct relevance to license management or role-based license optimization. Option B is wrong because Microsoft Stream is a video service for enterprise content management and does not address the administrative task of assigning or reassigning licenses based on role changes. Option C is wrong because Microsoft Forms is a survey and data collection tool, not a licensing or admin concept for managing user entitlements.

305
Multi-Selectmedium

A company is evaluating a move to the cloud. Which three of the following are advantages of using a public cloud model compared to a private cloud? (Choose three.)

Select 3 answers
.No capital expenditure for hardware
.Elastic scaling of resources on demand
.Provider-managed infrastructure maintenance
.Full control over physical security of data centers
.Guaranteed data residency in a specific geographic location
.Lower total cost for all long-term workloads

Why this answer

In a public cloud model, the cloud provider owns and manages the physical hardware, eliminating the need for the customer to make capital expenditures (CapEx) on servers, storage, and networking equipment. Public clouds offer elastic scaling, allowing resources like virtual machines or containers to be automatically provisioned or deprovisioned based on real-time demand, which is a core benefit of cloud computing. Provider-managed infrastructure maintenance means the cloud vendor handles all hardware patching, firmware updates, and physical security, offloading these operational responsibilities from the customer.

Exam trap

Microsoft often tests the misconception that public cloud always reduces costs for all workloads, but the trap is that long-term, predictable workloads can be more expensive in public cloud due to ongoing operational costs and lack of reserved instance optimization, while private cloud may offer lower TCO for such scenarios.

306
MCQmedium

You need to ensure that only authorized users from your tenant can access a SharePoint site. Which setting should you configure?

A.External sharing settings
B.Sensitivity labels
C.Conditional Access policy
D.Sharing links expiration
AnswerA

External sharing settings in SharePoint and OneDrive define the maximum level of external access allowed for a site, ranging from 'Anyone' (anonymous links) to 'Only people in your organization.' By configuring these settings at the tenant or site-collection level, administrators can prevent unauthorized external users from using anonymous or guest links. This is the definitive control for restricting site access to authorized users only.

Why this answer

External sharing settings control who outside your tenant can access SharePoint sites, files, and folders. By configuring these settings at the tenant or site level, you can restrict access to only authorized users from your tenant, blocking external users entirely. This is the direct mechanism for limiting access to internal users only.

Exam trap

The trap here is that candidates confuse external sharing settings with Conditional Access policies, thinking that CA policies can block external users from accessing SharePoint, when in fact CA policies apply to all users (including internal) and do not control the sharing invitation process.

How to eliminate wrong answers

Option B is wrong because sensitivity labels enforce classification and protection (encryption, watermarking) on content, not access control for external users. Option C is wrong because Conditional Access policies govern authentication and device compliance for all users, but they do not specifically block or allow external sharing of SharePoint sites. Option D is wrong because sharing links expiration controls how long a shared link is valid, not who can access the site; it does not prevent external users from being invited.

307
MCQmedium

A business stakeholder asks how Microsoft 365 can help them manage laptops and mobile devices with compliance policies and app protection. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Stream
B.Microsoft Planner
C.Microsoft Forms
D.Microsoft Intune
AnswerD

Microsoft Intune provides mobile device management and mobile application management, enforcing compliance policies and app protection on laptops and mobiles. This satisfies the stakeholder's device management and app protection requirement, unlike Entra ID, which handles identity and conditional access rather than device configuration.

Why this answer

Microsoft Intune is the correct answer because it is a cloud-based endpoint management solution that provides mobile device management (MDM) and mobile application management (MAM) capabilities. It allows administrators to enforce compliance policies (e.g., require PIN, encrypt device) and app protection policies (e.g., restrict copy/paste, prevent data leakage) on laptops and mobile devices, directly addressing the stakeholder's request.

Exam trap

The trap here is that candidates may confuse productivity tools (Stream, Planner, Forms) with security and management services, but Microsoft 365 separates collaboration features from endpoint management, which is exclusively handled by Intune in this context.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video-sharing and management service, not an endpoint management or compliance tool. Option B is wrong because Microsoft Planner is a task management and collaboration tool for organizing work, not for managing device compliance or app protection. Option C is wrong because Microsoft Forms is a survey and data collection tool, with no capabilities for device management or policy enforcement.

308
MCQmedium

A compliance administrator needs to apply encryption and usage restrictions to confidential documents. Which Microsoft 365 capability is the best fit? The design must avoid adding custom operational scripts.

A.OneDrive sync client
B.Sensitivity labels
C.Microsoft Bookings
D.Microsoft Teams live events
AnswerB

Sensitivity labels, defined in the Microsoft Purview compliance portal, classify and protect content by embedding metadata and applying information rights management (RMS) encryption directly to files and email. Administrators can configure label settings to enforce usage restrictions such as read-only, prohibit printing, block forwarding, and even custom user-assigned permissions, which then persist and travel with the content wherever it is shared. This gives the compliance administrator the necessary control to enforce both encryption and usage restrictions on sensitive data.

Why this answer

Sensitivity labels are the correct choice because they allow the compliance administrator to apply encryption and usage restrictions (such as 'Do Not Forward' or 'View Only') directly to confidential documents without writing any custom scripts. This capability is built into Microsoft 365 and integrates with Azure Information Protection to enforce protection policies at the file level, meeting the requirement for a no-code solution.

Exam trap

The trap here is that candidates may confuse the OneDrive sync client with a security tool, mistakenly thinking it can enforce encryption or restrictions, when in fact it only synchronizes files without applying any protection policies.

How to eliminate wrong answers

Option A is wrong because the OneDrive sync client is a file synchronization tool that syncs files between local devices and the cloud; it does not natively apply encryption or usage restrictions to documents. Option C is wrong because Microsoft Bookings is a scheduling and appointment management application, not a data protection or compliance tool. Option D is wrong because Microsoft Teams live events is a broadcast feature for streaming video to large audiences; it lacks the ability to apply encryption or usage restrictions to individual documents.

309
Multi-Selectmedium

A project team needs to collaborate on Teams channel conversations and meetings and co-author related Office files. Which two Microsoft 365 capabilities are most relevant?

Select 2 answers
A.Microsoft Teams
B.SharePoint Online document storage
C.Microsoft Purview eDiscovery case
D.Exchange anti-malware policy
AnswersA, B

Microsoft Teams supplies persistent channel conversations and scheduled meetings, forming the collaboration hub the project team needs. This satisfies the stem's requirement for channel discussions and meetings, while file co-authoring is delivered through the integrated SharePoint and Office workloads.

Why this answer

Microsoft Teams (A) is correct because it is the Microsoft 365 service that provides channel conversations, chat, and meetings, which directly satisfy the collaboration and meeting requirements. SharePoint Online document storage (B) is correct because Teams channels are backed by SharePoint Online, and SharePoint provides the co-authoring and versioned document storage for the related Office files. Microsoft Purview eDiscovery case (C) is not relevant because it is used for legal hold, search, and investigation of content, not for day-to-day collaboration or co-authoring.

Exchange anti-malware policy (D) is not relevant because it protects mail flow from malicious attachments and links, not Teams conversations, meetings, or Office file co-authoring.

Exam trap

The trap here is that candidates may think Microsoft Teams alone covers all collaboration needs, forgetting that SharePoint Online is the underlying file storage and co-authoring engine for Teams channel files.

310
MCQmedium

A business stakeholder asks how Microsoft 365 can help them check known incidents affecting Microsoft 365 services. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.Microsoft Stream
D.Service health
AnswerD

Service health in the Microsoft 365 admin centre publishes current and historical incidents and advisories affecting Microsoft 365 services. This satisfies the stakeholder's need to check known service incidents, distinct from Message centre, which covers upcoming changes rather than outages.

Why this answer

Service health in the Microsoft 365 admin center provides real-time status and incident information for all Microsoft 365 services. It allows administrators and stakeholders to check known incidents, advisories, and historical uptime data, directly addressing the need to monitor service availability.

Exam trap

The trap here is that candidates may confuse productivity tools (Forms, Whiteboard, Stream) with administrative or support features, failing to recognize that Service health is the dedicated console for incident monitoring within the Microsoft 365 admin center.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not a service monitoring or incident reporting feature. Option B is wrong because Microsoft Whiteboard is a digital canvas for collaboration, unrelated to checking service health or incidents. Option C is wrong because Microsoft Stream is a video management and sharing service, not a dashboard for service status or incident tracking.

311
Multi-Selecthard

Which THREE Microsoft 365 services can be used to store and manage files in the cloud?

Select 3 answers
A.OneDrive for Business
B.Microsoft Teams
C.Power BI
D.SharePoint
E.Exchange Online
AnswersA, B, D

OneDrive for Business provides each Microsoft 365 user a personal, cloud-hosted library for storing work files. It includes a sync client that mirrors local folders to the cloud, enables granular sharing, and integrates deeply with Office apps. Because it is a true storage service with quota and retention controls, it directly satisfies the question's requirement to store and manage files online.

Why this answer

OneDrive for Business is a cloud storage service that allows users to store, sync, and share files individually. It is part of Microsoft 365 and provides personal storage with up to 1 TB per user, integrating with Office apps for real-time co-authoring.

Exam trap

The trap here is that Microsoft Teams is listed as a correct answer because it can store files via its Files tab (which actually uses SharePoint or OneDrive under the hood), but candidates often confuse Teams as a primary storage service rather than a collaboration hub that relies on underlying storage services.

312
MCQeasy

A company uses a cloud provider that offers compute power as a service. The provider manages the physical servers, storage, and networking, but the company has full control over the operating system, applications, and configurations. Which cloud service model is being used?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerC

Infrastructure as a Service (IaaS) supplies on-demand virtual machines, virtual networks, and block storage, giving the customer full administrative control over the guest operating system, applications, and security configurations. The provider operates the physical hosts, virtualization layer, and data center facilities, while the customer selects compute sizes, scales capacity, and manages the guest OS like a traditional server. This direct provisioning of compute power and storage is the definitive example of compute power as a service, unlike more abstracted models.

Why this answer

The scenario describes Infrastructure as a Service (IaaS), where the cloud provider manages the underlying physical infrastructure (servers, storage, networking), but the customer retains full control over the operating system, applications, and configurations. This aligns with the IaaS model as defined by NIST SP 800-145, which provides virtualized computing resources over the internet.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve deploying applications, but PaaS removes OS control, while IaaS explicitly grants it, and the question's phrase 'full control over the operating system' is the critical differentiator.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) provides a complete application managed by the provider, where the customer has no control over the operating system or underlying infrastructure, only the application data. Option B is wrong because Platform as a Service (PaaS) abstracts the operating system and runtime environment, giving the customer control only over deployed applications and configuration settings, not the OS itself. Option D is wrong because Function as a Service (FaaS) is a serverless computing model where the provider manages all infrastructure and the customer only deploys individual functions, with no control over the OS or runtime environment.

313
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to increase from 100 to 2,000 users without buying new mail servers. Cloud concept or benefit best matches this requirement?

A.Data Loss Prevention (DLP)
B.Sensitivity labels
C.Microsoft Planner
D.Scalability
AnswerD

Scalability is a fundamental cloud characteristic meaning the system can proactively or reactively adjust resources—such as compute instances, throughput, storage quotas, and network capacity—to match changing demand, allowing you to pay only for what you consume. In Microsoft 365, services like Exchange Online and SharePoint Online use Microsoft's elastic global infrastructure to absorb spikes in user load or data growth without requiring customers to size or provision their own hardware. The help desk lead should document this exact capability as the correct cloud model and benefit.

Why this answer

Scalability is the correct answer because it refers to the ability of a cloud service like Microsoft 365 to dynamically allocate resources to accommodate growth from 100 to 2,000 users without requiring the purchase or provisioning of additional on-premises mail servers. Microsoft 365's multi-tenant architecture and elastic infrastructure automatically handle user load increases, making scalability the cloud concept that directly matches this requirement.

Exam trap

The trap here is that candidates may confuse operational features like DLP or Sensitivity labels with cloud benefits, failing to recognize that scalability is the specific cloud concept that directly addresses the ability to grow user counts without hardware investment.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive information from being shared or leaked, not a mechanism for scaling user capacity. Option B is wrong because Sensitivity labels are classification and protection tools for data governance, not related to increasing user counts or infrastructure scaling. Option C is wrong because Microsoft Planner is a task management and collaboration tool, not a cloud concept or benefit that addresses user capacity growth.

314
Multi-Selectmedium

Which three of the following are characteristics of cloud computing as defined by the National Institute of Standards and Technology (NIST)? (Choose three.)

Select 3 answers
.On-demand self-service
.Broad network access
.Resource pooling
.Dedicated hardware per tenant
.Fixed pricing models
.Limited scalability

Why this answer

NIST SP 800-145 defines cloud computing by five essential characteristics. On-demand self-service allows a consumer to provision computing capabilities automatically without requiring human interaction with each service provider. Broad network access means capabilities are available over the network and accessed through standard mechanisms (e.g., mobile phones, tablets, laptops, and workstations).

Resource pooling enables the provider's computing resources to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand.

Exam trap

Microsoft often tests the exact NIST definition by including plausible-sounding but non-NIST characteristics like 'dedicated hardware per tenant' or 'fixed pricing models,' which candidates mistakenly associate with cloud computing because they are common in traditional on-premises or managed hosting environments.

315
MCQhard

Your organization uses Microsoft 365 and wants to ensure that only managed devices can access corporate email in Exchange Online. Which conditional access policy setting should you configure?

A.Require device to be marked as compliant
B.Require approved client app
C.Require device to be joined to Azure AD
D.Require multi-factor authentication
AnswerA

Conditional Access with the 'Require device to be marked as compliant' grant checks the device's compliance status as evaluated by Microsoft Intune compliance policies. This status is only available for devices enrolled in Intune that meet rules like OS version, encryption, and threat-signal requirements. By enforcing this grant, only healthy, policy-verified devices can access email, blocking unmanaged or non-compliant devices.

