Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 526–600

794 questions total · 11pages · All types, answers revealed

Page 7

Page 8 of 11

Page 9
526
MCQmedium

A user reports that Microsoft Teams meetings frequently drop audio. During troubleshooting, you discover that the user's network has high jitter and packet loss. Which Microsoft 365 service should you use to analyze the user's connection quality and identify the root cause?

A.Microsoft Defender XDR
B.Microsoft 365 Network Connectivity Center
C.Microsoft Teams admin center
D.Microsoft Intune
AnswerB

The Microsoft 365 Network Connectivity Center is the correct tool because it provides real-time network performance telemetry, including packet loss, latency, and geolocation-based connectivity data for Microsoft 365 endpoints. This tool lets administrators diagnose poor Teams meeting quality by identifying where network bottlenecks occur and provides actionable insights for recovery. It is specifically built for analyzing network health across Microsoft 365 services, unlike the other admin consoles.

Why this answer

B is correct because Microsoft 365 Network Connectivity Center is specifically designed to analyze network performance metrics like jitter, packet loss, and latency in real time. It provides detailed insights into connection quality between a user's device and Microsoft 365 services, enabling you to pinpoint the root cause of audio drops in Teams meetings.

Exam trap

The trap here is that candidates often confuse the Microsoft Teams admin center's call analytics (which shows per-user call quality) with the Network Connectivity Center's broader network-level diagnostics, leading them to pick option C instead of B.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is a security solution for threat detection and response, not a network performance analysis tool. Option C is wrong because the Microsoft Teams admin center provides call analytics and quality dashboards for individual users, but it does not offer the broader network-level analysis and diagnostic tools that Network Connectivity Center provides. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, focused on device compliance and app policies, not network connectivity analysis.

527
MCQmedium

A small business with 10 employees needs desktop versions of Office apps (Word, Excel, PowerPoint), business-class email, and the ability to host online meetings with up to 250 attendees. They also require basic device management to enforce security policies on company-owned devices. They do not need advanced analytics or compliance features. Which Microsoft 365 plan is most suitable?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Business Premium
D.Microsoft 365 Apps for Business
AnswerC

Microsoft 365 Business Premium is the correct choice because it bundles the full Microsoft 365 Apps desktop suite with Exchange Online, Teams, and Microsoft Intune for endpoint management. This gives 10 employees native Word, Excel, PowerPoint, and Outlook installations while IT can enforce policies, push updates, and wipe lost devices. It is the only listed plan that satisfies both desktop app and device management requirements.

Why this answer

Microsoft 365 Business Premium is the most suitable plan because it includes desktop versions of Office apps (Word, Excel, PowerPoint), business-class email via Exchange Online, Microsoft Teams for hosting online meetings with up to 250 attendees, and Intune for basic device management to enforce security policies on company-owned devices. This plan uniquely combines the required productivity, communication, and security management features without the advanced analytics or compliance capabilities that would be unnecessary for this small business.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Standard as sufficient because it includes desktop apps and email, but they overlook the explicit requirement for basic device management, which is only available in Business Premium through Intune.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic provides only web and mobile versions of Office apps, not the desktop versions required by the scenario. Option B is wrong because Microsoft 365 Business Standard includes desktop Office apps and email but lacks the device management capabilities (Intune) needed to enforce security policies on company-owned devices. Option D is wrong because Microsoft 365 Apps for Business includes only desktop Office apps and does not include business-class email (Exchange Online) or the ability to host online meetings via Teams.

528
MCQeasy

A user needs to sign in to Microsoft 365 from an untrusted device. The company requires multifactor authentication (MFA) for all external access. Which Microsoft Entra ID feature enforces this requirement?

A.Microsoft Entra ID Protection
B.Security defaults
C.Microsoft Entra ID Password Protection
D.Conditional Access
AnswerD

Conditional Access evaluates signals such as device compliance and location, then enforces MFA when access originates from an untrusted device. This signal-based policy engine satisfies the requirement to apply MFA specifically to external access, rather than blanket-enforcing it for every sign-in.

Why this answer

Conditional Access in Microsoft Entra ID is the feature that enforces access controls based on conditions such as user, device, location, and application. It can require MFA for access from untrusted devices or external locations. By creating a Conditional Access policy that targets all users and requires MFA when the device is not compliant or not trusted, the company can enforce MFA for external access.

