Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 451–525

794 questions total · 11pages · All types, answers revealed

Page 6

Page 7 of 11

Page 8
451
MCQhard

Your organization uses Microsoft 365 E5 and experiences a security incident where a user's account is compromised. You need to immediately prevent the attacker from accessing Microsoft 365 services while preserving the user's data for investigation. Which action should you take?

A.Block sign-in for the user in Microsoft Entra ID
B.Delete the user account from Microsoft Entra ID
C.Revoke the user's sessions using Microsoft Entra ID
D.Reset the user's password
AnswerA

Blocking sign-in in Microsoft Entra ID flips the user account to a disabled state (Sign-in enabled = No), which immediately rejects all new authentication requests for Entra ID and Microsoft 365 services. This prevents the attacker from obtaining any additional access tokens, and while previously issued tokens may remain technically valid until expiration, most resource access attempts will fail on the next revalidation. Crucially, this action preserves all user data such as mailbox and OneDrive contents, allowing forensic investigation without any deletion of evidence.

Why this answer

Blocking sign-in for the user in Microsoft Entra ID immediately prevents the attacker from authenticating to any Microsoft 365 service, while the user's data remains intact in Exchange Online, SharePoint, and OneDrive for forensic analysis. This action does not delete or alter any data, preserving the full investigation trail.

Exam trap

The trap here is that candidates confuse 'revoke sessions' (which only kills current sessions but allows re-authentication) with 'block sign-in' (which prevents all future authentication), leading them to choose Option C as a quick fix without realizing the attacker can simply log back in.

How to eliminate wrong answers

Option B is wrong because deleting the user account permanently removes the user object and all associated data (mailbox, OneDrive files, SharePoint access) from Microsoft 365, destroying evidence needed for investigation. Option C is wrong because revoking sessions only terminates active tokens and sessions but does not prevent the attacker from re-authenticating with the compromised credentials, leaving the account still vulnerable. Option D is wrong because resetting the password alone does not invalidate existing refresh tokens or active sessions; the attacker could still use cached tokens or non-expired sessions to access services until those tokens expire or are explicitly revoked.

452
MCQmedium

A company with 500 Microsoft 365 E3 users wants to add the highest level of threat protection and advanced investigation capabilities for their security team. Which licensing add-on should they purchase?

A.Microsoft 365 E5 Security
B.Microsoft 365 E5 Compliance
C.Microsoft 365 E5
D.Microsoft Defender for Microsoft 365 Plan 2 only
AnswerA

Microsoft 365 E5 Security is an add-on for E3 that includes advanced security features such as Microsoft 365 Defender, Defender for Microsoft 365 Plan 2, Defender for Identity, and more, providing the highest threat protection and investigation.

Why this answer

Microsoft 365 E5 Security is the correct add-on because it bundles the highest level of threat protection (Microsoft Defender for Office 365 Plan 2, Microsoft Defender for Endpoint Plan 2, and Microsoft Defender for Identity) along with advanced investigation capabilities like automated investigation and response (AIR), threat analytics, and advanced hunting in Microsoft 365 Defender. This meets the requirement for top-tier threat protection and advanced investigation without upgrading the entire E3 base license to E5.

Exam trap

The trap here is that candidates often confuse 'Microsoft 365 E5' (a full suite upgrade) with 'Microsoft 365 E5 Security' (an add-on), or they assume that Defender for Office 365 Plan 2 alone provides all advanced investigation features, when in fact E5 Security bundles multiple Defender plans and advanced hunting tools.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 E5 Compliance focuses on data governance, eDiscovery, and compliance management (e.g., Communication Compliance, Insider Risk Management), not threat protection or advanced security investigation capabilities. Option C is wrong because Microsoft 365 E5 is a full suite upgrade that includes both security and compliance features, but the question asks for an add-on to existing E3 licenses, not a full license upgrade; purchasing E5 would be redundant and cost-inefficient. Option D is wrong because Microsoft Defender for Microsoft 365 Plan 2 only provides threat protection for email, collaboration tools, and endpoints, but it does not include the full breadth of advanced investigation capabilities (e.g., Microsoft Defender for Identity, Microsoft Defender for Cloud Apps) that are bundled in E5 Security.

453
MCQmedium

An administrator is reviewing a request from users who need to reset user passwords without assigning Global Administrator. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Password Administrator
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Password Administrator grants scoped rights to reset passwords for non-administrators and other Password Administrators, without the tenant-wide control Global Administrator carries. This least-privilege role in Microsoft Entra ID satisfies the requirement to reset user passwords while avoiding excessive permissions.

Why this answer

The Password Administrator role in Microsoft Entra ID (formerly Azure AD) allows users to reset passwords for non-administrator users and manage service requests without granting the highly privileged Global Administrator role. This directly addresses the user request while adhering to the principle of least privilege, making it the most relevant concept for this scenario.

Exam trap

The trap here is that candidates may confuse the Password Administrator role with the Global Administrator role, assuming only Global Admin can reset passwords, or they might pick a random Microsoft service like Forms or Stream because they sound 'administrative' without understanding the specific role-based access control (RBAC) permissions in Microsoft Entra ID.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration tool for visual brainstorming, not an administrative role or licensing concept for password management. Option C is wrong because Microsoft Forms is a survey and data collection tool, unrelated to user administration or password reset capabilities. Option D is wrong because Microsoft Stream is a video management and sharing service, with no role or feature for resetting user passwords.

454
MCQhard

A global consulting firm uses Microsoft 365 E5. Consultants frequently travel and need to access email, files, and Teams on personal iOS and Android devices without enrolling the devices in mobile device management. The security team requires that corporate data remain protected and that they can selectively wipe corporate data if a device is lost. Which Microsoft 365 feature should the firm implement?

A.Microsoft Intune device compliance policies
B.Microsoft Purview Information Barriers
C.Microsoft Intune app protection policies (MAM)
D.Microsoft Defender for Cloud Apps Conditional Access App Control
AnswerC

App protection policies in Intune protect corporate data at the app level without requiring device enrollment. They can enforce PIN, block copy-paste to personal apps, and enable selective wipe of corporate data from managed apps on iOS and Android. This directly meets the firm's need to secure email, files, and Teams on personal devices without MDM enrollment.

Why this answer

Intune app protection policies (mobile application management) secure corporate data within apps on personal devices without enrollment. They prevent data leakage between managed and unmanaged apps and allow selective wipe of corporate data. Device compliance policies, Information Barriers, and Conditional Access App Control do not provide the same app-level containerization and selective wipe for unenrolled devices.

Exam trap

The trap here is assuming that device compliance or Conditional Access App Control can protect data on unenrolled devices, when only app protection policies provide app-level containerization and selective wipe without enrollment.

455
MCQeasy

An HR manager needs to collect anonymous feedback from employees about a new benefits policy. They want the responses to be automatically summarized into charts and graphs. Which Microsoft 365 app is best suited for this task?

A.Microsoft Forms
B.Microsoft Excel
C.Microsoft Sway
D.Microsoft Power BI
AnswerA

Microsoft Forms supports anonymous responses and automatically generates charts and graphs from submitted answers, satisfying both the anonymity and summarisation constraints. It requires no additional configuration for basic visualisation, unlike Excel or Power BI, which would need manual setup. This makes it the most direct fit for collecting and summarising employee feedback.

Why this answer

Microsoft Forms is the correct choice because it is specifically designed for creating surveys and quizzes, with built-in support for anonymous responses and automatic generation of charts and graphs from collected data. The HR manager can create a feedback form, enable anonymous submissions, and view real-time summaries with visualizations directly within Forms, without needing additional tools.

Exam trap

The trap here is that candidates often confuse Microsoft Forms with Microsoft Power BI, assuming that any charting or graphing requirement must involve a dedicated analytics tool, but Forms handles simple survey summarization natively without needing Power BI's complexity.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel is a spreadsheet application for data analysis and manual chart creation, but it lacks native anonymous survey capabilities and does not automatically collect responses or generate charts without manual setup. Option C is wrong because Microsoft Sway is a presentation and storytelling app for creating interactive reports and newsletters, not for collecting feedback or generating charts from survey data. Option D is wrong because Microsoft Power BI is a business analytics service for advanced data visualization and reporting from multiple data sources, but it is overkill for simple anonymous feedback collection and does not provide built-in survey creation or anonymous response handling.

456
MCQmedium

Refer to the exhibit. An admin configures these two Conditional Access policies in Microsoft Entra ID. A user signs in from a new location with a device that is not compliant and is assigned a high risk level by identity protection. What will happen to the user's sign-in?

A.The user is granted access because the second policy requires MFA.
B.The user is prompted for MFA due to the second policy.
C.The user is blocked from signing in.
D.The user is allowed access but with session restrictions.
AnswerC

The user is blocked from signing in because the first Conditional Access policy is configured to block access when sign-in risk is high. Conditional Access aggregates all applicable policies, and a block action overrides any grant controls from other policies. Because the user's session cannot be established, no access is allowed and the sign-in attempt fails.

Why this answer

The first Conditional Access policy blocks all access for users assigned a high risk level. Since the user is assigned a high risk level by Identity Protection, this policy is triggered first, and because Conditional Access policies are evaluated in order and the first applicable policy that results in a block will prevent further evaluation, the user is blocked from signing in. The second policy requiring MFA for non-compliant devices is never evaluated because the block policy takes precedence.

Exam trap

The trap here is that candidates assume the second policy (requiring MFA) will be applied because the device is non-compliant, but they overlook that the first policy with a 'Block' grant control takes precedence and stops all further policy evaluation.

How to eliminate wrong answers

Option A is wrong because the user is blocked by the first policy before the second policy can grant access, and the second policy does not grant access unconditionally—it requires MFA. Option B is wrong because the user is blocked by the first policy, so they are never prompted for MFA by the second policy; the block overrides any subsequent grant controls. Option D is wrong because the user is blocked entirely, not allowed access with session restrictions; session restrictions would only apply if access were granted.

457
MCQeasy

A company wants to ensure that only managed and compliant devices can access corporate email in Microsoft 365. Which Microsoft Entra ID capability should they configure?

A.Conditional Access
B.Microsoft Authenticator
C.Privileged Identity Management
D.Identity Protection
AnswerA

Conditional Access enforces signal-based access decisions, so device compliance state from Intune can be required before Microsoft 365 email is granted. This directly satisfies the stem's constraint that only managed, compliant devices reach corporate email, since the policy evaluates device state at authentication rather than relying on user credentials alone.

Why this answer

Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals like device compliance and management state, then grants or blocks access to Microsoft 365 services such as Exchange Online. Configuring a policy that requires a compliant or hybrid Azure AD joined device ensures only managed, compliant devices can reach corporate email. This is the precise Entra ID capability designed for that enforcement.

Exam trap

MS-900 often tests the difference between authentication controls (MFA, Authenticator) and authorization/access controls (Conditional Access), so candidates who focus on 'access email' and pick an MFA option miss the device-compliance enforcement mechanism.

How to eliminate wrong answers

Option B is wrong because Microsoft Authenticator is an MFA method that strengthens authentication but does not evaluate or enforce device compliance. Option C is wrong because Privileged Identity Management manages just-in-time privileged role activation, not device-based access gating. Option D is wrong because Identity Protection detects risky users and sign-ins but does not enforce device management or compliance requirements.

458
MCQmedium

A sales manager wants to create an interactive dashboard that visualizes the sales pipeline, customer interactions, and team performance. The data resides in Dynamics 365. The manager needs to build the dashboard quickly without coding and share it with the team. Which Microsoft 365 app should they use?

A.Power BI
B.Power Apps
C.Power Automate
D.Power Virtual Agents
AnswerA

Power BI is Microsoft’s business analytics and data visualization service, purpose-built for creating interactive dashboards and reports from multiple data sources, including Dynamics 365, Excel, and Azure SQL. It provides drag-and-drop visual building, cross-filtering, user-friendly sharing through the Power BI Service, and natural-language querying, which directly supports a sales manager’s need to track and analyze performance data at a glance.

Why this answer

Power BI is the correct choice because it is a business analytics service that enables users to create interactive dashboards and visualizations from data sources like Dynamics 365 without writing code. It supports quick data modeling, real-time updates, and easy sharing with team members via Power BI service or embedded reports, meeting the manager's need for speed and collaboration.

Exam trap

The trap here is that candidates may confuse Power BI with Power Apps because both are part of the Power Platform and can integrate with Dynamics 365, but Power Apps is for building custom apps, not for creating dashboards or visualizations.

How to eliminate wrong answers

Option B (Power Apps) is wrong because it is a low-code platform for building custom applications, not for creating interactive dashboards or visualizations; it focuses on app logic and forms, not data analytics. Option C (Power Automate) is wrong because it is designed for workflow automation and process orchestration, not for building dashboards or visual data exploration. Option D (Power Virtual Agents) is wrong because it is a tool for creating conversational AI chatbots, not for data visualization or reporting.

459
MCQmedium

Your organization is deploying Microsoft 365 Copilot for sales teams. The compliance team requires that Copilot interactions with customer data in Dynamics 365 Sales be subject to retention policies. Which Microsoft Purview feature should you configure to manage this data?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Sensitivity Labels
C.Microsoft Purview eDiscovery
D.Microsoft Purview Communication Compliance
AnswerA

Microsoft Purview Data Lifecycle Management enforces retention policies for Copilot interactions.

Why this answer

Microsoft Purview Data Lifecycle Management enforces retention policies for Copilot interactions. Option B is incorrect because eDiscovery is for search and export. Option C is incorrect because Communication Compliance is for monitoring inappropriate messages.

Option D is incorrect because Sensitivity labels are for classification.

460
Multi-Selecteasy

Which TWO of the following are required to implement Microsoft Entra ID Conditional Access?

Select 2 answers
A.Microsoft 365 E5 license
B.Multifactor Authentication enabled for all users
C.Microsoft Entra ID P1 or P2 licenses
D.Global Administrator or Conditional Access Administrator role
E.Microsoft Intune subscription
AnswersC, D

Conditional Access is a premium feature of Microsoft Entra ID and specifically requires either Microsoft Entra ID P1 or P2 licenses for the users who will be targeted by the policies. Entra ID P1 provides the core policy engine (e.g., MFA, trusted locations, device-based access), while P2 adds risk-based conditional access driven by Identity Protection signals.

Why this answer

Conditional Access requires Azure AD P1 or P2 licenses and roles that allow policy management. MFA and Intune are not required for all policies.

461
MCQmedium

A non-profit organization with 50 employees needs business-grade email, online versions of Office apps, and 1 TB of cloud storage per user. They have a very limited budget and are eligible for Microsoft's non-profit program. Which Microsoft 365 plan provides these features at the lowest cost?