Why this answer

The 'Require device to be marked as compliant' setting in a Conditional Access policy integrates with Microsoft Intune to enforce that only devices meeting compliance policies (e.g., encryption, OS version, jailbreak detection) can access Exchange Online. This ensures corporate email is accessible only from managed, trusted devices, directly addressing the requirement.

Exam trap

The trap here is that candidates often confuse 'device compliance' with 'device join status' or 'app protection,' mistakenly selecting Azure AD join or approved client app when the question specifically targets managed device enforcement via compliance policies.

How to eliminate wrong answers

Option B is wrong because 'Require approved client app' controls which applications (e.g., Outlook mobile) can access data, not the device's management state; a device could be unmanaged but still use an approved app. Option C is wrong because 'Require device to be joined to Azure AD' enforces that the device is registered in Azure AD, but it does not verify compliance with security policies like encryption or patch levels. Option D is wrong because 'Require multi-factor authentication' adds an identity verification layer but does not restrict access based on device management or compliance status.

316
MCQeasy

A company uses a cloud service where they can rent virtual machines and storage. They have full control over the operating system and applications, while the provider manages the physical hardware. Which cloud service model is being used?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerA

IaaS delivers virtualized computing resources, such as virtual machines, storage, and virtual networks, on demand over the internet. The consumer retains full administrative control over the guest operating system, middleware, and applications, while the cloud provider manages physical servers, storage hardware, and hypervisor virtualization. This makes it ideal for hosting legacy workloads or running custom software without maintaining physical data center infrastructure.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the company rents virtual machines and storage, retains full control over the operating system and applications, while the cloud provider manages the underlying physical hardware. In IaaS, the provider abstracts the physical infrastructure (servers, networking, storage) and delivers it as on-demand virtualized resources, which aligns with the customer's responsibility for OS and app configuration.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve cloud-hosted resources, but the key differentiator is control over the operating system—IaaS gives OS control, PaaS does not.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS abstracts the operating system and runtime environment, providing a platform for application development and deployment where the customer does not manage the OS or middleware; here the customer has full OS control. Option C (SaaS) is wrong because SaaS delivers fully functional applications over the internet, with no customer control over the underlying OS or infrastructure—the customer only uses the software. Option D (On-premises deployment) is wrong because on-premises means the company owns and manages all hardware and software locally, not renting virtualized resources from a cloud provider.

317
Multi-Selecteasy

Which TWO are characteristics of the public cloud deployment model?

Select 2 answers
A.Services are owned by a third-party provider
B.Services are used by a single organization
C.Scalability is limited to existing hardware
D.Infrastructure is located on-premises
E.Multiple organizations share the same infrastructure
AnswersA, E

In the public cloud deployment model, the cloud provider owns and operates the compute, storage and networking resources, delivering services to customers over the internet. This satisfies the stem's requirement by distinguishing public cloud from private cloud, where the organisation itself owns the infrastructure.

Why this answer

Option A is correct because in the public cloud deployment model the cloud services and underlying infrastructure are owned, managed, and operated by a third-party cloud provider such as AWS, Microsoft Azure, or Google Cloud, and delivered to customers over the internet. Option E is correct because public cloud infrastructure is multi-tenant: compute, storage, and network resources are pooled and shared among many different organizations (tenants), with logical isolation enforced by the provider. Option B is incorrect because use by a single organization describes the private cloud model, not the public cloud.

Option C is incorrect because public cloud scalability is effectively elastic and limited only by the provider's vast resource pools, not by a customer's existing hardware. Option D is incorrect because on-premises infrastructure is characteristic of private or traditional data-center deployments, whereas public cloud infrastructure resides in the provider's data centers.

Exam trap

MS-900 often tests the confusion between public and private cloud characteristics, especially the misconception that 'shared infrastructure' means insecure or that public cloud requires on-premises hardware.

318
MCQmedium

An administrator is reviewing a request from users who need to discover cloud apps being used by employees and assess their risk. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Defender for Cloud Apps
C.Microsoft Stream
D.Microsoft Forms
AnswerB

Microsoft Defender for Cloud Apps is the correct answer because its Cloud Discovery feature analyzes traffic logs from proxies or integrated endpoints to identify the cloud applications in use across the organization. It leverages the Cloud App Catalog, which assigns risk scores to thousands of apps, and lets administrators create app discovery policies, assess compliance, and apply access controls. This cloud access security broker (CASB) capability is purpose-built for discovering and governing third-party cloud apps, meeting the users' requirement directly.

Why this answer

Microsoft Defender for Cloud Apps is the correct choice because it is a Cloud Access Security Broker (CASB) that provides visibility into cloud app usage, shadow IT discovery, and risk assessment. It integrates with Microsoft 365 to monitor user activities and apply data loss prevention (DLP) policies across sanctioned and unsanctioned cloud apps.

Exam trap

The trap here is that candidates may confuse productivity tools like Planner or Forms with security capabilities, or assume Stream has monitoring features due to its 'cloud' nature, but only Defender for Cloud Apps provides dedicated cloud app discovery and risk assessment.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and collaboration tool, not a security or compliance capability for discovering cloud apps or assessing risk. Option C is wrong because Microsoft Stream is a video hosting and sharing service within Microsoft 365, with no functionality for cloud app discovery or risk assessment. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, lacking any security, identity, or compliance features for monitoring cloud app usage.

319
Matchingmedium

Match each Microsoft 365 compliance term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Policy to prevent accidental sharing of sensitive information

Process to search and export content for legal cases

Rule to keep or delete content for a specified time

Tags to classify and protect data based on sensitivity

Why these pairings

Microsoft 365 compliance features include Data Loss Prevention (prevent data leaks), eDiscovery (search and export for legal needs), Retention Policies (manage content lifecycle), and Sensitivity Labels (classify and protect). Common confusions involve mixing the definitions of these tools.

320
MCQeasy

An organization needs to ensure that all Microsoft 365 data is encrypted at rest and in transit. Which of the following is a built-in encryption mechanism in Microsoft 365?

A.BitLocker Drive Encryption
B.Customer-managed keys (CMK) using Azure Key Vault
C.Office 365 Message Encryption
D.Azure Information Protection
AnswerA

Microsoft protects all Microsoft 365 data at rest in its datacenters with BitLocker Drive Encryption, which encrypts the entire physical drive using AES. This is a default, always-on layer applied to every disk hosting Exchange Online, SharePoint Online, and Teams content. Because it covers the full drive, it ensures that any Microsoft 365 data — regardless of workload or tenant — is encrypted at the disk level before any optional keys or services are considered.

Why this answer

BitLocker Drive Encryption is a built-in encryption mechanism in Microsoft 365 that encrypts data at rest on physical drives within Microsoft datacenters. It uses AES 256-bit encryption to protect data stored on disk volumes, ensuring that even if physical drives are removed, the data remains unreadable. Additionally, Microsoft 365 uses TLS 1.2+ for data in transit, but BitLocker specifically addresses the 'at rest' requirement as a native, default encryption layer.

Exam trap

The trap here is that candidates confuse optional customer-managed encryption features (like CMK or OME) with the built-in, default encryption mechanisms (like BitLocker) that Microsoft automatically applies to all data at rest in its datacenters.

How to eliminate wrong answers

Option B (Customer-managed keys using Azure Key Vault) is wrong because it is an optional, advanced encryption feature that allows customers to control their own encryption keys, but it is not a built-in default mechanism; Microsoft 365 uses service-managed keys by default. Option C (Office 365 Message Encryption) is wrong because it is a feature for encrypting email messages in transit and at rest for end-user communications, not for encrypting all Microsoft 365 data at rest in the underlying storage infrastructure. Option D (Azure Information Protection) is wrong because it is a classification and labeling solution that applies rights management and encryption to documents and emails, but it does not encrypt all Microsoft 365 data at the storage layer; it operates at the application level.

321
MCQhard

A financial services firm must comply with regulatory requirements that prevent accidental sharing of sensitive customer data via email. They need to automatically detect and block emails containing credit card numbers sent to external recipients. Which Microsoft 365 service should they configure?

A.Microsoft Defender XDR
B.Microsoft Purview
C.Microsoft Intune
D.Microsoft Entra ID
AnswerB

Microsoft Purview is the Microsoft 365 data governance and compliance solution that specifically includes Data Loss Prevention (DLP) capabilities for Exchange Online. Purview DLP policies can apply sensitive information types, trainable classifiers, and exact data match to email content and enforce actions such as blocking transmission, encrypting the message, or alerting a compliance officer. This directly enables a financial services firm to meet regulatory obligations by detecting and preventing the exfiltration of sensitive data in email.

Why this answer

Microsoft Purview (formerly Microsoft 365 Compliance) includes Data Loss Prevention (DLP) policies that can automatically detect sensitive data types, such as credit card numbers, in emails and block them from being sent to external recipients. This directly addresses the regulatory requirement to prevent accidental sharing of sensitive customer data via email.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (security threat detection) with Microsoft Purview (compliance and data protection), leading them to choose Defender for a data loss prevention scenario instead of the correct compliance service.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is a security solution focused on threat detection, investigation, and response across endpoints, email, and identities, not on compliance-driven data loss prevention for sensitive content like credit card numbers. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for inspecting email content or enforcing DLP rules. Option D is wrong because Microsoft Entra ID (formerly Azure AD) is an identity and access management service handling authentication and authorization, not email content inspection or DLP policy enforcement.

322
MCQeasy

A user needs to co-author a Word document stored in Microsoft SharePoint Online with external partners who do not have Microsoft 365 licenses. What must the administrator enable?

A.External sharing in SharePoint Online
B.Azure AD B2B collaboration
C.Anonymous access links for documents
D.Guest access in Microsoft Teams
AnswerA

External sharing in SharePoint Online is the correct mechanism because it allows sharing a Word document stored in a SharePoint site or OneDrive with authenticated external users. By configuring the sharing settings to grant edit permissions, external users can open the document in the Office desktop, web, or mobile apps and co-author in real time. This feature specifically applies to document-level collaboration in SharePoint, making it the direct and appropriate solution.

Why this answer

External sharing in SharePoint Online must be enabled at the tenant or site level to allow users to share documents with external partners who lack Microsoft 365 licenses. This setting controls the ability to send sharing invitations or generate shareable links for people outside the organization, which is the prerequisite for co-authoring with unlicensed external users.

Exam trap

The trap here is that candidates confuse Azure AD B2B collaboration as a separate setting that must be enabled, when in fact it is automatically activated once SharePoint external sharing is turned on, making the direct answer the SharePoint-level sharing configuration.

How to eliminate wrong answers

Option B is wrong because Azure AD B2B collaboration is the underlying identity mechanism that SharePoint external sharing uses, but it is not a setting an administrator must explicitly enable for this scenario—it is automatically available when external sharing is turned on. Option C is wrong because anonymous access links allow anyone with the link to view or edit the document without authentication, which is not the same as co-authoring with specific named external partners who need to sign in with a Microsoft account or one-time passcode. Option D is wrong because guest access in Microsoft Teams is a separate feature for inviting external users to Teams channels and chats, not for co-authoring a Word document stored in SharePoint Online.

323
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to compare Business Premium with Business Standard at a high level. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Business Premium adds advanced security and management capabilities
D.Microsoft Forms
AnswerC

Microsoft 365 Business Premium is a subscription bundle that layers Microsoft Entra ID P1, Intune, Microsoft Defender for Business, and Purview-based compliance features on top of Microsoft 365 business apps. These additional services give administrators advanced security and management capabilities such as Conditional Access, mobile device management, and automated threat protection. Choosing Business Premium directly fulfills the adoption plan's requirement to secure user identities, devices, and data rather than just providing a single collaboration app.

Why this answer

The primary differentiator between Microsoft 365 Business Premium and Business Standard is that Business Premium includes advanced security and management capabilities such as Microsoft Defender for Business, Azure Information Protection (AIP), and Intune for mobile device management (MDM). These features are not available in Business Standard, which focuses on productivity apps and cloud services without the same level of security and compliance controls.

Exam trap

The trap here is that candidates may focus on specific apps like Whiteboard or Stream, which are common across both plans, instead of recognizing that the core licensing differentiator is the inclusion of advanced security and management features in Business Premium.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaborative digital canvas included in both Business Premium and Business Standard, so it does not represent a high-level licensing difference. Option B is wrong because Microsoft Stream (for video sharing) is also available in both plans, with no advanced security or management distinction at the licensing level. Option D is wrong because Microsoft Forms is a survey and quiz tool included in both Business Premium and Business Standard, making it irrelevant to the comparison of advanced capabilities.

324
MCQhard

Your organization has Microsoft 365 E5 licenses. You want to ensure that users can access sensitive data only from compliant devices. Which Microsoft 365 service should you use?

A.Microsoft Entra ID
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview
D.Microsoft Intune
AnswerD

Microsoft Intune is the correct choice because it is the mobile device management (MDM) service in Microsoft 365 E5 that directly creates and manages device compliance policies. In Intune, you define conditions like operating system version thresholds, device health attestation, BitLocker or FileVault encryption status, and threat levels reported by Defender for Endpoint. These policies generate a compliance state that Entra ID uses in Conditional Access to allow or block access, but Intune is the component that actually builds and maintains those policies.

Why this answer

Microsoft Intune is the correct answer because it provides mobile device management (MDM) and mobile application management (MAM) capabilities that enforce compliance policies on devices before granting access to sensitive data. With Intune, you can define conditional access policies that require devices to be compliant (e.g., encrypted, jailbreak-detected, or running a minimum OS version) and then integrate with Microsoft Entra ID to block non-compliant devices from accessing corporate resources. This directly addresses the requirement to ensure users can access sensitive data only from compliant devices.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID's conditional access with device compliance enforcement, not realizing that Entra ID requires Intune to supply the device compliance status, making Intune the core service for device management.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is an identity and access management service that handles authentication and authorization, but it does not enforce device compliance policies on its own; it relies on Intune to provide device compliance signals for conditional access. Option B is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on discovering and controlling cloud app usage, detecting threats, and protecting data in transit, but it does not manage device compliance or enforce device-level access policies. Option C is wrong because Microsoft Purview is a data governance, risk, and compliance solution that provides data classification, labeling, and eDiscovery, but it does not manage device compliance or enforce device-based access controls.