Exam trap

MS-900 often tests the difference between Conditional Access and Security defaults, and candidates may pick Security defaults because it also enforces MFA, but it lacks the granularity to target untrusted devices specifically.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection is used to detect and remediate identity risks, such as leaked credentials or sign-in risks, but it does not directly enforce MFA for untrusted devices; it can trigger MFA based on risk, but not based on device trust. Option B is wrong because Security defaults provide a baseline set of security policies, including MFA for all users, but they are all-or-nothing and do not allow granular control based on device trust or location. Option C is wrong because Microsoft Entra ID Password Protection is used to detect and block weak or leaked passwords, not to enforce MFA.

529
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to manage leads, opportunities, customer accounts, and sales processes. Microsoft 365 app or service is the best fit?

A.Dynamics 365 Sales
B.Microsoft Planner
C.Microsoft Forms
D.Microsoft Purview Audit
AnswerA

Dynamics 365 Sales provides native lead, opportunity, account and sales-process management, matching the stem's requirement exactly. Microsoft 365 apps such as SharePoint or Teams lack these CRM entities, so they cannot manage the sales pipeline described.

Why this answer

Dynamics 365 Sales is purpose-built for managing leads, opportunities, customer accounts, and sales processes as part of the Microsoft 365 ecosystem. It provides a customer relationship management (CRM) platform with pipeline management, sales automation, and analytics, directly aligning with the consultant's requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task management features with CRM functionality, or assume Microsoft Forms can handle sales processes due to its data collection capabilities, but neither provides the structured pipeline and account management required for sales.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management tool for organizing work among teams, not designed for CRM functions like lead or opportunity tracking. Option C is wrong because Microsoft Forms is a survey and data collection tool, lacking sales process management capabilities. Option D is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user activities, unrelated to sales pipeline or customer account management.

530
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to delegate SharePoint and OneDrive administration without full tenant control. Microsoft 365 licensing, admin, or support concept is most relevant?

A.SharePoint Administrator
B.Microsoft Forms
C.Microsoft Whiteboard
D.Microsoft Stream
AnswerA

SharePoint Administrator is a Microsoft 365 administrative role in Azure Active Directory that grants full control over the SharePoint Online admin center, including site provisioning, storage quotas, sharing policies, and OneDrive for Business settings. It is the appropriate role for a help desk lead to document when the task involves managing tenant-level SharePoint and OneDrive configurations, as it includes the ability to assign site collection admins and monitor service health. While it does not replace Global Administrator for all tasks, it is the specific built-in role designed for day-to-day SharePoint and OneDrive administration.

Why this answer

The SharePoint Administrator role in Microsoft 365 provides delegated administration for SharePoint and OneDrive without granting full tenant-wide control. This role allows management of site collections, sharing policies, and storage limits while excluding access to other workloads like Exchange or Azure AD. It is the correct choice for the help desk lead's requirement.

Exam trap

The trap here is that candidates may confuse the SharePoint Administrator role with the Global Administrator role, assuming full control is needed, or mistakenly think a specific application (like Forms or Whiteboard) provides administrative delegation when they are merely end-user tools.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and quiz tool, not an administrative role or delegation mechanism for SharePoint/OneDrive. Option C (Microsoft Whiteboard) is wrong because it is a collaborative canvas application, unrelated to delegated administration. Option D (Microsoft Stream) is wrong because it is a video management service, not an administrative role for SharePoint or OneDrive.

531
MCQmedium

Your organization has 500 users and needs to comply with data residency requirements in the EU. You plan to purchase Microsoft 365 E3 subscriptions. Which licensing option should you choose to ensure data is stored only in EU datacenters?

A.Microsoft 365 Business Basic
B.Microsoft 365 E3 with Data Residency add-on
C.Office 365 E3
D.Microsoft 365 E5
AnswerB

Microsoft 365 E3 combined with the Data Residency add-on is the correct choice because E3 natively includes the full compliance suite—eDiscovery, retention policies, sensitivity labels, and DLP—while the add-on guarantees that content at rest is stored within the specified geographic boundary (e.g., EU datacenters). This pairing meets both the functional compliance tooling and the data residency requirement without paying for advanced security capabilities that are unnecessary for this scenario. It also includes Windows and Enterprise Mobility + Security, which Office 365 E3 lacks.

Why this answer

Microsoft 365 E3 with the Data Residency add-on ensures that customer data at rest is stored only in EU datacenters, meeting EU data residency requirements. The base Microsoft 365 E3 subscription does not guarantee EU-only storage; the add-on provides the necessary data location commitment and compliance controls.