A.Microsoft 365 Business Basic (non-profit)
B.Microsoft 365 Business Standard (non-profit)
C.Microsoft 365 E1 (non-profit)
D.Microsoft 365 E3 (non-profit)
AnswerA

Microsoft 365 Business Basic (nonprofit) provides each of the 50 users with a 50 GB Exchange Online mailbox, web and mobile versions of Office apps (Word, Excel, PowerPoint), Microsoft Teams, SharePoint, and 1 TB of OneDrive storage. It satisfies the business email, online Office, and cloud storage requirements without paying for installed desktop applications. Nonprofit pricing through Microsoft's eligibility program drastically reduces the per-user cost, making it the most cost-effective licensed plan for this organization.

Why this answer

Microsoft 365 Business Basic (non-profit) includes Exchange Online email, web/mobile versions of Office apps, and 1 TB of OneDrive storage per user at the lowest non-profit price point. It matches every stated requirement — business email, online Office apps, and 1 TB cloud storage — without paying for desktop Office licenses the non-profit does not need.

Exam trap

MS-900 often tests plan-tier feature boundaries — candidates pick Business Standard assuming 'Office apps' means desktop Office, but the question says 'online versions,' which Business Basic already includes at a lower price.

How to eliminate wrong answers

Option B is wrong because Business Standard costs more and adds desktop Office apps, which the organization did not request, so it is not the lowest-cost fit. Option C is wrong because Microsoft 365 E1 is an enterprise-tier plan priced higher than Business Basic and is aimed at larger organizations needing enterprise compliance features. Option D is wrong because E3 is the most expensive option here, bundling desktop Office, advanced compliance, and Windows Enterprise features that are unnecessary for a 50-person non-profit.

462
MCQhard

A legal team needs to place a hold on all data belonging to a specific user who is involved in a lawsuit. The hold must preserve Exchange Online email, SharePoint sites, and Teams chat messages. Which Microsoft Purview solution should they use?

A.eDiscovery (Standard)
B.Data Lifecycle Management (retention policies)
C.Communication Compliance
D.Audit log
AnswerA

eDiscovery (Standard) in Microsoft Purview enables legal teams to create cases and apply holds to content from Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams. A hold can be scoped to a specific user or refined with a search query, preserving all matching content even if users try to edit or delete it. This case-based preservation is exactly what is needed for a legal hold, making this the correct answer.

Why this answer

eDiscovery (Standard) is the correct solution because it allows legal teams to place a hold on a specific user's data across Exchange Online, SharePoint, and Teams. This hold preserves all content, including email, documents, and chat messages, ensuring that data cannot be altered or deleted during litigation. eDiscovery (Standard) is designed for legal holds and integrates with Microsoft Purview to manage custodians and preserve data.

Exam trap

The trap here is that candidates often confuse retention policies (which manage data lifecycle) with legal holds (which preserve data for litigation), leading them to choose Data Lifecycle Management instead of eDiscovery.

How to eliminate wrong answers

Option B (Data Lifecycle Management retention policies) is wrong because retention policies are used for managing data retention and deletion based on time or rules, not for placing a legal hold on a specific user's data in response to a lawsuit. Option C (Communication Compliance) is wrong because it is designed to monitor and detect policy violations in communications (e.g., harassment or insider trading), not to preserve data for legal holds. Option D (Audit log) is wrong because audit logs record user and admin activities for security investigations, but they do not place holds on data or preserve content for litigation.

463
MCQmedium

A global sales team uses Microsoft Teams for communication. They need to automate business workflows such as sending approval requests when a new lead is created in Dynamics 365. Which Microsoft 365 service should they integrate with Teams?

A.Power Apps
B.Power Automate
C.Power BI
D.Power Virtual Agents
AnswerB

Power Automate is the correct choice because it is Microsoft's dedicated workflow automation service, enabling users to create cloud flows that connect to hundreds of services, including Microsoft Teams and Dynamics 365. For a global sales team, you can design an approval flow triggered by a new lead or a Teams message, automatically routing the approval request to the appropriate manager and tracking its status in real time. It provides prebuilt templates for approval scenarios and supports both automated and manual triggers, making it the ideal solution for streamlining sales communications and approvals.

Why this answer

Power Automate (Option B) is the correct service because it is designed specifically for automating business workflows across Microsoft 365 and third-party services. When a new lead is created in Dynamics 365, a Power Automate flow can trigger an approval request in Teams, enabling seamless process automation without custom code.

Exam trap

The trap here is that candidates may confuse Power Automate with Power Apps, mistakenly thinking that building a custom app is necessary for workflow automation, whereas Power Automate is the dedicated service for no-code/low-code process automation.

How to eliminate wrong answers

Option A is wrong because Power Apps is a low-code platform for building custom applications, not for automating workflows or sending approval requests. Option C is wrong because Power BI is a business analytics tool for data visualization and reporting, not for workflow automation. Option D is wrong because Power Virtual Agents is a chatbot service for creating conversational AI agents, not for triggering automated approval workflows.

464
MCQhard

A sales team uses SharePoint Online to store contract templates. When a new contract is added to a specific library, a notification should be sent to a Microsoft Teams channel with a direct link to the document. Additionally, the contract owner must receive a custom approval request via email before the document is shared externally. Which Microsoft 365 services must be combined to achieve this?

A.Microsoft Power Automate and Microsoft Teams
B.Microsoft Teams and Microsoft Power Apps
C.Microsoft Forms and Microsoft Teams
D.Microsoft Power BI and Microsoft Teams
AnswerA

Power Automate is the correct choice because its SharePoint connector includes event-driven triggers such as "When a file is created or modified" in a document library. You can then use Teams actions to post a notification or adaptive card to a specific channel, and optionally add an email step. This provides exactly the automated contract-template workflow the sales team needs, with no custom code required.

Why this answer

Microsoft Power Automate can trigger a flow when a new contract is added to a SharePoint Online library, sending a notification with a direct link to a Microsoft Teams channel. Additionally, Power Automate can initiate a custom approval request via email to the contract owner before external sharing is allowed. This combination directly addresses both requirements without needing additional services.

Exam trap

The trap here is that candidates may assume Microsoft Teams alone can handle notifications and approvals, but Teams lacks native workflow automation for SharePoint events, requiring Power Automate as the orchestration layer.

How to eliminate wrong answers

Option B is wrong because Microsoft Power Apps is a low-code platform for building custom apps, not for automating workflows or sending notifications and approvals; it lacks the built-in triggers and actions for SharePoint events and Teams messaging. Option C is wrong because Microsoft Forms is used for creating surveys and quizzes, not for triggering notifications or approval workflows based on SharePoint document events. Option D is wrong because Microsoft Power BI is a business analytics tool for data visualization and reporting, not for workflow automation or real-time notifications.

465
MCQeasy

A company uses a cloud storage service that automatically increases its storage capacity without any manual intervention as new files are added. This behavior is an example of which cloud computing characteristic?

A.On-demand self-service
B.Broad network access
C.Resource pooling
D.Rapid elasticity
AnswerD

Rapid elasticity is the NIST essential characteristic that allows a cloud service to provision and release resources automatically, scaling out and in quickly and in line with real-time demand. A storage service that automatically increases or decreases its capacity based on usage is a textbook example of this behavior, because the customer perceives the scaling as seamless and often without pre-planning. This precisely matches the scenario, so it is the correct answer.

Why this answer

The scenario describes storage capacity automatically increasing as new files are added, which is the essence of rapid elasticity. This cloud characteristic allows resources to scale out and in automatically, often to the point where the user perceives unlimited capacity, without requiring manual provisioning or intervention.

Exam trap

The trap here is that candidates often confuse 'resource pooling' (the multi-tenant sharing of resources) with 'rapid elasticity' (the ability to scale resources up/down automatically), because both involve dynamic allocation, but pooling is about sharing among tenants while elasticity is about scaling for a single tenant's demand.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision computing resources (e.g., spinning up a VM) through a web portal or API without human interaction with the provider, not the automatic scaling of capacity. Option B is wrong because broad network access describes the ability to access cloud services over standard network protocols (e.g., HTTPS, SSH) from a wide variety of devices (laptops, phones, tablets), not the dynamic adjustment of storage. Option C is wrong because resource pooling means the provider's computing resources are pooled to serve multiple customers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to demand; it does not describe the automatic increase in capacity for a single customer's storage.

466
MCQeasy

Refer to the exhibit. A Contoso user tries to send an email containing a credit card number to an external recipient. What will happen?

A.The email is blocked and the user receives a notification.
B.The credit card number is removed and the email is sent.
C.The email is sent and an alert is generated for admin.
D.The email is delivered to the external recipient but placed in quarantine.
AnswerA

This is correct because the DLP policy is set to enforce mode with a block action. When the credit card number is detected as a sensitive info type, Outlook or Outlook on the web displays a policy tip to the sender, and the message is not delivered. The notification informs the user that the content violates policy and that the send is prevented.

Why this answer

The DLP policy enforces blocking of credit card numbers. Option B is wrong because the policy is enforced, not just audit. Option C is wrong because it blocks, not removes.

Option D is wrong because it blocks, not quarantines.

467
MCQeasy

A marketing team needs to create a visually compelling newsletter that can be distributed via email and viewed in a browser. Which Microsoft 365 app should they use?

A.Microsoft Publisher
B.Microsoft PowerPoint
C.Microsoft Word
D.Microsoft Sway
AnswerD

Sway is a Microsoft 365 application purpose-built for creating interactive, web-based newsletters, reports, and stories. It uses a responsive design engine that automatically arranges cards containing text, images, and multimedia to look good on any device, and it provides a simple shareable link for live viewing. With no manual layout required, Sway is the correct choice for a visually compelling newsletter that must be shared online.

Why this answer

Microsoft Sway is the correct choice because it is specifically designed for creating interactive, web-based newsletters and presentations that can be easily shared via a link and viewed in any browser. Unlike traditional desktop publishing tools, Sway uses a responsive design canvas that automatically adapts to different screen sizes, making it ideal for email distribution and browser viewing without requiring recipients to download attachments.

Exam trap

The trap here is that candidates often confuse Microsoft Publisher (a desktop publishing tool) with Sway because both can create visually rich content, but Publisher lacks the web-first, responsive, and browser-based sharing capabilities that the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because Microsoft Publisher is a desktop publishing application focused on print layouts (e.g., brochures, flyers) and does not natively support web-based distribution or responsive browser viewing without manual conversion. Option B is wrong because Microsoft PowerPoint is optimized for slide-based presentations and lacks the fluid, scrollable storytelling format and built-in web publishing features that Sway offers for newsletters. Option C is wrong because Microsoft Word is a word processor designed for documents and print, and while it can be saved as HTML, it does not provide a responsive, interactive web layout or easy browser-based sharing without attachments.

468
MCQmedium

A department head asks which Microsoft 365 option should be used to allow customers to book appointments online based on staff availability. Microsoft 365 app or service is the best fit?

A.Microsoft Planner
B.Microsoft Purview Audit
C.Microsoft Bookings
D.Microsoft Forms
AnswerC

Microsoft Bookings is a native scheduling service that lets organizations publish booking pages where clients can choose from available time slots based on staff calendars. It synchronizes with Exchange Online calendars, sends confirmation and reminder notifications, and can attach Teams or Skype meeting links for virtual appointments. This directly provides the appointment-booking capability the department head requires.

Why this answer

Microsoft Bookings is the correct choice because it is a Microsoft 365 app specifically designed to allow customers to book appointments online based on staff availability. It integrates with Exchange Online to synchronize staff calendars, manage time slots, and send automated confirmations, making it the ideal solution for scheduling customer-facing appointments.

Exam trap

The trap here is that candidates may confuse Microsoft Bookings with Microsoft Forms, thinking Forms can handle scheduling, but Forms lacks calendar integration and real-time availability checks, which are core to Bookings.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing team work and projects, not for scheduling customer appointments. Option B is wrong because Microsoft Purview Audit is a compliance and auditing service that logs user and admin activities, not a booking or scheduling tool. Option D is wrong because Microsoft Forms is used to create surveys, quizzes, and polls, not for managing staff availability or customer bookings.

469
MCQmedium

A training department needs to create interactive learning modules that include content pages, quizzes, and surveys. They also need to track completion and results for each learner. Which Microsoft 365 app should they use as the primary authoring tool for the quizzes and surveys?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Sway
D.Microsoft Viva Learning
AnswerB

Microsoft Forms is the correct tool because it provides a purpose-built Form/Quiz authoring surface with automatic scoring, feedback, branching, and response analytics. It integrates natively with SharePoint, Teams, and Viva Connections, enabling interactive quizzes and surveys to be embedded directly into learning modules, with submissions captured in Excel for tracking.

Why this answer

Microsoft Forms is the correct primary authoring tool because it is specifically designed for creating quizzes, surveys, and polls with automatic grading, branching logic, and result tracking. It integrates seamlessly with Microsoft Lists and Power Automate to record completion and results per learner, making it ideal for interactive learning modules.

Exam trap

The trap here is that candidates may confuse Microsoft Forms with Microsoft Sway because both can create interactive content, but Sway lacks quiz/survey functionality and result tracking, which Forms provides natively.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing platform, not an authoring tool for quizzes or surveys; it lacks native quiz creation and result tracking capabilities. Option C is wrong because Microsoft Sway is a digital storytelling and presentation tool for creating interactive reports and newsletters, but it does not support quiz creation, grading, or survey result tracking. Option D is wrong because Microsoft Viva Learning is a learning hub that aggregates content from various sources (e.g., LinkedIn Learning, SharePoint) but is not an authoring tool; it cannot create quizzes or surveys itself.

470
MCQeasy

While preparing a Microsoft 365 adoption plan, a consultant is asked to add and remove capacity quickly when demand changes. Cloud concept or benefit best matches this requirement?

A.Rapid elasticity
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Rapid elasticity is a fundamental cloud characteristic defined by NIST, allowing resources such as compute, storage, and network capacity to scale out and in automatically or near-instantly to match fluctuating demand. In a Microsoft 365 adoption plan, this ensures services like Exchange Online and Teams can handle traffic spikes without manual provisioning or over-purchasing hardware, directly reducing cost and improving responsiveness.

Why this answer

Rapid elasticity is a core cloud computing concept defined by NIST (SP 800-145) that allows resources to be provisioned and released elastically, often automatically, to scale rapidly outward and inward commensurate with demand. In Microsoft 365, this means the consultant can quickly add or remove user licenses, storage, or service capacity via the admin center or PowerShell without manual hardware provisioning, directly matching the requirement to adjust capacity on demand.