325
MCQeasy

A small business with 10 employees wants to use professional email with custom domain, web versions of Office apps, and 1 TB of cloud storage per user. Which Microsoft 365 plan meets these requirements?

A.Microsoft 365 Apps for Business
B.Microsoft 365 E3
C.Microsoft 365 Business Standard
D.Microsoft 365 Business Basic
AnswerD

Microsoft 365 Business Basic is the correct choice because it includes Exchange Online for professional email on a custom domain, Microsoft Teams, SharePoint, and web-based Office apps, plus 1 TB of OneDrive storage per user. This plan meets the small business's stated need for professional communication and collaboration at a lower per-user price than plans with desktop applications. The absence of desktop Office apps is acceptable because the situation calls for cloud-based productivity rather than locally installed software.

Why this answer

Microsoft 365 Business Basic provides professional email with a custom domain (Exchange Online), web versions of Office apps (Office for the web), and 1 TB of cloud storage per user (OneDrive for Business). This plan is designed for small businesses needing core productivity and communication tools at a lower cost, without desktop Office installations.

Exam trap

The trap here is that candidates often confuse Business Basic with Business Standard, assuming desktop Office apps are required for professional email, when Business Basic fully meets the stated needs with web-only Office apps and custom domain email.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Apps for Business includes only desktop and web versions of Office apps with 1 TB OneDrive storage, but it does not include Exchange Online for custom domain email. Option B is wrong because Microsoft 365 E3 is an enterprise plan with advanced security and compliance features, far exceeding the requirements and budget of a 10-employee small business. Option C is wrong because Microsoft 365 Business Standard includes desktop Office apps in addition to the required features, making it more expensive than necessary for a business that only needs web versions of Office apps.

326
MCQmedium

A project manager needs to create a visual timeline of project tasks, dependencies, and milestones to share with stakeholders. The timeline should be embedded in the project team's SharePoint site. Which Microsoft 365 app should they use?

A.Microsoft Planner
B.Microsoft Project for the web
C.Microsoft To Do
D.Microsoft Lists
AnswerB

Project for the web is the Microsoft 365 solution that provides a true interactive timeline (Gantt) view of tasks, where you can set predecessor/successor dependencies and milestones, and it calcs scheduling automatically. It is cloud-based and can be embedded in a SharePoint page for broader visibility, making it the only listed tool that fulfills the requirement of visualizing task dependencies over time.

Why this answer

Microsoft Project for the web is the correct choice because it is designed specifically for creating Gantt charts that visualize project tasks, dependencies, and milestones over a timeline. It integrates directly with SharePoint, allowing the timeline to be embedded as a web part on a team site for stakeholder viewing.

Exam trap

The trap here is that candidates confuse Planner's 'Board view' and 'Charts' (which show simple bar charts) with a true Gantt timeline, but Planner cannot display task dependencies or milestones in a timeline format.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner provides a Kanban-style board for task assignment and tracking, but it lacks a timeline view with dependency lines and milestone markers. Option C is wrong because Microsoft To Do is a personal task management app focused on individual to-do lists, not project-level timelines or dependencies. Option D is wrong because Microsoft Lists is a data-tracking app for creating custom lists (e.g., issue trackers), but it does not natively support Gantt chart timelines or dependency visualization.

327
MCQhard

A charitable organization with 50 employees wants to use Microsoft 365 for business‑grade email, calendar, and online versions of Office apps. Their budget is extremely limited. What should they do first to obtain licenses at a reduced cost?

A.Purchase Microsoft 365 Business Basic licenses through a volume licensing program
B.Apply for Microsoft 365 Nonprofit eligibility and then purchase discounted or donated plans
C.Use free consumer accounts like Outlook.com and Office Online
D.Sign up for a Microsoft 365 Business Premium trial and rely on extensions
AnswerB

The correct approach is to first validate the charity’s nonprofit status through Microsoft’s eligibility process, which accepts recognized nonprofit entities and then permits enrollment in the Microsoft 365 Nonprofit program. Once approved, the organization can receive donated Microsoft 365 Business Basic licenses or purchase discounted plans such as Microsoft 365 Business Premium or Enterprise at significantly reduced prices. This transforms a budget-limited 50-person charity from paying full retail into obtaining a professional, business-grade collaboration platform for minimal or no cost.

Why this answer

Microsoft offers discounted and donated plans specifically for eligible nonprofit organizations. By first applying for Microsoft 365 Nonprofit eligibility, the charitable organization can access Business Basic licenses at a significantly reduced cost or even receive donated subscriptions, aligning with their extremely limited budget while still obtaining business-grade email, calendar, and online Office apps.

Exam trap

The trap here is that candidates may assume volume licensing (Option A) is the standard way to get discounts, failing to recognize that Microsoft has a separate, more generous discount program specifically for nonprofits that must be applied for first.

How to eliminate wrong answers

Option A is wrong because volume licensing programs do not inherently provide the deep discounts or donated plans available to nonprofits; they are designed for commercial organizations and would not address the charitable organization's need for reduced cost. Option C is wrong because free consumer accounts (Outlook.com, Office Online) lack business-grade features such as custom domain email, centralized administration, and compliance capabilities required for a professional organization. Option D is wrong because a Business Premium trial is time-limited and does not provide a long-term, cost-effective solution; relying on extensions would violate Microsoft's licensing terms and does not offer the discounted pricing available through nonprofit eligibility.

328
MCQhard

A financial services company must prevent users from accidentally sharing sensitive customer data externally. They want to block sharing of any document containing a credit card number via email or SharePoint. What combination of Microsoft 365 compliance solutions should they use?

A.Sensitivity labels and Microsoft Purview Information Protection (Microsoft Purview Information Protection)
B.Data Loss Prevention (DLP) policies
C.Microsoft Purview Compliance Manager
D.Exchange Online Protection (EOP) and Microsoft Defender for Microsoft 365
AnswerB

DLP policies inspect content in Exchange email and SharePoint, detecting credit card numbers via sensitive information types and blocking external sharing. This directly satisfies the requirement to prevent accidental external disclosure of documents containing card numbers across both channels.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and block the sharing of sensitive information, such as credit card numbers, across email (Exchange Online) and SharePoint. By scanning content for predefined sensitive info types (e.g., credit card numbers using regex patterns from the DLP engine), DLP can automatically block or warn users before external sharing occurs, meeting the company's requirement.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data at rest) with DLP (which monitors and blocks data in motion), leading them to choose Option A, even though DLP is the correct solution for preventing accidental external sharing of sensitive content like credit card numbers.

How to eliminate wrong answers

Option A is wrong because sensitivity labels and Microsoft Purview Information Protection focus on classifying and protecting data through encryption and access controls, but they do not natively scan content in transit or block sharing based on sensitive data patterns like credit card numbers; DLP is required for that detection and enforcement. Option C is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance management tool that provides a score and recommendations for regulatory frameworks (e.g., GDPR, HIPAA), but it does not actively scan or block data sharing. Option D is wrong because Exchange Online Protection (EOP) provides anti-spam and anti-malware protection for email, and Microsoft Defender for Office 365 adds advanced threat protection (e.g., phishing, safe attachments), but neither includes the content-based sensitive data detection and blocking capabilities of DLP.

329
MCQmedium

A development team wants to deploy a custom web application. They choose a cloud service that provides the operating system, web server, and database management system. The team is responsible only for uploading and managing their application code. Which cloud service model does this represent?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerB

PaaS offers a fully managed hosting environment—covering the operating system, language runtime, web server, and database—so the development team deploys only their application code and artifacts, while the provider handles patching, load balancing, and health monitoring. Azure App Service is a prime example: the team controls the code, connection strings, and some configuration, but not the underlying infrastructure, so they can focus on the app. This directly matches the requirement of deploying a custom web application without managing infrastructure.

Why this answer

This scenario describes Platform as a Service (PaaS) because the cloud provider manages the underlying infrastructure—operating system, web server, and database management system—while the development team is responsible only for deploying and managing their custom application code. PaaS abstracts the platform layer, allowing developers to focus on code without worrying about OS patches, web server configuration, or database administration.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve deploying custom applications, but IaaS requires full control and management of the OS and middleware, whereas PaaS abstracts those layers away.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) would require the team to provision and manage the virtual machines, operating system, web server, and database software themselves, not just upload application code. Option C is wrong because Software as a Service (SaaS) delivers a fully functional application to end users over the internet, where the provider manages everything including the application code; the customer does not upload or manage custom code. Option D is wrong because Function as a Service (FaaS) is a serverless compute model where developers deploy individual functions that execute in response to events, not a full web application with a persistent web server and database management system.

330
MCQmedium

A manager wants to quickly create a survey to collect employee feedback on a new policy. The survey must automatically store responses in an Excel spreadsheet and trigger an email notification when a response is submitted. Which Microsoft 365 service should the manager use?

A.Microsoft Forms
B.Microsoft Lists
C.Microsoft Power Apps
D.Microsoft SharePoint
AnswerA

Microsoft Forms is the correct choice because it provides an out-of-the-box survey creation interface with ready-to-use question types, branching, and themes, enabling an employee feedback survey to be built in minutes. Responses are automatically collected into an Excel workbook for immediate analysis, and the built-in Power Automate integration allows you to trigger an email alert to a manager or HR whenever a new response is submitted, without writing any code.

Why this answer

Microsoft Forms is the correct choice because it is designed specifically for creating surveys and quizzes, and it natively integrates with Excel to automatically store responses in a spreadsheet. Additionally, Forms supports Power Automate flows out of the box, allowing you to trigger an email notification whenever a new response is submitted, meeting both requirements without custom development.

Exam trap

The trap here is that candidates may confuse Microsoft Lists with Forms because both can collect data, but Lists is a structured data repository, not a survey tool, and lacks the automatic Excel storage and email trigger capabilities that Forms offers through its native Power Automate integration.

How to eliminate wrong answers

Option B is wrong because Microsoft Lists is a data-tracking application for organizing information in a list format, not a survey tool; it lacks built-in survey creation and does not automatically store responses in Excel or trigger email notifications on submission. Option C is wrong because Microsoft Power Apps is a low-code platform for building custom applications, which would require significant development effort to create a survey and integrate Excel storage and email triggers, making it overkill for this simple task. Option D is wrong because Microsoft SharePoint is a content management and collaboration platform; while it can host surveys via SharePoint lists or web parts, it does not automatically store responses in Excel or provide native email notification triggers without additional configuration or Power Automate flows.

331
MCQmedium

A marketing manager needs to provision a new virtual machine to run a temporary campaign analysis. They log into the cloud provider's web portal, select a VM size, configure settings, and start the VM within minutes—all without any human interaction with the provider's IT staff. Which essential characteristic of cloud computing does this scenario best illustrate?

A.Resource pooling
B.Rapid elasticity
C.On-demand self-service
D.Measured service
AnswerC

On-demand self-service is the NIST cloud characteristic where a user can provision compute capabilities, such as virtual machines, without requiring human interaction with the service provider. The marketing manager uses a web portal or API to create a VM for the project, receiving the resource immediately and independently. This exactly matches the described scenario: the user initiates and completes the provisioning themselves, making on-demand self-service the correct answer.

Why this answer

The scenario describes a user provisioning a virtual machine independently through a web portal without any human interaction with the provider's IT staff. This directly maps to the NIST-defined essential characteristic of on-demand self-service, where a consumer can unilaterally provision computing capabilities as needed automatically without requiring human interaction with each service provider.

Exam trap

The trap here is that candidates confuse 'rapid elasticity' with the speed of initial provisioning, but rapid elasticity specifically refers to the ability to automatically scale resources up or down in response to workload changes, not the one-time act of creating a resource without human help.

How to eliminate wrong answers

Option A is wrong because resource pooling refers to the provider's multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand, not the user's ability to provision resources without human intervention. Option B is wrong because rapid elasticity describes the ability to quickly scale resources up or down, often automatically, to meet demand; the scenario focuses on the initial provisioning action, not scaling behavior. Option D is wrong because measured service involves metering and reporting resource usage for billing and optimization (e.g., pay-per-use), which is not illustrated by the act of provisioning a VM without IT staff involvement.

332
MCQmedium

A compliance team needs to ensure that any email sent from the Finance department that contains a bank account number is automatically encrypted. External recipients must be able to reply securely without needing to sign up for any service. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Message Encryption
C.Microsoft Purview Information Protection (sensitivity labels)
D.Microsoft Defender for Office 365
AnswerB

Microsoft Purview Message Encryption is the actual email encryption service that protects message content in transit and at rest. It is the underlying technology invoked when a DLP policy detects sensitive data, and it enables sending encrypted emails to any recipient, including external users without Microsoft Entra ID accounts, via a secure web experience. Additionally, it supports secure reply without requiring the recipient to sign up for an account, making it the correct answer for automatic email encryption.

Why this answer

Microsoft Purview Message Encryption (B) is the correct solution because it allows the organization to automatically encrypt emails based on conditions (e.g., emails from Finance containing bank account numbers) and enables external recipients to reply securely using the encrypted reply portal without requiring any sign-up or additional software. This is achieved through Azure Rights Management (Azure RMS) and the Office 365 Message Encryption (OME) portal, which provides a seamless, browser-based experience for external users.

