Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 376–450

794 questions total · 11pages · All types, answers revealed

Page 5

Page 6 of 11

Page 7
376
MCQhard

A large enterprise needs to enforce that all documents containing financial data are automatically classified and encrypted when shared externally. Which combination of Microsoft 365 services should be used?

A.Microsoft Forms and Microsoft Stream
B.Microsoft Sentinel and Microsoft Defender XDR
C.Microsoft Purview Information Protection and Microsoft Defender for Cloud Apps
D.Microsoft Intune and Microsoft Entra ID
AnswerC

Microsoft Purview Information Protection provides sensitivity labels that can classify and, when configured, encrypt documents using rights-management templates, while Microsoft Defender for Cloud Apps acts as a cloud access security broker to enforce policies on those labels—such as blocking download or applying visual markings. Together, they create a complete control plane that can conditionally require a label, apply automatic classification, and govern sharing behavior for documents in SharePoint, OneDrive, or third-party cloud apps. This directly enforces the enterprise requirement to protect all documents containing sensitive data.

Why this answer

Microsoft Purview Information Protection provides the classification and labeling capabilities to automatically identify documents containing financial data, while Microsoft Defender for Cloud Apps enables policy-based encryption and protection controls when those documents are shared externally. Together, they enforce data loss prevention (DLP) by applying sensitivity labels that trigger encryption upon external sharing, meeting the enterprise requirement.

Exam trap

The trap here is that candidates confuse security monitoring tools (Sentinel, Defender XDR) with data classification and encryption tools, or they mistakenly think device management (Intune) or identity (Entra ID) can enforce content-level encryption on documents shared externally.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey tool and Microsoft Stream is a video platform; neither provides document classification, encryption, or external sharing controls. Option B is wrong because Microsoft Sentinel is a SIEM/SOAR for security incident detection and Microsoft Defender XDR is for endpoint, email, and identity threat protection; they do not classify or encrypt documents based on content. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution, and Microsoft Entra ID is an identity and access management service; neither directly classifies or encrypts document content for external sharing.

377
MCQmedium

A project manager wants a shared workspace where team members can create and track tasks, set deadlines, and collaborate on documents. This workspace should integrate with Microsoft Teams for quick access. Which Microsoft 365 service is best suited for this purpose?

A.Microsoft Lists
B.Microsoft Planner
C.Microsoft To Do
D.Microsoft Project Online
AnswerB

Microsoft Planner is a collaborative task management tool built around a visual Kanban board where each task has assignees, due dates, checklists, labels, and file attachments. Every Planner plan is backed by a Microsoft 365 Group, giving the team a shared mailbox, calendar, and SharePoint document library for co-authoring, and the Board can be embedded into Teams as a tab. Its simplicity and native Teams integration make it the correct choice for a shared workspace with assignments and deadlines.

Why this answer

Microsoft Planner is the correct choice because it provides a shared workspace (Plan) where team members can create and track tasks, set deadlines, and collaborate on documents. It integrates natively with Microsoft Teams via the Planner tab, allowing quick access within a Teams channel, and supports file attachments from SharePoint/OneDrive for collaboration.

Exam trap

The trap here is that candidates often confuse Microsoft Lists with Planner because both involve tracking items, but Lists is for static data collection (like a spreadsheet) while Planner is for dynamic task management with assignments and deadlines.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data-tracking app for creating custom lists (e.g., issue trackers, inventories) but lacks built-in task assignment, deadline tracking, and Kanban-style task management that Planner offers. Option C is wrong because Microsoft To Do is a personal task management tool for individual users, not designed for team collaboration or shared workspaces with document collaboration. Option D is wrong because Microsoft Project Online is a full-featured project management solution for complex scheduling, resource management, and Gantt charts, which is overkill for a simple shared workspace and does not integrate as seamlessly with Teams for quick task tracking.

378
MCQmedium

A company with 300 users is choosing between Microsoft 365 Business Premium and Microsoft 365 E3. They need desktop Office apps, email, Teams, and basic device management (including Microsoft Intune). They do not need advanced compliance or analytics. Which plan is more cost-effective?

A.Microsoft 365 Business Premium
B.Microsoft 365 E3
C.Microsoft 365 Business Standard
D.Microsoft 365 F3
AnswerA

Microsoft 365 Business Premium includes desktop Office apps, Exchange email, Teams and Intune device management, capped at 300 seats. With exactly 300 users and no advanced compliance or analytics requirement, it delivers the needed capabilities at lower cost than E3.

Why this answer

Microsoft 365 Business Premium is the most cost-effective choice because it includes desktop Office apps, Exchange Online email, Teams, and Microsoft Intune for basic device management, all for a lower per-user price than E3. The company's stated needs (no advanced compliance or analytics) align perfectly with Business Premium's feature set, making E3's additional capabilities unnecessary and more expensive.

Exam trap

The trap here is that candidates often assume E3 is always 'better' for larger organizations, but the MS-900 exam tests whether you can match specific feature requirements (especially Intune and desktop apps) to the most cost-effective plan, not just the highest-tier one.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 E3 includes advanced compliance (e.g., eDiscovery, retention policies) and analytics (e.g., Power BI Pro) that the company does not need, making it a more expensive plan for the same required features. Option C is wrong because Microsoft 365 Business Standard lacks Microsoft Intune for device management, which is explicitly required by the company. Option D is wrong because Microsoft 365 F3 is designed for frontline workers and does not include desktop Office apps (only web and mobile versions), failing the requirement for desktop Office apps.

379
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to block emails containing credit card numbers from being sent externally. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.Microsoft Stream
D.Microsoft Forms
AnswerB

Data Loss Prevention (DLP) is a compliance feature in Microsoft 365 that uses predefined sensitive information types and custom rules to inspect content across Exchange, SharePoint, OneDrive, and Teams. It can automatically block sharing of files containing passport numbers, health records, or other regulated data, and can display policy tips to users before they take risky actions. DLP policies support conditions, exceptions, and actions such as blocking access, encrypting content, or sending incident reports, making it the correct capability for this security and compliance control.

Why this answer

Data Loss Prevention (DLP) in Microsoft 365 is the correct capability because it is specifically designed to detect and protect sensitive information, such as credit card numbers, by scanning email content and attachments. DLP policies can be configured to block external transmission of emails containing sensitive data, using built-in sensitive information types like the Credit Card Number rule that matches patterns based on Luhn checksum validation. This directly addresses the service owner's requirement to prevent credit card numbers from being sent externally.

Exam trap

The trap here is that candidates may confuse Microsoft 365 compliance tools with unrelated productivity apps, assuming any 'Microsoft' tool can handle security tasks, but only DLP is purpose-built for content-based email restrictions.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and project planning tool, not a security or compliance feature; it cannot inspect or block email content. Option C is wrong because Microsoft Stream is a video hosting and sharing platform, with no capability to scan or enforce policies on email transmissions. Option D is wrong because Microsoft Forms is a survey and data collection tool, lacking any data loss prevention or email filtering functionality.

380
Matchingmedium

Match each Microsoft 365 security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Protects against malicious links and attachments in email

Identity and access management service

Policy-based controls to enforce MFA or block access

Mobile device and application management

Why these pairings

Azure AD Identity Protection focuses on identity risks; Microsoft Defender for Office 365 secures email and documents; Microsoft Defender for Endpoint protects devices; Microsoft Information Protection handles data classification and protection. The distractors swap functions between these features.

381
MCQhard

An organization needs to prevent users from sharing documents that contain credit card numbers via email and Microsoft Teams. When a user attempts to share such a document, they should see a policy tip explaining the restriction. Which Microsoft Purview solution should the compliance team configure?

A.Microsoft Purview Information Barriers
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Retention Policies
D.Microsoft Purview Sensitivity Labels
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is designed to identify, monitor, and protect sensitive data through content analysis based on sensitive information types, including credit card numbers. DLP policies can be applied to Exchange, SharePoint, OneDrive, Teams, and endpoints, and they evaluate actions like external sharing or downloads. When a user attempts to share a document containing a credit card number, the policy can block the sharing action and display a policy tip that informs the user about the violation. This matches the requirement precisely.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive information types—such as credit card numbers—in documents and communications. DLP policies can be configured to block or warn users via policy tips when they attempt to share such content through email or Microsoft Teams, enforcing compliance without disrupting legitimate work.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels (which classify data) with DLP (which enforces actions based on that classification or on sensitive data patterns), leading them to choose D when the question specifically asks for a solution that scans for credit card numbers and shows policy tips.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Barriers restrict communication and collaboration between specific user groups (e.g., to prevent conflicts of interest), but they do not inspect content for sensitive data like credit card numbers or provide policy tips. Option C is wrong because Microsoft Purview Retention Policies manage how long content is kept or deleted for legal or regulatory purposes, not to prevent sharing of sensitive data in real time. Option D is wrong because Microsoft Purview Sensitivity Labels classify and protect content based on sensitivity (e.g., 'Confidential'), but they do not natively scan for specific data patterns like credit card numbers or trigger policy tips on their own; they require integration with DLP for such enforcement.

382
MCQmedium

A marketing manager needs to create a modern intranet site that publishes news, important announcements, and upcoming events. The site must be responsive on mobile devices and allow employees to like, comment, and share articles. Which Microsoft 365 service should they use?

A.Microsoft Teams
B.SharePoint Communication site
C.Microsoft Viva Engage
D.Microsoft Viva Connections
AnswerB

SharePoint Communication sites are the specific modern intranet site type built to broadcast information to a broad audience. They provide flexible page layouts, news web parts, audience targeting, scheduling, approval workflows, and responsive mobile rendering, making them ideal for a marketing manager publishing company news and events. These sites integrate with Viva Connections and Teams, but the communication site itself is the authoritative content repository and structured intranet destination.

Why this answer

A SharePoint Communication site is designed for broadcasting news, announcements, and events to a broad audience, with built-in support for responsive mobile rendering and social features like likes, comments, and sharing. This makes it the correct choice for a modern intranet that needs to engage employees across devices.

Exam trap

The trap here is that candidates often confuse Microsoft Viva Connections (a dashboard) with the underlying content source (SharePoint Communication site), leading them to select D when the question explicitly asks for the service used to create the intranet site.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration hub focused on persistent conversations and channel-based teamwork, not a publishing platform for news and announcements with like/comment/share capabilities. Option C is wrong because Microsoft Viva Engage (formerly Yammer) is an enterprise social network for community discussions and knowledge sharing, but it lacks the structured page publishing and modern intranet site features required for news and events. Option D is wrong because Microsoft Viva Connections is a personalized dashboard that aggregates content from SharePoint, Teams, and other sources, but it is not a site creation service itself—it depends on a SharePoint Communication site as its underlying content source.

383
Multi-Selecthard

Which THREE conditions must be met for a Microsoft 365 tenant to use Customer Lockbox?

Select 3 answers
A.An authorized admin must submit a support request to Microsoft.
B.The tenant must be on a Microsoft 365 E3 plan.
C.Microsoft engineers must require access to customer data for troubleshooting.
D.Internal administrators must request access to user mailboxes.
E.The organization must have a Microsoft 365 E5 or G5 license.
AnswersA, C, E

Customer Lockbox is triggered only for active support incidents. An authorized admin (such as a Global Administrator) must first open a service request with Microsoft Support, providing the necessary context and consent for the troubleshooting session. Without this initial support ticket, there is no engagement from Microsoft engineers, and therefore no lockbox request can be generated, making this a prerequisite for the feature to function.

Why this answer

Customer Lockbox requires an authorized admin to explicitly approve or deny a Microsoft engineer's access request. This ensures that no data access occurs without the customer's explicit consent, aligning with the principle of 'approval-based access control' for support scenarios.

Exam trap

The trap here is that candidates often confuse Customer Lockbox with internal admin access controls (like Privileged Access Management) or assume it's available on lower-tier plans like E3, when in fact it requires E5/G5 licensing and is specifically for Microsoft-initiated support access.

384
MCQhard

A healthcare provider must ensure that patient health information (PHI) is not accidentally shared outside the organization. They want to automatically detect if an email contains PHI (such as diagnosis codes) and block it from being sent externally. Additionally, the sender should receive a notification explaining the block. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Insider Risk Management
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is correct because it is designed precisely for this scenario: identifying sensitive information types (such as U.S. HIPAA data or generic health record patterns) and enforcing protective actions on outbound messages. When a DLP policy is applied to Exchange Online, the service scans email content and attachments in transit, matches against defined conditions, and can block the email, send a policy tip to the sender, or generate an incident report. For a healthcare provider, DLP can use regulatory templates (like HIPAA) to automatically prevent accidental or deliberate leakage of patient health information via email.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive information—such as patient health information (PHI) with diagnosis codes—in emails and automatically block external transmission while sending a notification to the sender. DLP policies can be configured with sensitive information types (e.g., HIPAA-defined PHI patterns) and rules to enforce actions like blocking and policy tips.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling) with DLP (enforcement), assuming that applying a sensitivity label alone will block external sharing, when in fact DLP is required to enforce the block and notification action.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying and labeling sensitive data (e.g., applying sensitivity labels) but does not inherently enforce real-time blocking of email transmission or send sender notifications; it requires integration with DLP for such actions. Option C is wrong because Microsoft Purview Insider Risk Management is designed to detect and investigate risky user activities (e.g., data exfiltration by insiders) using analytics and alerts, not to automatically block outbound emails containing specific content. Option D is wrong because Microsoft Purview Audit provides logging and investigation of past activities (e.g., who accessed what), but it cannot proactively block emails or notify senders in real time.

385
MCQmedium

Contoso has a Microsoft 365 E5 tenant. The security team needs to investigate a potential insider data exfiltration incident. They must be able to review the original content of emails and documents that a specific user accessed, and preserve that content so it cannot be altered or deleted by the user during the investigation. Which Microsoft Purview capability should they use?

A.Communication compliance policies in Microsoft Purview
B.Records management file plan with a retention label applied to the user's mailbox
C.Audit log search in the Microsoft Purview compliance portal
D.eDiscovery (Premium) with a case hold applied to the custodian
AnswerD

eDiscovery (Premium) supports custodian management and legal holds that preserve content in place, including email, SharePoint, OneDrive, and Teams. Applying a hold to the custodian ensures the user cannot modify or delete the preserved items while investigators review the original content, which directly satisfies the requirement to review and preserve accessed data.