Exam trap

The trap here is that candidates confuse a specific Microsoft 365 tool (like Planner) with a fundamental cloud characteristic (rapid elasticity), because the question asks for a 'cloud concept or benefit' but lists product names as distractors, testing whether you can distinguish between abstract cloud attributes and concrete service features.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not a cloud concept or benefit related to scaling capacity. Option C is wrong because Data Loss Prevention (DLP) is a security feature that helps protect sensitive data from being shared inappropriately, not a mechanism for adding or removing capacity. Option D is wrong because sensitivity labels are classification and protection controls for data (e.g., encrypting or marking documents), unrelated to the elastic scaling of cloud resources.

471
MCQmedium

A financial services company uses a public cloud provider for its development and testing environments, but keeps its production data and applications on-premises due to strict regulatory requirements. Which cloud deployment model is the company using?

A.Hybrid cloud
B.Public cloud
C.Private cloud
D.Community cloud
AnswerA

Hybrid cloud describes an environment that integrates a public cloud provider with on-premises infrastructure, and here the company uses public cloud for dev/test while keeping production on-premises for regulatory data residency. This mixed deployment lets the organization balance scalability and cost efficiency with strict compliance requirements, which is the defining characteristic of hybrid cloud. It is not purely public or private because both resource locations are actively used.

Why this answer

The company uses a hybrid cloud model because it combines on-premises infrastructure (private cloud) for production workloads with a public cloud provider for development and testing. This allows the organization to meet strict regulatory requirements for data residency and security while leveraging the scalability and cost benefits of the public cloud for non-sensitive workloads.

Exam trap

The trap here is that candidates may confuse 'hybrid cloud' with 'public cloud' because the company uses a public provider, but the key distinction is the combination of on-premises and public resources, not exclusive use of one.

How to eliminate wrong answers

Option B (Public cloud) is wrong because the company keeps production data and applications on-premises, not entirely in the public cloud; a pure public cloud model would have all workloads hosted by a third-party provider. Option C (Private cloud) is wrong because the company uses a public cloud provider for development and testing, which is not part of a solely private cloud deployment. Option D (Community cloud) is wrong because the infrastructure is not shared among multiple organizations with common concerns (e.g., regulatory compliance); instead, it is a mix of private and public resources tailored to a single organization.

472
Multi-Selecteasy

Which TWO Microsoft 365 apps can be used to create and edit documents collaboratively in real time? (Select exactly 2.)

Select 2 answers
A.Microsoft Teams
B.Outlook on the web
C.Access for the web
D.Word for the web
E.OneNote for the web
AnswersD, E

Word for the web is a full browser-based word processor that lets users create, format, and edit .docx documents with real-time co-authoring, comment mentions, and autosave. Multiple authors can view edits by other users within seconds, with version history accessible through the ribbon's File menu. Because it provides the core Office editing experience plus live collaboration, it is one of the two correct answers.

Why this answer

Word for the web and OneNote for the web are both part of the Microsoft 365 web apps suite that support real-time co-authoring. They leverage the Office Online Server infrastructure and the Fluid Framework to allow multiple users to edit the same document simultaneously, with changes syncing via WebSocket connections and operational transforms.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a document editing app because it allows file sharing and preview, but it does not natively provide the real-time collaborative editing capability; that is a feature of the web versions of Office apps like Word and OneNote.

473
MCQeasy

An organization needs to automatically delete Microsoft Teams chat messages after 90 days to comply with a data minimization policy. Which Microsoft Purview feature should they use?

A.Data Loss Prevention (DLP)
B.Retention policies
C.Communication Compliance
D.Information Barriers
AnswerB

Retention policies are the correct mechanism because Microsoft 365 lets you assign a single policy to Teams channel conversations and 1:1/group chats that specifies a retention period (e.g., 90 days) and a disposition action of 'delete automatically' when that period ends. The policy evaluates content age based on the message's creation or last modification date, and Teams will permanently remove messages from the chat view while optionally preserving them for eDiscovery if you enable a preservation hold. This is exactly the lifecycle-management capability the question asks for.

Why this answer

Retention policies in Microsoft Purview are designed to either retain data for a specified period, delete it after that period, or both. For Microsoft Teams chat messages, a retention policy can be configured to automatically delete messages after 90 days, directly supporting a data minimization policy. This is the correct feature because it provides time-based deletion for compliance requirements.

Exam trap

The trap here is that candidates often confuse retention policies (which manage data lifecycle and deletion) with Data Loss Prevention (DLP), assuming DLP can also delete data after a period, but DLP only blocks or alerts on data in motion, not on scheduled deletion.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies are used to detect and prevent the accidental sharing of sensitive information (e.g., credit card numbers) through rules and actions like blocking or warning users, not for scheduling automatic deletion of messages after a set time. Option C is wrong because Communication Compliance is designed to monitor communications for policy violations (e.g., harassment, insider trading) by analyzing messages and flagging them for review, not for enforcing retention or deletion schedules. Option D is wrong because Information Barriers are used to restrict communication and collaboration between specific groups (e.g., to prevent conflicts of interest), not to manage data lifecycle or deletion timelines.

474
MCQmedium

A tenant administrator is advising a department that wants to web/mobile Office apps, business email, Teams, OneDrive, and SharePoint, but not desktop Office apps. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft 365 Business Basic
AnswerD

Microsoft 365 Business Basic is the correct per-user subscription because it supplies the core cloud workloads—Exchange Online for email, SharePoint Online for document storage, Teams for collaboration, and browser/mobile versions of Word, Excel, PowerPoint, and Outlook—while deliberately excluding desktop Office installations. This matches the department's desire for a lightweight, web-first productivity solution under centralized tenant administration. With Business Basic, the tenant administrator can assign licenses, enforce conditional access policies, and provide support from a single admin console.

Why this answer

Microsoft 365 Business Basic is the subscription that includes web and mobile versions of Office apps, business email (Exchange Online), Teams, OneDrive, and SharePoint, but excludes the desktop Office applications. That matches the department's requirement exactly. Business Standard and Premium would include desktop apps, which the department explicitly does not want.

Exam trap

MS-900 often tests the boundary between Business Basic, Standard, and Premium — candidates confuse 'Office apps' (web/mobile) with 'desktop Office apps' and pick a higher SKU than required.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for enterprise video hosting and does not provide email, Office web apps, or the requested productivity suite. Option B is wrong because Microsoft Whiteboard is a collaborative canvas tool, not a licensing SKU that delivers email, Teams, OneDrive, and SharePoint. Option C is wrong because Microsoft Forms is a survey/quiz tool included within Microsoft 365, not a licensing plan that grants the requested services.

475
MCQmedium

During a Microsoft 365 planning workshop, provide business-class email, calendars, contacts, and mailboxes. Microsoft 365 app or service is the best fit?

A.Exchange Online
B.Microsoft Purview Audit
C.Microsoft Forms
D.Microsoft Planner
AnswerA

Exchange Online is the correct answer because it is Microsoft 365's enterprise-grade hosted messaging service, providing business email, shared calendars, contacts, and mailbox management. During a planning workshop, Exchange Online enables users to schedule meetings, share free/busy availability, and communicate via email, which are essential for collaborative business coordination. Its architecture supports public folders, resource mailboxes, and distribution groups, making it the foundational communication tool in a Microsoft 365 tenant.

Why this answer

Exchange Online is the correct choice because it is Microsoft's cloud-hosted messaging platform that provides business-class email, shared calendars, contact management, and mailbox services. It is the core service within Microsoft 365 designed specifically for these communication and collaboration needs, supporting features like shared mailboxes, resource mailboxes, and calendar sharing via Exchange Web Services (EWS) and MAPI over HTTP.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Audit (a compliance tool) with Exchange Online's mailbox auditing or confuse Planner or Forms as capable of handling email and calendar functions, when in fact only Exchange Online provides the core messaging infrastructure.

How to eliminate wrong answers

Option B (Microsoft Purview Audit) is wrong because it is a compliance and auditing solution that logs user and admin activities across Microsoft 365 services; it does not provide email, calendar, or mailbox functionality. Option C (Microsoft Forms) is wrong because it is a survey and quiz creation tool that collects responses via web forms; it lacks any email hosting, calendar, or contact management capabilities. Option D (Microsoft Planner) is wrong because it is a task management and project planning application integrated with Microsoft Teams and SharePoint; it does not handle email, calendars, or mailboxes.

476
MCQeasy

A user receives a phishing email that bypasses the spam filter. The security team wants to report the email to Microsoft for analysis. Which Microsoft 365 Defender portal should they use?

A.Microsoft 365 Defender portal
B.Exchange admin center
C.Azure portal
D.Microsoft Purview compliance portal
AnswerA

Correct. The Microsoft 365 Defender portal is the unified security operations center for Microsoft 365, and its Email & collaboration > Submissions page is explicitly designed for admins to submit suspicious emails (including phishing that bypassed filters) to Microsoft for in-depth analysis. Submitting a sample triggers automated detonation and feeds threat intelligence back into Microsoft's filtering stack, which is the correct remediation workflow for a phish that evaded existing protections.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) is the correct destination for submitting user-reported phishing emails for analysis. It provides the Submissions page under Email & collaboration, where security teams can send suspicious messages directly to Microsoft for review, bypassing the spam filter's failure. This portal consolidates threat intelligence and automated investigation capabilities for email threats.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal with the Exchange admin center, thinking email-related tasks must be done in EAC, but Microsoft 365 Defender is the dedicated security hub for threat submission and analysis.

How to eliminate wrong answers

Option B (Exchange admin center) is wrong because it is used for managing Exchange Online mail flow, transport rules, and mailbox settings, not for submitting phishing samples to Microsoft for analysis. Option C (Azure portal) is wrong because it manages Azure infrastructure, subscriptions, and resources, not Microsoft 365 security operations like email threat submissions. Option D (Microsoft Purview compliance portal) is wrong because it focuses on data governance, compliance, eDiscovery, and retention policies, not on reporting phishing emails for security analysis.

477
MCQmedium

An organization is concerned about data leakage from sensitive emails. They want to enforce encryption on emails containing financial information automatically. Which Microsoft 365 solution should they configure?

A.Data Loss Prevention (DLP) policies
B.Microsoft Purview Message Encryption
C.Microsoft Purview Information Protection (Microsoft Purview Information Protection)
D.Exchange Online Protection (EOP)
AnswerB

Microsoft Purview Message Encryption is the correct answer. It is a dedicated email encryption capability built on Azure Rights Management, allowing organizations to send and receive encrypted messages across domains. You can configure mail flow rules (transport rules) to automatically encrypt messages based on conditions such as the presence of sensitive content, specified users, or message classifications. This directly achieves the goal of encrypting sensitive emails, both in transit and at rest, and provides a secure access experience for recipients.

Why this answer

Microsoft Purview Message Encryption (Option B) is the correct solution because it enables organizations to send and receive encrypted email messages, and it can be configured with mail flow rules to automatically encrypt emails containing sensitive financial information. This service leverages Azure Rights Management (Azure RMS) to provide persistent protection that follows the email, ensuring only authorized recipients can decrypt and read the content.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) policies with encryption capabilities, assuming DLP can automatically encrypt emails, when in fact DLP only detects and blocks or warns, while Message Encryption is the service that actually applies encryption to outbound emails.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies detect and prevent accidental sharing of sensitive data but do not enforce encryption on emails; they can trigger actions like blocking or warning, but encryption is not a native DLP action. Option C is wrong because Microsoft Purview Information Protection (formerly Azure Information Protection) classifies and labels content but does not automatically encrypt emails in transit; it applies labels that can include encryption, but the automatic encryption of outbound emails based on content is handled by Message Encryption policies. Option D is wrong because Exchange Online Protection (EOP) provides anti-spam, anti-malware, and message hygiene but does not offer encryption capabilities; it focuses on protecting the email infrastructure, not the confidentiality of message content.

478
MCQhard

A compliance officer wants to automatically encrypt outgoing emails containing credit card numbers and also prevent recipients from forwarding or copying the content. Which Microsoft Purview solution should be applied?

A.Data Loss Prevention (DLP) policy with encryption
B.Sensitivity label with encryption and rights management
C.Microsoft Information Bar
D.Azure Information Protection unified labeling client
AnswerB

Sensitivity labels in Microsoft Purview are the correct mechanism because they support automatic application of encryption and usage restrictions such as 'Do Not Forward' or 'View-Only' through label policies. When a label is auto-applied based on sensitive content types or user actions, the associated encryption is enforced via Azure Rights Management, giving the compliance officer the required control. This native integration allows for automatic encryption of outgoing emails without requiring end-user intervention.

Why this answer

Sensitivity labels with encryption and rights management (Azure Rights Management) allow you to apply persistent protection that encrypts the email and restricts actions like forwarding, copying, or printing. This meets both requirements: automatic detection of credit card numbers via auto-labeling policies and enforcement of usage restrictions through Rights Management templates (e.g., Do Not Forward).

Exam trap

The trap here is that candidates confuse DLP policies with sensitivity labels, thinking DLP alone can enforce usage restrictions like 'prevent forwarding,' when in fact DLP only detects and optionally triggers a label that provides the encryption and rights management.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy can detect credit card numbers and trigger encryption via a sensitivity label, but DLP itself does not apply rights management restrictions (e.g., prevent forwarding or copying); it relies on an associated sensitivity label for that protection. Option C is wrong because Microsoft Information Bar is a deprecated feature that only displayed a visual banner in Office apps; it does not enforce encryption or rights restrictions on outgoing emails. Option D is wrong because the Azure Information Protection unified labeling client is a legacy client-side tool for labeling files and emails on Windows, not a cloud-based policy that automatically encrypts and restricts outgoing emails in Exchange Online.

479
MCQeasy

A marketing manager can access the company's cloud resources from her laptop at home, her tablet while traveling, and her smartphone. Which essential characteristic of cloud computing does this describe?

A.Resource pooling
B.Scalability
C.Broad network access
D.Measured service
AnswerC

Broad network access is the cloud characteristic that makes capabilities available over the network and accessible through standard protocols from heterogeneous client platforms, including laptops, tablets, and smartphones. The marketing manager's ability to reach company cloud resources from multiple devices directly exemplifies this capability, because the same service is usable regardless of device type or location. This is why broad network access is the correct answer.

Why this answer

Broad network access means cloud resources can be accessed over standard network protocols (e.g., HTTPS, TLS) from a wide range of client devices, such as laptops, tablets, and smartphones. The scenario explicitly describes access from multiple device types and locations, which is the defining characteristic of broad network access as per NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'broad network access' with 'resource pooling' because both involve multiple users or devices, but resource pooling is about the provider's shared infrastructure, not the consumer's ability to use different device types.

How to eliminate wrong answers

Option A is wrong because resource pooling refers to the provider's multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand, not to the ability to access resources from various devices. Option B is wrong because scalability (or rapid elasticity) is the capability to automatically scale resources up or down based on demand, not the cross-device access described. Option D is wrong because measured service involves metering and billing for resource usage (e.g., pay-per-use), not the device-agnostic access pattern.