Exam trap

The trap here is that candidates often confuse the automatic encryption trigger in DLP policies with the actual encryption mechanism, forgetting that DLP alone cannot encrypt emails or provide the secure reply portal—those capabilities require Message Encryption (OME) to be configured as the action.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention (DLP) can detect sensitive data like bank account numbers and trigger actions such as blocking or warning, but it does not natively provide automatic encryption of emails with a secure reply mechanism for external recipients; DLP policies can integrate with Message Encryption, but the encryption itself is not a DLP feature. Option C is wrong because Microsoft Purview Information Protection (sensitivity labels) can apply encryption to emails and documents, but they require the recipient to have a Microsoft 365 account or use the Azure RMS client, and they do not offer the built-in, no-sign-up secure reply portal that Message Encryption provides for external users. Option D is wrong because Microsoft Defender for Office 365 focuses on threat protection (anti-phishing, anti-malware, safe attachments/links) and does not include native email encryption or secure reply capabilities for external recipients.

333
MCQhard

Refer to the exhibit. A device management report from Microsoft Intune shows a device with non-compliant status. Which action should the administrator take to bring the device into compliance?

A.Enable BitLocker encryption
B.Force a check-in
C.Remediate jailbreak status
D.Install antivirus software
AnswerA

BitLocker Device Encryption is a required compliance setting in Microsoft Intune for Windows devices. The report shows the device as not encrypted, so enabling BitLocker directly addresses this specific noncompliance by invoking the full volume encryption process, which is often a prerequisite for conditional access policies.

Why this answer

The device is marked non-compliant because Intune's compliance policy requires BitLocker encryption on Windows devices. Enabling BitLocker satisfies that policy requirement, allowing the device to report as compliant on its next check-in.

Exam trap

The trap here is that candidates confuse a non-compliant status with a connectivity or agent issue, and choose 'Force a check-in' instead of addressing the specific missing configuration (BitLocker) that caused the non-compliance.

How to eliminate wrong answers

Option B is wrong because forcing a check-in only triggers a re-evaluation of the current state; it does not resolve the underlying missing encryption. Option C is wrong because jailbreak status applies to iOS/iPadOS devices, not Windows, and is unrelated to BitLocker compliance. Option D is wrong because antivirus software is a separate compliance setting (e.g., requiring Windows Defender or a third-party AV), but the exhibit specifically indicates a BitLocker encryption requirement, not an antivirus requirement.

334
MCQmedium

A project manager needs a digital notebook where team members can capture meeting notes, add ink drawings using a stylus, and share content in real time. The solution must integrate with Microsoft Teams and support tagging for easy search. Which Microsoft 365 app is best suited?

A.OneNote
B.Word Online
C.SharePoint Wiki
D.Microsoft Lists
AnswerA

OneNote is a dedicated digital notebook that combines native inking support with real-time co-authoring, hierarchical sections/pages, and tag-based organization. Its free-form canvas allows meeting attendees to sketch diagrams, annotate shared notes, and sync seamlessly across devices via OneDrive, making it the correct choice for collaborative note-taking with hand-drawn content.

Why this answer

OneNote is the best fit because it provides a digital notebook with support for ink drawings via stylus, real-time collaboration, and tagging for search. It integrates natively with Microsoft Teams through the OneNote tab, allowing team members to capture and share meeting notes directly within Teams channels.

Exam trap

The trap here is that candidates may confuse Word Online's co-authoring capabilities with OneNote's specialized notebook features, overlooking the specific requirements for ink drawings and tagging that are native to OneNote.

How to eliminate wrong answers

Option B (Word Online) is wrong because while it supports real-time co-authoring and basic drawing tools, it lacks a dedicated notebook structure for organizing meeting notes and does not support ink drawings with a stylus as seamlessly as OneNote. Option C (SharePoint Wiki) is wrong because it is a web-based wiki for static content, not a real-time collaborative notebook, and it does not support stylus input or tagging for search in the same way. Option D (Microsoft Lists) is wrong because it is designed for tracking and organizing data in list format, not for capturing freeform meeting notes with ink drawings or real-time sharing.

335
MCQeasy

A company is evaluating moving its on-premises infrastructure to a cloud environment. They want a service that provides virtual machines, storage, and networking capabilities while retaining full control over the operating system and applications. Which cloud service model best meets this requirement?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Private Cloud
AnswerC

IaaS offers virtualized compute, storage, and networking resources via services like Azure Virtual Machines, with the customer retaining control over the guest OS, applications, and middleware while the provider manages the physical datacenter. This service model supports a direct lift-and-shift migration of on-premises servers, including preservation of existing OS images and system configurations, with minimal re-architecture. Because the evaluation specifically targets moving infrastructure, IaaS is the correct choice as it gives the needed visibility and control over the entire computing stack.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources, including virtual machines, storage, and networking, over the internet. The customer retains full administrative control over the operating system, applications, and middleware, while the cloud provider manages the underlying physical hardware. This matches the requirement for full OS and application control.

Exam trap

The trap here is that candidates often confuse Private Cloud (a deployment model) with a service model, mistakenly thinking it inherently provides full OS control, when in fact the level of control depends on whether IaaS, PaaS, or SaaS is used within that private cloud.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) delivers fully managed applications accessed via a browser or client, where the customer has no control over the underlying OS or infrastructure. Option B is wrong because Platform as a Service (PaaS) abstracts the OS and runtime environment, allowing the customer to deploy only custom applications without managing the OS or virtual machines. Option D is wrong because Private Cloud is a deployment model (not a service model) that can use any service model (IaaS, PaaS, SaaS) and does not inherently guarantee full OS control unless specifically implemented as IaaS.

336
MCQhard

A multinational organization with 5,000 users is licensed with Microsoft 365 E3. They need to comply with a regulation that requires retaining all Exchange Online mailbox content for 7 years and providing advanced eDiscovery capabilities (including predictive coding) to search through that data. Which Microsoft 365 add-on license should they purchase to meet these requirements most cost-effectively?

A.Microsoft 365 E5 Compliance add-on
B.Exchange Online Archiving for Exchange Online Plan 2
C.Microsoft 365 E5 (full suite upgrade)
D.Microsoft Purview Audit (Standard) add-on
AnswerA

Microsoft 365 E5 Compliance is an add-on license that can be stacked on an existing E3, E5, or certain other Microsoft 365 plans to enable advanced eDiscovery features such as predictive coding, review sets, and exports, along with legal hold, communication compliance, information barriers, and granular retention labels/policies. This directly addresses the requirement to search and preserve content across Exchange, SharePoint, OneDrive, and Teams for litigation. It delivers the necessary compliance tools without the cost of a full suite upgrade, making it the most precise and cost-effective licensing choice.

Why this answer

Microsoft 365 E5 Compliance add-on provides the required 7-year retention via retention policies and advanced eDiscovery (including predictive coding) without upgrading the entire E3 suite. This add-on is the most cost-effective way to meet regulatory retention and advanced search needs while keeping the existing E3 licensing.

Exam trap

The trap here is that candidates often confuse the basic archiving or audit capabilities (Options B and D) with the advanced eDiscovery and retention features that require the E5 Compliance add-on, or they mistakenly think a full E5 suite upgrade is necessary when a targeted add-on is more cost-effective.

How to eliminate wrong answers

Option B is wrong because Exchange Online Archiving for Exchange Online Plan 2 only adds unlimited archiving and basic retention, not advanced eDiscovery features like predictive coding. Option C is wrong because upgrading to the full Microsoft 365 E5 suite includes many unnecessary services (e.g., advanced security, analytics) at a higher cost, making it less cost-effective than the targeted E5 Compliance add-on. Option D is wrong because Microsoft Purview Audit (Standard) provides only basic audit log search and retention (90 days), lacking the 7-year retention and predictive coding capabilities required.

337
MCQmedium

A compliance officer at Fabrikam needs to ensure that all Microsoft 365 data is retained for exactly 7 years and then permanently deleted, regardless of user actions. Which Microsoft 365 capability should the officer use?

A.Litigation Hold in Exchange Online
B.Retention policies in Microsoft Purview
C.Microsoft 365 Backup
D.Data Loss Prevention policies in Microsoft Purview
AnswerB

Retention policies in Microsoft Purview allow organizations to retain or delete content across Microsoft 365 workloads based on a specified duration. They can be applied to Exchange Online, SharePoint Online, OneDrive, Teams, and more. This capability ensures data is kept for the required period and then permanently deleted, meeting the compliance requirement.

Why this answer

Retention policies in Microsoft Purview are specifically designed to manage the lifecycle of content across Microsoft 365 services. They can retain content for a defined period and then delete it, ensuring compliance with regulations that require both retention and eventual disposal. This makes retention policies the correct tool for the stated requirement.

Exam trap

The trap here is assuming that any hold or retention feature will automatically delete data after a period, when many holds only preserve data indefinitely.

338
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to avoid giving every IT staff member Global Administrator. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Assign specific admin roles based on job responsibility
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Role-based access control grants each IT staff member only the permissions their duties require, such as Exchange Administrator or Helpdesk Administrator. This scoped assignment satisfies the constraint of avoiding Global Administrator for everyone, applying least privilege across Microsoft 365 admin roles.

Why this answer

The question asks which concept is most relevant when a service owner needs to avoid giving every IT staff member Global Administrator access. Assigning specific admin roles based on job responsibility (Option B) directly addresses this by following the principle of least privilege, allowing granular control over Microsoft 365 administrative tasks without granting full, unrestricted access. This is a core identity and access management concept tied to Microsoft 365 licensing and administration.

Exam trap

The trap here is that candidates may confuse productivity tools (Whiteboard, Forms, Stream) with administrative concepts, failing to recognize that the core issue is about role-based access control and licensing, not feature functionality.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration tool for visual brainstorming, not an admin role or licensing concept that controls administrative permissions. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to administrative role assignment or access control. Option D is wrong because Microsoft Stream is a video hosting and sharing service, with no relevance to assigning admin roles or managing administrative privileges.

339
Multi-Selectmedium

Which TWO components are part of Microsoft's Service Trust Portal?

Select 2 answers
A.Audit reports and compliance guides
B.Azure portal
C.Compliance Manager
D.Microsoft Purview compliance portal
E.Microsoft 365 Defender portal
AnswersA, C

The Service Trust Portal (STP) is Microsoft's central web repository for trust-related documentation, including independent audit reports such as SOC 1/2/3 and ISO 27001 certificates, as well as compliance guides that map Microsoft cloud services to specific regulatory requirements. Customers rely on these artifacts to perform their own due diligence and to evidence Microsoft's operational controls during external audits, directly supporting the shared responsibility model. The portal also offers a searchable document library with version history, making these two elements foundational to the STP's purpose.

Why this answer

Options A and C are correct. The Service Trust Portal provides compliance reports, audit reports, and trust documents. Options B, D, and E are not part of the Service Trust Portal; they are separate portals.

340
MCQeasy

A user needs to create a form to collect feedback from customers. The responses should be automatically stored in an Excel spreadsheet in OneDrive. Which Microsoft 365 app should they use?

A.Microsoft Lists
B.Microsoft Forms
C.Microsoft Power Apps
D.Microsoft Sway
AnswerB

Microsoft Forms is the correct tool because it is a purpose-built survey and quiz service within Microsoft 365, designed specifically for creating feedback forms with multiple question types, branching logic, and anonymous response settings. When users submit responses, Forms automatically compiles them into an Excel workbook, enabling easy analysis and visualization without requiring additional customization. Its straightforward workflow — create, distribute, collect, and export — directly matches the stated need to collect feedback from customers.

Why this answer

Microsoft Forms is the correct app because it is specifically designed for creating surveys, quizzes, and feedback forms, and it natively integrates with Excel to automatically store responses in a spreadsheet hosted on OneDrive. This meets the user's requirement without additional configuration or custom development.

Exam trap

The trap here is that candidates may confuse Microsoft Lists with Forms because both can collect data, but Lists requires manual setup for Excel export and lacks the automatic, one-click response-to-Excel workflow that Forms provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a tracking and organization app for managing data in list format (e.g., issue tracking, inventory), not for creating forms with automatic Excel storage. Option C is wrong because Microsoft Power Apps is a low-code platform for building custom business applications, which is overkill and not the intended tool for simple form creation and Excel integration. Option D is wrong because Microsoft Sway is a presentation and storytelling app for creating interactive reports and newsletters, not for collecting form responses or storing them in Excel.

341
Multi-Selectmedium

A security team wants Microsoft 365 access to be allowed only when a user's device is marked compliant by management policy. Which two capabilities are normally combined? (Choose two.)

Select 2 answers
A.Microsoft Stream
B.Microsoft Intune compliance policies
C.Microsoft Forms
D.Conditional Access
AnswersB, D

Microsoft Intune compliance policies define the actual hardware and software requirements that devices must meet—such as OS version, encryption, jailbreak/root status, and threat level—before they are considered compliant. These policies evaluate each enrolled device and assign a compliance state that downstream access controls can consume. This is the component that establishes what 'allowed only' means in terms of device health, making it the right answer.

Why this answer

Microsoft Intune compliance policies define the rules that a device must meet (e.g., encryption, OS version, threat level) to be considered compliant. Conditional Access enforces access decisions based on signals like device compliance status, blocking or granting access to Microsoft 365 services. Together, they ensure only compliant devices can access corporate resources.

Exam trap

The trap here is that candidates often confuse Microsoft Intune compliance policies with device management enrollment, forgetting that Conditional Access is the enforcement engine that actually gates access based on the compliance signal.

342
MCQeasy

A project manager needs to create a shared workspace for a cross-functional team to manage tasks, share files, track deadlines, and have threaded conversations. Which Microsoft 365 app should be the primary platform for this workspace?

A.Microsoft SharePoint
B.Microsoft Teams
C.Microsoft Planner
D.Microsoft To Do
AnswerB

Microsoft Teams is designed specifically as a shared workspace, offering persistent channels with threaded conversations, native file sharing and co-authoring via the SharePoint-backed Files tab, and integration of Planner tasks through the Tasks by Planner and To Do app. This convergence of chat, files, meetings, and tasks within a single interface makes it the ideal hub for a cross-functional team. Additionally, Teams supports multiple channels for distinct workstreams, ensuring that communication and collaboration are contextual and organized, which is exactly what dynamic team environments need.