Why this answer

The requirement combines two needs: review the original content a specific user accessed, and prevent that user from altering or deleting it during the investigation. eDiscovery (Premium) provides custodian-scoped holds that preserve data in place across Exchange Online, SharePoint Online, OneDrive, and Teams, while giving investigators a review set to examine the original items. Audit search, communication compliance, and records retention labels do not deliver custodian-based preservation with content review.

Exam trap

The trap here is assuming that audit log search or a retention label preserves content, when only an eDiscovery hold on the custodian actually prevents the user from altering or deleting the original items.

386
Multi-Selectmedium

Which three of the following are core components of Microsoft’s Zero Trust security model as implemented in Microsoft 365? (Choose three.)

Select 3 answers
.Verify explicitly
.Use least privileged access
.Assume breach
.Encrypt all data at rest only
.Deploy a single firewall for all traffic
.Require on-premises identity provider

Why this answer

The Zero Trust security model is built on three foundational principles: verify explicitly, use least privileged access, and assume breach. In Microsoft 365, 'verify explicitly' means authenticating and authorizing every access request based on all available data points (user identity, device health, location, etc.). 'Use least privileged access' limits user permissions to only what is necessary, enforced through tools like Privileged Identity Management (PIM) and Conditional Access. 'Assume breach' designs the environment to minimize blast radius and segment access, assuming an attacker is already present, which drives practices like micro-segmentation and continuous monitoring.

Exam trap

The trap here is that candidates often confuse security best practices (like encryption or firewalls) with the core Zero Trust principles, or mistakenly think Zero Trust requires on-premises identity, when in fact it is designed to work with cloud-native identity providers like Azure AD.

387
MCQhard

A multinational corporation wants to provide a single sign-on experience for employees accessing third-party SaaS applications alongside Microsoft 365. Which Microsoft Entra ID feature should they use?

A.Password hash synchronization
B.Microsoft Entra ID as identity provider with SSO integration
C.Multifactor authentication
D.Seamless single sign-on
AnswerB

Microsoft Entra ID as identity provider with SSO integration serves as the central cloud identity provider that supports industry-standard SSO protocols such as SAML 2.0, OpenID Connect, and WS-Fed. A user authenticates once to Entra ID and receives a session token that is accepted by thousands of pre-integrated SaaS applications, eliminating the need to sign in again to each application. This directly fulfills the multinational's requirement for single sign-on, making it the correct option.

Why this answer

Microsoft Entra ID as an identity provider with SSO integration (Option B) is correct because it allows the organization to act as the central identity source for both Microsoft 365 and third-party SaaS applications. By configuring federated SSO (using SAML 2.0 or OpenID Connect), users authenticate once against Entra ID and gain seamless access to all integrated apps, eliminating the need for separate credentials.

Exam trap

The trap here is that candidates confuse 'Seamless SSO' (Option D) with full SSO federation, but Seamless SSO only handles the initial sign-in experience on domain-joined devices and does not extend SSO to third-party SaaS applications.

How to eliminate wrong answers

Option A is wrong because password hash synchronization only syncs user password hashes from on-premises AD to Entra ID for authentication; it does not provide SSO to third-party SaaS apps on its own. Option C is wrong because multifactor authentication is a security feature that adds a second verification step, not an SSO mechanism; it can be used alongside SSO but does not enable single sign-on. Option D is wrong because Seamless SSO is a feature that automatically signs users in when they are on a domain-joined device connected to the corporate network, but it only works for Microsoft 365 and other Entra ID-integrated apps, not for third-party SaaS applications that require explicit federation.

388
MCQhard

Fabrikam Inc. has 5,000 users and is currently using Microsoft 365 E3. They want to enable Microsoft Copilot for Microsoft 365 for all users. The finance team is concerned about the additional cost and wants to explore if any existing licenses include Copilot or if they can use a lower-cost option. The IT team has determined that Copilot requires a qualifying license such as E3 or E5. Fabrikam also needs to maintain their current level of service for Exchange, SharePoint, Teams, and OneDrive. They do not need any additional security or compliance features beyond what E3 provides. Which licensing strategy should they implement to enable Copilot for all users while minimizing total cost?

A.Switch to Microsoft 365 Business Premium and add Copilot
B.Upgrade all users to Microsoft 365 E5
C.Keep Microsoft 365 E3 and purchase Copilot add-on licenses for all users
D.Purchase standalone Copilot licenses without changing the base plan
AnswerC

Microsoft 365 E3 is a qualifying base license for Microsoft 365 Copilot, and the Copilot add-on can be licensed per user to provide the AI-powered assistance Fabrikam needs. Since the company already uses E3, they can simply purchase the Copilot add-on for all 5,000 users without changing the underlying plan. This avoids the cost of upgrading to E5 or switching to a plan with a user limit, meeting the requirement at minimal additional expense.

Why this answer

Microsoft 365 E3 is a qualifying base license for Copilot for Microsoft 365, and the Copilot add-on can be purchased per user without changing the existing plan. This allows Fabrikam to retain their current E3 service levels for Exchange, SharePoint, Teams, and OneDrive while adding Copilot functionality at the lowest incremental cost, as they do not need the extra security or compliance features of E5.

Exam trap

The trap here is that candidates may assume Copilot requires an E5 license or that a Business Premium license can support 5,000 users, but Microsoft explicitly limits Business Premium to 300 users and requires a qualifying base license for Copilot, making the add-on on E3 the only cost-effective and technically valid option.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Premium is designed for organizations with up to 300 users, not 5,000 users, and it lacks the enterprise-level features for Exchange, SharePoint, Teams, and OneDrive that E3 provides; switching would break their current service level requirements. Option B is wrong because upgrading all users to Microsoft 365 E5 adds significant cost for advanced security and compliance features (e.g., Microsoft Defender for Office 365, eDiscovery, and Advanced Audit) that Fabrikam explicitly does not need, making it an unnecessarily expensive solution. Option D is wrong because standalone Copilot licenses cannot be purchased without a qualifying base license such as E3 or E5; Microsoft requires an active subscription to a qualifying plan before adding Copilot, so this option is technically invalid.

389
MCQmedium

A tenant administrator is advising a department that wants to use persistent chat, online meetings, channels, and shared files organized by project. Microsoft 365 app or service is the best fit?

A.Microsoft Forms
B.Microsoft Teams
C.Microsoft Planner
D.Microsoft Purview Audit
AnswerB

Microsoft Teams is the correct choice because it is a comprehensive collaboration hub that brings together persistent chat, meetings, video calls, channels for organized discussions, and shared file storage via SharePoint. It enables department members to work together in real time on documents, hold virtual meetings, and maintain a central repository of information—all within a single, governed platform. This matches the department's need for a unified collaboration environment.

Why this answer

Microsoft Teams is the best fit because it provides persistent chat, online meetings, channels, and shared files organized by project. Teams integrates with SharePoint for file storage and OneNote for notes, allowing each channel to have its own file repository and meeting scheduling, directly matching the department's requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task boards with project organization, but Planner lacks the persistent chat, meetings, and channel-based file sharing that Teams provides for project collaboration.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz tool, not designed for persistent chat, meetings, channels, or shared file organization. Option C is wrong because Microsoft Planner is a task management and lightweight project tracking tool that lacks persistent chat, online meetings, and channel-based file sharing. Option D is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user activities, not a collaboration platform for chat, meetings, or file organization.

390
MCQeasy

A company wants to use a cloud service where they can deploy their own custom applications without managing the underlying operating system or hardware. The cloud provider handles the runtime, middleware, and infrastructure. Which cloud service model best fits this requirement?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerB

Platform as a Service (PaaS) provides a fully managed application-hosting environment, including the runtime, programming model, data services, and scaling facilities. You deploy your own custom application code, while the provider handles the underlying OS, patching, and capacity; this directly matches the need to deploy custom apps without infrastructure management. This is why PaaS is the correct choice.

Why this answer

Platform as a Service (PaaS) is the correct model because it provides a managed environment where the company can deploy custom applications without managing the underlying OS, hardware, runtime, or middleware. The cloud provider handles all infrastructure and platform layers, allowing developers to focus solely on code and application logic.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both allow custom application deployment, but IaaS requires managing the OS and middleware, whereas PaaS abstracts those layers entirely.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized hardware resources (e.g., VMs, storage, networking) but requires the customer to manage the operating system, runtime, middleware, and applications, which contradicts the requirement of not managing the OS or hardware. Option C is wrong because Software as a Service (SaaS) delivers ready-to-use applications accessed via a browser or API, not a platform for deploying custom applications; the customer cannot control or deploy their own code. Option D is wrong because Desktop as a Service (DaaS) provides virtual desktop environments, not a platform for deploying custom applications; it focuses on delivering desktop experiences rather than application hosting and development.

391
MCQmedium

A department head asks which Microsoft 365 option should be used to review file access, sharing changes, and administrator actions during an investigation. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Forms
B.Microsoft Planner
C.Microsoft Purview Audit
D.Microsoft Stream
AnswerC

Microsoft Purview Audit (formerly Office 365 Audit) captures and retains a searchable log of user, admin, and system actions across services such as Exchange Online, SharePoint Online, OneDrive, Teams, and Entra ID. It is the correct choice for a department head needing to investigate 'who did what, when, and where' because the audit log can be queried in the Purview compliance portal or via the Audit Graph API. Licensing, retention policies, and event-level detail are also configurable to meet compliance requirements.

Why this answer

Microsoft Purview Audit (formerly Office 365 Audit Log) is the correct choice because it provides a unified audit log that captures file access, sharing changes, and administrator actions across Microsoft 365 services. This capability is essential for security investigations, as it allows administrators to search and export detailed records of user and admin activities, meeting the department head's requirement for reviewing historical actions.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Audit with other Microsoft 365 tools that have 'audit' in their name (e.g., Azure AD audit logs) or mistakenly think that a general productivity tool like Planner or Forms can provide security investigation capabilities, when only Purview Audit is designed for this purpose.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz creation tool, not a security or compliance capability; it does not log file access, sharing changes, or admin actions. Option B is wrong because Microsoft Planner is a task management and project planning application, lacking any audit logging or security investigation features. Option D is wrong because Microsoft Stream is a video hosting and sharing service, which does not provide audit logs for file access, sharing changes, or administrator actions.

392
MCQmedium

A project team needs to create a central workspace where they can store project documents, assign tasks, track a shared calendar of milestones, and have threaded discussions about each item. The solution must integrate directly with Microsoft Teams. Which Microsoft 365 service provides this out-of-the-box?

A.SharePoint Online
B.Microsoft Lists
C.Planner
D.Project Online
AnswerA

SharePoint Online provides the full collaborative workspace the team needs: a team site includes document libraries for file storage and versioning, list apps for tracking tasks and issues, a shared calendar web part, and a discussion board for threaded conversations. These capabilities can also be surfaced directly inside Microsoft Teams via tabs, making SharePoint the underlying storage and permissions backbone for Teams-connected teamwork.

Why this answer

SharePoint Online provides a central workspace with document libraries for storing project documents, task lists for assignment, shared calendars for milestones, and discussion boards for threaded conversations. It integrates natively with Microsoft Teams via the SharePoint tab, allowing the team to access all these features directly within the Teams interface without additional configuration.

Exam trap

The trap here is that candidates often confuse Planner or Microsoft Lists as a complete workspace solution, but they lack the document storage, calendar, and threaded discussion capabilities that SharePoint Online provides out-of-the-box.

How to eliminate wrong answers

Option B (Microsoft Lists) is wrong because it is a data-tracking app for creating simple lists (e.g., issue trackers, inventories) but does not include document storage, shared calendars, or threaded discussions out-of-the-box. Option C (Planner) is wrong because it focuses solely on task management with Kanban boards and charts, lacking document libraries, calendars, and threaded discussions. Option D (Project Online) is wrong because it is a premium project management solution for complex scheduling and resource management, not a lightweight central workspace, and its integration with Teams requires additional connectors or third-party tools.

393
MCQeasy

Your company uses Microsoft 365 Business Premium and wants to enable remote wipe of company data on employees' personal mobile devices if they are lost or stolen. Which service provides this capability?

A.Microsoft Intune Mobile Application Management (MAM)
B.Microsoft Entra ID
C.Microsoft Defender for Cloud Apps
D.Microsoft Purview Compliance Manager
AnswerA

Microsoft Intune Mobile Application Management (MAM) is the correct answer because it uses app protection policies that work directly on mobile apps, regardless of device enrollment. These policies enforce data-protection controls such as app-level PIN, encryption, and conditional launch, and critically support selective wipe, which removes only corporate data from an app like Outlook while leaving personal data intact. This makes MAM ideal for BYOD scenarios where employees access company resources from personal devices.

Why this answer

Microsoft Intune Mobile Application Management (MAM) enables selective remote wipe of company data from personal mobile devices without wiping personal data. This is achieved through app-level policies that can remove corporate data from managed apps (e.g., Outlook, Teams) when a device is lost or stolen, using the Intune company portal or a wipe command triggered by an administrator.

Exam trap

The trap here is that candidates often confuse Intune Mobile Device Management (MDM) with Mobile Application Management (MAM), assuming full device wipe is required, but the question specifically asks for selective wipe of company data on personal devices, which is a MAM capability.

How to eliminate wrong answers

Option B (Microsoft Entra ID) is wrong because it is an identity and access management service that handles authentication and authorization, not device or app data wipe capabilities. Option C (Microsoft Defender for Cloud Apps) is wrong because it focuses on cloud app discovery, data loss prevention, and threat detection, not remote wipe of company data from mobile devices. Option D (Microsoft Purview Compliance Manager) is wrong because it is a compliance management tool that helps assess and manage regulatory compliance posture, not a device management or data wipe service.

394
Multi-Selecthard

Which FOUR Microsoft 365 services are part of the Microsoft Defender XDR suite?

Select 4 answers
A.Microsoft Defender for Endpoint
B.Microsoft Defender for Cloud Apps
C.Microsoft Sentinel
D.Microsoft Defender for Office 365
E.Microsoft Defender for Identity
AnswersA, B, D, E

Microsoft Defender for Endpoint natively shares endpoint telemetry with the other Defender XDR workloads, so correlated incidents and automated investigation appear in a single portal. It satisfies the stem's requirement for a constituent service of the suite, unlike standalone compliance or identity products such as Microsoft Entra ID.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across four Defender workloads. Option A, Microsoft Defender for Endpoint, is correct because it is the endpoint detection and response (EDR) pillar that surfaces device alerts and integrates into the XDR incident queue. Option B, Microsoft Defender for Cloud Apps, is correct because it is the Cloud App Security (CASB) component that feeds SaaS and cloud-app telemetry into Defender XDR.