480
MCQmedium

You have the above Microsoft Purview DLP policy JSON. What will this policy do?

A.Block internal sharing of documents labeled Confidential
B.Alert when Confidential documents are shared externally
C.Block external sharing of documents labeled Confidential
D.Apply encryption to documents labeled Confidential when shared externally
AnswerC

This is the correct interpretation because the rule's condition combines the sensitivity label 'Confidential' with an external sharing activity, and the configured action is blockAccess. When an external user attempts to access or share such a document, the blockAccess action denies that access, effectively blocking the external sharing. This precisely matches the described functionality.

Why this answer

The JSON policy defines a DLP rule that blocks external sharing of documents labeled 'Confidential'. The 'Actions' section includes 'BlockExternalSharing', which prevents users from sharing these documents with external recipients via SharePoint, OneDrive, or Teams. The 'Condition' specifies that the policy applies only to content with the 'Confidential' sensitivity label, ensuring internal sharing remains unaffected.

Exam trap

The trap here is that candidates often confuse 'block external sharing' with 'alert on external sharing' or 'apply encryption', failing to read the specific action in the JSON and assuming a generic protection behavior.

How to eliminate wrong answers

Option A is wrong because the policy does not block internal sharing; the 'BlockExternalSharing' action specifically targets external sharing, and no rule blocks internal sharing of Confidential documents. Option B is wrong because the policy does not include an 'Alert' action; it only blocks external sharing without sending notifications or alerts. Option D is wrong because the policy does not apply encryption; encryption would require an 'ApplyEncryption' action or a sensitivity label with encryption settings, which is not present in the JSON.

481
MCQeasy

A company needs to ensure that sensitive documents stored in SharePoint Online are automatically encrypted and cannot be shared with external users. Which Microsoft Purview feature should they use?

A.Communication compliance
B.Data Loss Prevention (DLP) policies
C.Retention labels
D.Sensitivity labels
AnswerD

Sensitivity labels are the correct solution because they enable persistent protection by applying encryption, permissions, and visual markings to documents and emails, and these protections travel with the file even when it is shared externally. Labels can be assigned manually, automatically based on content matching, or through recommended patterns, and they integrate with Azure Information Protection and Rights Management to enforce read-only, edit, or no-access permissions. Once applied, the document is encrypted and access is restricted according to the label's policy, directly satisfying the requirement to secure sensitive documents. This classification-based approach differs from reactive controls like DLP or communication compliance.

Why this answer

Sensitivity labels are the correct choice because they enforce encryption and access restrictions directly on documents, including blocking external sharing. Unlike DLP policies, which detect and prevent sharing after the fact, sensitivity labels apply persistent protection that travels with the file, ensuring it remains encrypted even if downloaded or shared outside SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, assuming DLP can both detect and encrypt content, but DLP only monitors and blocks sharing actions—it does not apply persistent encryption to the files themselves.

How to eliminate wrong answers

Option A is wrong because Communication compliance is designed to monitor and detect inappropriate communications (e.g., offensive language or regulatory violations) in Exchange Online, Teams, and Yammer, not to encrypt or restrict sharing of documents. Option B is wrong because Data Loss Prevention (DLP) policies can block external sharing of sensitive content, but they do not automatically encrypt the documents themselves; encryption requires a sensitivity label or Azure Information Protection. Option C is wrong because Retention labels are used to manage data lifecycle (retain or delete content) and do not provide encryption or access controls; they are unrelated to preventing external sharing.

482
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to understand the impact of removing a user's license. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.The user may lose access to services included in that license
D.Microsoft Stream
AnswerC

In Microsoft 365, a user license is the entitlement mechanism that grants access to the suite of services (Exchange Online, SharePoint, Teams, etc.). If the license is removed or expires, the tenant administrator can control access, and the user typically loses sign-in access to those services or the services become read-only/degraded, depending on the service and grace period.

Why this answer

When a user's Microsoft 365 license is removed, the tenant-level service remains active, but the user loses access to all services included in that specific license. This is because Microsoft 365 licensing is user-based: each license grants a set of service plans (e.g., Exchange Online, SharePoint, Teams), and removing the license revokes those entitlements. The consultant must understand this fundamental licensing concept to assess the operational impact on the user's productivity and data accessibility.

Exam trap

The trap here is that candidates may confuse individual Microsoft 365 services (like Forms, Whiteboard, or Stream) with the overarching licensing concept, leading them to pick a specific app name instead of recognizing that license removal impacts all services included in that license.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a specific application within Microsoft 365, not a licensing or support concept; it is irrelevant to understanding the impact of license removal. Option B is wrong because Microsoft Whiteboard is another individual service, not a licensing principle; it does not explain how license removal affects user access. Option D is wrong because Microsoft Stream is a video service, not a licensing or admin concept; it does not address the core licensing mechanism of service plan revocation upon license removal.

483
MCQeasy

A newly hired administrator at Northwind Traders needs to understand who can access customer data stored in Microsoft 365 and what Microsoft itself does with that data. Which Microsoft 365 Trust Center resource should they consult to review Microsoft's commitments about data handling, privacy, and security controls?

A.The Microsoft 365 Service Health dashboard in the Microsoft 365 admin center
B.The Microsoft 365 roadmap
C.The Microsoft 365 Trust Center
D.The Microsoft Purview compliance portal audit log
AnswerC

The Microsoft 365 Trust Center is the public portal where Microsoft documents its privacy practices, security controls, compliance offerings, and data-handling commitments, including the Microsoft Product Terms and data protection addendum references. It directly answers the question of who can access customer data and how Microsoft protects it, making it the correct resource to consult.

Why this answer

The Microsoft 365 Trust Center is the authoritative public source for Microsoft's privacy, security, compliance, and data-handling commitments, including how Microsoft employees access customer data and which certifications apply. Service Health, the roadmap, and the audit log are operational or planning tools inside the tenant; they describe the tenant's own state and Microsoft's product plans, not the vendor's contractual and privacy obligations.

Exam trap

The trap here is confusing tenant operational portals, such as Service Health or the audit log, with the public Trust Center that documents Microsoft's own privacy and security commitments.

484
MCQhard

An organization must comply with GDPR and needs to respond to a data subject access request (DSAR) within 30 days. Which Microsoft Purview solution helps search for personal data across Microsoft 365?

A.Data Loss Prevention (DLP)
B.Records Management
C.Audit (Premium)
D.eDiscovery (Premium)
AnswerD

eDiscovery (Premium) supports searching Microsoft 365 content for personal data, satisfying the GDPR 30-day DSAR constraint. Its case-based workflow, custodian management and review sets let compliance teams locate, hold and export responsive items across Exchange, SharePoint, OneDrive and Teams, unlike audit or retention tooling that cannot perform targeted content search.

Why this answer

eDiscovery (Premium) in Microsoft Purview is purpose-built for identifying, collecting, and reviewing content across Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams) in response to legal and regulatory requests like GDPR DSARs. It supports keyword searches, custodian-based holds, and case management workflows that map directly to the DSAR process. Its search capabilities span mailboxes, sites, and chats, which is exactly what a DSAR requires to locate all personal data tied to a data subject.

Exam trap

MS-900 often tests the confusion between Audit (Premium), which logs activity, and eDiscovery (Premium), which actually searches and collects content — candidates pick Audit because 'search' sounds like log search.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention is designed to detect and block sensitive information in motion (e.g., sharing credit card numbers externally) via policies and tips, not to search and collect existing content for a DSAR. Option B is wrong because Records Management governs retention labels, disposition, and the lifecycle of records — it does not provide investigative search across mailboxes and sites. Option C is wrong because Audit (Premium) provides forensic logging and long-term retention of user/admin activity events, but it does not search content itself for personal data tied to a data subject.

485
Multi-Selectmedium

A company uses Microsoft 365 E5. They want to implement a solution to automatically classify and protect sensitive data in emails and documents. Which THREE Microsoft Purview features should they use?

Select 3 answers
A.Sensitivity labels
B.Auto-labeling policies
C.Retention policies
D.eDiscovery
E.Data Loss Prevention (DLP) policies
AnswersA, B, E

Sensitivity labels are the core data classification and protection mechanism in Microsoft 365. They apply persistent protection such as encryption, rights management (RMS), and visual markings (headers/footers/watermarks) to files and emails across SharePoint, OneDrive, Teams, and Windows endpoints. Labels also drive conditional access policies and can apply automatically or manually, making them the foundation for any information protection strategy.

Why this answer

Sensitivity labels are correct because they allow organizations to classify and protect sensitive data by applying encryption, markings, and access restrictions directly to emails and documents. Auto-labeling policies extend this by automatically applying sensitivity labels based on conditions like sensitive information types or patterns, ensuring consistent protection without manual user intervention. Data Loss Prevention (DLP) policies are correct because they detect and prevent accidental sharing of sensitive data by enforcing rules on email and document transmission, such as blocking or warning when sensitive content is detected.

Exam trap

The trap here is that candidates often confuse retention policies (which manage data retention and deletion) with data classification and protection features, leading them to incorrectly select retention policies as a solution for automatically classifying and protecting sensitive data.

486
MCQhard

A compliance administrator needs to ensure that any document containing a patient's health information (e.g., medical record number) is automatically encrypted and restricted to authorized users. The encryption should be enforced regardless of where the document is saved (SharePoint, OneDrive, or email). Which Microsoft Purview feature should they configure?

A.Information Rights Management (IRM)
B.Auto-labeling policies with sensitivity labels
C.Data Loss Prevention (DLP) policies
D.Retention labels
AnswerB

Auto-labeling policies detect sensitive information types such as medical record numbers and apply sensitivity labels automatically. Those labels enforce encryption and access restrictions across SharePoint, OneDrive and Exchange, satisfying the requirement for protection regardless of storage location.

Why this answer

Auto-labeling policies with sensitivity labels are the correct choice because they can automatically apply encryption and access restrictions to documents containing sensitive data like medical record numbers, regardless of where the document is saved (SharePoint, OneDrive, or email). Sensitivity labels support persistent protection that travels with the file, enforcing encryption and authorized user restrictions even when the file is moved or copied. This meets the requirement for automatic, location-independent encryption and access control.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, thinking DLP can enforce encryption, but DLP only monitors and blocks actions—it does not apply persistent protection like sensitivity labels do.

How to eliminate wrong answers

Option A is wrong because Information Rights Management (IRM) applies encryption and permissions only at the file level within a specific application (e.g., Word, Outlook) and does not automatically scan for content patterns like medical record numbers; it requires manual or rule-based application and does not integrate with auto-labeling for content-based classification. Option C is wrong because Data Loss Prevention (DLP) policies can detect sensitive information and block or alert on actions, but they do not natively encrypt or restrict access to documents; DLP is about preventing data exfiltration, not applying persistent protection. Option D is wrong because retention labels are designed for managing data lifecycle (retention and deletion), not for encryption or access control; they do not enforce encryption or restrict user access based on content.

487
MCQhard

Your organization has a Microsoft 365 E5 subscription and wants to centrally manage security incidents across identities, endpoints, and cloud apps. Which Microsoft solution provides this capability?

A.Microsoft Entra ID Protection
B.Microsoft Sentinel
C.Microsoft Defender XDR
D.Microsoft Defender for Endpoint
AnswerC

Microsoft Defender XDR correlates signals across identities, endpoints, email and cloud apps into unified incidents, delivering the centralised cross-domain security incident management the E5 subscription requires. It is the Microsoft solution purpose-built for this integrated detection and response capability.

Why this answer

Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications. It integrates signals from Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into a single portal. This provides centralized security incident management across the specified domains.

Exam trap

MS-900 often tests the distinction between XDR (integrated threat protection across domains) and SIEM (Sentinel, which aggregates logs); candidates may pick Sentinel for centralized incident management, but the question specifies native cross-domain incident management for Microsoft 365 E5.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection focuses on identity risk detection and conditional access, not cross-domain incident management for endpoints and cloud apps. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution that aggregates data from many sources, but it is not the integrated XDR suite that natively manages incidents across Microsoft 365 workloads; it requires connectors and configuration. Option D is wrong because Microsoft Defender for Endpoint only covers endpoint detection and response, not identities or cloud apps.

488
MCQmedium

A healthcare organization needs to automatically apply a sensitivity label to any document stored in a SharePoint document library that contains patient diagnosis codes. The label should prevent the document from being shared externally. The classification must happen after the document is saved, not during creation. Which Microsoft Purview solution should be configured?

A.Auto-labeling with sensitivity labels in Microsoft Purview
B.Microsoft Purview Data Loss Prevention (DLP) policies
C.Microsoft Purview retention labels
D.Microsoft Purview Information Barriers
AnswerA

Auto-labeling in Microsoft Purview is the correct choice because it evaluates content in SharePoint and OneDrive against sensitive info types or trainable classifiers, then automatically applies a sensitivity label that triggers protection such as encryption or restricting external sharing. This is a classification-first approach, which directly satisfies the requirement to 'automatically apply' a sensitivity label without manual user intervention.

Why this answer

Auto-labeling with sensitivity labels in Microsoft Purview is correct because it automatically applies a sensitivity label to documents containing sensitive content (like patient diagnosis codes) after they are saved to SharePoint. This label can enforce protection actions such as preventing external sharing, meeting the requirement for post-save classification.

Exam trap

The trap here is confusing auto-labeling (which applies labels after save) with manual or default labeling (which applies during creation), or mistaking DLP policies for labeling solutions when DLP only detects and blocks sharing without applying persistent labels.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) policies detect and prevent sharing of sensitive data in transit or at rest but do not automatically apply sensitivity labels to documents. Option C is wrong because retention labels manage data lifecycle (retention and deletion) and do not enforce protection actions like blocking external sharing. Option D is wrong because Information Barriers restrict communication between specific groups but do not classify documents or control external sharing based on content.

489
MCQmedium

A department asks for the Microsoft 365 service best suited for department document libraries with version history. Which service should they use?

A.Microsoft Purview Compliance Manager
B.SharePoint Online
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

SharePoint Online provides department document libraries with built-in version history, retaining prior versions of files and enabling restore. It is the Microsoft 365 service purpose-built for team document storage and collaboration, matching the department's requirement.

Why this answer

SharePoint Online is the correct answer because it provides document libraries with built-in version history, allowing users to track, restore, and manage previous versions of documents. This feature is essential for collaboration and compliance, as it enables rollback to earlier versions and audit trails without additional configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's compliance features with document version history, but version history is a core SharePoint Online capability, not a compliance or security tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that helps assess and manage regulatory compliance risks, not a service for document storage or version history. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring privileged access to Azure AD and other Microsoft Online Services, not for document libraries. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response, not a document management service with version history capabilities.