Why this answer

Microsoft Teams is the correct primary platform because it integrates chat, threaded conversations, file sharing, task management (via integrated Planner or Tasks by Planner and To Do), and deadline tracking into a single shared workspace. Unlike SharePoint, which is a document management and intranet platform, Teams provides a real-time collaboration hub with persistent threaded conversations and direct task assignment capabilities, making it ideal for cross-functional team coordination.

Exam trap

The trap here is that candidates often confuse SharePoint as the primary collaboration workspace because it is a powerful content management platform, but the question specifically requires threaded conversations and real-time task management, which are native to Teams, not SharePoint.

How to eliminate wrong answers

Option A is wrong because Microsoft SharePoint is a document management and intranet portal platform focused on content storage, version control, and site-based collaboration, not a real-time workspace with threaded conversations and integrated task management. Option C is wrong because Microsoft Planner is a lightweight task management tool that provides Kanban boards and task assignments but lacks native threaded conversations, file sharing, and a persistent chat workspace. Option D is wrong because Microsoft To Do is a personal task management app designed for individual productivity and list-based task tracking, not for team collaboration, shared workspaces, or threaded conversations.

343
MCQmedium

Your company uses Microsoft 365 and wants to ensure that when employees access Microsoft 365 from unmanaged devices, they can only view data but not download or print it. Which technology should you use?

A.Microsoft Intune compliance policies
B.Microsoft Entra Conditional Access with session controls
C.Sensitivity labels with encryption
D.Microsoft Purview Data Loss Prevention (DLP) policies
AnswerB

Conditional Access with session controls applies Cloud App Security policies that restrict unmanaged devices to view-only access, blocking download and print. This satisfies the stem's constraint of allowing viewing while preventing data exfiltration from unmanaged endpoints.

Why this answer

Microsoft Entra Conditional Access with session controls allows you to restrict access from unmanaged devices to view-only mode, preventing download or print. Session controls like 'Use app enforced restrictions' or 'Use Conditional Access App Control' (with Microsoft Cloud App Security) can enforce limited access. This meets the requirement of allowing view but blocking download/print.

Exam trap

MS-900 often tests the difference between data protection technologies, and candidates may confuse DLP or sensitivity labels with session controls, not realizing that only Conditional Access session controls can enforce view-only in real-time for unmanaged devices.

How to eliminate wrong answers

Option A is wrong because Intune compliance policies determine device compliance but do not directly control session actions like download/print; they can be used in Conditional Access to block access, but not to allow view-only. Option C is wrong because sensitivity labels with encryption protect data at rest and in transit, but they do not prevent download/print from unmanaged devices in real-time. Option D is wrong because DLP policies can block sharing or printing, but they are not as granular for unmanaged device access and typically apply to data at rest or in motion, not session control.

344
MCQmedium

During a Microsoft 365 planning workshop, let users reset forgotten passwords without calling the help desk. Microsoft security, identity, or compliance capability should it use?

A.Self-service password reset (SSPR)
B.Microsoft Planner
C.Microsoft Stream
D.Microsoft Forms
AnswerA

Self-service password reset (SSPR) is an Azure Active Directory feature that lets users verify their identity with methods such as phone, email, or the Microsoft Authenticator app, then reset their password without administrator involvement. It reduces helpdesk workload and strengthens security by enforcing multi-factor verification before password changes. In Microsoft 365, SSPR can be enabled for all users and integrated with conditional access policies to require registration and secure resets.

Why this answer

Self-service password reset (SSPR) is the correct Microsoft 365 capability because it allows users to reset their own forgotten passwords without requiring help desk intervention. SSPR is part of Microsoft Entra ID (formerly Azure Active Directory) and enforces security through multi-factor authentication verification before allowing a password change. This directly addresses the requirement to reduce help desk calls while maintaining identity security.

Exam trap

The trap here is that candidates confuse productivity tools (Planner, Stream, Forms) with security capabilities, assuming any Microsoft 365 service can handle identity tasks, when only Entra ID-based features like SSPR are designed for password management.

How to eliminate wrong answers

Option B (Microsoft Planner) is wrong because it is a task management and project planning tool, not an identity or security feature; it cannot reset passwords. Option C (Microsoft Stream) is wrong because it is a video sharing and management platform, unrelated to authentication or password operations. Option D (Microsoft Forms) is wrong because it is a survey and data collection tool, with no capability to modify user passwords or manage identity.

345
MCQmedium

A sales team needs to track leads, manage customer contact information, record interactions, and automate follow-up email sequences. Which Microsoft 365 app should they use as the primary platform?

A.Microsoft Dynamics 365 Sales
B.Microsoft Power Automate
C.Microsoft SharePoint
D.Microsoft Teams
AnswerA

Microsoft Dynamics 365 Sales is the dedicated customer relationship management (CRM) solution for sales teams, built on the Microsoft Dataverse. It includes native lead and opportunity entities, configurable business process flows, activity tracking, and embedded email integration so salespeople can log every customer interaction and move deals through defined pipelines. Because it is a model-driven app, you get built-in security roles, relationship hierarchies, and a reporting layer specifically tailored to sales metrics, making it the correct choice for managing leads and customer contact information.

Why this answer

Microsoft Dynamics 365 Sales is a customer relationship management (CRM) application specifically designed to manage leads, track customer contact information, record interactions, and automate sales processes such as follow-up email sequences. It provides built-in lead scoring, opportunity management, and workflow automation that directly match the sales team's requirements, making it the correct primary platform.

Exam trap

The trap here is that candidates often confuse Microsoft Power Automate as the primary tool for automation, overlooking that Dynamics 365 Sales provides the CRM foundation needed to manage leads and contacts, while Power Automate is only an add-on for extending workflows.

How to eliminate wrong answers

Option B is wrong because Microsoft Power Automate is a workflow automation tool that can create flows to trigger actions, but it is not a primary platform for managing leads, contacts, or interactions; it lacks native CRM data models and lead management features. Option C is wrong because Microsoft SharePoint is a document management and collaboration platform focused on content storage, sharing, and intranet sites, not designed for tracking sales leads or automating email sequences. Option D is wrong because Microsoft Teams is a chat-based collaboration workspace for real-time communication and meetings, not a CRM system capable of managing customer relationships or automating sales workflows.

346
MCQeasy

A small law firm uses Microsoft 365 Business Premium. The partners want to ensure that all confidential client documents stored in SharePoint Online are protected with encryption at rest and that they can classify and label documents to restrict access. Which Microsoft 365 feature should they use?

A.Exchange Online transport rules
B.Microsoft Purview Information Protection sensitivity labels
C.Microsoft Defender for Office 365 safe attachments
D.SharePoint Online site-level permissions
AnswerB

Sensitivity labels in Microsoft Purview Information Protection allow organizations to classify and protect documents and emails by applying encryption, access restrictions, and visual markings. In SharePoint Online, labels can enforce encryption at rest and control who can access content. This directly meets the law firm's need to classify and label confidential documents to restrict access while ensuring encryption.

Why this answer

Microsoft Purview Information Protection sensitivity labels are the correct choice because they enable classification, labeling, and encryption of documents in SharePoint Online, ensuring confidential client files are protected and access is restricted. Site permissions, Safe Attachments, and transport rules do not provide document-level classification and encryption.

Exam trap

The trap here is assuming that SharePoint permissions alone provide document encryption and classification, when they only control site access and do not label or encrypt individual files.

347
Multi-Selecteasy

Which TWO are features of Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Mobile device management
B.Identity and access management
C.Data Loss Prevention policies
D.Multi-Factor Authentication
E.Sensitivity labels
AnswersB, D

Identity and access management is a core Microsoft Entra ID capability, providing authentication, authorisation, and conditional access for users and applications. It satisfies the requirement by governing who can access which resources across cloud and on-premises environments.

Why this answer

Option B (Identity and access management) is correct because Microsoft Entra ID is Microsoft's cloud-based identity provider, delivering authentication, authorization, SSO, conditional access, and directory services for users, groups, and applications. Option D (Multi-Factor Authentication) is correct because Entra ID natively provides Microsoft Entra multifactor authentication, requiring a second verification factor such as the Microsoft Authenticator app, SMS, or a FIDO2 key during sign-in. Option A (Mobile device management) does not belong because MDM is delivered by Microsoft Intune, not Entra ID, even though Intune integrates with Entra ID for identity.

Option C (Data Loss Prevention policies) does not belong because DLP is a Microsoft Purview compliance capability that protects sensitive data across Exchange, SharePoint, and endpoints. Option E (Sensitivity labels) does not belong because sensitivity labels are also a Microsoft Purview Information Protection feature used to classify and protect content, not an Entra ID identity feature.

Exam trap

MS-900 often tests the confusion between identity features (Entra ID) and device/compliance features (Intune, Purview), so candidates must remember that MDM, DLP, and sensitivity labels belong to other Microsoft 365 services.

348
MCQmedium

Your organization is planning to migrate on-premises workloads to Microsoft 365. Which cloud deployment model describes using both on-premises infrastructure and Microsoft 365 services?

A.Private cloud
B.Community cloud
C.Public cloud
D.Hybrid cloud
AnswerD

Hybrid cloud combines on-premises infrastructure with public cloud services such as Microsoft 365, letting workloads span both environments. This directly satisfies the stem's requirement to keep on-premises systems while consuming Microsoft 365, unlike purely public or private models.

Why this answer

Hybrid cloud is the deployment model that combines on-premises infrastructure with public cloud services like Microsoft 365. This model allows organizations to keep some resources on-premises while leveraging cloud services for others, providing flexibility and integration.

Exam trap

MS-900 often tests the definition of hybrid cloud, and candidates may confuse it with multi-cloud or private cloud, but the key is the combination of on-premises and public cloud services.

How to eliminate wrong answers

Option A is wrong because private cloud is dedicated to a single organization and does not include public cloud services like Microsoft 365. Option B is wrong because community cloud is shared by several organizations with common interests, not a mix of on-premises and public cloud. Option C is wrong because public cloud is entirely off-premises and does not include on-premises infrastructure.

349
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to give external partners controlled access to Teams and SharePoint resources. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Entra External ID / B2B collaboration
B.Microsoft Stream
C.Microsoft Forms
D.Microsoft Planner
AnswerA

Microsoft Entra External ID, specifically B2B collaboration, offers a secure identity and access management framework for external guests or partners. It leverages Azure AD's conditional access, multi-factor authentication, and compliance policies to enforce controlled access to directory resources and applications. This directly addresses the requirement for governed external collaboration without duplicating user accounts, making it the correct choice for an adoption plan.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2B collaboration) is the correct capability because it enables organizations to securely share Teams and SharePoint resources with external partners by inviting them as guest users. This feature uses identity federation to allow partners to authenticate with their own credentials, while enforcing conditional access policies and compliance controls. It directly addresses the requirement for controlled, compliant external access without exposing internal directories or requiring additional licenses for partners.

Exam trap

The trap here is that candidates may confuse collaboration tools (Stream, Forms, Planner) with identity and access management capabilities, failing to recognize that only Microsoft Entra External ID (B2B collaboration) provides the necessary security and compliance controls for external partner access.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because it is a video management and sharing service, not an identity or access management tool; it cannot control external partner access to Teams or SharePoint. Option C (Microsoft Forms) is wrong because it is a survey and data collection tool, lacking any capability to manage external identities or access permissions. Option D (Microsoft Planner) is wrong because it is a task management and planning application, with no functionality for identity federation, guest user management, or access control to external partners.

350
MCQhard

A security administrator needs to audit all activities related to a specific user in Exchange Online, SharePoint Online, and Microsoft Entra ID for the past 90 days. They also need to export the audit log as a CSV file. Which Microsoft Purview solution provides this capability without additional licensing beyond Microsoft 365 E3?

A.Microsoft Purview Audit (Standard)
B.Microsoft Purview Audit (Premium)
C.Microsoft Purview eDiscovery (Standard)
D.Microsoft Purview Content Search
AnswerA

Microsoft Purview Audit (Standard) retains Exchange, SharePoint and Microsoft Entra ID activity for 90 days and supports CSV export of search results. It is included with Microsoft 365 E3, so no add-on licence is needed, satisfying the no-additional-licensing constraint.

Why this answer

Microsoft Purview Audit (Standard) is included with Microsoft 365 E3 and provides the ability to search and export audit logs for user activities across Exchange Online, SharePoint Online, and Microsoft Entra ID for up to 90 days. This meets the administrator's requirement without needing additional licensing.

Exam trap

The trap here is that candidates confuse 'auditing user activities' with 'searching for content' and pick Content Search or eDiscovery, not realizing that audit logs track actions (like 'User logged in' or 'Deleted file') while Content Search finds the actual data files.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit (Premium) offers extended retention (up to 1 year) and intelligent insights, but it requires an E5 or add-on license, not E3. Option C is wrong because Microsoft Purview eDiscovery (Standard) is designed for legal holds and case-based content searches, not for exporting a raw audit log of user activities as a CSV. Option D is wrong because Microsoft Purview Content Search is used to find and export content (emails, documents) from mailboxes and sites, not to audit administrative or user actions in the audit log.

351
MCQhard

Your company uses Microsoft 365 E5 and has enabled Microsoft Purview Audit (Premium). The security team needs to investigate a potential data breach by searching for all activities related to a specific user in the last 90 days. Which tool should they use?

A.Microsoft Purview Compliance Manager
B.Microsoft Purview Content Search
C.Microsoft Purview Audit (Premium) log search
D.Microsoft Purview eDiscovery (Premium)
AnswerC

Purview Audit (Premium) log search captures user and admin sign-in, file access, and configuration change events, offering a rich activity trail, but it is limited to audit log events and cannot hold or deep-search across all content locations like mailboxes and sites. For a comprehensive investigation that requires preserving evidence and analyzing responsive documents, eDiscovery Premium is the appropriate tool.