Option D, Microsoft Defender for Office 365, is correct because it protects email, collaboration, and Office apps (phishing, malware, URL detonation) and shares incidents with the suite. Option E, Microsoft Defender for Identity, is correct because it monitors on-premises Active Directory signals (DC sensors) to detect identity-based attacks and is a native XDR pillar. Option C, Microsoft Sentinel, is not part of Defender XDR; it is a separate cloud-native SIEM/SOAR product that can ingest Defender XDR incidents but is licensed and managed independently.

Exam trap

Candidates often mistakenly believe the suite includes only three of these four services or incorrectly include Microsoft Sentinel. In reality, all four Defender components are integral parts of Defender XDR.

395
Multi-Selectmedium

Which TWO Microsoft 365 services can be used to create and manage custom forms for data collection, such as employee feedback surveys?

Select 2 answers
A.SharePoint Online
B.Microsoft Lists
C.Microsoft Forms
D.Excel Online
E.Microsoft Power Apps
AnswersC, E

Microsoft Forms is the dedicated survey and form builder in Microsoft 365, purpose-built for creating quizzes, polls, and data-collection forms. It provides an intuitive designer, branching rules, built-in response analytics, and automatic export of responses to an Excel Online workbook. Because it is natively designed for building and distributing forms, it is one of the two correct services that can directly create and manage forms.

Why this answer

Microsoft Forms is purpose-built for creating custom forms, surveys, and quizzes, with automatic data collection into Excel Online. It provides a simple interface for designing feedback forms and viewing responses in real-time, making it the correct choice for employee feedback surveys.

Exam trap

The trap here is that candidates may confuse Microsoft Lists or SharePoint Online as form-building tools because they can display or store form data, but they lack the native form creation and response management capabilities of Microsoft Forms.

396
MCQmedium

A tenant administrator needs help from Microsoft for a service issue affecting Exchange Online. Which option best matches the requirement?

A.Microsoft Defender for Cloud only
B.Azure Virtual Desktop only
C.Microsoft 365 admin center support request
D.A free personal Microsoft account only
AnswerC

In a Microsoft 365 enterprise tenant, the official and supported method to obtain Microsoft assistance is to create a support request from the Microsoft 365 admin center via the 'Support > New service request' workflow. This process authenticates the administrator with a work or school account that holds the Service Support Administrator role, captures tenant-scoped details, and routes the request to Microsoft's support team with the appropriate priority and service-level agreement. It is the only correct channel listed for a tenant administrator seeking help with a Microsoft 365 service.

Why this answer

The Microsoft 365 admin center is the correct portal for tenant administrators to submit support requests for service issues affecting Exchange Online. It provides direct access to Microsoft's support team, including options for severity-based tickets and service health monitoring, which are essential for resolving production-impacting issues.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud or Azure Virtual Desktop as support portals, but only the Microsoft 365 admin center provides the specific support request workflow for Exchange Online service issues.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a security management tool for hybrid cloud workloads, not a support channel for Exchange Online service issues. Option B is wrong because Azure Virtual Desktop is a desktop and app virtualization service, unrelated to submitting support requests for Exchange Online. Option D is wrong because a free personal Microsoft account (e.g., Outlook.com) cannot access tenant-level support; only a work or school account with appropriate admin roles can create support requests in the Microsoft 365 admin center.

397
MCQeasy

A company uses a cloud provider and is billed monthly based only on the exact amount of storage used and the number of compute hours consumed. They can increase or decrease usage at any time without upfront commitments. Which cloud computing characteristic does this billing model primarily demonstrate?

A.On-demand self-service
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswerC

Measured service is the cloud characteristic where resource usage is automatically metered, monitored, controlled, and reported, enabling a transparent pay-per-use billing model. The scenario's statement that the company is billed monthly based on actual usage is a textbook example of this attribute. It allows the provider to charge only for consumed resources and gives the customer visibility into usage and costs.

Why this answer

The billing model charges only for actual storage used and compute hours consumed, with no upfront commitments and the ability to adjust usage at any time. This directly aligns with the 'measured service' characteristic, where cloud resource usage is metered, monitored, and billed based on consumption. The key is that the provider tracks and reports usage transparently, enabling a pay-per-use model.

Exam trap

The trap here is that candidates confuse 'measured service' with 'rapid elasticity' because both involve scaling, but measured service is specifically about metering and billing, not the speed of scaling.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision resources automatically without human interaction, not the billing mechanism. Option B is wrong because rapid elasticity describes the ability to quickly scale resources up or down, which is a separate characteristic from how usage is metered and billed. Option D is wrong because resource pooling refers to the provider's multi-tenant model where physical and virtual resources are shared among customers, not the consumption-based billing approach.

398
Multi-Selectmedium

A company is expanding globally and needs to meet data residency and compliance requirements in multiple regions. Which three Microsoft 365 compliance and privacy features should they consider? (Choose three.)

Select 3 answers
.Data Loss Prevention (DLP) policies
.Compliance Manager
.Customer Lockbox
.Azure Active Directory (Azure AD) Connect
.Microsoft 365 Copilot
.Exchange Online archival mailboxes

Why this answer

Data Loss Prevention (DLP) policies help organizations identify, monitor, and protect sensitive data across Microsoft 365 services, ensuring compliance with regional data residency requirements by preventing unauthorized sharing or leakage. Compliance Manager provides a centralized dashboard to assess compliance posture against regulations like GDPR, ISO 27001, and local data residency laws, offering actionable recommendations. Customer Lockbox ensures that Microsoft support engineers cannot access customer data without explicit approval, addressing privacy and data sovereignty concerns in multi-region deployments.

Exam trap

The trap here is that candidates confuse Azure AD Connect as a compliance feature because it involves identity management, but it is purely an identity synchronization tool with no direct role in data residency or privacy compliance.

399
MCQhard

A company is evaluating cloud service models for running custom line-of-business applications. They need full control over the operating system and applications, but want to avoid managing physical hardware. Which cloud service model should they choose?

A.Software as a Service (SaaS)
B.Infrastructure as a Service (IaaS)
C.Platform as a Service (PaaS)
D.Function as a Service (FaaS)
AnswerB

IaaS supplies virtualised compute, storage and networking while the customer retains control of the guest operating system and installed applications. This satisfies the requirement for full OS and application control without procuring or maintaining physical servers, unlike PaaS or SaaS.

Why this answer

IaaS provides virtualized compute, storage, and networking where the customer retains full control over the operating system, middleware, and applications while the provider manages the physical hardware, hypervisor, and datacenter. Because the requirement is 'full control over OS and applications' without managing physical hardware, IaaS is the exact fit — the customer patches the OS and deploys their own line-of-business software on provider-managed VMs.

Exam trap

MS-900 often tests the shared responsibility boundary by pairing 'full control over OS' with 'no hardware management' — candidates who reflexively pick PaaS because it sounds 'cloud-native' miss that only IaaS grants OS-level control.

How to eliminate wrong answers

Option A is wrong because SaaS delivers a fully managed, vendor-controlled application where the customer has no access to the OS or application internals, so it cannot host custom line-of-business code with OS-level control. Option C is wrong because PaaS abstracts the OS entirely — the customer deploys code to a managed runtime and cannot control or patch the underlying operating system. Option D is wrong because FaaS (serverless functions) is event-driven and even more abstracted than PaaS, offering no OS control and imposing execution-time and statelessness constraints unsuitable for full custom LOB applications.

400
MCQmedium

A non-profit organization with 150 employees needs business-grade email, online and desktop versions of Office apps, 1 TB cloud storage per user, and the ability to manage user permissions on mobile devices. They are eligible for non-profit licensing. Which plan should they choose to meet all requirements most cost-effectively?

A.Microsoft 365 Business Basic (Nonprofit)
B.Microsoft 365 Business Standard (Nonprofit)
C.Microsoft 365 Business Premium (Nonprofit)
D.Microsoft 365 E3 (Nonprofit)
AnswerC

Microsoft 365 Business Premium combines the full desktop and mobile Office apps with cloud storage and extends them with Microsoft Intune, Azure AD Premium P1, and Microsoft Defender for Business. This gives all 150 users advanced device management, identity-based conditional access, and integrated threat protection while still being licensed under the Business-family model intended for organizations under 300 seats. For a nonprofit, it delivers the specified productivity, storage, and security requirements without the unnecessary compliance depth or higher cost of enterprise-grade plans.

Why this answer

Microsoft 365 Business Premium (Nonprofit) is the correct choice because it includes business-grade email (Exchange Online), desktop and online Office apps, 1 TB OneDrive storage per user, and Microsoft Intune for mobile device management (MDM) to manage user permissions on mobile devices. This plan provides all required capabilities at the lowest cost among options that include desktop apps and MDM, leveraging the nonprofit discount.

Exam trap

The trap here is that candidates often confuse Business Standard (which has desktop apps but no MDM) with Business Premium (which adds MDM), or assume E3 is necessary for mobile device management when Business Premium already includes Intune at a lower cost.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic (Nonprofit) provides only web and mobile versions of Office apps, not the desktop versions required. Option B is wrong because Microsoft 365 Business Standard (Nonprofit) includes desktop apps but lacks mobile device management (MDM) capabilities needed to manage user permissions on mobile devices. Option D is wrong because Microsoft 365 E3 (Nonprofit) includes all features but is significantly more expensive than Business Premium, making it not the most cost-effective choice for a 150-employee organization.

401
MCQeasy

A small business with 10 employees needs the desktop versions of Microsoft 365 apps (Word, Excel, PowerPoint) and 1 TB of cloud storage per user. They do not need business email because they use a separate provider. Which Microsoft 365 plan should they purchase?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Apps for Business
D.Microsoft 365 Business Premium
AnswerC

Microsoft 365 Apps for Business is the correct choice because it delivers the full desktop versions of Office applications (Word, Excel, PowerPoint, Outlook, and others) that can be installed on up to five devices per user, along with 1 TB of OneDrive storage, yet it deliberately excludes Exchange Online email and other collaboration workloads. For a small business that only needs desktop Office, this plan meets the requirement at the lowest cost among the options that provide desktop apps.

Why this answer

Microsoft 365 Apps for Business is the correct plan because it provides the desktop versions of Word, Excel, and PowerPoint along with 1 TB of OneDrive cloud storage per user, but does not include Exchange Online (business email). This matches the requirement exactly, as the customer uses a separate email provider and only needs the Office apps and storage.

Exam trap

The trap here is that candidates often assume Business Standard is the minimum for desktop apps, forgetting that Microsoft 365 Apps for Business is a separate, lower-cost plan that excludes Exchange Online and is specifically designed for organizations that do not need Microsoft-hosted email.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic includes only web and mobile versions of the Office apps (no desktop apps) and includes Exchange Online email, which the customer does not need. Option B is wrong because Microsoft 365 Business Standard includes desktop apps and 1 TB storage but also includes Exchange Online email, making it an unnecessary expense for a customer who already has a separate email provider. Option D is wrong because Microsoft 365 Business Premium includes everything in Business Standard plus advanced security and device management features (e.g., Microsoft Defender, Intune), which are not required and add cost without benefit.

402
MCQmedium

A compliance officer needs to automatically classify and protect documents stored in SharePoint Online that contain personal data such as passport numbers. The classification should happen without user intervention and must apply encryption and access restrictions. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels with auto-labeling
C.eDiscovery (Standard)
D.Communication Compliance
AnswerB

Auto-labeling policies in Microsoft Purview use a classification engine to scan documents and emails for sensitive data types (e.g., credit card numbers, PII) and automatically attach a sensitivity label to each item. The label itself carries protection actions such as encryption via Azure Rights Management, access restrictions, and visual markings, making it the correct tool for automatic classification and protection. Auto-labeling can run client-side in Office apps or service-side across SharePoint, OneDrive, and Exchange, ensuring persistent, metadata-based security controls are applied without user interaction.

Why this answer

Sensitivity labels with auto-labeling (Option B) are the correct solution because they can automatically classify documents based on patterns like passport numbers using trainable classifiers or exact data match (EDM), and then apply encryption and access restrictions via the label's protection settings—all without user intervention. This meets the compliance officer's requirement for automatic classification and protection of personal data in SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP only monitors and blocks sharing actions, while auto-labeling applies persistent protection (encryption and access restrictions) directly to the document content.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy detects and blocks sharing of sensitive data but does not automatically classify or apply persistent encryption and access restrictions to documents; it only triggers alerts or blocks actions. Option C is wrong because eDiscovery (Standard) is used for searching and exporting content for legal or investigative purposes, not for automatic classification or protection of documents. Option D is wrong because Communication Compliance is designed to monitor and detect policy violations in communications like email and Teams, not to classify or protect documents stored in SharePoint Online.

403
MCQeasy

A user reports that they cannot access their email on their mobile device. The IT administrator suspects a device compliance issue. Which Microsoft 365 service can the administrator use to check the device's compliance status?

A.Microsoft Purview compliance portal
B.Microsoft Intune
C.Microsoft Exchange admin center
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Intune is the correct answer because it is the service that manages device compliance and integrates with Conditional Access in Microsoft Entra ID. Intune collects health and configuration signals—such as OS version, jailbreak/root status, encryption, and threat-defense status—and marks a device as compliant or noncompliant. When a user tries to access email on a mobile device, Exchange Online consults Conditional Access, which checks the device's compliance state from Intune and blocks access if the device does not meet policy. This is exactly the mechanism that would prevent a noncompliant device from reaching email.

Why this answer

Microsoft Intune is the correct tool because it is the mobile device management (MDM) and mobile application management (MAM) component of Microsoft 365. It allows administrators to define compliance policies (e.g., requiring encryption, a minimum OS version, or a healthy device attestation) and then check a device's compliance status in real time. When a device is non-compliant, Intune can block access to corporate resources like email, which matches the user's reported issue.

Exam trap

The trap here is that candidates confuse the Microsoft Purview compliance portal (which handles regulatory compliance and data protection) with device compliance (which is a mobile device management function handled exclusively by Intune).