490
MCQmedium

A company uses Microsoft 365 and wants to ensure that sensitive customer data in emails and documents is automatically classified and protected based on content. Which service should they implement?

A.Microsoft Entra ID
B.Microsoft Intune
C.Microsoft Defender for Cloud Apps
D.Microsoft Purview Information Protection
AnswerD

Microsoft Purview Information Protection is the correct service because it provides sensitivity labels that can be applied automatically based on sensitive info types, trainable classifiers, and machine-learning models. These labels classify data in SharePoint, OneDrive, Exchange, and endpoints, and then enforce protection actions like encryption or access restrictions. This directly addresses the requirement to ensure sensitive data is identified and protected, making it the appropriate choice.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides automated classification, labeling, and protection of sensitive data based on content inspection, such as credit card numbers or social security numbers, using trainable classifiers and sensitivity labels. This directly addresses the requirement to automatically classify and protect sensitive customer data in emails and documents within Microsoft 365.

Exam trap

Microsoft often tests the distinction between Microsoft Purview Information Protection (content classification and labeling) and Microsoft Defender for Cloud Apps (cloud app security and DLP), leading candidates to mistakenly choose Defender for Cloud Apps because they associate 'protection' with security monitoring rather than content-based classification.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is an identity and access management service that handles authentication and authorization, not content-based data classification or protection. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for classifying or protecting data within emails and documents. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility and control over cloud app usage, including threat detection and data loss prevention (DLP) policies, but it does not natively perform automatic content-based classification and labeling of emails and documents; that is the role of Purview Information Protection.

491
MCQhard

A legal team at a company needs to preserve all data belonging to a user who is involved in litigation. The preservation must cover Exchange Online email, SharePoint sites, OneDrive for Business files, and Teams chat messages. They also need to be able to search the preserved content and export it. Which Microsoft Purview solution should they use?

A.eDiscovery (Standard) case hold
B.Litigation Hold
C.Auto-apply retention labels
D.Data Loss Prevention (DLP) policy
AnswerA

An eDiscovery (Standard) case hold is the correct solution because it applies a preservation hold across all Microsoft 365 data sources associated with a user, including Exchange mailboxes, SharePoint and OneDrive sites, and Microsoft Teams content. This hold is managed within an eDiscovery case, which also provides integrated search and export capabilities for legal review, ensuring that data is both preserved and accessible for litigation.

Why this answer

eDiscovery (Standard) allows you to create a case, place a hold on user mailboxes, SharePoint sites, OneDrive accounts, and Teams chat messages to preserve content relevant to litigation. It also provides built-in search and export capabilities, making it the correct solution for the legal team's requirements.

Exam trap

The trap here is that candidates often confuse Litigation Hold with eDiscovery holds, assuming Litigation Hold covers all data sources, when in reality it only applies to Exchange mailboxes and lacks the search and export features needed for comprehensive eDiscovery.

How to eliminate wrong answers

Option B (Litigation Hold) is wrong because it only preserves mailbox content (Exchange Online) and does not cover SharePoint, OneDrive, or Teams chat messages, nor does it provide search and export functionality. Option C (Auto-apply retention labels) is wrong because it automates retention and deletion policies based on conditions, but it does not create a litigation-specific hold with search and export capabilities. Option D (Data Loss Prevention (DLP) policy) is wrong because it is designed to prevent data leakage by monitoring and blocking sensitive information, not to preserve data for legal discovery.

492
MCQmedium

Your organization is adopting Microsoft 365 Copilot and wants to ensure that Copilot responses are based only on organizational data that the user has permission to access. Which Microsoft 365 feature ensures this?

A.Microsoft Purview Compliance Manager
B.Microsoft Entra ID
C.Microsoft Intune
D.Microsoft Graph permissions
AnswerD

Microsoft Graph permissions are the correct answer because Copilot for Microsoft 365 operates by calling Microsoft Graph APIs on behalf of the signed-in user, inheriting that user's effective permissions. It can only access resources—such as emails, calendar items, documents, and chats—for which the user has at least the appropriate delegated permission scope, and it respects sensitivity labels and other restrictions. This ensures Copilot cannot surface data the user is not already allowed to see, maintaining least-privilege access.

Why this answer

Microsoft Graph permissions are the correct answer because Copilot uses Microsoft Graph to access organizational data. When a user asks a question, Copilot queries the Microsoft Graph API, which enforces the user's existing permissions (e.g., from Entra ID and SharePoint) to ensure responses are based only on data the user is authorized to see. This is the core mechanism that ties Copilot's responses to the user's access rights.

Exam trap

The trap here is that candidates often confuse identity management (Entra ID) with data-level permission enforcement (Microsoft Graph permissions), assuming that because Entra ID handles authentication, it also controls what data Copilot can access, but the actual data access control is delegated to Graph's permission model.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a tool for assessing and managing compliance posture (e.g., against regulations like GDPR), not for controlling real-time data access permissions for Copilot. Option B is wrong because Microsoft Entra ID (formerly Azure AD) is the identity and authentication service that defines user accounts and groups, but it does not directly enforce data-level permissions within Microsoft Graph queries; it provides the identity token that Graph uses, but the actual permission check is done via Graph permissions. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for controlling data access permissions within Microsoft 365 services like Copilot.

493
MCQeasy

A company wants to use a cloud service that provides ready-to-use business applications such as email, collaboration, and customer relationship management without managing the underlying infrastructure. Which cloud service model is this?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Private cloud
AnswerC

SaaS is a complete, cloud-hosted application delivered over the internet, where the provider manages the entire stack—from infrastructure and middleware to security patches and version updates. Subscribers access the ready-to-use business functionality via a browser or mobile app, needing no installation or development, as exemplified by Exchange Online and Dynamics 365. This model aligns directly with the requirement of using a cloud service that provides ready-to-use business applications.

Why this answer

(SaaS) is correct because Software as a Service delivers ready-to-use business applications like Microsoft 365 (Exchange Online for email, Teams for collaboration, Dynamics 365 for CRM) over the internet, with the provider managing all underlying infrastructure, including servers, storage, and networking. The customer simply accesses the software via a web browser or client app without any responsibility for patching, scaling, or hardware maintenance.

Exam trap

The trap here is that candidates often confuse PaaS with SaaS because both abstract infrastructure, but PaaS requires the customer to develop and manage the application code, whereas SaaS provides fully functional, ready-to-use applications—a distinction Microsoft emphasizes in the MS-900 by focusing on the 'what you manage' vs. 'what the provider manages' model.

How to eliminate wrong answers

Option A (IaaS) is wrong because it provides virtualized computing resources (e.g., virtual machines, storage, networks) but requires the customer to deploy and manage their own operating systems, middleware, and applications—not ready-to-use business apps. Option B (PaaS) is wrong because it offers a platform for developing, testing, and deploying custom applications (e.g., Azure App Services) but does not include pre-built business applications like email or CRM; the customer still writes and manages the application code. Option D (Private cloud) is wrong because it refers to a deployment model where cloud resources are used exclusively by a single organization, either on-premises or hosted, and does not inherently provide ready-to-use business applications; it still requires the organization to manage or procure the software layer.

494
MCQmedium

A sales team needs to track customer interactions, manage leads, and automate follow-up emails. Which Microsoft 365 app is specifically designed for this customer relationship management (CRM) purpose?

A.Microsoft Dynamics 365 Sales
B.Microsoft Outlook
C.Microsoft SharePoint
D.Microsoft Power Automate
AnswerA

Dynamics 365 Sales provides native CRM entities — leads, opportunities and accounts — plus built-in workflow automation for follow-up emails, satisfying the sales team's requirement to track interactions and manage the pipeline without custom development.

Why this answer

Microsoft Dynamics 365 Sales is a dedicated customer relationship management (CRM) application within the Dynamics 365 suite, purpose-built for tracking customer interactions, managing leads, and automating follow-up emails. Unlike general productivity tools, it provides structured pipelines, lead scoring, and workflow automation specifically for sales processes.

Exam trap

The trap here is that candidates confuse a general productivity tool (Outlook) or a workflow engine (Power Automate) with a full CRM solution, overlooking that Dynamics 365 Sales is the only option specifically architected for end-to-end customer relationship management.

How to eliminate wrong answers

Option B is wrong because Microsoft Outlook is an email and calendar client, not a CRM system; it lacks lead management, pipeline tracking, and automated follow-up workflows. Option C is wrong because Microsoft SharePoint is a document management and collaboration platform, not designed for CRM functions like lead scoring or interaction tracking. Option D is wrong because Microsoft Power Automate is a workflow automation tool that can integrate with CRM systems but is not a CRM application itself; it has no native lead or customer interaction management capabilities.

495
MCQmedium

Your organization uses Microsoft 365 E5 and wants to automatically classify emails containing credit card numbers as 'Sensitive' and apply encryption when sent externally. Which Microsoft Purview feature should you use?

A.Sensitivity labels
B.Retention policies
C.Microsoft Purview Data Loss Prevention (DLP)
D.Microsoft Purview Information Protection
AnswerC

Microsoft Purview Data Loss Prevention (DLP) policies are the correct mechanism because they combine sensitive info type detection with rule actions. In an Exchange Online DLP policy, you create conditions that look for credit cards, PII, or custom patterns, and then set the action to 'Encrypt email messages' (using Azure Rights Management) when the condition matches. This operates at send time and can apply encryption dynamically to outbound messages, which is exactly what the organization wants to do. Additionally, DLP can optionally apply a sensitivity label for consistent protection across clients.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct feature because it is specifically designed to detect sensitive data types—such as credit card numbers—via built-in sensitive info types (e.g., Credit Card Number) and automatically enforce protective actions like blocking or encrypting emails when sent externally. Unlike sensitivity labels, DLP policies can inspect content in transit (Exchange Online) and apply encryption through transport rules or Office 365 Message Encryption (OME) without requiring user-applied labels.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection (the umbrella suite) with the specific DLP feature, or they incorrectly assume sensitivity labels can automatically detect and encrypt based on content patterns without a DLP policy to trigger the label application.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are primarily for manual or automatic classification and protection (e.g., encryption) of documents and emails based on label settings, but they do not natively scan for specific data patterns like credit card numbers to trigger encryption on outbound emails—that requires a DLP policy to detect the sensitive info type and then apply a label or encryption action. Option B is wrong because retention policies are used to retain or delete content based on age or compliance requirements, not to classify or encrypt emails in transit based on sensitive data detection. Option D is wrong because Microsoft Purview Information Protection is the overarching suite that includes sensitivity labels and encryption, but the specific feature that automatically detects credit card numbers and enforces encryption on outbound emails is a DLP policy, not Information Protection alone.

496
Multi-Selecteasy

Which THREE of the following are key pillars of the Microsoft Trusted Cloud? (Choose three.)

Select 3 answers
A.Cost optimization
B.Performance
C.Security
D.Privacy
E.Compliance
AnswersC, D, E

Security is a foundational Trusted Cloud pillar, covering protection of data and infrastructure through encryption, identity controls, and threat detection. Microsoft invests heavily in securing Microsoft Entra ID and Azure, making security one of the three pillars alongside privacy and compliance.

Why this answer

The Microsoft Trusted Cloud is built on three foundational pillars: Security, Privacy, and Compliance. Option C (Security) is correct because Microsoft protects customer data using defense-in-depth measures such as encryption, identity controls, and threat detection across its cloud services. Option D (Privacy) is correct because Microsoft commits to being transparent about data collection and usage, giving customers control over their data and not using it for advertising without consent.

Option E (Compliance) is correct because Microsoft maintains a broad portfolio of certifications and attestations (e.g., ISO 27001, SOC, GDPR, HIPAA) so customers can meet their own regulatory obligations. Options A (Cost optimization) and B (Performance) are not pillars of the Trusted Cloud; they are general cloud benefits addressed by tools like Azure Cost Management and Azure Monitor, but they are not part of the trust framework.

Exam trap

MS-900 often tests whether candidates can distinguish the three Trusted Cloud pillars (Security, Privacy, Compliance) from Well-Architected Framework pillars like cost optimization and performance — the trap is selecting generic cloud-quality attributes instead of the trust-specific trio.

497
MCQmedium

A company with 300 users currently has Microsoft 365 Business Premium licenses. They want to add the highest level of automated threat investigation and response capabilities for all users. Which licensing option should they purchase?

A.Upgrade all users to Microsoft 365 E5
B.Add the Microsoft 365 E5 Security add-on for each user
C.Add the Microsoft 365 Defender for Office 365 Plan 2 add-on for each user
D.Add the Microsoft 365 Business Premium Threat Protection add-on
AnswerC

Add the Microsoft 365 Defender for Office 365 Plan 2 add-on: Business Premium already includes Microsoft Defender for Office 365 Plan 1, which provides safe links, safe attachments, and anti-phishing protection for email and SharePoint. Adding the Plan 2 add-on per user elevates that protection with advanced features such as automated investigation and response, threat hunting, and detailed incident reporting. This is the exact SKU designed to address your need for advanced investigation, and it should be licensed for every user who needs those capabilities.

Why this answer

Microsoft 365 Defender for Office 365 Plan 2 provides the highest level of automated investigation and response (AIR) capabilities, including threat hunting, automated remediation, and simulation training. Since the company already has Microsoft 365 Business Premium, which includes Defender for Office 365 Plan 1, adding Plan 2 as an add-on is the most cost-effective way to achieve the desired capabilities without upgrading to E5.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 E5 Security add-on (Option B) with the more targeted Defender for Office 365 Plan 2 add-on, not realizing that the E5 Security add-on includes additional, unnecessary features and costs more, while the question specifically asks for the highest level of automated threat investigation and response for all users, which is exactly what Defender for Office 365 Plan 2 provides.

How to eliminate wrong answers

Option A is wrong because upgrading all users to Microsoft 365 E5 would provide the same capabilities but at a significantly higher cost per user, and the question asks for an add-on to the existing Business Premium licenses, not a full upgrade. Option B is wrong because the Microsoft 365 E5 Security add-on includes Defender for Office 365 Plan 2, but it also bundles other security features (e.g., Microsoft Defender for Identity, Defender for Cloud Apps) that are not required, making it more expensive than the targeted Plan 2 add-on. Option D is wrong because there is no official 'Microsoft 365 Business Premium Threat Protection add-on'—this is a fictitious option that does not exist in Microsoft's licensing catalog.

498
MCQhard

A Litware security team must ensure that when an employee leaves, their mailbox is preserved for five years and remains searchable by the eDiscovery team, but the mailbox must not consume an Exchange Online license. Which Microsoft 365 capability should they configure?