Why this answer

Microsoft Purview Audit (Premium) log search is the appropriate tool to search the unified audit log for activities performed by a specific user across Microsoft 365 services. Since the security team needs to find all user-related activities in the last 90 days, the audit log search (Option C) directly meets this requirement. eDiscovery (Premium) is designed for finding content (e.g., emails, documents) and for legal holds, not for searching user activity logs.

Exam trap

The trap is that candidates may assume eDiscovery (Premium) is the right choice for a breach investigation because it sounds comprehensive, but eDiscovery does not search audit logs for user actions. The audit log search is the tool specifically built for reviewing user and admin activities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance management tool that evaluates your organization's compliance posture against regulations, not a tool for searching user-specific activities or audit logs. Option B is wrong because Microsoft Purview Content Search is designed to search for content (e.g., emails, documents) across Microsoft 365 data sources, not to search for user activities or audit log entries. Option C is wrong because Microsoft Purview Audit (Premium) log search is used to search and export audit log records for general activities, but it lacks the advanced investigation features (e.g., deep case management, review sets, and advanced indexing) that eDiscovery (Premium) provides for a thorough breach investigation.

352
MCQeasy

In a Software as a Service (SaaS) model, which of the following responsibilities is typically handled by the cloud provider?

A.Managing user passwords and accounts
B.Patching the underlying operating system and application
C.Configuring application settings for the organization
D.Backing up customer data
AnswerB

For Microsoft 365, Microsoft handles patching the underlying Windows Server operating systems, the hypervisor/fabric, Exchange Online mailboxes, SharePoint servers, and Teams services because the customer never has administrative access to the VM or host OS. The provider applies security and feature updates on a continuous deployment schedule to maintain service availability and protection. This is exactly the kind of infrastructure maintenance that remains with the SaaS vendor, unlike tenant configuration or user administration.

Why this answer

In a SaaS model, the cloud provider is responsible for managing the underlying infrastructure, including patching the operating system and the application itself. This is a core tenet of the shared responsibility model, where the provider handles the security and maintenance of the software stack, while the customer is responsible for data and user access. For example, in Microsoft 365, Microsoft automatically applies security updates to Exchange Online and SharePoint without customer intervention.

Exam trap

The trap here is that candidates often confuse 'backing up customer data' (Option D) as a provider responsibility, but in SaaS, the provider ensures infrastructure redundancy, while the customer must configure and verify their own backup and recovery policies, such as using Microsoft 365 Backup or third-party tools.

How to eliminate wrong answers

Option A is wrong because managing user passwords and accounts is a customer responsibility, as the customer controls identity and access management (IAM) within their tenant, such as configuring Azure AD password policies or self-service password reset. Option C is wrong because configuring application settings for the organization, like setting up email retention policies or SharePoint site permissions, is performed by the customer's administrators, not the provider. Option D is wrong because while the provider may offer backup infrastructure, the customer is typically responsible for ensuring their data is backed up according to their own compliance needs; for instance, in Microsoft 365, customers must enable and manage retention policies and backup configurations.

353
MCQmedium

A company uses Microsoft 365 and wants to create a custom app to automate expense report approvals without writing code. Which service should they use?

A.SharePoint Designer
B.Azure Logic Apps
C.Power Automate
D.Power Apps
AnswerD

Power Apps is the correct answer because it is the Microsoft Power Platform's low-code application development service, purpose-built for creating custom business apps without extensive coding. It provides both canvas apps, which give designers pixel-level control over the user interface, and model-driven apps, which are built on Dataverse and automatically generate a responsive, data-centric UI. Power Apps integrates directly with Microsoft 365 data sources like SharePoint, Dynamics 365, and hundreds of other connectors, making it the ideal tool for organizations that need a custom app within the Microsoft ecosystem.

Why this answer

Power Apps is the correct choice because it enables users to build custom business applications with a low-code or no-code approach, integrating directly with Microsoft 365 data sources like SharePoint and Outlook. For automating expense report approvals, Power Apps can create a custom app that triggers approval workflows via Power Automate, all without writing traditional code.

Exam trap

The trap here is confusing Power Automate (which automates workflows) with Power Apps (which builds custom apps), as both are part of the Power Platform and often used together, but only Power Apps provides the user interface for a custom app.

How to eliminate wrong answers

Option A is wrong because SharePoint Designer is a legacy tool for customizing SharePoint workflows and forms, but it requires code-like actions and is deprecated for new development. Option B is wrong because Azure Logic Apps is a cloud-based integration service for automating workflows across enterprise systems, but it is more complex and code-oriented than needed for a simple no-code custom app. Option C is wrong because Power Automate is a workflow automation service that can handle approval processes, but it does not create custom apps with user interfaces; it focuses on automating flows between services.

354
MCQmedium

A sales manager wants to create a visual representation of the sales pipeline, including stages, deal values, and win probability. They want to share this interactive chart with the team via a web link that updates automatically from the underlying data in Microsoft Lists. Which Microsoft 365 app should they use?

A.Microsoft Power BI
B.Microsoft Excel
C.Microsoft Forms
D.Microsoft SharePoint
AnswerA

Power BI is the correct choice because it has a native Microsoft Lists connector that lets you ingest pipeline data directly into a data model, then build interactive dashboards with slicers, drill-throughs, and cross-filtering. Once published to the Power BI Service, the report is accessible via a secure web link, and a scheduled refresh can automatically pull updated list data without manual exports or file re-uploads.

Why this answer

Power BI is Microsoft's dedicated business intelligence and data visualization service, designed to build interactive dashboards and reports from data sources such as Microsoft Lists, Excel, and SharePoint. It supports automatic refresh schedules and can publish reports to a web link (Publish to web) that updates as the underlying data changes. This directly satisfies the sales manager's requirement for an interactive, auto-updating pipeline visualization.

Exam trap

MS-900 often tests the confusion between Excel's charting capabilities and Power BI's dedicated BI/auto-refresh features, tempting candidates to pick Excel for 'visualization' questions.

How to eliminate wrong answers

Option B is wrong because Excel can create charts and even publish to the web, but it is a spreadsheet application, not a dedicated BI tool, and its web-published charts do not refresh automatically from Microsoft Lists without manual republishing or Power BI integration. Option C is wrong because Microsoft Forms is a survey/quiz tool for collecting responses, not for visualizing or sharing data pipelines. Option D is wrong because SharePoint is a collaboration and document management platform; while it can host lists and embed web parts, it does not natively produce interactive, auto-refreshing BI visualizations of the kind described.

355
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to host custom applications on virtual machines while managing the operating system. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Infrastructure as a Service (IaaS)
C.Hybrid cloud
D.Software as a Service (SaaS)
AnswerB

Infrastructure as a Service (IaaS) is the correct answer because it provides virtualized compute resources—such as virtual machines, storage, and networking—while the customer retains responsibility for the operating system, its patches, and the applications deployed on top. This gives a service owner the flexibility to configure the environment like a traditional on-premises data center without purchasing physical hardware. In the Microsoft ecosystem, Azure virtual machines exemplify IaaS, and this model is distinct from PaaS and SaaS because the provider only manages the physical or virtual infrastructure layer, not the OS or application stack.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, including virtual machines where the user manages the operating system and can host custom applications. This matches the requirement because the service owner needs full control over the OS and the ability to deploy custom applications without managing physical hardware.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve hosting applications, but PaaS removes OS management responsibility, which is explicitly required in the question.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) abstracts the underlying infrastructure, including the operating system, so the user does not manage the OS or virtual machines; instead, they deploy applications to a managed runtime environment. Option C is wrong because Hybrid cloud is a deployment model that combines public and private clouds, not a service model that provides virtual machines with OS management. Option D is wrong because Software as a Service (SaaS) delivers fully managed applications accessed via a browser or client, with no user control over the underlying OS or virtual machines.

356
MCQhard

A financial services firm uses Microsoft 365 E5. Compliance officers must ensure that sensitive client data in Exchange Online, SharePoint Online, and OneDrive for Business is classified and protected consistently, and that documents are labeled with protection settings that travel with the file. Which Microsoft 365 service should they implement?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention
C.Microsoft Purview eDiscovery
D.Microsoft Defender for Office 365
AnswerA

Microsoft Purview Information Protection provides sensitivity labels and encryption that classify and protect data across Exchange Online, SharePoint Online, OneDrive, and Office apps. Labels can apply persistent protection that travels with the file, even when it is shared externally, which directly meets the compliance officers' requirement for consistent classification and protection of sensitive client data.

Why this answer

Microsoft Purview Information Protection delivers sensitivity labels and encryption that classify and protect content across Exchange Online, SharePoint Online, OneDrive, and Office apps, with protection that persists when files are shared. Data Loss Prevention, Defender for Office 365, and eDiscovery address blocking risky sharing, threat protection, and legal investigations respectively, but none provides the labeling and persistent protection the compliance officers need.

Exam trap

The trap here is assuming that any Microsoft Purview workload that mentions sensitive data, such as Data Loss Prevention, can classify and encrypt documents, when labeling and persistent protection are specifically the domain of Information Protection.

357
MCQmedium

A project manager wants to create a collaborative workspace that includes a shared calendar, a document library, and a task list. The workspace should be accessible from within Microsoft Teams and allow team members to discuss topics in a threaded conversation. Which Microsoft 365 service should they use as the foundation?

A.Microsoft Teams with a channel
B.SharePoint Team Site
C.Microsoft Planner
D.Microsoft Viva Engage Community
AnswerB

A SharePoint Team Site is the correct choice because it natively provides a shared calendar list, a document library, and task management capabilities in one place. This team site can be connected to Microsoft Teams for chat and meetings, but the calendar and files live in SharePoint, making it the actual collaboration workspace. It fully satisfies the requirement of a shared calendar without relying on external services.

Why this answer

A SharePoint Team Site provides the foundational structure for a collaborative workspace with a shared calendar, document library, and task list. It integrates natively with Microsoft Teams, allowing the workspace to be accessed via a Teams channel, and supports threaded conversations through the connected Teams channel or Yammer web parts. This makes it the correct choice for the described requirements.

Exam trap

The trap here is that candidates often confuse a Microsoft Teams channel (Option A) as the workspace itself, not realizing that the channel is merely a collaboration layer that depends on SharePoint for persistent storage and structured components like calendars and document libraries.

How to eliminate wrong answers

Option A is wrong because a Microsoft Teams channel is a communication interface within a team, not a standalone workspace; it relies on an underlying SharePoint site for document libraries, calendars, and task lists. Option C is wrong because Microsoft Planner is a task management tool that provides task lists and boards but lacks a shared calendar and document library, and it does not serve as a full collaborative workspace foundation. Option D is wrong because Microsoft Viva Engage Community is designed for broad organizational discussions and social networking, not for structured collaboration with a shared calendar, document library, and task list within a Teams channel.

358
MCQeasy

An administrator is reviewing a request from users who need to let users provision resources from a portal without provider interaction. Cloud concept or benefit best matches this requirement?

A.On-demand self-service
B.Data Loss Prevention (DLP)
C.Microsoft Planner
D.Sensitivity labels
AnswerA

On-demand self-service is a core NIST cloud characteristic where users can provision computing resources, such as virtual machines, storage, or Microsoft 365 workloads, automatically and without human interaction with the provider. In a Microsoft 365 context, this is why administrators can delegate resource creation to users through Azure Lighthouse, self-service groups, or dynamic membership rules. This capability directly supports the scenario of letting users provision what they need, making it the only correct answer.

Why this answer

The requirement describes users provisioning resources from a portal without provider interaction, which is the core definition of on-demand self-service as defined by NIST SP 800-145. In Microsoft 365, this maps to capabilities like users creating Teams, SharePoint sites, or Azure resources via self-service portals without IT intervention.

Exam trap

The trap here is that candidates confuse 'self-service' with any user-facing feature (like Planner or DLP policies), but the question specifically tests the NIST cloud characteristic of on-demand self-service, not a specific Microsoft tool.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) is a security policy feature that prevents sensitive data from being shared or leaked, not a provisioning mechanism. Option C is wrong because Microsoft Planner is a task management tool for organizing work, not a cloud concept for resource provisioning. Option D is wrong because sensitivity labels are classification and protection controls applied to data (e.g., encryption, marking), not a method for users to provision resources.

359
MCQmedium

A multinational organization wants a central hub for employee communication that includes company-wide announcements, topic-based communities, and the ability to integrate with SharePoint and Power BI dashboards. Which Microsoft 365 service is designed specifically for this purpose?

A.Microsoft Teams
B.Microsoft Viva Engage
C.SharePoint Online
D.Outlook
AnswerB

Microsoft Viva Engage is an enterprise social network that allows organizations to create company-wide announcements, topic-based communities, and integrate with other apps like SharePoint and Power BI. It is the intended service for broad employee communication.

Why this answer

Microsoft Viva Engage (formerly Yammer) is designed as a social networking and employee communication hub that provides company-wide announcements, topic-based communities, and seamless integration with SharePoint and Power BI dashboards. It focuses on fostering open communication across the organization, unlike collaboration tools that are team-centric.

Exam trap

The trap here is that candidates often confuse Microsoft Teams' 'general' channel or SharePoint's news web part with a true company-wide social hub, but Viva Engage is the only service purpose-built for open, topic-based communities and organization-wide announcements with native integration to SharePoint and Power BI.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is primarily a chat-based collaboration workspace for teams and channels, not a central hub for company-wide announcements and topic-based communities; it lacks the enterprise social network features like broadcast announcements to the entire organization. Option C is wrong because SharePoint Online is a document management and intranet platform that can host announcements and dashboards but is not specifically designed as a social communication hub with topic-based communities and company-wide feeds. Option D is wrong because Outlook is an email and calendar client, not a platform for topic-based communities or integrated social networking; it cannot replace the community-driven, announcement-focused functionality of Viva Engage.