How to eliminate wrong answers

Option A is wrong because the Microsoft Purview compliance portal focuses on data governance, eDiscovery, and compliance management (e.g., retention policies, audit logs), not on checking device compliance status for mobile access. Option C is wrong because the Microsoft Exchange admin center manages mailboxes, transport rules, and mailbox permissions, but it does not have native device compliance checking; it relies on Intune for conditional access decisions. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility into cloud app usage and threat protection, not a device compliance checker for mobile email access.

404
Multi-Selectmedium

Which THREE of the following are benefits of using Microsoft Viva?

Select 3 answers
A.Detects and blocks phishing attacks.
B.Connects employees with company news and resources.
C.Improves employee engagement and well-being.
D.Provides personalized learning and skill development.
E.Backs up user data automatically.
AnswersB, C, D

Viva Connections delivers a tailored digital dashboard and feed inside Teams and SharePoint where employees see company news, policies, tasks, and useful resources from HR and leadership. It centralizes the employee experience with cards for announcements, events, and quick actions, so this is a genuine Viva benefit. This function is distinct from Viva Insights and Viva Learning, which focus on wellbeing and skill development respectively.

Why this answer

Microsoft Viva Connections provides a personalized dashboard that aggregates company news, resources, and communications from SharePoint, Yammer, and Stream, enabling employees to stay informed and engaged directly within Microsoft Teams. This integration reduces information silos and ensures timely access to relevant organizational content.

Exam trap

The trap here is that candidates may confuse Microsoft Viva's employee experience modules (Connections, Insights, Learning) with security or backup features that belong to other Microsoft 365 services like Defender or OneDrive.

405
MCQeasy

A training manager needs to create a simple video that includes screen recordings, webcam overlay, and transitions to announce a new compliance policy. The manager wants to use a Microsoft 365 app that is designed for video creation and editing. Which Microsoft 365 app should the manager use?

A.Microsoft Clipchamp
B.Microsoft Stream
C.Microsoft Teams
D.Microsoft PowerPoint
AnswerA

Clipchamp is Microsoft's web-based video editor included with Microsoft 365 consumer and commercial plans. Its timeline-based editor combines screen recordings, webcam footage, imported images, and audio, then lets you trim clips, add transitions, text overlays, filters, and captions before exporting or publishing. That makes it the appropriate tool for creating a simple training video, because you can produce and polish a finished MP4 in one workflow.

Why this answer

Microsoft Clipchamp is the correct app because it is a dedicated video creation and editing tool included with Microsoft 365, specifically designed for tasks like combining screen recordings, webcam overlays, and transitions. Unlike other Microsoft 365 apps, Clipchamp provides a full timeline-based editor with built-in support for these features, making it ideal for producing a polished compliance policy announcement video.

Exam trap

The trap here is that candidates often confuse Microsoft Stream (a video hosting service) with a video editor, or assume PowerPoint's recording features are sufficient for multi-track video editing, when Clipchamp is the only Microsoft 365 app purpose-built for creating and editing videos with screen recordings, webcam overlays, and transitions.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because Stream is a video hosting and sharing platform, not a video creation or editing tool; it lacks features like screen recording, webcam overlay, and transition editing. Option C (Microsoft Teams) is wrong because Teams is a collaboration and communication app focused on chat, meetings, and file sharing, not a video editor; while it can record meetings, it cannot edit or add transitions to existing recordings. Option D (Microsoft PowerPoint) is wrong because PowerPoint is a presentation software that can record slides with narration and webcam, but it does not support multi-track video editing, screen recording with overlay, or custom transitions between video clips; its video export is limited to slide-based recordings.

406
MCQhard

A multinational corporation needs to restrict access to Microsoft 365 services based on user location and device state. They have offices in countries with strict data sovereignty laws. Which combination of Microsoft Entra ID features should they use to enforce these policies?

A.Microsoft Entra ID Governance
B.Conditional Access with location policies and device compliance
C.Identity Protection and Privileged Identity Management
D.Conditional Access with device compliance policies only
E.Conditional Access with location policies only
AnswerB

Conditional Access with location policies and device compliance provides the precise combination required to restrict access to Microsoft 365 resources. Named locations (configured with trusted IP ranges or countries) allow administrators to block or allow access based on the user's geographic origin. Requiring device compliance ensures that only devices meeting your organization's security policies (e.g., encryption, patch level) can access resources, satisfying both the geolocation and device health requirements concurrently.

Why this answer

Conditional Access in Microsoft Entra ID allows administrators to enforce granular access policies based on signals like user location and device state. By combining location policies (e.g., blocking access from specific countries or requiring trusted IPs) with device compliance policies (e.g., requiring devices to be marked as compliant via Intune or domain-joined), the organization can meet data sovereignty requirements and restrict access based on both criteria simultaneously.

Exam trap

The trap here is that candidates often pick a single-condition option (D or E) because they overlook the requirement to enforce both location and device state simultaneously, or they confuse Identity Protection or Privileged Identity Management with Conditional Access capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Governance focuses on identity lifecycle, access reviews, and entitlement management, not on enforcing real-time access restrictions based on location or device state. Option C is wrong because Identity Protection handles risk-based signals (e.g., leaked credentials, anomalous sign-ins) and Privileged Identity Management manages just-in-time privileged role activation; neither directly enforces location or device compliance policies. Option D is wrong because using only device compliance policies ignores the location requirement, which is essential for data sovereignty compliance.

Option E is wrong because using only location policies ignores the device state requirement, leaving the organization unable to enforce device compliance.

407
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to explain why providers can lower unit costs by operating at large scale. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Economies of scale
D.Data Loss Prevention (DLP)
AnswerC

Economies of scale refer to the cost advantages that Microsoft Azure achieves by operating hyper-scale data centers serving millions of customers. Fixed costs like hardware, cooling, and power are spread across a massive user base, reducing the per-unit cost for each tenant. This allows Microsoft to offer pay-as-you-go pricing that is often cheaper than running a private data center. It is a core cloud benefit and directly answers the stated requirement.

Why this answer

Economies of scale is the correct answer because it directly describes the cost advantage that cloud providers achieve by operating at massive scale. By aggregating compute, storage, and network resources across millions of customers, providers like Microsoft can spread fixed costs (data centers, hardware, cooling, staffing) over a larger base, reducing the per-unit cost for each tenant. This is a foundational cloud concept, not a specific security or productivity feature.

Exam trap

Microsoft often tests the distinction between cloud economic concepts (like economies of scale) and specific security or productivity features, leading candidates to pick a familiar term like 'Data Loss Prevention' instead of the correct foundational principle.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Information Protection (MIP) feature used to classify and protect data based on sensitivity, not a cost or scale concept. Option B is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, unrelated to the economic principle of cost reduction through scale. Option D is wrong because Data Loss Prevention (DLP) is a security policy mechanism that prevents accidental sharing of sensitive data, not a cloud economics concept.

408
MCQmedium

A company wants to ensure that sensitive documents classified as 'Confidential' are automatically encrypted and have restricted access permissions applied when they are shared via email. The protection must persist even if the email is forwarded to external parties. Which Microsoft Purview solution should be used?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Message Encryption
D.Microsoft Purview Compliance Manager
AnswerA

Sensitivity labels in Microsoft Purview Information Protection can apply persistent encryption via Azure Rights Management so that documents carry their own usage restrictions (view, edit, print, forward) wherever they travel. Because the encryption and permissions are embedded in the document itself, the protection remains enforced when the file is sent to external users or copied to another tenant. This is exactly what you need for confidential documents that must stay controlled after they leave the organization.

Why this answer

Microsoft Purview Information Protection (A) is correct because it enables classification and labeling of documents (e.g., 'Confidential'), with built-in encryption and rights management that persists regardless of where the document is shared or forwarded. This is achieved through Azure Rights Management (Azure RMS), which enforces access restrictions even when the email is forwarded to external parties, ensuring the protection travels with the content.

Exam trap

The trap here is that candidates confuse Microsoft Purview Message Encryption (which encrypts the email transport) with Information Protection (which applies persistent rights management to the content itself), leading them to choose C when the question explicitly requires protection that persists after forwarding.

How to eliminate wrong answers

Option B (Microsoft Purview Data Loss Prevention) is wrong because DLP policies detect and prevent accidental sharing of sensitive data but do not apply persistent encryption or access restrictions that survive forwarding; they block or warn at the point of transmission. Option C (Microsoft Purview Message Encryption) is wrong because it encrypts the email message itself (using OME) but does not apply persistent rights management to attachments or documents; once decrypted, the content loses protection. Option D (Microsoft Purview Compliance Manager) is wrong because it is a risk assessment and compliance management tool that tracks regulatory posture, not a solution for applying encryption or access controls to content.

409
MCQeasy

A company is adopting Microsoft 365 and wants to ensure they can investigate security incidents across email, endpoints, and identities in a unified console. Which Microsoft 365 workload should they use?

A.Microsoft Intune
B.Microsoft Sentinel
C.Microsoft Purview Compliance Portal
D.Microsoft Defender XDR
AnswerD

Microsoft Defender XDR is the unified security operations platform native to Microsoft 365, correlating signals from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into a single incident queue. It provides automated investigation and response, an attack story, and threat analytics, enabling security teams to investigate and remediate across email, endpoints, identities, and cloud apps from one console. This directly meets the requirement for Microsoft 365 security incident investigation, making it the correct answer.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified console for investigating security incidents across email, endpoints, and identities. It correlates alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into a single incident queue, enabling cross-domain threat hunting and automated response.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel is for ingesting logs from any source and requires manual correlation, while Defender XDR provides native, automated cross-domain incident correlation specifically for Microsoft 365 workloads.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a Mobile Device Management (MDM) and Mobile Application Management (MAM) service focused on device compliance and app policies, not on security incident investigation across email, endpoints, and identities. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that ingests logs from multiple sources but is not a unified console for Microsoft 365-specific security incidents; it requires separate data connectors and is broader in scope. Option C is wrong because Microsoft Purview Compliance Portal is designed for data governance, compliance management, and eDiscovery, not for real-time security incident investigation across email, endpoints, and identities.

410
MCQmedium

A retail company experiences sudden traffic spikes during holiday sales. Which cloud characteristic would best help them handle this without overprovisioning?

A.Broad network access
B.Measured service
C.Rapid elasticity
D.Resource pooling
AnswerC

Rapid elasticity lets the retailer scale compute and storage outward automatically during holiday demand and release capacity afterwards, paying only for consumption. This satisfies the constraint of handling sudden traffic spikes without overprovisioning fixed on-premises hardware.

Why this answer

(Rapid elasticity) is correct because it enables cloud resources to automatically scale up or down to handle sudden traffic spikes without the need for overprovisioning. Option A (Broad network access) refers to accessibility over the network, not scaling. Option B (Measured service) is about metering and billing for usage.

Option D (Resource pooling) involves multi-tenant sharing of resources.

411
MCQeasy

A sales team needs to create a shared list of customer contact information with custom fields like company, email, phone, and deal stage. The list should be accessible from within Outlook and allow real-time updates by multiple users. Which Microsoft 365 app should they use?

A.Microsoft Lists
B.Microsoft To Do
C.Microsoft Planner
D.Microsoft Dynamics 365
AnswerA

Microsoft Lists is a SharePoint-backed data-tracking app in Microsoft 365 that lets you build a tailored customer contact list with custom columns for name, email, phone, and other fields. It supports real-time multi-user editing, version history, and sorting or filtering, and it appears in Outlook via the "My Lists" entry point or direct list sharing. Because it is built on SharePoint, it can be embedded in Teams and automated with Power Automate, making it the correct fit for a shared, structured list.

Why this answer

Microsoft Lists is the correct choice because it provides a customizable, shared list that supports custom columns (e.g., company, email, phone, deal stage) and real-time collaboration. It integrates directly with Outlook via the Lists app or by adding a list as a tab in Outlook, allowing the sales team to access and update the list without leaving their email client.

Exam trap

The trap here is that candidates may confuse Microsoft Lists with Microsoft To Do or Planner because both involve task tracking, but Lists is the only one that supports custom columns and real-time multi-user editing for structured data like contacts.

How to eliminate wrong answers

Option B is wrong because Microsoft To Do is a personal task management app that does not support custom fields or real-time multi-user editing of shared lists; it lacks the column customization and collaborative features needed. Option C is wrong because Microsoft Planner is designed for team task management with boards and buckets, not for creating a shared list of contacts with custom fields, and it does not integrate directly into Outlook for inline access. Option D is wrong because Microsoft Dynamics 365 is a full Customer Relationship Management (CRM) platform that is far more complex and costly than needed; it is not a simple list app and does not provide the lightweight, Outlook-integrated shared list functionality required.

412
MCQmedium

An organization wants to monitor and respond to security incidents across their Microsoft 365 environment, including email, endpoints, and cloud apps. Which solution should they deploy?

A.Microsoft Intune
B.Microsoft Defender XDR
C.Microsoft Sentinel
D.Microsoft Defender for Office 365
AnswerB

Microsoft Defender XDR (formerly Microsoft 365 Defender) is an integrated XDR service that natively aggregates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. It uses AI and automated response actions to investigate and remediate incidents in a single console, covering email, endpoints, identities, and applications. This exactly matches the requirement to monitor and respond to security incidents across the full Microsoft 365 environment, making it the correct choice.

Why this answer

Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified extended detection and response solution that correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps (Defender for Cloud Apps). It provides a single portal for monitoring and responding to security incidents across the Microsoft 365 environment, making it the correct choice.

Exam trap

MS-900 often tests the difference between XDR (Defender XDR) and SIEM (Sentinel) — candidates may choose Sentinel thinking it covers all Microsoft 365 workloads, but the question specifically asks for integrated monitoring and response across email, endpoints, and cloud apps, which is Defender XDR's role.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device and application management (MDM/MAM) service, not a security incident monitoring and response solution. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution that ingests data from many sources, but it is not specifically the integrated XDR solution for Microsoft 365 workloads; Sentinel is broader and often used alongside Defender XDR. Option D is wrong because Microsoft Defender for Office 365 only covers email and collaboration threats, not endpoints or cloud apps, so it is not the comprehensive cross-domain solution required.

413
MCQmedium

An administrator is reviewing a request from users who need to reduce maintenance of power, cooling, and server replacement. Cloud concept or benefit best matches this requirement?