A.Configure an inactive mailbox by applying a Microsoft Purview retention policy to the account
B.Export the mailbox to a PST file and store it in SharePoint Online
C.Place the mailbox on Litigation Hold, then remove the Exchange Online license
D.Convert the mailbox to a shared mailbox and remove the license
AnswerA

An inactive mailbox is created when a mailbox is placed on retention or eDiscovery hold and then its Exchange Online license is removed. Microsoft Purview keeps the content in place, the mailbox remains fully searchable by eDiscovery, and retention settings enforce the five-year period before permanent deletion, exactly matching the scenario without ongoing license cost.

Why this answer

Inactive mailboxes exist precisely for the departure scenario: a hold or retention policy preserves the content, the license is removed, and the mailbox persists as a searchable, non-licensed object. Litigation Hold alone still needs a license, shared mailboxes carry no retention guarantee, and exporting to PST moves data out of the searchable store. The inactive mailbox therefore satisfies both the preservation and the licensing constraints.

Exam trap

The trap here is believing that any hold by itself keeps a mailbox alive for free, when in fact the license must be removed only after a Microsoft Purview retention policy or eDiscovery hold is in place to create an inactive mailbox.

499
MCQmedium

A sales manager needs a visual tool to track the sales pipeline with stages, deal values, and assigned team members. The team should be able to update the board in real time and see changes instantly. Which Microsoft 365 app is most suitable?

A.Microsoft Lists
B.Microsoft Dynamics 365 Sales
C.Microsoft Planner
D.Microsoft Excel
AnswerA

Microsoft Lists provides a visual, web-based tracking tool by letting you create a list with custom columns for deal stage, value, and owner, and then switch to a Board or Gallery view to display records as cards that move between stages. Because each list is backed by SharePoint, edits sync in real time and team members can see the pipeline update immediately. You retain the robustness of a data table rather than a simple task card, so monetary values, rollups, and filtering are natively supported.

Why this answer

Microsoft Lists is the most suitable app because it provides a customizable, real-time collaborative board view that can track sales pipeline stages, deal values, and assigned team members. Lists supports real-time co-authoring and instant updates via SharePoint, making it ideal for a visual, always-current sales tracking tool without requiring a full CRM system.

Exam trap

The trap here is that candidates often confuse Microsoft Planner's task board with a sales pipeline tool, but Planner lacks custom fields for deal values and real-time data updates across multiple users, making Lists the correct choice for this specific requirement.

How to eliminate wrong answers

Option B (Microsoft Dynamics 365 Sales) is wrong because it is a full-featured CRM platform designed for complex sales processes, not a simple visual board tool; it requires licensing and setup beyond the scope of a lightweight team tracking need. Option C (Microsoft Planner) is wrong because it is task-oriented with Kanban boards but lacks native fields for deal values and pipeline stages, and its real-time sync is limited to task status, not custom data like monetary amounts. Option D (Microsoft Excel) is wrong because while it can track data, it does not support real-time collaborative board views with instant updates; changes require manual refresh or sharing, and it lacks the visual pipeline stage representation needed.

500
MCQmedium

A manager wants to create a team site to collaborate with external partners on a project. They need to share documents with external users and control permissions. Which Microsoft 365 service should they use?

A.Microsoft Viva Connections
B.Microsoft Teams
C.OneDrive for Business
D.SharePoint Online
AnswerD

SharePoint Online team sites are the correct solution because they provide a dedicated, cloud-hosted collaboration site with document libraries, lists, page content, and granular permission settings. Site-level external sharing can be enabled in the SharePoint admin center to invite external users with specific roles such as site member or visitor, giving the manager the needed control. This matches the requirement of creating a team site for external collaboration better than any of the other options.

Why this answer

SharePoint Online is the correct choice because it provides team sites with granular permission controls, including the ability to share documents with external users via secure links or direct invitations. It supports external sharing at the site level, allowing the manager to collaborate with partners while maintaining control over permissions and document access.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the primary collaboration tool for external sharing, but Teams relies on SharePoint for file storage and permission management, making SharePoint the correct answer when the question emphasizes creating a team site and controlling permissions.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Connections is a personalized employee experience app within Teams and SharePoint, not designed for external collaboration or document sharing with partners. Option B is wrong because Microsoft Teams is primarily a chat-based collaboration platform that relies on SharePoint for file storage; while it can share with external users, the question specifically asks for a service to create a team site and control permissions, which is SharePoint's core function. Option C is wrong because OneDrive for Business is a personal storage service for individual users, not designed for creating team sites or managing external partner collaboration with granular permissions.

501
MCQmedium

A company needs a dedicated, private network connection between its on-premises data center and Microsoft's cloud infrastructure to support a hybrid deployment with low latency and high reliability. The connection must not traverse the public internet. Which service should they use?

A.Azure ExpressRoute
B.Azure VPN Gateway
C.Azure Virtual WAN
D.Microsoft Entra ID Application Proxy
AnswerA

Azure ExpressRoute provisions a dedicated, private Layer 2 or Layer 3 circuit through an MPLS or network service provider, extending an on-premises infrastructure directly into Azure at Microsoft edge locations without traversing the public internet. This private connectivity offers lower and more consistent latency, higher security, bandwidth up to 100 Gbps, and a 99.95% availability SLA when redundant circuits are configured. For a company that specifically requires a dedicated private network connection for hybrid workloads, ExpressRoute is the Azure service built exactly for that scenario.

Why this answer

Azure ExpressRoute is the correct choice because it provides a dedicated, private network connection from an on-premises data center directly into Microsoft's cloud infrastructure, bypassing the public internet entirely. This ensures low latency, high reliability, and consistent performance for hybrid deployments, as the traffic traverses a private MPLS or Ethernet link rather than the unpredictable internet.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway with a private connection because it uses encryption, but the key differentiator is that VPN traffic still traverses the public internet, whereas ExpressRoute bypasses it entirely for a truly private, dedicated link.

How to eliminate wrong answers

Option B (Azure VPN Gateway) is wrong because it creates an encrypted tunnel over the public internet, which means traffic traverses the internet and cannot guarantee the low latency, high reliability, or complete privacy required by the scenario. Option C (Azure Virtual WAN) is wrong because it is a networking service that aggregates branch connectivity and can use ExpressRoute or VPN, but by itself it does not provide a dedicated private connection; it is a management and routing overlay, not a direct private link. Option D (Microsoft Entra ID Application Proxy) is wrong because it is an identity and access proxy for publishing on-premises web applications to external users via the internet, not a private network connection between data centers and Azure.

502
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to use a dedicated environment controlled by one organization. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Private cloud
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerB

Private cloud is a deployment model in which computing resources are dedicated exclusively to one organization, whether hosted on-premises or by a provider. It gives the service owner isolated tenancy, custom control over networking and compliance, and predictable capacity, directly matching the scenario's cloud model or benefit. In Microsoft's portfolio, this maps to offerings like Azure Stack rather than shared Microsoft 365 services.

Why this answer

A private cloud is a dedicated environment controlled by a single organization, providing exclusive access and management over resources. This matches the requirement for a dedicated environment, as opposed to public cloud or hybrid models where control is shared or distributed.

Exam trap

The trap here is that candidates confuse Microsoft 365 service features (like Planner, DLP, or sensitivity labels) with cloud deployment models, failing to recognize that 'dedicated environment controlled by one organization' is the textbook definition of a private cloud.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool within Microsoft 365, not a cloud deployment model or concept. Option C is wrong because Data Loss Prevention (DLP) is a security policy feature that helps prevent data leaks, not a cloud environment type. Option D is wrong because sensitivity labels are classification tools for data protection, not a cloud concept describing dedicated infrastructure control.

503
Multi-Selecthard

Which THREE are key characteristics of cloud computing as defined by NIST?

Select 3 answers
A.High availability
B.Broad network access
C.Resource pooling
D.On-demand self-service
E.Reserved capacity
AnswersB, C, D

Broad network access is a NIST essential characteristic: capabilities are available over the network through standard mechanisms, accessible from heterogeneous client platforms such as laptops, tablets, and phones. This satisfies the stem's request for a NIST-defined cloud characteristic.

Why this answer

The NIST SP 800-145 definition of cloud computing lists five essential characteristics, and three of them appear here: Broad network access (B), Resource pooling (C), and On-demand self-service (D). Broad network access (B) is correct because cloud capabilities must be available over the network through standard mechanisms that promote use by heterogeneous thin or thick client platforms such as mobile phones, laptops, and PDAs. Resource pooling (C) is correct because the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to demand.

On-demand self-service (D) is correct because a consumer can unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with each service provider. The other two NIST characteristics not listed among the options are rapid elasticity and measured service. High availability (A) is a desirable quality attribute but is not one of the five NIST essential characteristics, and reserved capacity (E) describes a purchasing or pricing model rather than a defining characteristic of cloud computing.

Exam trap

MS-900 often tests the NIST essential characteristics, and candidates may include high availability or reserved capacity because they are common cloud features, but they are not part of the NIST definition.

504
Drag & Dropmedium

Drag and drop the steps to assign a Microsoft 365 license to a user via the admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

License assignment involves selecting the user, managing licenses, choosing the product, and saving.

505
MCQhard

A graphic designer needs to create a professional printed brochure with custom page layouts, text wrapping around images, and precise control over typography. Which Microsoft 365 app is designed for this type of desktop publishing task?

A.Microsoft Publisher
B.Microsoft Sway
C.Microsoft Word
D.Microsoft PowerPoint
AnswerA

Microsoft Publisher is the correct choice because it is a dedicated desktop publishing (DTP) application within Microsoft 365, purpose-built for professional print production. It provides precise layout controls such as master pages, guide lines, and baseline grids, along with print-ready output features like CMYK color separation, bleed settings, and crop marks. These tools are essential for creating brochures, flyers, and newsletters that meet commercial printing standards, which generic productivity apps cannot match.

Why this answer

Microsoft Publisher is the correct choice because it is specifically designed for desktop publishing tasks such as creating professional brochures with custom page layouts, text wrapping around images, and precise typography control. Unlike general-purpose apps, Publisher offers advanced layout tools like master pages, baseline guides, and typographic controls that are essential for print-ready documents.

Exam trap

The trap here is that candidates often confuse Microsoft Word's basic text wrapping and image placement capabilities with the full desktop publishing features of Publisher, assuming Word can handle professional print layouts when it lacks the necessary precision and print-production tools.

How to eliminate wrong answers

Option B is wrong because Microsoft Sway is a web-based storytelling and presentation app focused on interactive, responsive layouts for digital consumption, not precise print desktop publishing. Option C is wrong because Microsoft Word is a word processor optimized for text-heavy documents and basic formatting, lacking the advanced layout and typography controls needed for professional brochure design. Option D is wrong because Microsoft PowerPoint is designed for slide-based presentations with sequential content, not for creating multi-page print layouts with text wrapping and precise typography.

506
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Purview Information Protection? (Choose three.)

Select 3 answers
A.Auto-classify content based on sensitive data types
B.Apply sensitivity labels to documents and emails
C.Encrypt documents and control access using labels
D.Block sharing of sensitive data via email
E.Define retention policies for mailboxes
AnswersA, B, C

Auto-classification scans content for sensitive data types, such as credit card or national insurance numbers, and applies labels without manual intervention. This directly satisfies the stem's requirement for a Microsoft Purview Information Protection capability, since automated, policy-driven labelling of sensitive content is a core function of that service.

Why this answer

Microsoft Purview Information Protection provides auto-classification of content by detecting sensitive data types (e.g., credit card or national ID patterns) through trainable classifiers and sensitive information types, which justifies option A. It also lets organizations apply sensitivity labels to documents and emails across Microsoft 365 apps, making option B correct. Those same sensitivity labels can enforce encryption and access restrictions (e.g., via Azure Rights Management), so option C is correct.

Option D is not a core Information Protection capability; blocking email sharing of sensitive data is handled by Data Loss Prevention (DLP) policies, a related but distinct workload. Option E is also incorrect here because retention policies for mailboxes belong to Microsoft Purview Data Lifecycle Management, not Information Protection.

Exam trap

The trap is confusing Information Protection with other Purview solutions like DLP or Data Lifecycle Management; candidates may select capabilities that belong to those other solutions.

507
MCQmedium

A project team needs a centralized workspace that includes a shared calendar, a document library for storing deliverables, a task list with assignments, and the ability to have threaded discussions about each item. They want a solution that is available out of the box in Microsoft 365 and integrates with Microsoft Teams. Which service should they use?

A.Microsoft Teams
B.SharePoint team site
C.Microsoft Viva Engage
D.Microsoft Planner
AnswerB

A SharePoint team site is a true centralized workspace because it includes a document library for storing and co-authoring files, a built-in calendar, custom lists, and a discussion board web part out of the box. This site can be used directly in a browser or surfaced within Microsoft Teams as a tab, making it the correct answer. It is also the default content host for Teams, so the files and some lists in a team are actually stored in the associated SharePoint site.

Why this answer

A SharePoint team site provides a centralized workspace with a shared calendar, document library, task list, and threaded discussions out of the box, and it integrates natively with Microsoft Teams (each team is backed by a SharePoint site). This matches all stated requirements without custom development. Microsoft Teams is a collaboration hub but relies on SharePoint for file storage and doesn't natively provide a document library or task list as standalone features.

Exam trap

The trap is choosing Microsoft Teams because the question mentions Teams integration — but Teams is the front-end collaboration layer, while SharePoint provides the actual workspace components (document library, calendar, task list).

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat/collaboration interface that uses SharePoint behind the scenes for files; it does not itself provide a shared calendar, document library, or task list as out-of-the-box components. Option C is wrong because Microsoft Viva Engage (formerly Yammer) is an enterprise social network focused on communities and conversations, not structured project workspaces with calendars and document libraries. Option D is wrong because Microsoft Planner provides task management only — it lacks a shared calendar, document library, and threaded discussions.

508
MCQmedium

A company runs a critical application on-premises but wants to extend capacity to the cloud during peak demand without purchasing additional hardware. Which cloud deployment model best describes this strategy?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Multi-cloud
AnswerC

Hybrid cloud is correct because it explicitly combines an on-premises environment with one or more public cloud services, connected through a secure, dedicated network (e.g., VPN gateway, Azure ExpressRoute) and often unified identity for consistent management. This architecture allows a critical application to remain running on-premises while 'bursting' into the public cloud during peak load—scaling out additional instances or offloading batch processing to the cloud. The company's stated goal directly matches the hybrid cloud value proposition of preserving existing investments while gaining elastic capacity and resilience.

Why this answer

A hybrid cloud model combines on-premises infrastructure (private cloud) with public cloud resources, enabling a company to 'burst' into the public cloud during peak demand without purchasing additional hardware. This strategy, often called cloud bursting, allows the critical application to run locally under normal conditions and seamlessly extend capacity to a public cloud provider like Azure during spikes.