360
MCQeasy

A public relations team needs to create an interactive, visually rich newsletter that includes embedded video and dynamic content from a SharePoint list. Which app should they use?

A.Sway
B.PowerPoint
C.SharePoint News
D.Microsoft Stream
AnswerA

Sway's card-based, responsive canvas is purpose-built for interactive digital storytelling; it automatically rearranges text, images, and embedded video into a fluid layout that adapts to any device. It supports direct embedding of dynamic SharePoint content and social media, requiring no manual updates, making it the ideal choice for a visually engaging newsletter.

Why this answer

Sway is the correct choice because it is designed specifically for creating interactive, visually rich newsletters that can embed videos and dynamically pull content from SharePoint lists using its integration with Microsoft 365. Unlike other apps, Sway offers a responsive design canvas that adapts to different devices and allows embedding of multimedia elements directly, making it ideal for a public relations team's needs.

Exam trap

The trap here is that candidates often confuse SharePoint News with Sway because both can display news and embed videos, but SharePoint News is a site-level feature for internal communications, not a standalone app for creating interactive, visually rich newsletters with dynamic content from SharePoint lists.

How to eliminate wrong answers

Option B (PowerPoint) is wrong because it is a presentation tool focused on slide-based content, not a newsletter format, and lacks native support for dynamically pulling content from SharePoint lists without complex add-ins. Option C (SharePoint News) is wrong because while it can display news posts and embed videos, it does not provide the same level of interactive, visually rich design flexibility as Sway and is more suited for internal communications within a SharePoint site. Option D (Microsoft Stream) is wrong because it is a video hosting and management platform, not a content creation tool for newsletters, and cannot generate interactive documents with embedded dynamic content from SharePoint lists.

361
MCQeasy

A sales team wants to maintain a shared list of high-priority leads with custom columns for company name, contact person, deal value, and stage. Team members need to update the list in real time and view the change history. Which Microsoft 365 app should they use?

A.Microsoft Lists
B.Microsoft Excel
C.Microsoft SharePoint
D.Microsoft Teams
AnswerA

Microsoft Lists is the dedicated list management app in Microsoft 365, purpose-built for tracking structured data like a high-priority sales target list. It offers rich column types (choice, person, date), custom views, conditional formatting, item-level versioning, and real-time co-authoring. Because Lists stores data in SharePoint but exposes a simplified UI, it gives the sales team immediate collaboration without requiring a full SharePoint site design.

Why this answer

Microsoft Lists is the M365 app purpose-built for shared, structured lists with custom columns, real-time co-authoring, and built-in version history. It supports column types such as text, choice, person, currency, and date, and integrates with Teams and SharePoint. This matches the sales team's need for a shared, editable lead tracker with change history.

Exam trap

The trap is choosing Excel because it is familiar for tabular data; the exam expects you to recognize that shared lists with custom columns and version history are the domain of Microsoft Lists.

How to eliminate wrong answers

Option B is wrong because Excel is a spreadsheet, not a shared list app; while co-authoring is supported, it lacks the structured list semantics, per-item version history, and Teams integration that Microsoft Lists provides. Option C is wrong because SharePoint is the underlying platform that hosts lists, but the user-facing app for creating and managing them is Microsoft Lists; SharePoint alone is too broad and does not directly answer the app question. Option D is wrong because Microsoft Teams is a collaboration hub that can host a Lists tab, but it is not the app used to create and manage the list itself.

362
MCQmedium

A company uses Microsoft Purview to monitor for potential data security incidents. They want to automatically detect and remediate activities like downloading large amounts of data to a personal device. Which solution should they configure?

A.Data Loss Prevention (DLP)
B.Insider Risk Management
C.Audit
D.eDiscovery
AnswerB

Insider Risk Management is the Microsoft Purview solution built specifically to identify, triage, and respond to risky user behavior by aggregating signals from Windows, Microsoft 365, and HR systems into a consolidated risk score. It uses predefined risk indicator policies—such as mass file downloads, unusual device connections, or repeated data exfiltration—and applies machine learning to surface anomalous patterns with a case-management workflow. When a threshold is met, it can automatically escalate to an investigation, notify the user, or trigger a policy response, making it the correct choice for monitoring and remediating potential data loss from insiders.

Why this answer

Insider Risk Management is the correct solution because it is specifically designed to detect and remediate risky user activities that could lead to data security incidents, such as downloading large amounts of data to a personal device. It uses machine learning and behavioral analytics to identify anomalous patterns and can trigger automated remediation actions like blocking the activity or notifying the user.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with Insider Risk Management, assuming DLP handles all data security incidents, but DLP focuses on content-based policies (e.g., credit card numbers) rather than behavioral detection of risky user actions like bulk downloads to personal devices.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is focused on preventing data exfiltration by enforcing policies on data in use, in transit, or at rest, but it does not natively detect or remediate behavioral patterns like downloading large volumes to a personal device; it typically blocks or alerts on policy violations based on content inspection. Option C is wrong because Audit (Microsoft Purview Audit) is a logging and investigation tool that records user and admin activities for compliance and forensic analysis, but it does not automatically detect or remediate risky behaviors in real time. Option D is wrong because eDiscovery is used for legal and regulatory discovery of electronic content, such as searching and exporting data for litigation or investigations, and has no capability to automatically detect or remediate data security incidents.

363
MCQmedium

An administrator is reviewing a request from users who need to protect users from phishing, unsafe links, and malicious attachments. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Defender for Office 365
B.Microsoft Stream
C.Microsoft Forms
D.Microsoft Planner
AnswerA

Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects users from advanced threats such as phishing, ransomware, and business email compromise. Its Safe Attachments and Safe Links features proactively scan and sandbox attachments and URLs in real time, while anti-phishing policies use machine learning and heuristics to detect impersonation attempts. This is the correct choice because it is specifically designed to safeguard users against malicious content delivered via email and collaboration tools.

Why this answer

Microsoft Defender for Office 365 is the correct choice because it provides advanced threat protection specifically designed to safeguard users against phishing, unsafe links, and malicious attachments. It includes features like Safe Links, Safe Attachments, and anti-phishing policies that scan and detonate URLs and attachments in real-time, leveraging threat intelligence from the Microsoft Intelligent Security Graph.

Exam trap

The trap here is that candidates may confuse general Microsoft 365 productivity apps (Stream, Forms, Planner) with security services, assuming any Microsoft tool can provide protection, but only Defender for Office 365 is purpose-built for phishing and malware defense.

How to eliminate wrong answers

Option B is wrong because Microsoft Stream is a video hosting and sharing service, not a security tool; it cannot protect against phishing, unsafe links, or malicious attachments. Option C is wrong because Microsoft Forms is a survey and quiz creation tool that lacks any built-in threat protection capabilities for email or links. Option D is wrong because Microsoft Planner is a task management and project planning application, with no security features to defend against phishing or malicious content.

364
MCQmedium

A customer reports that their Microsoft 365 Business Basic subscription is about to expire. They want to ensure uninterrupted service. What should they do?

A.Cancel the subscription immediately
B.Wait for the grace period to expire
C.Ensure recurring billing is enabled
D.Purchase an additional add-on license
AnswerC

Ensuring recurring billing is enabled is the correct action because, with this setting on, Microsoft automatically charges the stored payment method on the subscription's expiry date and renews the Microsoft 365 Business Basic license without interruption. You can verify this in the Microsoft 365 admin center under Billing > Your products, where the recurring billing toggle should be set to On for continuous service. If recurring billing was previously disabled, re-enabling it guarantees that the subscription follows the standard auto-renewal process and avoids any gap in services or user access.

Why this answer

Enabling recurring billing ensures that the subscription automatically renews before the expiration date, preventing any lapse in service. Without recurring billing, the subscription will expire at the end of the billing period, and the customer would lose access to Microsoft 365 services after a short grace period. This is the direct mechanism to maintain uninterrupted service for a Microsoft 365 Business Basic subscription.

Exam trap

The trap here is that candidates may confuse add-on licenses with subscription renewal, thinking that purchasing more licenses extends the subscription term, when in fact add-ons only increase the number of users or add features without affecting the subscription's expiration date.

How to eliminate wrong answers

Option A is wrong because canceling the subscription immediately would terminate service right away, causing an outage rather than ensuring continuity. Option B is wrong because waiting for the grace period to expire would result in the subscription being disabled and data potentially being deleted after the grace period ends, which does not ensure uninterrupted service. Option D is wrong because purchasing an additional add-on license does not affect the renewal or expiration of the base subscription; it only adds extra features or capacity, not extending the subscription term.

365
MCQhard

A multinational organization with 500 users currently has Microsoft 365 E3 licenses. They need to perform advanced threat hunting using queries across email, endpoints, and identities to investigate a security incident. They also need the ability to automatically isolate infected endpoints. What is the most cost-effective licensing addition?

A.Microsoft 365 E5 Security
B.Microsoft 365 E5
C.Microsoft 365 E5 Compliance
D.Enterprise Mobility + Security (EMS) E5
AnswerA

Microsoft 365 E5 Security is a targeted add-on for organizations on Microsoft 365 E3 that unlocks the full Microsoft 365 Defender stack. This includes Defender for Endpoint P2, Defender for Office 365 P2, Defender for Identity, and Defender for Cloud Apps, enabling advanced threat hunting via KQL, automated investigation and response, and automated endpoint isolation. It provides comprehensive security operations capabilities without the extra cost of non-security features found in the full E5 suite.

Why this answer

Microsoft 365 E5 Security is the most cost-effective addition because it provides advanced threat hunting via Microsoft 365 Defender (including queries across email, endpoints, and identities) and automated endpoint isolation through Microsoft Defender for Endpoint. This add-on delivers the required capabilities without the full cost of upgrading all users to Microsoft 365 E5, which would also include unnecessary features like advanced compliance and analytics.

Exam trap

The trap here is that candidates often confuse Microsoft 365 E5 Security with the full Microsoft 365 E5 license, assuming the full E5 is required for security features, when in fact the Security add-on provides the specific threat hunting and isolation capabilities at a lower cost.

How to eliminate wrong answers

Option B (Microsoft 365 E5) is wrong because it includes the full suite of E5 features (e.g., advanced compliance, analytics, and voice capabilities) at a higher per-user cost, making it less cost-effective than just adding the Security add-on. Option C (Microsoft 365 E5 Compliance) is wrong because it focuses on eDiscovery, data loss prevention, and information protection, not on advanced threat hunting with queries across email, endpoints, and identities or automated endpoint isolation. Option D (Enterprise Mobility + Security (EMS) E5) is wrong because it provides identity and access management (e.g., Azure AD P2, Intune) and mobile device management, but lacks the advanced threat hunting and automated endpoint isolation capabilities found in Microsoft 365 Defender.

366
MCQhard

You are configuring a Communication Compliance policy to detect workplace harassment. The policy currently includes conditions for sensitive information types (credit card numbers, SSN) and keywords. After deployment, the policy generates many irrelevant alerts for routine HR communications that contain the keywords but no harassment. What should you modify to improve detection accuracy?

A.Expand the keyword list to include more terms
B.Add more sensitive information types
C.Enable audit logging for all communications
D.Use a trainable classifier for 'harassment' instead of keyword matching
AnswerD

Trainable classifiers use machine learning trained on labelled examples to recognise contextual patterns of harassment, rather than matching isolated keywords. This reduces false positives from routine HR communications that merely contain those terms, improving detection accuracy.

Why this answer

Trainable classifiers in Microsoft Purview use machine learning to identify specific types of content based on examples, rather than relying on predefined keywords or sensitive information types. For detecting workplace harassment, a trainable classifier can be trained with actual examples of harassing language, making it far more accurate than keyword matching, which often triggers false positives in routine HR communications. This directly addresses the problem of irrelevant alerts.

Exam trap

MS-900 often tests the difference between keyword-based detection and trainable classifiers, and candidates may incorrectly think that adding more keywords or SITs will improve accuracy, when in fact it can worsen false positives.

How to eliminate wrong answers

Option A is wrong because expanding the keyword list would likely increase false positives, not reduce them, as more routine communications would match the keywords. Option B is wrong because adding more sensitive information types (like credit card numbers) is irrelevant to harassment detection and would not improve accuracy for this scenario. Option C is wrong because enabling audit logging only records activities; it does not affect the detection logic or reduce false positives in Communication Compliance policies.

367
MCQmedium

A growing company with 120 users currently holds Microsoft 365 Business Basic licenses. They need to add endpoint management (Microsoft Intune) and advanced threat protection (Microsoft Defender for Office 365 Plan 1). They also want to keep their existing Business Basic subscriptions. What is the most cost-effective way to add these capabilities?

A.Upgrade all users to Microsoft 365 Business Premium
B.Add Microsoft 365 Business Premium licenses as a standalone for all users
C.Purchase add-on subscriptions for Microsoft Intune Plan 1 and Microsoft Defender for Office 365 Plan 1
D.Switch to Microsoft 365 E3 and drop Business Basic
AnswerC

The correct approach is to purchase Microsoft Intune Plan 1 and Microsoft Defender for Office 365 Plan 1 as add-on subscriptions for the existing Business Basic users. These are incremental, per-user services designed to be attached to base plans, delivering exactly the mobile device management and email threat protection required without changing current workloads. For 120 users, this minimizes cost by paying only for the missing capabilities while preserving the existing Office 365 services and administrator familiarity.

Why this answer

Microsoft 365 Business Basic supports add-on subscriptions for Microsoft Intune Plan 1 and Microsoft Defender for Office 365 Plan 1, allowing the company to retain their existing licenses while adding endpoint management and advanced threat protection. This is the most cost-effective approach as it avoids the higher per-user cost of upgrading to Business Premium or switching to E3, which would include unnecessary features like desktop Office apps.