A.Reduced data center management
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Reduced data centre management describes offloading physical responsibilities — power, cooling, and server replacement — to the cloud provider, who maintains the underlying hardware. The organisation consumes services instead of operating facilities, directly matching the stated requirement.

Why this answer

The users' requirement to reduce maintenance of power, cooling, and server replacement directly maps to the cloud benefit of reduced data center management. By moving to a cloud model, the cloud provider assumes responsibility for the physical infrastructure, including hardware lifecycle, environmental controls, and facility upkeep, allowing the organization to offload these operational burdens.

Exam trap

The trap here is that candidates may confuse operational benefits like reduced maintenance with specific Microsoft 365 features (Planner, DLP, sensitivity labels), failing to recognize that the question is about fundamental cloud concepts and benefits, not individual product capabilities.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management and planning application within Microsoft 365, not a cloud concept or benefit related to infrastructure maintenance. Option C is wrong because Data Loss Prevention (DLP) is a security policy technology that helps protect sensitive data from unauthorized sharing or leakage, not a benefit addressing physical data center maintenance. Option D is wrong because sensitivity labels are classification and protection tools applied to data and documents for governance and compliance, not a cloud concept that reduces power, cooling, or server replacement tasks.

414
Multi-Selectmedium

A company uses Microsoft 365 E3 and wants to implement a collaboration solution that allows multiple users to co-author documents in real time, track version history, and set permissions at the document level. Which THREE Microsoft 365 services can fulfill these requirements?

Select 3 answers
A.SharePoint Online
B.OneDrive for Business
C.Microsoft Teams
D.Exchange Online
E.Yammer
AnswersA, B, C

SharePoint Online satisfies the co-authoring, version history and document-level permission requirements through its document libraries, which store files in OneDrive-backed storage and enforce item-level permissions via Microsoft Entra ID security groups. Real-time co-authoring uses the Office co-authoring service, while version history retains prior copies within each library.

Why this answer

SharePoint Online (A) is correct because it provides document libraries with real-time co-authoring in Office apps, built-in version history, and item-level (document-level) permissions via SharePoint groups and unique permission inheritance breaks. OneDrive for Business (B) is correct because it is built on the same SharePoint document library engine, so it also supports real-time co-authoring, version history, and per-file sharing permissions for individual users. Microsoft Teams (C) is correct because its Files tab is backed by SharePoint Online or OneDrive, enabling real-time co-authoring, version tracking, and document-level permission management directly within team and channel contexts.

Exchange Online (D) is incorrect because it is a mail, calendaring, and messaging service, not a document collaboration or permission platform. Yammer (E) is incorrect because it is an enterprise social networking service for conversations and communities, not a document co-authoring or version-control solution.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a separate collaboration tool, but Teams relies on SharePoint Online and OneDrive for its file storage and co-authoring capabilities, making it a valid answer when the question explicitly asks for services that fulfill the requirements directly.

415
MCQmedium

A compliance officer needs to identify users who are at risk of leaking sensitive data based on their activities such as copying files to USB drives or emailing content outside the organization. The solution must also allow reviewing the activities in a case-based workflow. Which Microsoft Purview solution should they use?

A.Microsoft Purview Data Loss Prevention
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Audit (Premium)
D.Microsoft Purview Communication Compliance
AnswerB

Microsoft Purview Insider Risk Management is the correct solution because it correlates signals from audit logs, DLP alerts, and other behavioral indicators to mathematically assess a user's risk of insider activity. It uses predefined and customizable policies to detect anomalies such as mass file downloads, unusual access times, or exfiltration attempts, and then places the user in a triage space with a case-based workflow. This is specifically designed to help compliance officers identify, investigate, and act on users who are at risk of committing data leaks.

Why this answer

Microsoft Purview Insider Risk Management is specifically designed to detect, investigate, and act on risky user activities that could lead to data leaks, such as copying files to USB drives or emailing sensitive content externally. It provides a case-based workflow for reviewing and managing these activities, aligning directly with the compliance officer's requirements.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with Insider Risk Management, but DLP is a preventive control that blocks actions in real-time, whereas Insider Risk Management is a detective control that identifies risky users and provides a case workflow for post-event review.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention (DLP) focuses on preventing data leaks through policies that block or warn users in real-time, but it does not provide a case-based workflow for reviewing activities after they occur. Option C is wrong because Microsoft Purview Audit (Premium) logs user and admin activities for forensic investigation but lacks the risk analysis, user risk scoring, and case management workflow needed to identify at-risk users proactively. Option D is wrong because Microsoft Purview Communication Compliance is designed to detect policy violations in communications (e.g., harassment, insider trading) and does not cover activities like copying files to USB drives or emailing content outside the organization.

416
MCQeasy

An e-commerce website hosted on a cloud provider automatically adds more virtual machines to handle increased traffic during Black Friday and removes them after the event. Which cloud characteristic does this illustrate?

A.Rapid elasticity
B.On-demand self-service
C.Resource pooling
D.Measured service
AnswerA

Rapid elasticity is the correct NIST characteristic because it enables the cloud to automatically provision and release compute resources—such as VMs—in response to fluctuating demand. In this scenario, the e-commerce site's traffic spikes trigger an immediate increase in VM instances, and when traffic subsides, those instances are automatically deprovisioned, making the resource pool appear infinite and highly responsive.

Why this answer

Rapid elasticity is the cloud characteristic that enables resources to scale out (add VMs) automatically in response to demand spikes like Black Friday traffic, and scale in (remove VMs) when demand subsides. This is distinct from manual scaling because it happens automatically and dynamically, often using autoscaling policies tied to metrics such as CPU utilization or request count.

Exam trap

The trap here is that candidates confuse 'rapid elasticity' with 'on-demand self-service' because both involve automation, but elasticity specifically refers to automatic scaling in response to load, not just the ability to provision resources on demand.

How to eliminate wrong answers

Option B (On-demand self-service) is wrong because it refers to a user provisioning resources without human intervention, not the automatic scaling of resources in response to load. Option C (Resource pooling) is wrong because it describes the provider's multi-tenant model where physical and virtual resources are shared across customers, not the ability to scale up/down. Option D (Measured service) is wrong because it involves metering resource usage for billing and optimization, not the dynamic adjustment of capacity.

417
MCQmedium

An administrator needs to monitor and investigate potential data breaches by reviewing detailed records of file access and sharing activities across Microsoft 365. They require a centralized report showing who accessed what, from where, and any unusual patterns. Which tool should they use?

A.Microsoft 365 Defender
B.Microsoft Purview Audit (Standard)
C.Microsoft Purview eDiscovery
D.Microsoft Secure Score
AnswerB

Microsoft Purview Audit (Standard) is the correct tool because it records timestamped events for user and admin actions across Exchange, SharePoint, OneDrive, Teams, and Azure AD. Investigators can query the unified audit log to identify exactly when a file was accessed, downloaded, shared, or deleted and which account performed the action. This historical, activity-level evidence is essential for monitoring, triaging, and thoroughly investigating a potential data breach, with default retention of 90 days for standard events.

Why this answer

Microsoft Purview Audit (Standard) is the correct tool because it provides a centralized, searchable log of all file access and sharing activities across Microsoft 365 services, including who accessed what, from which IP address, and when. This allows administrators to detect and investigate unusual patterns indicative of data breaches by reviewing detailed audit records.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Defender (a threat protection tool) with audit logging, but the question specifically asks for a centralized report of historical file access and sharing activities, which only Purview Audit provides.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Defender is a security incident response and threat protection platform that focuses on detecting and responding to active threats (like malware or phishing), not on providing detailed historical audit logs of file access and sharing activities. Option C is wrong because Microsoft Purview eDiscovery is designed for legal discovery and compliance searches to find and export content (e.g., emails, documents) for litigation, not for monitoring real-time or historical access patterns. Option D is wrong because Microsoft Secure Score is a security posture assessment tool that measures an organization's security configuration against best practices, not a logging or monitoring tool for file access activities.

418
MCQeasy

A company uses a cloud service that provides virtual machines. The company manages the operating system, middleware, and applications, while the cloud provider manages the physical hardware, networking, and data center security. Which cloud service model does this represent?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerA

IaaS (Infrastructure as a Service) delivers virtualized compute resources as ready-to-use VMs, and the customer retains full control over the guest operating system, runtime, and application stack. The cloud provider is responsible for the physical hosts, the hypervisor, and the data-center networking, while the customer patches, configures, and secures the OS. In this scenario, the company is using a cloud service that provides virtual machines, which directly matches the IaaS delivery model.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer manages the operating system, middleware, and applications, while the cloud provider is responsible for the physical hardware, networking, and data center security. In IaaS, the provider delivers virtualized computing resources over the internet, and the customer retains control over the guest OS, storage, and deployed applications, which matches the division of responsibilities given.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve virtual machines, but PaaS abstracts the OS and middleware, so the key differentiator is who manages the operating system and middleware—if the customer manages them, it is IaaS.

How to eliminate wrong answers

Option B (PaaS) is wrong because in Platform as a Service, the provider manages the operating system, middleware, and runtime environment, leaving the customer to only deploy and manage their own applications and data, not the OS or middleware. Option C (SaaS) is wrong because in Software as a Service, the provider manages the entire application stack, including the operating system, middleware, and applications, and the customer only uses the software via a web browser or client, with no management of the underlying infrastructure. Option D (DaaS) is wrong because Desktop as a Service delivers virtual desktops to end users, where the provider manages the desktop OS and underlying infrastructure, and the customer typically does not manage the OS or middleware as described.

419
MCQeasy

A project team needs a central location to store and collaborate on project documents, with version history, co-authoring, and the ability to share files securely with external partners. Which Microsoft 365 service provides these capabilities?

A.Exchange Online
B.SharePoint Online
C.Microsoft Stream
D.Microsoft Viva Engage
AnswerB

SharePoint Online provides managed document libraries designed for persistent team collaboration. It supports versioning, real-time co-authoring, metadata, workflows, and external sharing controls, all on a single secure platform. Site permissions can be scoped by site, library, folder, or item, making it the appropriate central location for the project team's content.

Why this answer

SharePoint Online is the correct choice because it provides a centralized document library with version history, real-time co-authoring via Office Online integration, and granular external sharing controls through secure links or direct invitations. These capabilities align directly with the project team's need for collaborative document management and secure external partner access.

Exam trap

The trap here is that candidates confuse Exchange Online's file attachments (which lack version history and co-authoring) with a proper document management system, or mistakenly think Microsoft Stream's sharing features equate to collaborative document editing.

How to eliminate wrong answers

Option A is wrong because Exchange Online is an email and calendaring service based on the MAPI/HTTP protocol, not a document storage or collaboration platform; it lacks version history and co-authoring for files. Option C is wrong because Microsoft Stream is a video hosting and sharing service for enterprise video content, not designed for document collaboration or version control. Option D is wrong because Microsoft Viva Engage (formerly Yammer) is a social networking and employee engagement tool focused on communities and conversations, not structured document management or secure external file sharing.

420
MCQhard

A company wants to automate approval workflows for expense reports. Which Microsoft 365 service should they use?

A.Microsoft Planner
B.Microsoft Forms
C.SharePoint
D.Power Automate
AnswerD

Power Automate is the correct service because it provides a dedicated workflow automation platform with a built-in approval action that supports multiple approvers, conditional routing, and integration with Microsoft 365 services like Outlook, Teams, and SharePoint. Using the 'When a new expense report is submitted' trigger (e.g., from Forms or SharePoint), you can create a flow that sends an approval request, waits for the approver's response, and then updates a status or sends a notification — all without requiring custom code. This directly fulfills the requirement to automate approval workflows for expense reports.

Why this answer

Power Automate is the correct service because it provides workflow automation capabilities, including the ability to create approval workflows for expense reports. It integrates with various Microsoft 365 services and third-party apps, allowing users to design automated processes that trigger approvals based on specific conditions, such as submission of an expense report via email or SharePoint.

Exam trap

The trap here is that candidates may confuse SharePoint's ability to host documents and trigger workflows with being the actual automation engine, but SharePoint requires Power Automate (or legacy SharePoint Designer) to execute the approval logic.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing work among teams, not a workflow automation service; it lacks the ability to create automated approval processes. Option B is wrong because Microsoft Forms is used for creating surveys and quizzes, not for automating workflows; it can collect data but cannot initiate or manage approval workflows. Option C is wrong because SharePoint is a document management and collaboration platform that can store expense reports and trigger workflows via Power Automate, but it does not natively provide the automation engine itself; SharePoint alone cannot create or run approval workflows without Power Automate or SharePoint Designer.

421
MCQmedium

A company with 40 users needs email, Teams, web Office apps, and cloud file storage but not desktop Office apps. Which option best matches the requirement?

A.A free personal Microsoft account only
B.Microsoft 365 Business Basic
C.Azure Virtual Desktop only
D.Microsoft Defender for Cloud only
AnswerB

Microsoft 365 Business Basic is a commercial plan that includes Exchange Online for hosted email, Microsoft Teams, SharePoint Online, OneDrive for Business, and browser-based (web/mobile) versions of Office apps like Word, Excel, and PowerPoint. For 40 users, it provides an Azure AD-backed tenant with centralized admin, user management, security, and compliance features. Because the requirement mentions web Office apps rather than desktop installations, this plan is the most appropriate and cost-effective choice, and it is the correct answer.

Why this answer

Microsoft 365 Business Basic provides Exchange Online for email, Teams for collaboration, web versions of Office apps (Word, Excel, PowerPoint), and OneDrive for cloud file storage — all without including desktop Office apps. This plan is designed specifically for organizations that need cloud productivity tools but not locally installed Office applications, matching the 40-user requirement exactly.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Basic with Microsoft 365 Business Standard (which includes desktop Office apps), or mistakenly think a free personal account can serve business needs, overlooking the lack of centralized administration, business-grade security, and collaboration features like Teams.

How to eliminate wrong answers

Option A is wrong because a free personal Microsoft account (e.g., Outlook.com) does not include Teams for business, lacks administrative controls for a company of 40 users, and offers only limited cloud storage without enterprise-grade security or compliance features. Option C is wrong because Azure Virtual Desktop only provides virtualized Windows desktops and apps, not the core services of email, Teams, web Office apps, or cloud file storage — it is a delivery platform, not a subscription that includes those services. Option D is wrong because Microsoft Defender for Cloud is a cloud security posture management and workload protection service, not a productivity suite; it does not provide email, Teams, Office apps, or file storage.