Exam trap

The trap here is that candidates confuse 'hybrid cloud' with 'multi-cloud,' but hybrid cloud specifically involves a mix of on-premises and public cloud, while multi-cloud involves multiple public clouds without any on-premises component.

How to eliminate wrong answers

Option A is wrong because a pure public cloud model would require migrating the entire critical application off-premises, which contradicts the requirement to keep it on-premises and only extend capacity during peak demand. Option B is wrong because a private cloud is entirely on-premises and would still require purchasing additional hardware to handle peak loads, defeating the goal of avoiding hardware purchases. Option D is wrong because multi-cloud refers to using multiple public cloud providers (e.g., AWS and Azure) simultaneously, not extending an on-premises environment to the cloud.

509
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to control who can purchase or change subscriptions. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Forms
C.Admin roles and billing permissions
D.Microsoft Stream
AnswerC

Admin roles and billing permissions are the mechanisms that determine which users can manage Microsoft 365 subscriptions, assign licenses, and oversee financial transactions. For example, a Global Administrator has full control, while a Billing Administrator or License Administrator has specific delegated authority for purchasing and license management. The consultant must review these roles to identify the responsible person, making this the correct answer.

Why this answer

The question asks about controlling who can purchase or change subscriptions, which is a billing and licensing administration task. Admin roles and billing permissions in Microsoft 365 allow you to delegate specific permissions, such as the Billing Administrator role, which grants the ability to make purchases, manage subscriptions, and handle support tickets. This directly addresses the requirement to restrict subscription changes to authorized personnel.

Exam trap

The trap here is that candidates may confuse collaboration tools (Whiteboard, Forms, Stream) with administrative control, assuming any Microsoft 365 service can manage subscriptions, when in fact only specific admin roles and billing permissions handle subscription changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a licensing or admin control mechanism; it has no role in managing subscriptions or billing permissions. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to subscription management or admin role delegation. Option D is wrong because Microsoft Stream is a video hosting and sharing service within Microsoft 365, and it does not provide any functionality for controlling subscription purchases or admin permissions.

510
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to require users to approve sign-ins with a mobile app after entering a password. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Multifactor authentication (MFA)
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Multifactor authentication (MFA) is a core identity security feature in Microsoft 365 that requires a user to provide at least two verification methods, such as a password plus a code from an authenticator app or a phone call. This significantly reduces the risk of account compromise because a stolen password alone is insufficient to gain access. MFA is enforced at the identity layer via Azure Active Directory, and can be applied globally or through Conditional Access policies, making it the correct capability when documenting a security control for the help desk lead.

Why this answer

Multifactor authentication (MFA) is the correct capability because it requires users to provide a second form of verification—such as approving a sign-in via the Microsoft Authenticator mobile app—after entering their password. This aligns with the security best practice of 'something you know' (password) plus 'something you have' (mobile device approval), which is a core MFA scenario in Microsoft Entra ID (formerly Azure AD).

Exam trap

The trap here is that candidates may confuse productivity tools (Planner, Forms, Stream) with security capabilities, mistakenly thinking any Microsoft 365 app can enforce authentication policies, when only identity and access management services like MFA in Microsoft Entra ID can do so.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and project planning tool, not a security or identity capability; it cannot enforce sign-in approval workflows. Option C is wrong because Microsoft Forms is a survey and data collection tool, not an identity or authentication service; it has no role in requiring mobile app approval for sign-ins. Option D is wrong because Microsoft Stream is a video hosting and sharing platform, not a security or identity feature; it cannot be used to enforce multifactor authentication policies.

511
MCQeasy

A company wants to run a workload that requires the highest level of physical security and control over hardware. They have the budget to purchase and maintain their own data center. Which cloud deployment model should they choose?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerB

A private cloud places infrastructure on hardware the organisation owns and controls, delivering the highest physical security and hardware control the workload demands. Because the company has budget to purchase and maintain its own data centre, this deployment model directly satisfies both constraints.

Why this answer

A private cloud deployment model is correct because it provides dedicated infrastructure for a single organization, offering the highest level of physical security and full control over hardware. This model allows the company to purchase, own, and manage its own data center, ensuring compliance with stringent security requirements and complete hardware isolation.

Exam trap

The trap here is that candidates often confuse 'hybrid cloud' with 'best of both worlds' and overlook that the question explicitly demands the highest physical security and hardware control, which only a private cloud with dedicated on-premises hardware can provide.

How to eliminate wrong answers

Option A is wrong because the public cloud model shares physical hardware among multiple tenants via hypervisors, which reduces direct control over hardware and cannot guarantee the highest level of physical security. Option C is wrong because the hybrid cloud model combines public and private clouds, but the public cloud component inherently lacks the dedicated hardware control required, and the model does not mandate exclusive hardware ownership. Option D is wrong because the community cloud model shares infrastructure among several organizations with common concerns, which still involves shared hardware and does not provide the exclusive physical control and security of a single-tenant private cloud.

512
Matchingmedium

Match each Microsoft 365 pricing model to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Each user requires a license; most common model

License assigned to a device, not a user

Additional feature purchased on top of a base plan

Single service subscription, e.g., Exchange Online Plan 1

Why these pairings

Microsoft 365 offers different pricing models: per-user (each user licensed), per-device (each device licensed), and consumption-based (pay per use). Common confusions include swapping per-user and per-device, or confusing consumption with subscriptions.

513
MCQeasy

An administrator needs to assign Microsoft 365 licenses to new users in bulk. They have a CSV file with user details and want to use a script. Which tool should they use?

A.Microsoft Graph PowerShell
B.Microsoft 365 admin center
C.Azure CLI
D.Exchange admin center
AnswerA

Microsoft Graph PowerShell is the correct choice because it exposes the Microsoft Graph API's license assignment capabilities through cmdlets such as Set-MgUserLicense. This module allows administrators to script the assignment of one or more licenses to users in bulk by specifying the user's UserPrincipalName and the corresponding SKU IDs, with the ability to disable service plans during assignment. It is the only listed option that provides a programmatic, automation-friendly interface for Microsoft 365 license management, making it ideal for dynamic or large-scale licensing operations.

Why this answer

Microsoft Graph PowerShell is the correct tool because it provides cmdlets like `New-MgUser` and `Set-MgUserLicense` that can process a CSV file and assign licenses in bulk via the Microsoft Graph API. This is the modern, scriptable approach for automating license assignments without manual steps in a GUI.

Exam trap

The trap here is that candidates often confuse Azure CLI with Microsoft Graph PowerShell, assuming any command-line tool can manage Microsoft 365 licensing, but Azure CLI lacks the specific Graph API endpoints for license assignment.

How to eliminate wrong answers

Option B is wrong because the Microsoft 365 admin center is a web-based GUI for manual, one-by-one or small-group license assignments, not a scriptable tool for bulk operations from a CSV. Option C is wrong because Azure CLI is designed for managing Azure resources (VMs, storage, etc.), not for assigning Microsoft 365 licenses via Graph API. Option D is wrong because the Exchange admin center is focused on Exchange Online mailboxes and transport rules, not on license management across the Microsoft 365 tenant.

514
Multi-Selecteasy

Which TWO Microsoft 365 services provide capabilities for insider risk management?

Select 2 answers
A.Microsoft Entra ID
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Communication Compliance
D.Microsoft Intune
E.Microsoft Defender XDR
AnswersB, C

Microsoft Purview Insider Risk Management is a dedicated solution designed to detect, investigate, and act on potential internal threats such as data exfiltration or sabotage. It uses machine learning and predefined risk indicators to score user activities across Microsoft 365, enabling security teams to identify subtle patterns of insider misuse. This service directly fulfills insider risk management requirements.

Why this answer

Microsoft Purview Insider Risk Management (option B) is a dedicated service that uses machine learning and behavioral analytics to detect, investigate, and respond to risky user activities such as data theft, policy violations, or unauthorized access. It correlates signals from Microsoft 365 logs, HR data, and user behavior to identify potential insider threats, making it the primary tool for insider risk management.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (external threat detection) with insider risk management, or mistakenly think Entra ID's identity protection features cover internal user behavior monitoring, when in fact only Purview Insider Risk Management and Communication Compliance directly address insider risk scenarios.

515
MCQmedium

A marketing team needs a shared workspace where they can store documents, manage a shared calendar, conduct video meetings, and collaborate on announcements. They want this workspace to be integrated with other Microsoft 365 apps. Which Microsoft 365 service is best suited for this requirement?

A.Microsoft Teams
B.Yammer
C.SharePoint
D.Microsoft Stream
AnswerA

Microsoft Teams provides a purpose-built multi-faceted workspace: each team contains channels for threaded conversations, a SharePoint-backed document library for file storage, a shared Outlook calendar (via the Calendar app), and native video/audio meetings. This integrated hub also supports third-party and Microsoft 365 app additions, such as Planner or Power BI, without leaving the client. That combination directly satisfies a marketing team's need for a shared workspace with notes, files, calendar, and meetings.

Why this answer

Microsoft Teams is best suited because it provides a shared workspace that integrates document storage (via SharePoint), a shared calendar (via Exchange), video meetings (via Teams meetings), and collaboration on announcements (via channel posts and the Announcement app), all within a single interface that natively integrates with other Microsoft 365 apps.

Exam trap

The trap here is that candidates often confuse SharePoint's document management capabilities with a complete workspace solution, overlooking that SharePoint alone cannot provide integrated video meetings or real-time chat without additional services.

How to eliminate wrong answers

Option B (Yammer) is wrong because Yammer is an enterprise social network focused on organization-wide conversations and communities, not a team workspace with integrated document storage, shared calendars, or video meetings. Option C (SharePoint) is wrong because while SharePoint provides document storage and some calendar functionality, it lacks native video meeting capabilities and real-time chat, requiring additional tools like Teams or Skype for Business for meetings. Option D (Microsoft Stream) is wrong because Stream is a video hosting and management platform for enterprise video content, not a collaborative workspace for documents, calendars, meetings, or announcements.

516
MCQmedium

A healthcare organization must keep sensitive patient data on-premises due to regulatory compliance, but wants to use cloud services for other applications like customer relationship management and collaboration. Which cloud deployment model best meets this requirement?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

A hybrid cloud combines an organization's on-premises infrastructure, such as an Azure Stack edge device or local datacenter, with public cloud services via a secure connection like VPN or ExpressRoute. This allows sensitive patient data to remain resident in the on-premises environment while compute and storage for non-sensitive workloads scale into the public cloud, directly satisfying the stated requirement.

Why this answer

The hybrid cloud model is correct because it allows the healthcare organization to keep sensitive patient data on-premises (private cloud) for regulatory compliance (e.g., HIPAA), while leveraging public cloud services for customer relationship management and collaboration tools like Microsoft Dynamics 365 and Microsoft 365. This deployment model provides a unified environment where workloads can be distributed across on-premises and cloud infrastructure, ensuring data sovereignty and compliance without sacrificing scalability or cost efficiency.

Exam trap

The trap here is that candidates often confuse 'private cloud' as the only compliant option for sensitive data, overlooking that hybrid cloud allows the organization to meet compliance for specific workloads while still benefiting from public cloud economics for others.

How to eliminate wrong answers

Option A is wrong because a public cloud model would require all workloads, including sensitive patient data, to run on shared infrastructure managed by a third-party provider, which violates regulatory compliance requirements for data residency and control. Option B is wrong because a private cloud model, while secure and compliant, would force the organization to host all applications—including CRM and collaboration tools—on-premises, negating the cost and scalability benefits of cloud services for non-sensitive workloads. Option D is wrong because a community cloud is designed for organizations with shared compliance concerns (e.g., multiple healthcare entities), but it still requires all participants to adhere to a common regulatory framework and does not inherently allow selective placement of sensitive data on-premises while using public cloud for other apps.

517
MCQhard

Refer to the exhibit. The administrator wants to reduce costs by reclaiming unused licenses. However, they must ensure that no user loses access to services. What should they do?

A.Purchase fewer licenses next month to offset the unused count
B.Identify users with no activity for 90 days and remove their licenses
C.Remove licenses from 30 users who have not logged in for 30 days
D.Reassign the 30 unused licenses to new users
AnswerB

A 90-day inactivity threshold is a reliable, commonly used indicator that a license is genuinely unused. Using Azure AD sign-in logs or Microsoft 365 usage reports, you can identify accounts with no logon or service activity for that window, then unassign and remove those licenses to immediately reduce the bill while preserving the seats for reallocation.

Why this answer

The administrator should identify users with no activity for 90 days and then remove their licenses. This approach directly reclaims unused licenses while ensuring that only truly inactive users lose access, minimizing the risk of disrupting active users. Microsoft 365 provides usage reports (e.g., in the Microsoft 365 admin center) that can show sign-in activity over the last 30, 60, or 90 days, allowing precise identification of dormant accounts.

Exam trap

The trap here is that candidates confuse 'reclaiming unused licenses' with 'reassigning licenses' or use an overly short inactivity period (30 days), failing to recognize that Microsoft 365 requires a longer, more conservative threshold to avoid disrupting users who are temporarily inactive.

How to eliminate wrong answers

Option A is wrong because purchasing fewer licenses next month does not reclaim currently unused licenses; it only reduces future costs and does not address the immediate need to free up licenses without risking service disruption. Option C is wrong because removing licenses from users who have not logged in for 30 days is too aggressive; 30 days of inactivity may include legitimate users on vacation or leave, and Microsoft 365 best practices recommend a longer inactivity period (e.g., 90 days) to avoid accidentally removing active users. Option D is wrong because reassigning the 30 unused licenses to new users does not reclaim licenses; it simply redistributes them, leaving the total license count unchanged and not reducing costs.

518
MCQhard

A security administrator needs to automatically restrict access to documents that contain 'PII' (personally identifiable information) so that only employees in the 'Data Privacy' security group can view them. Additionally, editing and printing of these documents must be disabled. Which combination of Microsoft Purview features should be used?

A.Sensitivity labels with auto-labeling and encryption that restricts permissions to the 'Data Privacy' group
B.Data Loss Prevention (DLP) policy with a block action
C.Retention policy with a restrict action
D.Privileged Identity Management (PIM)
AnswerA

This is the correct approach because sensitivity labels in Microsoft Purview can be configured to automatically detect sensitive data types (such as PII) during file uploads or edits, and then apply encryption that dynamically restricts access to approved members of the 'Data Privacy' group. The label's encryption settings enforce an 'only view' or 'co-author' permission level, meaning users outside the group cannot open the document even if they discover it. This combines classification with persistent access control, which directly satisfies the requirement.