Exam trap

The trap here is that candidates assume higher-tier plans like E5 automatically include all compliance features, but data residency requires a specific add-on regardless of the base plan tier.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic is a plan for smaller organizations (up to 300 users) and does not include the Data Residency add-on or guarantee EU-only datacenter storage. Option C is wrong because Office 365 E3 lacks the Windows and Enterprise Mobility + Security components of Microsoft 365 E3, and more importantly, it does not include the Data Residency add-on option for EU-only storage. Option D is wrong because Microsoft 365 E5, while a higher-tier plan, does not inherently enforce EU-only data storage; it also requires the Data Residency add-on to meet this specific requirement.

532
MCQeasy

Which cloud computing characteristic allows users to provision resources such as virtual machines and storage without requiring human interaction with the service provider?

A.Measured service
B.On-demand self-service
C.Resource pooling
D.Rapid elasticity
AnswerB

On-demand self-service lets consumers provision compute and storage capabilities automatically, without human interaction with the provider. This directly satisfies the stem's constraint: resources are obtained unilaterally through self-service portals or APIs, with no manual request or approval from Microsoft. Elasticity and measured service address scaling and billing, not autonomous provisioning.

Why this answer

On-demand self-service is the cloud characteristic that lets consumers provision computing capabilities such as VMs and storage automatically, without requiring human interaction with the service provider. This is one of the five essential characteristics defined by NIST SP 800-145. It directly matches the scenario of unilaterally provisioning resources via a portal or API.

Exam trap

The trap is confusing the five NIST characteristics—candidates often pick rapid elasticity because provisioning sounds like scaling, but the key phrase is 'without human interaction with the service provider,' which defines self-service.

How to eliminate wrong answers

Option A is wrong because measured service refers to automatic metering and billing of resource usage, not the ability to self-provision. Option C is wrong because resource pooling describes the provider's multi-tenant model where resources are pooled to serve multiple consumers, not the user's ability to provision independently. Option D is wrong because rapid elasticity is about scaling resources up or down quickly to match demand, not the initial self-service provisioning action.

533
MCQeasy

Your organization is deploying Microsoft 365 for a healthcare company that must comply with HIPAA. Which Microsoft 365 compliance feature should you use to prevent sensitive patient data from being shared externally via email?

A.Microsoft Purview Message Encryption
B.Microsoft Purview eDiscovery
C.Microsoft Purview Audit
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerD

Microsoft Purview Data Loss Prevention (DLP) enforces policies that scan email content and attachments for sensitive data types, such as medical record numbers or diagnosis codes, and automatically blocks external sharing when a HIPAA-defined information type is detected. This satisfies the stem’s requirement to prevent patient data from leaving the organisation via email, using content analysis and rule-based actions rather than relying on user permissions alone.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is designed to identify, monitor, and automatically protect sensitive information across Microsoft 365 workloads, including Exchange Online, SharePoint, OneDrive, and Teams. DLP policies can detect sensitive data types such as HIPAA-related identifiers (e.g., U.S. Social Security numbers, medical record numbers) and enforce actions like blocking external email sharing or requiring encryption.

This directly addresses the requirement to prevent sensitive patient data from being shared externally via email.

Exam trap

MS-900 often tests the difference between features that protect data (DLP) and those that merely audit or encrypt after the fact, causing candidates to confuse DLP with Message Encryption or eDiscovery.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Message Encryption only encrypts email messages and attachments; it does not prevent sharing—it secures the content after it is sent, but the email can still be sent externally. Option B is wrong because Microsoft Purview eDiscovery is used for identifying, collecting, and producing electronic data for legal cases; it does not enforce real-time policy actions to block external sharing. Option C is wrong because Microsoft Purview Audit provides logging and visibility into user and admin activities, but it does not prevent or block actions; it only records them for later review.

534
Multi-Selectmedium

Which TWO of the following are key benefits of using Microsoft Purview Information Protection? (Choose two.)

Select 2 answers
A.It automatically detects and blocks phishing emails.
B.It enables organizations to meet compliance requirements by applying protection.
C.It manages device compliance with Conditional Access.
D.It provides backup and recovery for SharePoint Online.
E.It helps classify and protect sensitive data across Microsoft 365.
AnswersB, E

Microsoft Information Protection directly supports compliance by allowing organizations to apply sensitivity labels, encryption, and usage restrictions to data, helping align with regulatory requirements like GDPR, HIPAA, and internal data governance policies. By automatically classifying and protecting sensitive content, MIP enables admins to demonstrate that appropriate safeguards are in place, which is often a central component of compliance audits and data protection regulations.