422
MCQeasy

A company with 500 Microsoft 365 Business Premium users encounters a critical service outage that prevents all users from accessing email. They need to report the incident and expect a response within 1 hour. Which support option should they use to achieve this while keeping additional costs as low as possible?

A.Create a service request through the Microsoft 365 admin center, which includes a standard support incident.
B.Purchase a Microsoft Professional Direct support subscription and submit a Severity A incident.
C.Purchase a Microsoft Premier Support plan and submit a critical incident.
D.Post the issue in the Microsoft 365 Tech Community forum.
AnswerB

Purchasing Microsoft Professional Direct support provides a formal SLA for response times, including a guaranteed 1-hour response for Severity A incidents, which are defined as critical issues that require immediate action. This plan is the most cost-effective paid option for a 500-user company because it offers the required SLA without the higher cost of Premier Support. Submitting a Severity A incident under this plan ensures Microsoft engineers are contractually obligated to respond within the 1-hour window.

Why this answer

Microsoft 365 Business Premium includes only standard support incidents with no guaranteed response time. To achieve a 1-hour response for a critical outage (Severity A), you need a paid support plan. The Professional Direct support subscription is the most cost-effective option that provides a 1-hour response for Severity A incidents, making option B correct.

Exam trap

The trap here is that candidates assume standard support included with Microsoft 365 Business Premium provides a fast response for critical issues, but Microsoft explicitly excludes SLA guarantees for standard support, requiring a paid plan like Professional Direct for a 1-hour response.

How to eliminate wrong answers

Option A is wrong because standard support incidents included with Microsoft 365 Business Premium do not offer a guaranteed response time; they are typically handled within 8 hours or more, not within 1 hour. Option C is wrong because while Premier Support can provide a 1-hour response for critical incidents, it is significantly more expensive than Professional Direct and is overkill for this requirement, as Professional Direct already meets the need at lower cost. Option D is wrong because the Microsoft 365 Tech Community forum is a peer-to-peer discussion platform with no formal support SLA or guaranteed response time, and it cannot be used to report a critical service outage requiring a 1-hour response.

423
Multi-Selecthard

Which THREE Microsoft 365 services are part of Microsoft Defender XDR (Extended Detection and Response)? (Select three.)

Select 3 answers
A.Microsoft Defender for Endpoint
B.Microsoft Purview
C.Microsoft Defender for Identity
D.Microsoft Sentinel
E.Microsoft Defender for Office 365
AnswersA, C, E

Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution that provides antivirus, attack surface reduction, endpoint detection and response (EDR), and vulnerability management for Windows, macOS, Linux, iOS, and Android devices. It is one of the core signal suppliers to Microsoft Defender XDR, whose unified incident engine correlates device telemetry with identity and email alerts. In this question it is correct because it represents the device-protection workload of Microsoft 365 Defender.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is a unified security suite that correlates signals across endpoints, identities, and email/collaboration. Microsoft Defender for Endpoint is correct because it provides endpoint detection and response (EDR) capabilities, collecting telemetry from Windows, macOS, Linux, Android, and iOS devices to detect and remediate advanced threats.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with a component of Defender XDR, but Sentinel is a separate Azure service that ingests logs from Defender XDR rather than being part of the XDR product itself.

424
MCQeasy

Your organization wants to provide employees with a personalized news feed and internal communications dashboard. Which Microsoft 365 service should you use?

A.Microsoft Stream
B.Microsoft Viva Topics
C.Microsoft Viva Connections
D.SharePoint Online
AnswerC

Microsoft Viva Connections is the correct choice because it provides a personalized employee dashboard that aggregates corporate news, targeted communications, and frequently used resources into a single, navigable interface. It is built on SharePoint and delivered as a Teams app, using audience targeting and Microsoft Graph to tailor content to each user's role, location, or department. Viva Connections also integrates with Viva Engage and other Viva modules, making it the dedicated entry point for internal communications and daily employee tasks.

Why this answer

Microsoft Viva Connections is the correct choice because it provides a personalized news feed and internal communications dashboard directly within Microsoft Teams. It aggregates content from SharePoint, Yammer, and other sources to create a curated employee experience, aligning with the requirement for a centralized communications hub.

Exam trap

The trap here is that candidates often confuse SharePoint Online's news web part with Viva Connections' personalized dashboard, but Viva Connections is the dedicated service for a unified, personalized employee experience within Teams.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video management and sharing service, not a news feed or communications dashboard. Option B is wrong because Microsoft Viva Topics uses AI to organize knowledge into topic pages, but it does not provide a personalized news feed or internal communications dashboard. Option D is wrong because SharePoint Online is a document management and collaboration platform that can host news posts, but it lacks the personalized, dashboard-style aggregation and integration with Teams that Viva Connections offers.

425
MCQhard

An organization uses Microsoft Bookings to manage customer appointments. Staff need to see their Bookings calendar within Outlook. What must be configured?

A.Configure calendar sharing between Bookings and Outlook.
B.Run a PowerShell script to sync calendars.
C.Add staff members to the Bookings calendar.
D.Integrate Bookings with Dynamics 365.
AnswerC

Adding staff members to the Bookings calendar is the correct action because it is the explicit step that enables the automatic Outlook integration. When staff are added, they are granted access to the underlying Exchange Online mailbox that stores Bookings appointments, and Exchange's auto-mapping feature automatically surfaces those booking items in each staff member's own Outlook calendar, requiring no manual configuration.

Why this answer

For staff to see their Bookings calendar within Outlook, they must be added as staff members in the Bookings calendar. This automatically creates a Bookings-specific calendar in their Outlook that syncs appointments. No additional sharing or scripting is required.

Exam trap

The trap here is that candidates may think additional sharing or scripting is required, but Microsoft has designed Bookings to automatically integrate with Outlook once staff membership is configured, making the other options unnecessary overhead.

How to eliminate wrong answers

Option A is wrong because calendar sharing between Bookings and Outlook is not a separate configuration step; the integration is built-in once staff are added. Option B is wrong because no PowerShell script is needed to sync calendars; the synchronization happens automatically via Exchange Web Services (EWS) when staff are members. Option D is wrong because integrating Bookings with Dynamics 365 is an advanced feature for customer relationship management, not a prerequisite for staff to see their Bookings calendar in Outlook.

426
Multi-Selectmedium

Which three options describe key capabilities of Microsoft Purview that help organizations manage compliance and data governance in Microsoft 365? (Choose three.)

Select 3 answers
.Automatically classify and label sensitive data across Microsoft 365 services
.Apply retention policies and labels to preserve or delete content based on legal requirements
.Conduct eDiscovery searches and hold content for legal cases
.Manage user passwords and enforce multi-factor authentication
.Monitor network traffic to prevent DDoS attacks
.Provide anti-malware and phishing protection in email

Why this answer

Microsoft Purview provides integrated data governance and compliance capabilities across Microsoft 365. It automatically classifies and labels sensitive data using trainable classifiers and exact data match, applies retention policies and labels to meet legal and regulatory requirements, and enables eDiscovery searches with legal hold to preserve content for litigation. These three capabilities directly address data classification, lifecycle management, and legal discovery.

Exam trap

The trap here is that candidates confuse Microsoft Purview with other Microsoft 365 security services like Microsoft Entra ID (identity) or Microsoft Defender (threat protection), leading them to select options that are valid security features but not part of Purview's compliance and data governance scope.

427
MCQmedium

An organization uses Microsoft 365 Copilot and wants to ensure that Copilot responses are based only on data the user has permission to access. Which principle does this enforce?

A.Defense in depth
B.Segregation of duties
C.Zero Trust
D.Least privilege
AnswerD

Least privilege ensures Copilot responses surface only content the signed-in user already has permission to access, because Copilot inherits the user's existing Microsoft 365 permissions. This satisfies the constraint that responses must respect each user's access rights.

Why this answer

Microsoft 365 Copilot respects the permissions of the signed-in user, meaning it only surfaces data the user already has access to. This enforces the principle of least privilege by ensuring users cannot use Copilot to access information beyond their authorized scope. It does not grant new access; it inherits existing access controls.

Exam trap

MS-900 often tests the distinction between security principles — candidates may pick Zero Trust because it sounds more comprehensive, but the specific enforcement of user permissions is least privilege.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered security strategy, not the specific principle that Copilot enforces regarding data access permissions. Option B is wrong because segregation of duties is about separating critical tasks among different people to prevent fraud, not about data access based on user permissions. Option C is wrong because Zero Trust is a broader security model that assumes no implicit trust, but the specific behavior described — Copilot only using data the user can access — is a direct application of least privilege.

428
MCQeasy

A company wants to ensure that all Microsoft 365 users authenticate using multi-factor authentication (MFA). Which Microsoft 365 security feature should they configure?

A.Microsoft Intune compliance policies
B.Microsoft Purview Data Loss Prevention
C.Microsoft Defender XDR
D.Microsoft Entra ID Conditional Access
AnswerD

Microsoft Entra ID Conditional Access is the correct solution because it enables administrators to build granular policies that evaluate sign-in risk, location, device compliance, and user attributes, and then require MFA as one of the access controls. By targeting all users or specific groups, an organization can ensure MFA is enforced for every authentication attempt, satisfying the requirement.

Why this answer

Microsoft Entra ID Conditional Access is the policy engine that evaluates signals (user, device, location, application, risk) and enforces access decisions, including requiring MFA. To ensure all Microsoft 365 users authenticate with MFA, an administrator creates a Conditional Access policy targeting all users and all cloud apps (or the Office 365 app suite) with a grant control of 'Require multifactor authentication.' This is the native, centralized mechanism for enforcing MFA across Microsoft 365 workloads.

Exam trap

MS-900 often tests the misconception that Intune compliance policies or Defender XDR enforce MFA, when in fact Conditional Access is the policy engine that requires MFA and can use compliance or risk as conditions.

How to eliminate wrong answers

Option A is wrong because Intune compliance policies evaluate device health (OS version, encryption, jailbreak status) and mark devices compliant or non-compliant; they do not themselves enforce MFA — they can be used as a condition in Conditional Access, but they are not the MFA enforcement feature. Option B is wrong because Microsoft Purview Data Loss Prevention identifies and protects sensitive data (e.g., credit card numbers, PHI) in emails, documents, and endpoints; it has no role in authentication or MFA enforcement. Option C is wrong because Microsoft Defender XDR is a threat detection and response platform that correlates signals across endpoints, identities, email, and cloud apps; while it can feed risk signals into Conditional Access, it does not configure or enforce MFA.

429
MCQmedium

A department asks for the Microsoft 365 service best suited for interactive business dashboards. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Purview Compliance Manager
B.Power BI
C.Microsoft Defender for Endpoint
D.Microsoft Entra Privileged Identity Management
AnswerB

Power BI delivers interactive dashboards natively, with no custom operational scripts required. Its semantic models and scheduled refresh handle data preparation, satisfying the stem's constraint directly. Unlike Excel or bespoke reporting, Power BI provides governed, shareable visualisations through Microsoft Fabric and Microsoft Entra ID authentication, matching the department's stated need.

Why this answer

Power BI is the correct choice because it is Microsoft's dedicated business analytics service that enables users to create interactive dashboards and reports from various data sources. It provides drag-and-drop visualization tools, real-time data refresh, and natural language querying (Q&A) without requiring custom operational scripts, aligning perfectly with the department's requirement for no-code dashboard creation.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's compliance dashboards (which are static compliance scorecards) with interactive business dashboards, or assume that security tools like Defender for Endpoint include business analytics features, leading them to select a wrong option that sounds 'dashboard-like' but serves a completely different purpose.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that assesses and reports on an organization's compliance posture against regulations; it does not create interactive business dashboards. Option C is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response; it is not designed for business analytics or dashboarding. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged access to Azure AD and Azure resources; it has no capability for building interactive dashboards.

430
MCQmedium

An organization uses Microsoft Teams and wants to record meetings for compliance purposes. Which Microsoft 365 service provides meeting recording with automatic transcription?

A.Microsoft OneDrive
B.Microsoft Teams meeting recording
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Microsoft Teams meeting recording is the native feature that captures the meeting's audio, video, screen sharing, and chat transcript. The organizer or a presenter clicks the record button in the meeting controls, and the recording is then processed, transcribed, and stored for playback. It is the only correct method to record a Teams meeting directly.

Why this answer

Microsoft Teams meeting recording with automatic transcription is a native feature of Teams itself, not a separate service. When a meeting is recorded, Teams stores the recording in OneDrive or SharePoint, but the recording and transcription capabilities are part of the Teams meeting experience. Option B is correct because Teams meeting recording directly provides the recording and automatic transcription for compliance purposes.

Exam trap

Microsoft often tests the misconception that Microsoft Stream is the service that provides meeting recording and transcription, but in reality, Stream is only a playback and management interface, while the recording and transcription are native Teams features.

How to eliminate wrong answers

Option A is wrong because Microsoft OneDrive is a cloud storage service that stores the recorded file after the meeting, but it does not provide the meeting recording or transcription functionality itself. Option C is wrong because Microsoft Forms is a survey and quiz tool, not a meeting recording or transcription service. Option D is wrong because Microsoft Stream (classic) was previously used for storing and managing meeting recordings, but as of 2023, Teams meeting recordings are stored in OneDrive/SharePoint, and Stream (on SharePoint) is a video playback portal, not the service that performs recording or transcription.

431
MCQeasy

While preparing a Microsoft 365 adoption plan, a consultant is asked to avoid buying servers upfront and pay monthly based on usage. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Operational expenditure (OpEx) model
D.Microsoft Planner
AnswerC

The OpEx model satisfies the requirement to avoid upfront server purchases by shifting costs to monthly, usage-based payments. Unlike capital expenditure, which demands significant initial hardware investment, OpEx aligns spending with consumption, directly matching the consultant's mandate to eliminate upfront infrastructure costs while maintaining Microsoft 365 services.

Why this answer

The operational expenditure (OpEx) model is correct because it aligns with the requirement to avoid upfront capital investment (CapEx) and instead pay monthly based on usage. In Microsoft 365, this is delivered through subscription-based licensing (e.g., per-user per-month plans), which shifts costs from large upfront server purchases to predictable monthly payments that scale with consumption.