Exam trap

The trap here is that candidates often assume they must upgrade to a higher-tier plan (like Business Premium or E3) to get Intune and Defender, overlooking that Microsoft 365 Business Basic supports targeted add-on subscriptions for specific capabilities, which is the most cost-effective path.

How to eliminate wrong answers

Option A is wrong because upgrading all users to Microsoft 365 Business Premium would include features like desktop Office apps and other capabilities not required, resulting in unnecessary cost per user compared to purchasing only the needed add-ons. Option B is wrong because adding Business Premium as a standalone license for all users is redundant and more expensive than using add-ons, as it would duplicate the Business Basic subscription and include unneeded features. Option D is wrong because switching to Microsoft 365 E3 would drop the existing Business Basic subscriptions and introduce a higher per-user cost with features like advanced compliance and eDiscovery that are not required, making it less cost-effective than add-ons.

368
MCQmedium

A company has 100 Microsoft 365 E3 users. They need to add advanced threat protection (Microsoft Defender for Microsoft 365 Plan 2) and advanced compliance (eDiscovery Premium) for all users. They want to minimize additional costs while keeping their existing E3 subscriptions. What is the most cost-effective licensing strategy?

A.Purchase both the Microsoft 365 E5 Compliance add-on and the Microsoft 365 E5 Security add-on
B.Upgrade all users to Microsoft 365 E5
C.Purchase only the Microsoft 365 E5 Compliance add-on
D.Purchase only the Microsoft 365 E5 Security add-on
AnswerA

E5 Security covers Defender for Microsoft 365 Plan 2; E5 Compliance covers eDiscovery Premium. Buying both add-ons for 100 users costs less than migrating everyone to full E5 licences, satisfying the minimise-additional-cost constraint while retaining existing E3 subscriptions.

Why this answer

The Microsoft 365 E5 Security add-on provides Microsoft Defender for Office 365 Plan 2, and the Microsoft 365 E5 Compliance add-on provides eDiscovery Premium. Purchasing both add-ons for existing E3 users delivers the required advanced threat protection and advanced compliance capabilities without the full cost of upgrading to E5, making it the most cost-effective strategy.

Exam trap

The trap here is that candidates may assume upgrading to E5 is the only way to get both advanced security and compliance features, overlooking the cost-saving option of purchasing the specific E5 add-ons for existing E3 users.

How to eliminate wrong answers

Option B is wrong because upgrading all users to Microsoft 365 E5 includes both the security and compliance features but at a higher per-user cost than purchasing the two add-ons separately, which is unnecessary when E3 licenses are already in place. Option C is wrong because purchasing only the E5 Compliance add-on provides eDiscovery Premium but does not include Microsoft Defender for Office 365 Plan 2, leaving the advanced threat protection requirement unmet. Option D is wrong because purchasing only the E5 Security add-on provides Microsoft Defender for Office 365 Plan 2 but does not include eDiscovery Premium, failing to address the advanced compliance requirement.

369
MCQeasy

A company is deploying Microsoft 365 and wants to ensure that customer financial data remains within the European Union. Which Microsoft 365 feature should the administrator configure?

A.Apply sensitivity labels using Microsoft Purview.
B.Configure Data Location settings in the Microsoft 365 admin center.
C.Set up Conditional Access policies in Microsoft Entra ID.
D.Implement Data Loss Prevention (DLP) policies.
AnswerB

Data Location settings are found in the Microsoft 365 admin center under Org settings, and they allow administrators to view and, with Multi-Geo, assign the geographic region where customer data at rest is stored for workloads like Exchange Online and SharePoint. Configuring these settings directly enforces data residency at rest by controlling the tenant's committed data location for core services. This is the only option that addresses storage location itself.

Why this answer

The Data Location settings in the Microsoft 365 admin center allow administrators to specify the geographic region where data at rest is stored, including the European Union. This ensures compliance with data residency requirements by controlling where customer financial data is physically stored, leveraging Microsoft's commitment to data sovereignty within defined geo-boundaries.

Exam trap

The trap here is that candidates often confuse data residency controls (Data Location settings) with data protection mechanisms like sensitivity labels or DLP, assuming any security feature can enforce geographic storage, but only Data Location settings directly control physical data storage regions.

How to eliminate wrong answers

Option A is wrong because sensitivity labels classify and protect data based on sensitivity, but they do not control the geographic location where data is stored; they are applied to documents and emails for access control and encryption. Option C is wrong because Conditional Access policies enforce access controls based on conditions like user location or device compliance, but they do not determine the physical storage location of data. Option D is wrong because Data Loss Prevention (DLP) policies prevent accidental sharing of sensitive data by monitoring and blocking content, but they do not configure where data is stored geographically.

370
MCQeasy

A company wants to prevent employees from forwarding sensitive emails outside the organization. Which Microsoft Purview feature should they use?

A.Microsoft Intune Mobile Application Management
B.Microsoft Entra ID Conditional Access
C.Microsoft Defender for Office 365 Anti-Phishing
D.Microsoft Purview Message Encryption
AnswerD

Message Encryption wraps outbound email in protection that travels with the message, so recipients outside the organisation cannot forward, copy, or print the sensitive content. This directly satisfies the requirement to prevent external forwarding, unlike sensitivity labels, which rely on client-side enforcement.

Why this answer

Microsoft Purview Message Encryption (part of Purview Information Protection) lets organizations encrypt and apply usage restrictions to email, including preventing forwarding, printing, or copying of sensitive messages. It uses Azure Rights Management to enforce protection that travels with the message, so even if a recipient tries to forward it outside the organization, the protection persists. This directly addresses the requirement to prevent forwarding sensitive emails outside the organization.

Exam trap

MS-900 often tests the confusion between data protection features (Purview Message Encryption, DLP) and access/identity controls (Conditional Access, Intune MAM) — candidates pick Conditional Access thinking it restricts email forwarding, but it only gates access to resources.

How to eliminate wrong answers

Option A is wrong because Intune Mobile Application Management controls app-level data sharing on mobile devices (e.g., preventing copy/paste between apps) but does not govern email forwarding behavior for recipients outside the organization. Option B is wrong because Entra ID Conditional Access controls access to cloud resources based on user, device, location, and risk signals — it does not encrypt or restrict forwarding of email content. Option C is wrong because Defender for Office 365 Anti-Phishing detects and blocks phishing attempts; it does not prevent a user from forwarding a legitimate sensitive email outside the organization.

371
MCQmedium

A compliance administrator needs to assess compliance posture against standards and improvement actions. Which Microsoft 365 capability is the best fit? The design must avoid adding custom operational scripts.

A.OneDrive sync client
B.Microsoft Teams live events
C.Microsoft Purview Compliance Manager
D.Microsoft Bookings
AnswerC

Microsoft Purview Compliance Manager is the intended Microsoft 365 solution for assessing compliance posture. It provides data-driven risk assessments across the tenant, uses a compliance score to illustrate overall standing, and maps evaluated controls to industry standards and regulations such as ISO 27001, NIST, GDPR, and Microsoft's data protection baseline. Compliance Manager also generates prioritized improvement actions, includes automated control testing, and allows you to track implementation of required controls, making it the correct choice for a compliance administrator measuring and managing the organization's compliance posture.

Why this answer

Microsoft Purview Compliance Manager is the correct choice because it provides a built-in, no-code solution for assessing compliance posture against standards (e.g., ISO 27001, NIST) and generates actionable improvement actions. It eliminates the need for custom operational scripts by offering pre-configured assessments and automated tracking of controls.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager with broader security tools like Microsoft Secure Score or Defender for Cloud, but the question specifically requires a compliance posture assessment tool that avoids custom scripts, which Compliance Manager uniquely fulfills.

How to eliminate wrong answers

Option A is wrong because the OneDrive sync client is a file synchronization tool for local and cloud storage, not a compliance assessment or improvement action tool. Option B is wrong because Microsoft Teams live events is a broadcasting feature for real-time virtual events, with no capability to evaluate compliance posture or generate improvement actions. Option D is wrong because Microsoft Bookings is a scheduling and appointment management app, entirely unrelated to compliance assessments or standards-based posture analysis.

372
MCQeasy

An organization wants to use Microsoft 365 to automatically classify and protect sensitive data in emails and documents. Which service should they use?

A.Microsoft Purview Information Protection
B.Microsoft Intune
C.Microsoft Defender for Office 365
D.Microsoft Entra ID
AnswerA

Microsoft Purview Information Protection automatically classifies and protects sensitive data by applying sensitivity labels based on sensitive info types, trainable classifiers, and machine-learning models. It can trigger encryption or access restrictions immediately when content is created or edited, making it the direct answer for automatic data-level protection.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides data classification, labeling, and protection capabilities directly within Microsoft 365. It uses sensitivity labels to automatically classify emails and documents based on conditions like content patterns or custom keywords, and then applies encryption, rights management, or visual markings (e.g., headers/footers) to protect sensitive data both at rest and in transit.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (which protects against threats) with Purview Information Protection (which classifies and protects data), leading them to select Option C because they associate 'protect' with security rather than data governance.

How to eliminate wrong answers

Option B (Microsoft Intune) is wrong because it is a mobile device management (MDM) and mobile application management (MAM) service focused on managing devices and apps, not on classifying or protecting data content within emails and documents. Option C (Microsoft Defender for Office 365) is wrong because it is a security service that protects against threats like phishing, malware, and malicious links in email and collaboration tools, but it does not perform automatic data classification or sensitivity labeling. Option D (Microsoft Entra ID) is wrong because it is an identity and access management (IAM) service that handles authentication, single sign-on, and conditional access policies, not data classification or protection of content.

373
MCQeasy

A company wants to use a cloud service where they only manage their data and user access, while the cloud provider handles everything from the physical infrastructure to the applications. Which cloud service model is this?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerC

SaaS delivers a complete, provider-managed application stack: the customer configures only data and user access, while the provider owns servers, storage, networking, runtime, and the application itself. That matches the stem's division of responsibility exactly.

Why this answer

This scenario describes Software as a Service (SaaS), where the cloud provider manages the entire stack—physical infrastructure, operating system, middleware, runtime, data, and applications—while the customer only manages their data and user access. In SaaS, the provider delivers fully functional applications over the internet, such as Microsoft 365, where users simply log in and use the software without any infrastructure or platform management responsibilities.

Exam trap

The trap here is that candidates often confuse PaaS with SaaS because both abstract infrastructure, but PaaS still requires the customer to manage their own applications and data, whereas SaaS offloads even application management to the provider.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides only virtualized computing resources (e.g., VMs, storage, networks), and the customer must manage the operating systems, middleware, runtime, data, and applications themselves. Option B is wrong because Platform as a Service (PaaS) abstracts the underlying infrastructure and middleware, but the customer still manages their own applications and data, not just user access and data. Option D is wrong because an on-premises deployment means the company manages everything—from physical hardware to applications—which is the opposite of the described model where the provider handles all layers.

374
Multi-Selecthard

Which THREE of the following are capabilities of Microsoft Entra ID that support identity security? (Choose three.)

Select 3 answers
A.Microsoft Defender XDR
B.Microsoft Intune
C.Privileged Identity Management (PIM)
D.Conditional Access
E.Identity Protection
AnswersC, D, E

Privileged Identity Management grants just-in-time, time-bound activation of elevated directory roles, with approval and audit trails. This satisfies identity security by eliminating standing administrative access, which is the primary risk PIM is designed to mitigate.

Why this answer

Privileged Identity Management (PIM) is correct because it provides just-in-time privileged access with approval workflows, time-bound role activation, and access reviews, directly reducing standing admin rights in Microsoft Entra ID. Conditional Access is correct because it enforces signal-based access policies (user, device, location, risk) to grant, block, or require MFA/compliant device before access to resources. Identity Protection is correct because it detects and remediates identity risks using signals like leaked credentials, anonymous IP addresses, and atypical sign-in behavior, feeding risk detections into Conditional Access.

Microsoft Defender XDR is not an Entra ID identity-security capability; it is a broader extended detection and response suite spanning endpoints, email, identities, and cloud apps. Microsoft Intune is a device and application management service (MDM/MAM) rather than a native Entra ID identity-security capability, even though it integrates with Conditional Access for device compliance.

Exam trap

MS-900 often tests whether candidates can distinguish Entra ID identity security features from broader Microsoft 365 security and management tools like Defender XDR and Intune.

375
MCQhard

A multinational company uses Microsoft 365 and wants to ensure that data stored in SharePoint Online is only accessible from specific geographic regions. The company has offices in the US, EU, and Asia. You need to implement a solution that restricts access based on the user's physical location. Which feature should you configure?

A.Data Residency in Microsoft Purview
B.Conditional Access policies in Microsoft Entra ID
C.Geofencing in Microsoft Intune
D.Location-Based Policies in SharePoint Admin Center
AnswerB

Conditional Access policies in Microsoft Entra ID evaluate named locations and sign-in conditions, then block or permit access to SharePoint Online accordingly. This enforces geographic restriction at authentication time, which SharePoint site-level permissions alone cannot achieve.

Why this answer

Option B is correct because Conditional Access policies in Microsoft Entra ID can restrict access based on the user's physical location by using named locations or IP ranges. This allows the company to enforce that SharePoint Online data is only accessible from specific geographic regions.

Exam trap

MS-900 often tests the confusion between data residency (where data is stored) and access restrictions based on location; candidates might pick Data Residency thinking it controls access, but it only controls storage location.

How to eliminate wrong answers

Option A is wrong because Data Residency in Microsoft Purview is about where data is stored at rest, not about restricting access based on user location. Option C is wrong because Geofencing in Microsoft Intune is used for mobile device management to restrict device usage based on location, not for controlling access to SharePoint Online. Option D is wrong because Location-Based Policies in SharePoint Admin Center do not exist; SharePoint access control is managed via Conditional Access or IP policies in SharePoint, but the primary method for location-based access is Conditional Access.

Page 4

Page 5 of 11

Page 6

All pages