Why this answer

Sensitivity labels in Microsoft Purview can be configured with auto-labeling to automatically detect and classify documents containing PII, and then apply encryption that restricts access to only the 'Data Privacy' security group. Additionally, the label can enforce usage rights such as 'View Only' to disable editing and printing, meeting all requirements.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, not realizing that DLP blocks data in motion or at rest but cannot enforce persistent document-level permissions like disabling editing or printing.

How to eliminate wrong answers

Option B is wrong because a DLP policy with a block action can prevent sharing or transmission of PII data but cannot restrict access to documents already stored or disable editing/printing within the document itself. Option C is wrong because a retention policy is designed to preserve or delete data based on timeframes, not to restrict access or control permissions on documents. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments and does not classify, label, or restrict access to documents based on content.

519
MCQmedium

A consulting firm needs a tool to allow customers to book 30-minute online consulting sessions. The tool must show real-time availability of consultants, send automatic reminders, and allow customers to reschedule. Which Microsoft 365 app should they use?

A.Microsoft Bookings
B.Microsoft Teams
C.Microsoft Forms
D.Microsoft Lists
AnswerA

Microsoft Bookings provides a shared booking page with real-time calendar availability, letting customers self-schedule 30-minute sessions. It automatically sends confirmation and reminder emails and permits customer rescheduling, directly satisfying all three stated requirements without custom development.

Why this answer

Microsoft Bookings is the correct choice because it is a Microsoft 365 app specifically designed for scheduling and managing appointments. It provides a public booking page that shows real-time consultant availability, sends automatic email and SMS reminders, and allows customers to reschedule or cancel bookings directly, meeting all the stated requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Teams' scheduling feature (which is for internal meetings) with the customer-facing appointment booking capabilities of Microsoft Bookings, leading them to incorrectly select Teams.

How to eliminate wrong answers

Option B is wrong because Microsoft Teams is a collaboration and communication platform (chat, meetings, calls) and does not include native appointment scheduling with real-time availability display, automatic reminders, or customer-facing rescheduling capabilities. Option C is wrong because Microsoft Forms is a survey and quiz creation tool for collecting data; it cannot manage real-time availability, send automatic reminders, or handle rescheduling of appointments. Option D is wrong because Microsoft Lists is a data tracking and organization app for creating lists and workflows; it lacks built-in scheduling features like real-time availability, automated reminders, and customer self-service rescheduling.

520
MCQhard

You are the Microsoft 365 administrator for Contoso Ltd., a multinational company with 5,000 employees. The company uses Microsoft 365 E5 licenses for all users. The HR department has requested a solution to onboard new employees more efficiently. Currently, when a new employee is hired, IT manually creates a user account in Microsoft Entra ID (formerly Azure AD), assigns licenses, creates a mailbox in Exchange Online, and provisions a OneDrive for Business account. This process takes approximately 2 hours per employee and is prone to errors. The HR team uses a third-party HR system (Workday) to manage employee records. When an employee is hired in Workday, HR wants the process to be automated so that within 15 minutes, the employee has a Microsoft 365 account, appropriate licenses based on their department, and access to Microsoft Teams and SharePoint Online. Additionally, the employee should be automatically added to a Microsoft 365 group for their department. The solution must minimize manual intervention and ensure that only authorized HR personnel can trigger the automation. What should you implement?

A.Deploy Microsoft Identity Manager (MIM) to synchronize Workday with on-premises AD, then sync to Entra ID.
B.Configure Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center.
C.Create a Power Automate flow that triggers when a new employee is added to a SharePoint Online list, then uses Graph API to create the user.
D.Develop a custom solution using Microsoft Graph API and Azure Functions that polls Workday for changes.
AnswerB

Configuring Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center is the correct solution because it enables native, automated lifecycle management between Workday as the HR source of truth and Entra ID. This prebuilt connector handles user creation, attribute mapping, group membership, and license assignment based on business rules, and it continuously syncs updates and terminations. It uses the latest provisioning service, which is cloud-native, eliminates the need for on-premises infrastructure, and is the Microsoft-recommended approach for this integration.

Why this answer

Workday to Microsoft Entra ID user provisioning is a built-in, cloud-native integration that automates the entire lifecycle of user accounts—creation, license assignment, group membership, and access to apps like Teams and SharePoint—directly from Workday HR events. It meets the 15-minute requirement, minimizes manual intervention, and can be scoped to allow only authorized HR personnel to trigger the automation via role-based access control in Entra ID.

Exam trap

The trap here is that candidates often confuse on-premises identity tools like MIM with cloud-native provisioning, or they overcomplicate the solution with custom development when a built-in connector exists, failing to recognize that Microsoft 365 E5 includes Entra ID P2 features that support automated HR-driven provisioning.

How to eliminate wrong answers

Option A is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution that requires a local Active Directory infrastructure and adds complexity, latency, and manual steps; it does not provide the cloud-native, near-real-time provisioning from Workday directly to Entra ID that the scenario demands. Option C is wrong because a Power Automate flow triggered by a SharePoint Online list is not a secure or reliable way to create user accounts—it bypasses proper HR source-of-truth integration, lacks lifecycle management, and introduces security risks by relying on a manually maintained list. Option D is wrong because developing a custom solution with Microsoft Graph API and Azure Functions that polls Workday is unnecessarily complex, requires ongoing maintenance, and does not leverage the pre-built, supported Workday-to-Entra ID provisioning connector that is designed for this exact use case.

521
MCQmedium

A project team needs to track action items and issues in a shared list that is accessible from within Outlook and SharePoint. They need to be able to create custom columns, set reminders, and view a history of changes. Which Microsoft 365 app is best suited for this?

A.Microsoft Lists
B.Microsoft To Do
C.Microsoft Planner
D.Microsoft Viva Engage
AnswerA

Microsoft Lists is a data-centric tracking application built on SharePoint that lets teams create customizable lists with tailored columns such as status, owner, due date, and priority for managing action items and issues. It provides full per-item version history, which preserves an audit trail of every change, and integrates seamlessly with Microsoft Teams, Power Automate, and Power Apps for notifications and automation. These capabilities make it the appropriate choice for shared, structured issue tracking.

Why this answer

Microsoft Lists is the correct choice because it provides a shared, customizable list that integrates directly with both Outlook and SharePoint. It allows users to create custom columns, set reminders via Power Automate or column formatting, and track version history for changes, meeting all specified requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Planner's task boards with the structured list and column customization capabilities of Microsoft Lists, overlooking the specific need for custom columns and change history.

How to eliminate wrong answers

Option B is wrong because Microsoft To Do is a personal task management app that lacks shared lists accessible from SharePoint and does not support custom columns or change history tracking. Option C is wrong because Microsoft Planner is designed for team task management with boards and buckets, but it does not offer custom columns or a detailed change history view like Lists does. Option D is wrong because Microsoft Viva Engage is an employee engagement and social networking platform, not a list or task tracking tool, and it cannot create custom columns or track action items with reminders.

522
MCQhard

A security administrator needs to automatically restrict access to documents labeled as 'Highly Confidential' when accessed from devices that are not joined to the domain. The restriction should block editing and printing, and apply encryption. Which combination of Microsoft 365 solutions should the administrator use?

A.Microsoft Purview Information Protection + Microsoft Entra ID Conditional Access
B.Microsoft Purview Data Loss Prevention + Microsoft Entra ID Identity Protection
C.Microsoft Defender for Office 365 + Microsoft 365 Business Premium
D.Microsoft Purview Audit + Microsoft Entra ID Privileged Identity Management
AnswerA

Sensitivity labels from Microsoft Purview Information Protection can be configured to encrypt documents and apply usage rights, while Microsoft Entra ID Conditional Access evaluates policy at sign-in and can require the device to be hybrid Azure AD joined and compliant before allowing access to labeled content. This combination creates a layered enforcement: the label protects the file wherever it travels, and Conditional Access blocks access from non-compliant devices to the cloud location hosting the document. Together they directly satisfy the requirement to automatically restrict access to highly confidential documents based on device state.

Why this answer

Microsoft Purview Information Protection (MIP) allows you to create sensitivity labels that apply encryption, restrict editing, and block printing on documents. Microsoft Entra ID Conditional Access can then enforce that these labels are automatically applied based on device compliance (e.g., devices not joined to the domain). Together, they provide the automated, policy-driven restriction described.

Exam trap

The trap here is that candidates confuse Microsoft Purview Data Loss Prevention (DLP) with Information Protection, not realizing DLP only monitors and blocks data in transit (e.g., email) and cannot enforce encryption or usage restrictions on documents at rest.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) detects and prevents accidental sharing of sensitive data but does not apply encryption or restrict editing/printing on documents; it blocks transmission via email or apps. Microsoft Entra ID Identity Protection focuses on user risk and sign-in anomalies, not device-based access control. Option C is wrong because Microsoft Defender for Office 365 protects against email threats (phishing, malware) and does not enforce document-level restrictions like encryption or editing/printing.

Microsoft 365 Business Premium is a licensing bundle, not a specific solution for this scenario. Option D is wrong because Microsoft Purview Audit logs user and admin activities but does not enforce access restrictions. Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role assignments, not document-level encryption or device-based access control.

523
MCQhard

An organization has users who frequently collaborate on documents across departments. They want to ensure that when a document is shared with external partners, the external users must authenticate using Azure AD credentials and cannot download or print the document. Which combination of Microsoft 365 features should they use?

A.Microsoft Teams guest access and Microsoft Defender for Cloud Apps session policies
B.OneDrive sharing settings with 'Anyone' links and Microsoft Purview Data Loss Prevention
C.SharePoint external sharing with 'Specific people' and Microsoft Purview Information Protection with 'View Only' permission
D.SharePoint anonymous sharing links and Microsoft Purview Sensitivity Labels
AnswerC

SharePoint external sharing configured with 'Specific people' requires each external user to authenticate with a Microsoft account or organizational account before accessing content, ensuring that access is traceable and intended recipients are verified. When combined with Microsoft Purview Information Protection's 'View Only' permission, the sensitivity label enforces restrictive permissions that prevent download, print, or modification of the document, even after it is accessed. This pairing directly satisfies the need to restrict download and print for external collaborators while maintaining controlled, authenticated access.

Why this answer

SharePoint 'Specific people' external sharing restricts access to explicitly invited users who must authenticate with Azure AD credentials, while Microsoft Purview Information Protection's 'View Only' permission prevents downloading, printing, and copying of the document. This combination meets both requirements: enforced authentication and restricted document actions.

Exam trap

The trap here is that candidates often confuse SharePoint external sharing settings (which control access) with Microsoft Purview Information Protection (which controls usage rights), and mistakenly think that simply restricting sharing to 'Specific people' alone prevents download/print, or that Sensitivity Labels alone enforce authentication.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams guest access does not inherently prevent download or print actions; it relies on additional configuration, and Microsoft Defender for Cloud Apps session policies are for monitoring and controlling app access, not for granular document-level restrictions like view-only. Option B is wrong because 'Anyone' links allow anonymous access without Azure AD authentication, and Microsoft Purview Data Loss Prevention (DLP) is designed to prevent data leaks via policies, not to enforce per-document view-only permissions. Option D is wrong because SharePoint anonymous sharing links do not require Azure AD authentication, and Microsoft Purview Sensitivity Labels can apply encryption but do not natively enforce a 'View Only' permission that blocks download and print without additional configuration.

524
MCQmedium

A company wants to prevent users from sharing documents that contain credit card numbers via email. When a user attempts to share such a document, they should see a policy tip explaining the restriction and the share should be blocked. Which Microsoft Purview solution should the compliance team configure?

A.Retention policy
B.Data Loss Prevention (DLP) policy
C.Sensitivity label
D.Information Barriers
AnswerB

Data Loss Prevention (DLP) policies in Microsoft Purview are designed to identify, monitor, and protect sensitive information by inspecting content for predefined sensitive info types, such as credit card numbers, using pattern matching and validation. When a match is detected, DLP can enforce sophisticated actions like blocking the email or sharing attempt, notifying the user with a policy tip, and optionally encrypting the item. DLP works across Exchange, SharePoint, OneDrive, Teams, and devices, making it the correct control for preventing the exfiltration of documents containing credit card data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect sensitive information types—such as credit card numbers—in documents and emails, and then automatically block sharing while displaying a policy tip to the user. This matches the requirement exactly: DLP can inspect content for credit card patterns using built-in sensitive info types (e.g., Credit Card Number), enforce actions like 'Block' with an overridable policy tip, and apply to Exchange Online, SharePoint, OneDrive, and Teams. Retention policies only manage data lifecycle, not content-based blocking.

Exam trap

Microsoft often tests the distinction between DLP (which inspects content for sensitive data and blocks actions) and Sensitivity labels (which apply classification and protection but do not natively scan for specific data patterns like credit card numbers to enforce blocking with policy tips).

How to eliminate wrong answers

Option A is wrong because a Retention policy is used to preserve or delete data based on age or legal requirements, not to inspect content for sensitive information or block sharing in real time. Option C is wrong because a Sensitivity label applies classification and protection (e.g., encryption, visual markings) but does not natively scan for specific data patterns like credit card numbers or enforce block actions with policy tips; it relies on manual or automatic labeling, not content inspection for predefined sensitive types. Option D is wrong because Information Barriers are designed to restrict communication and collaboration between specific groups (e.g., to prevent conflicts of interest), not to scan content for sensitive data or block sharing based on data patterns.

525
Multi-Selectmedium

An organization wants to block sharing of documents containing credit card numbers. Which two statements are accurate about the Microsoft 365 capability involved?

Select 2 answers
A.Data Loss Prevention policies
B.It replaces the need for identity and access management
C.It requires every document to be made public
D.The policy should be tested with a limited group before broad rollout
AnswersA, D

Microsoft Purview Data Loss Prevention (DLP) policies detect sensitive information types, such as credit card numbers, using built-in data classification patterns and then enforce actions like blocking external sharing, preventing transmission, or applying encryption across Exchange Online, SharePoint, OneDrive, and Teams. These policies can also trigger informative policy tips to users and generate audit events for compliance monitoring. This directly fulfills the requirement to block sharing of documents that contain credit card numbers.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft 365 are specifically designed to detect and block the sharing of sensitive information, such as credit card numbers, by scanning content for predefined or custom sensitive information types. When a match is found, DLP can enforce actions like blocking the share or sending a notification, directly addressing the organization's requirement. This capability operates across Exchange Online, SharePoint, OneDrive, and Teams, providing comprehensive protection against accidental or malicious data leaks.

Exam trap

The trap here is that candidates may confuse DLP with identity and access management (IAM) or assume DLP requires public exposure of documents, when in fact DLP is a content-aware security control that operates independently of access permissions and typically restricts sharing rather than requiring it.

Page 6

Page 7 of 11

Page 8

All pages