Exam trap

The trap here is that candidates may confuse 'operational expenditure' with a specific tool or feature (like Planner or DLP) because they focus on the word 'plan' in the question, rather than recognizing that OpEx is a fundamental cloud financial model distinct from any product or security feature.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data (e.g., encrypt emails or mark documents as confidential), not a financial or deployment model. Option B is wrong because Data Loss Prevention (DLP) is a policy-based security feature that detects and prevents accidental sharing of sensitive information (e.g., credit card numbers), not a cost or procurement model. Option D is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365 (part of the Power Platform and Teams), not a cloud concept or benefit related to payment or infrastructure.

432
MCQhard

Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that users can access their mailboxes using Outlook for Windows without re-entering credentials each time. Which Microsoft 365 service should you configure to enable single sign-on (SSO) and modern authentication?

A.Microsoft Entra ID
B.Microsoft Intune
C.Microsoft Purview
D.Microsoft Sentinel
AnswerA

Microsoft Entra ID is the cloud identity and access management service (previously Azure AD) that provides authentication, single sign-on, and conditional access for Exchange Online. When migrating from on-premises Exchange, you must synchronize and authenticate user identities to access mailboxes, using protocols like OAuth 2.0 and modern authentication. Without Entra ID, Exchange Online cannot verify user credentials or enforce MFA.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the identity and access management service that provides single sign-on (SSO) and modern authentication (OAuth 2.0, OpenID Connect) for Exchange Online. When configured, Outlook for Windows can use the Microsoft Entra ID token to authenticate silently, eliminating the need for users to re-enter credentials each time they access their mailbox.

Exam trap

The trap here is that candidates confuse Microsoft Intune (device management) with identity services, or assume that any Microsoft 365 security or management tool can enable SSO, when only the identity provider (Microsoft Entra ID) can issue authentication tokens for modern auth.

How to eliminate wrong answers

Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service; it does not handle authentication or SSO for Exchange Online. Option C is wrong because Microsoft Purview is a compliance and data governance solution (e.g., data loss prevention, eDiscovery); it has no role in enabling SSO or modern authentication. Option D is wrong because Microsoft Sentinel is a cloud-native security information and event management (SIEM) service; it is used for threat detection and response, not for identity-based authentication.

433
MCQhard

Fabrikam Inc. is a technology company that uses Microsoft 365 E5. They have implemented Microsoft Defender XDR to monitor for threats. The security team wants to receive alerts when a user is compromised, such as when a user's credentials are used from an unusual location. They also want to automatically block the user from signing in until the risk is mitigated. You need to configure a solution that automatically detects and responds to such identity risks. What should you configure?

A.Enable Microsoft Defender for Cloud Apps to monitor user activities.
B.Configure Identity Protection in Microsoft Entra ID to detect risky sign-ins and enable the 'User risk policy' to automatically block high-risk users.
C.Deploy Microsoft Sentinel and create analytics rules to detect and respond to identity threats.
D.Create a Conditional Access policy that requires MFA for all sign-ins.
AnswerB

Identity Protection evaluates sign-in telemetry for anomalous location and other risk signals, raising user risk automatically. The user risk policy then enforces the required response, blocking high-risk accounts from signing in until remediation, which meets the automatic detection and blocking requirement.

Why this answer

Microsoft Entra ID Identity Protection detects risky sign-ins and user risk, and allows configuring risk policies to automatically block or require password change for high-risk users. The 'User risk policy' can block access when user risk is high, which meets the requirement to automatically block compromised users. This is the native solution for identity risk detection and response.

Exam trap

MS-900 often tests the difference between Identity Protection and Conditional Access; candidates may choose a generic MFA policy instead of the risk-based policy that automatically blocks high-risk users.

How to eliminate wrong answers

Option A is wrong because Defender for Cloud Apps monitors user activities but does not automatically block sign-ins based on identity risk; it focuses on cloud app security. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution that requires custom analytics rules and automation, not an out-of-the-box identity risk response. Option D is wrong because a Conditional Access policy requiring MFA for all sign-ins does not specifically detect risky sign-ins or block high-risk users; it applies MFA broadly but not based on risk.

434
Multi-Selecthard

Which TWO Microsoft 365 compliance features are available in Microsoft Purview to help organizations manage and protect sensitive data?

Select 2 answers
A.Microsoft Defender for Cloud Apps
B.Data Lifecycle Management
C.Microsoft Entra ID Protection
D.Microsoft Defender XDR
E.Data Loss Prevention (DLP)
AnswersB, E

Data Lifecycle Management is a Microsoft Purview compliance solution that enables organizations to define retention and deletion policies for content across workloads such as Exchange, SharePoint, OneDrive, and Teams. It helps meet legal, regulatory, and business requirements by ensuring data is retained only as long as necessary and then systematically disposed of, reducing risk of over-retention or premature deletion.

Why this answer

Data Lifecycle Management (B) is correct because it enables organizations to govern their data through retention policies and retention labels, automatically retaining or deleting content based on regulatory requirements. Data Loss Prevention (DLP) (E) is correct because it identifies, monitors, and protects sensitive data across Microsoft 365 services (Exchange, SharePoint, OneDrive, Teams) by applying policies that prevent unauthorized sharing or leakage.

Exam trap

Microsoft often tests the distinction between security tools (Defender, Entra ID Protection) and compliance tools (Purview features), so candidates mistakenly select Defender for Cloud Apps or Defender XDR because they associate 'protect sensitive data' with security rather than data governance and loss prevention.

435
MCQeasy

A company uses a cloud provider that hosts multiple customers on the same physical servers. Each customer's data and applications are isolated, but customers have no knowledge or control over the exact physical location of their resources. Which cloud characteristic does this describe?

A.Resource pooling
B.Rapid elasticity
C.On-demand self-service
D.Measured service
AnswerA

Resource pooling is the cloud characteristic that lets a provider serve many customers, or tenants, from shared physical infrastructure—servers, storage, and network—while isolating each tenant's data and workloads through virtualization and access controls. In Microsoft 365, this means compute and storage capacity are pooled across customers but logically segmented per tenant. This directly matches the scenario's wording, so it is the correct answer.

Why this answer

Resource pooling is the correct answer because the scenario describes a multi-tenant model where the cloud provider's physical and virtual resources are pooled to serve multiple customers, with isolation between tenants. Customers have no knowledge or control over the exact physical location of their resources, which is a defining characteristic of resource pooling as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates often confuse resource pooling with rapid elasticity because both involve shared infrastructure, but resource pooling specifically focuses on multi-tenancy and location transparency, not dynamic scaling.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because it refers to the ability to quickly scale resources up or down based on demand, not to multi-tenant isolation or location transparency. Option C (On-demand self-service) is wrong because it describes the capability for a user to provision computing capabilities automatically without requiring human interaction with the provider, not the pooling of resources across customers. Option D (Measured service) is wrong because it involves metering and billing based on usage (e.g., pay-per-use), not the sharing of physical infrastructure among multiple tenants.

436
MCQmedium

During requirements gathering, an IT manager says the organization must remove a departing user's license safely. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.Preserve or transfer required data according to offboarding policy before reclaiming a license
D.Microsoft Stream
AnswerC

Before reclaiming a Microsoft 365 license, the administrator must preserve or transfer the user's data—such as Exchange mailbox contents and OneDrive files—according to the organization's offboarding policy. Removing a license can initiate a deletion process that makes data unrecoverable after a short grace period, so exporting to PST, moving content to a shared mailbox, or applying a compliance hold is necessary. This practice prevents data loss and ensures compliance with eDiscovery and legal retention obligations.

Why this answer

The most relevant concept for safely removing a departing user's license is the offboarding policy, which includes preserving or transferring required data (e.g., via eDiscovery, retention policies, or data migration) before reclaiming the license. This ensures compliance and data integrity, as license removal can trigger data deletion after a grace period (e.g., 30 days for Exchange Online). The other options are productivity tools, not licensing or offboarding concepts.

Exam trap

The trap here is that candidates confuse productivity tools (Forms, Whiteboard, Stream) with licensing or offboarding concepts, overlooking that the question explicitly asks for the most relevant licensing, admin, or support concept, which is the offboarding policy for data preservation.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not related to license management or user offboarding. Option B is wrong because Microsoft Whiteboard is a digital canvas for collaboration, irrelevant to licensing or data preservation during offboarding. Option D is wrong because Microsoft Stream is a video hosting and sharing service, not a licensing or support concept for removing a user's license safely.

437
MCQmedium

A company subscribes to a cloud service where they can provision virtual machines, choose the operating system, install any software, and manage all applications. The cloud provider is responsible for the underlying physical hardware and network infrastructure. Which cloud service model is being used?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises
AnswerA

IaaS is correct because the provider supplies virtualized compute, storage, and networking on physical servers it owns and operates, while customers provision these resources as virtual machines and install their own operating systems, runtime environments, and applications. This gives customers the same administrative control over the OS and application stack as they would have on physical servers, without needing to manage datacenter hardware, cooling, or power. The ability to define the OS version, configure its settings, and deploy arbitrary software exactly matches the scenario's description of controlling both OS and applications.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer provisions virtual machines, chooses the operating system, installs software, and manages applications, while the cloud provider is responsible for the underlying physical hardware and network infrastructure. In IaaS, the provider delivers virtualized computing resources over the internet, and the customer retains control over the OS, storage, and deployed applications, which matches the description exactly.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but PaaS abstracts the OS and runtime, whereas IaaS gives the customer full control over the OS and software installation, as explicitly stated in the question.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS provides a managed platform where the provider handles the OS, runtime, and middleware, and the customer only deploys and manages applications—not the OS or full software stack. Option C (SaaS) is wrong because SaaS delivers fully managed applications accessed via a browser or client, with no customer control over the underlying infrastructure, OS, or software installation. Option D (On-premises) is wrong because on-premises deployment means the customer owns and manages all hardware, software, and networking within their own data center, contradicting the cloud provider's responsibility for physical infrastructure.

438
MCQhard

A multinational organization uses Microsoft 365 and wants to comply with data residency requirements. They need to ensure that data for European users stays within the European Union. Which Microsoft 365 feature should they configure?

A.Create retention policies for EU users.
B.Set conditional access policies to restrict access from outside EU.
C.Use data loss prevention policies to block data movement.
D.Configure multi-geo capabilities in SharePoint Online and OneDrive.
AnswerD

Multi-Geo capabilities in SharePoint Online and OneDrive for Business let an organization maintain a single Microsoft 365 tenant while provisioning data at rest in specific satellite geographic locations. By assigning EU users to a European Geo location, the administrator ensures their SharePoint sites and OneDrive libraries are stored in EU datacenters, meeting data residency requirements. This is the correct answer because it directly controls the physical storage location for the relevant workloads, unlike policy-based controls that only affect data lifecycle, access, or movement.

Why this answer

Multi-Geo capabilities in SharePoint Online and OneDrive allow organizations to provision and store data at rest in specific geographic locations, such as the European Union, to meet data residency requirements. This feature enables tenant administrators to define a preferred data location for users, ensuring their content remains within the EU boundary.

Exam trap

The trap here is that candidates confuse data residency (where data is stored at rest) with data protection mechanisms like retention, access control, or DLP, which address data lifecycle and security but not physical storage location.

How to eliminate wrong answers

Option A is wrong because retention policies control how long data is kept, not where it is stored geographically; they do not enforce data residency. Option B is wrong because conditional access policies control authentication and access based on location, but they do not determine where data is physically stored at rest. Option C is wrong because data loss prevention policies prevent sensitive data from being shared or exfiltrated, but they do not control the geographic location of data storage.

439
MCQeasy

A user wants to schedule a meeting with colleagues and automatically record the meeting for later viewing. Which Microsoft 365 apps should they use?

A.Microsoft SharePoint and Microsoft Viva Topics
B.Microsoft Viva Engage and Microsoft Forms
C.Microsoft OneDrive and Microsoft Stream
D.Microsoft Outlook and Microsoft Teams
AnswerD

Outlook integrates with Exchange Online to provide a shared calendar, meeting invitation workflow, and attendee availability tracking. Microsoft Teams provides the online meeting infrastructure, including audio/video conferencing, meeting recording, and live captions. Together, they automate the entire process: Outlook schedules the meeting with calendar invites, and Teams can be set to record the session for later access.

Why this answer

Microsoft Outlook is used to schedule the meeting and send invitations, while Microsoft Teams provides the platform to conduct the online meeting with the capability to automatically record the session. The recording is saved to Microsoft Stream (or OneDrive/SharePoint depending on the version), but the core apps for scheduling and recording are Outlook and Teams.

Exam trap

The trap here is that candidates may think Microsoft Stream alone is sufficient for recording, but Stream is only the storage/playback service, not the app that schedules or conducts the meeting with recording capability.

How to eliminate wrong answers

Option A is wrong because Microsoft SharePoint is a document management and collaboration platform, and Viva Topics uses AI to organize knowledge; neither provides meeting scheduling or recording. Option B is wrong because Viva Engage is an enterprise social network and Forms is for surveys and quizzes; neither supports meeting scheduling or recording. Option C is wrong because OneDrive is for file storage and sync, and Stream is a video service; while Stream can host recordings, OneDrive does not schedule meetings, and the combination lacks the scheduling and real-time meeting capabilities.

440
Multi-Selecteasy

Which TWO Microsoft 365 apps are included in the Microsoft 365 Business Basic subscription?

Select 2 answers
A.Microsoft Teams
B.Microsoft Outlook (web)
C.Microsoft Power BI Pro
D.Microsoft Word (desktop app)
E.Microsoft Purview Compliance Portal
AnswersA, B

Microsoft Teams is included in Microsoft 365 Business Basic as the primary chat, meetings, and collaboration hub. In Business Basic, Teams provides full chat, audio/video conferencing, mobile and web access, and guest collaboration through its cloud-based service, so users do not need a desktop Office installation to work together. Teams is a correct answer because it is explicitly part of the Business Basic subscription rather than an add-on or separate workload.

Why this answer

Microsoft 365 Business Basic is a cloud-only subscription that includes web and mobile versions of Office apps, not desktop installations. Microsoft Teams is included as the core collaboration hub for chat, meetings, and file sharing. Microsoft Outlook (web) is also included, providing email, calendar, and contacts via a browser interface.

Exam trap

The trap here is that candidates often confuse 'Business Basic' with 'Business Standard' or 'Apps for Business,' assuming desktop Office apps are included, or they mistakenly think Power BI Pro is a standard component of any Microsoft 365 plan.

441
MCQhard

A company has employees who frequently work from home on personal devices. They need to ensure corporate data in Microsoft 365 is protected even if the device is lost or compromised, without managing the entire device. What should they implement?

A.Microsoft Intune App Protection Policies
B.Microsoft Defender for Endpoint
C.Microsoft Entra Conditional Access
D.Microsoft Purview Data Loss Prevention
AnswerA

Intune App Protection Policies (APP) are the correct choice because they provide mobile application management (MAM) capabilities that do not require device enrollment or full device management. APP applies policy directly to managed apps, allowing control over corporate data via features like preventing copy/paste, restricting save-as, enforcing app-level encryption, and enabling selective wipe of corporate data without removing personal data from a BYOD device. This gives protection of corporate data within apps on unmanaged personal devices, which is exactly what is needed for employees working from home on personal devices.

Why this answer

Microsoft Intune App Protection Policies (MAM) protect data at the app level without device enrollment. Conditional Access controls access. DLP prevents data loss.

MAM is the correct approach for unmanaged devices.

442
Multi-Selecteasy

Which TWO Microsoft 365 services are primarily used for enterprise social networking and communication within an organization?

Select 2 answers
A.Microsoft Teams
B.Microsoft Viva Engage
C.Microsoft SharePoint
D.Microsoft Stream
E.Exchange Online
AnswersA, B

Microsoft Teams is the correct answer because it is the primary hub for persistent, threaded chat and channel-based communication in Microsoft 365. Teams allows users to send direct messages, create group conversations, and collaborate in channels organized by project or topic, all while integrating with Office apps and meeting features. Its real-time messaging capabilities directly fulfill the 'communication' requirement for enterprise collaboration, distinct from document storage or video hosting.

Why this answer

Microsoft Teams is correct because it serves as the primary hub for persistent chat, meetings, and collaboration, integrating enterprise social networking features such as channels, @mentions, and threaded conversations. Microsoft Viva Engage (formerly Yammer) is correct because it provides a dedicated enterprise social network for broad organizational communication, communities, and knowledge sharing, distinct from Teams' more team-focused interactions.

Exam trap

Microsoft often tests the distinction between collaboration tools by making SharePoint or Exchange Online seem like social networking options, but the trap here is confusing document management or email with enterprise social networking, which requires persistent, community-driven communication features.

443
MCQmedium

A tenant administrator is advising a department that wants to avoid service disruption before subscription renewal. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Subscription status, renewal dates, billing information, and payment methods
C.Microsoft Whiteboard
D.Microsoft Stream
AnswerB

Subscription status, renewal dates, billing information, and payment methods are the authoritative data points a tenant administrator must review to advise on licensing continuity. These items indicate whether the tenant's Microsoft 365 subscriptions are active, when they will renew or expire, and whether the financial account is in good standing. Without this information, a department could face service disruption when a subscription lapses or payment fails. This data is available in the Microsoft 365 admin center under Billing > Subscriptions and Billing > Payment methods, which is the only reliable source for such administrative details.

Why this answer

The scenario involves avoiding service disruption before subscription renewal, which directly relates to managing subscription status, renewal dates, billing information, and payment methods. These are core billing and subscription management concepts within Microsoft 365 administration, ensuring continuous service access by preventing lapses in payment or renewal.

Exam trap

The trap here is that candidates may confuse productivity tools (Forms, Whiteboard, Stream) with administrative billing concepts, overlooking that the question specifically targets subscription lifecycle management to avoid disruption.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not related to subscription management or billing. Option C is wrong because Microsoft Whiteboard is a collaborative digital canvas application, irrelevant to subscription renewal or service disruption. Option D is wrong because Microsoft Stream is a video sharing and management service, not involved in billing or subscription status.

444
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to reduce maintenance of power, cooling, and server replacement. Cloud concept or benefit best matches this requirement?

A.Reduced data center management
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

In Microsoft 365, Microsoft owns and operates the physical data centers, hardware, networking, and virtualization layers, so organizations eliminate the need to procure, rack, patch, and maintain physical servers. This also includes handling capacity planning, hardware failure replacement, and infrastructure-level security updates, all backed by Microsoft's SLAs. As a result, IT staff can focus on application-level configuration and business value instead of data center operations.

Why this answer

Reduced data center management is the correct answer because the requirement to reduce maintenance of power, cooling, and server replacement directly maps to the cloud benefit of offloading physical infrastructure responsibilities to the cloud provider. In Microsoft 365, this is realized through the shared responsibility model where Microsoft manages the underlying hardware, facilities, and environmental controls, allowing the organization to focus on application and data management rather than data center operations.

Exam trap

The trap here is that candidates may confuse operational benefits (like reduced maintenance) with productivity tools (Planner) or security features (DLP, sensitivity labels), rather than recognizing that the question is testing the foundational cloud concept of offloading infrastructure management to the provider.

How to eliminate wrong answers

Option B (Microsoft Planner) is wrong because it is a task management and planning tool within Microsoft 365, not a cloud concept or benefit related to reducing physical infrastructure maintenance. Option C (Data Loss Prevention or DLP) is wrong because it is a security feature that helps prevent accidental sharing of sensitive data, not a cloud concept that reduces power, cooling, or server replacement efforts. Option D (Sensitivity labels) is wrong because they are classification and protection mechanisms for data governance, not a cloud benefit addressing data center operational overhead.

445
MCQmedium

A company is migrating its on-premises workloads to Microsoft 365. The IT team wants to minimize latency for users in Europe while ensuring data residency requirements are met. Which cloud concept should the team consider?

A.Geography
B.Hybrid deployment
C.Redundancy
D.Multi-tenancy
AnswerA

Geography, in Microsoft 365/Azure, refers to the distinct regional boundary containing datacenters where your tenant data is stored at rest. During a migration, selecting the correct geography ensures data resides in the region that minimizes network latency for your users and satisfies data-residency compliance, such as staying within an EU or US boundary. Without this deliberate choice, your workloads may land in a distant region, causing slower access and regulatory exposure.

Why this answer

Geography in Microsoft 365 refers to a defined geographic boundary (e.g., Europe) that contains one or more Azure regions where data is stored and processed at rest. By selecting a Geography, the IT team ensures that user data remains within European borders to meet data residency requirements, while the proximity of the data centers to users in Europe minimizes network latency. This concept directly addresses both performance and compliance needs without requiring complex hybrid configurations.

Exam trap

The trap here is that candidates often confuse 'Geography' with 'Region' or think that 'Hybrid deployment' can solve latency and residency issues, but Geography is the specific Microsoft 365 concept that ties data residency to a fixed set of data centers within a geographic boundary.

How to eliminate wrong answers

Option B (Hybrid deployment) is wrong because it describes a mix of on-premises and cloud services, not a mechanism to control data location or latency for a specific geographic region. Option C (Redundancy) is wrong because it focuses on data replication and high availability across multiple sites, not on minimizing latency or enforcing data residency boundaries. Option D (Multi-tenancy) is wrong because it refers to sharing infrastructure among multiple customers, which does not influence where data is stored or how close it is to users.

446
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to use Microsoft 365 and another public cloud provider for different workloads. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Sensitivity labels
C.Multi-cloud
D.Data Loss Prevention (DLP)
AnswerC

Multi-cloud describes using two or more public cloud providers for different workloads, exactly matching the requirement to combine Microsoft 365 with another public cloud provider. It is a deployment model, not a licensing or cost benefit.

Why this answer

Multi-cloud is the correct answer because the requirement explicitly involves using Microsoft 365 alongside another public cloud provider for different workloads. Multi-cloud refers to the strategy of leveraging services from multiple cloud providers (e.g., Microsoft Azure and AWS) to avoid vendor lock-in, optimize costs, or meet compliance needs. This directly matches the scenario of using Microsoft 365 and another public cloud provider together.

Exam trap

The trap here is that candidates may confuse 'multi-cloud' with 'hybrid cloud' (which combines public and private cloud) or mistakenly think a specific Microsoft 365 feature like DLP or Sensitivity labels is the answer, when the question is about the overarching cloud concept of using multiple public providers.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not a cloud concept or benefit that addresses multi-provider workload distribution. Option B is wrong because Sensitivity labels are a Microsoft Information Protection feature used to classify and protect data based on sensitivity, not a cloud deployment model or strategy for using multiple providers. Option D is wrong because Data Loss Prevention (DLP) is a security policy mechanism to prevent accidental sharing of sensitive data, not a cloud concept describing the use of multiple cloud providers.

447
MCQmedium

A company uses Microsoft 365 E3. They want to upgrade to include advanced compliance features like communication compliance and insider risk management. Which add-on license do they need?

A.Microsoft 365 E5 Compliance
B.Microsoft 365 E5 Security
C.Microsoft Purview Compliance Manager
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft 365 E5 Compliance is a paid add-on for E3 that delivers advanced compliance workloads, including communication compliance for monitoring employee communications and insider risk management for detecting suspicious activities. These features are not available in E3 by default, making this the correct upgrade to satisfy the stated compliance requirement.

Why this answer

Microsoft 365 E5 Compliance is the correct add-on license because it includes advanced compliance features such as Communication Compliance (for monitoring and detecting inappropriate messages) and Insider Risk Management (for identifying and mitigating internal data risks). These features are not available in the base Microsoft 365 E3 subscription and require the E5 Compliance SKU to unlock.

Exam trap

The trap here is that candidates often confuse Microsoft 365 E5 Security with Microsoft 365 E5 Compliance, assuming that advanced security features automatically include compliance capabilities, but Microsoft separates these into distinct SKUs with different feature sets.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 E5 Security provides advanced security features like Microsoft Defender for Office 365 and Microsoft Defender for Identity, but it does not include Communication Compliance or Insider Risk Management, which are compliance-specific capabilities. Option C is wrong because Microsoft Purview Compliance Manager is a tool within the Microsoft Purview compliance portal for managing compliance assessments and controls, not a license add-on; it is included with E5 Compliance but cannot be purchased as a standalone license to enable the required features. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on securing cloud applications and data, not a license that provides Communication Compliance or Insider Risk Management.

448
Matchingmedium

Match each Microsoft 365 service level agreement (SLA) term to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Service is available at least 99.9% of the time monthly

Discount on bill if SLA is not met

Scheduled downtime for updates

Minimum spend or term length in contract

Why these pairings

Correct matches: Monthly Uptime Percentage is the availability percentage, Service Credit is the compensation for not meeting that percentage, Downtime is the period of unavailability, and SLA is the overarching agreement. Common confusions involve swapping the definitions of Monthly Uptime Percentage and Service Credit.

449
MCQhard

A global financial services firm needs to protect highly confidential documents containing trade secrets. The protection must restrict access to a specific group of employees, prevent editing and printing, and remain enforced even if the document is downloaded and saved to an external device. Which Microsoft Purview solution should be used?

A.Sensitivity labels (Azure Information Protection)
B.Data Loss Prevention (DLP) policy
C.Information Barriers
D.Advanced Audit
AnswerA

Sensitivity labels are correct because they use Azure Rights Management (RMS) at the Microsoft Purview Information Protection layer to encrypt documents and assign granular usage rights, such as view, edit, copy, print, and forward permissions. These rights are embedded in the file itself, so the protection persists even if the document is saved to an external drive or shared with third parties. A global financial services firm specifically needs this persistent encryption and revocable access control to protect highly sensitive data after it leaves Microsoft 365.

Why this answer

Sensitivity labels from Azure Information Protection (AIP) allow you to classify and protect documents with persistent protection that travels with the file, even when it is downloaded to an external device. By configuring a sensitivity label with encryption, you can restrict access to a specific group of employees, disable editing and printing, and enforce these restrictions regardless of where the file is stored. This meets all the requirements of the scenario, including persistent protection after download.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, thinking DLP can protect files after download, but DLP only monitors and blocks at the point of sharing, not persistently encrypting the file.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are designed to detect and prevent the sharing of sensitive information via email, Teams, or cloud apps, but they do not apply persistent protection (encryption, rights management) to files after they are downloaded to an external device. Option C is wrong because Information Barriers are used to prevent communication and collaboration between specific groups (e.g., to avoid conflicts of interest), not to protect documents with encryption or restrict editing/printing. Option D is wrong because Advanced Audit provides detailed logging and investigation of user and admin activities, but it does not enforce access controls or persistent protection on documents.

450
MCQmedium

A compliance officer needs to automatically classify documents stored in SharePoint Online that contain personally identifiable information (PII) such as social security numbers. The classification must apply a sensitivity label that encrypts the document and restricts access to only employees in the Legal department. The process should run without any user interaction. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Information Protection with auto-labeling
D.Microsoft Purview Insider Risk Management
AnswerC

Microsoft Purview Information Protection with auto-labeling is the correct solution because it natively applies sensitivity labels to files and emails based on content matches such as sensitive info types, trainable classifiers, or manual conditions. When an auto-labeling policy applies a sensitivity label, that label can automatically enforce encryption via Azure Rights Management, add visual markings, and restrict access, and the classification persists with the document or email across platforms. This provides the compliance officer with true automatic classification and protection without requiring user intervention.

Why this answer

Microsoft Purview Information Protection with auto-labeling can automatically detect PII (e.g., social security numbers) in documents stored in SharePoint Online and apply a sensitivity label that encrypts the content and restricts access to the Legal department. This process runs without user interaction, meeting the compliance officer's requirement for automatic classification and protection.

Exam trap

The trap here is that candidates often confuse DLP policies (which block sharing) with auto-labeling policies (which apply sensitivity labels and encryption), but DLP does not automatically encrypt or restrict access via sensitivity labels.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management focuses on retaining or deleting data based on policies (e.g., retention labels), not on automatically classifying or encrypting documents with sensitivity labels. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent unauthorized sharing or exfiltration of sensitive data (e.g., blocking emails or file transfers), not to apply sensitivity labels that encrypt and restrict access. Option D is wrong because Microsoft Purview Insider Risk Management detects risky user activities (e.g., data theft by insiders) through analytics and alerts, but does not automatically classify or encrypt documents with sensitivity labels.

Page 5

Page 6 of 11

Page 7

All pages