Why this answer

Microsoft Purview Information Protection (MIP) enables organizations to meet compliance requirements by applying protection labels that enforce encryption, access restrictions, and visual markings (e.g., headers/footers) on sensitive data. This directly supports regulatory frameworks like GDPR, HIPAA, and ISO 27001 by ensuring data is protected both at rest and in transit across Microsoft 365 services.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection with Microsoft Defender for Office 365 or Microsoft Entra Conditional Access, because all three are security-related, but Purview specifically handles data classification and protection, not threat detection or access control.

535
MCQmedium

A marketing team needs to create a dashboard that shows real-time sales data from Dynamics 365 and customer feedback from social media. Which Microsoft 365 service should they use to build this dashboard?

A.Microsoft Power BI
B.Microsoft Power Automate
C.Microsoft SharePoint
D.Microsoft Power Apps
AnswerA

Microsoft Power BI is the correct choice because it is a dedicated business analytics and data visualization service that connects to dozens of data sources, including Dynamics 365, social media, and Azure, to build live dashboards. It supports streaming datasets, push datasets, and DirectQuery to render near-real-time visuals that update as underlying data changes, without requiring manual refresh. Team members can embed these dashboards in Microsoft Teams or SharePoint pages, but the visualization engine itself remains Power BI.

Why this answer

Microsoft Power BI is the correct service because it is designed to connect to multiple data sources, including Dynamics 365 for real-time sales data and social media APIs for customer feedback, and then create interactive, real-time dashboards. It provides built-in connectors, real-time streaming datasets, and the ability to publish dashboards for team-wide access, making it the ideal tool for this marketing requirement.

Exam trap

The trap here is that candidates often confuse Power Automate or Power Apps as dashboard-building tools because they are part of the Power Platform, but only Power BI provides the dedicated data visualization and real-time analytics capabilities required for this scenario.

How to eliminate wrong answers

Option B (Microsoft Power Automate) is wrong because it is a workflow automation tool that triggers actions based on events, not a dashboard or visualization service; it cannot natively render charts or graphs. Option C (Microsoft SharePoint) is wrong because it is a document management and collaboration platform that can host web parts but lacks native real-time data visualization and direct integration with Dynamics 365 and social media APIs for live dashboards. Option D (Microsoft Power Apps) is wrong because it is a low-code application development platform for building custom apps, not a business intelligence tool for creating dashboards; while it can display data, it does not provide the dedicated analytics, real-time streaming, and visualization capabilities of Power BI.

536
MCQhard

You are designing a solution for a global company that needs to store documents in a central location with granular permission control. Which service should you recommend?

A.Microsoft Teams
B.OneDrive for Business
C.Exchange Online
D.SharePoint
AnswerD

SharePoint Online is Microsoft 365's centralized document management platform, offering site collections, document libraries, version history, workflows, and granular permission inheritance. It supports co-authoring, metadata classification, content types, retention labels, and eDiscovery, making it suitable for a global company that needs structured collaboration across departments and sites. SharePoint is the correct foundation on which Teams files and OneDrive sync can be built.

Why this answer

SharePoint is the correct choice because it is designed as a centralized document management and collaboration platform that supports granular permission control at the site, library, folder, and item levels. Unlike other services, SharePoint allows administrators to define unique permissions using SharePoint groups or Azure AD security groups, enabling precise access management for a global company's document storage needs.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint, thinking OneDrive can serve as a central document repository, but OneDrive is designed for personal storage and lacks the centralized administration and granular permission inheritance that SharePoint provides for enterprise document management.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration workspace that stores files in the underlying SharePoint site for each team, but it does not provide native granular permission control beyond team-level settings; permissions are inherited from SharePoint. Option B is wrong because OneDrive for Business is a personal cloud storage service intended for individual file storage and sharing, not for centralized document storage with granular permission control across an organization; it lacks site-level administration and advanced permission inheritance features. Option C is wrong because Exchange Online is an email and calendaring service that stores mailbox data, not documents; it does not offer document storage or permission management for files.

537
MCQmedium

A company has 50 users with Microsoft 365 Business Basic licenses. They want to allow dial-in access to their online meetings for participants who cannot use VoIP. They need to minimize additional licensing costs. What should they purchase?

A.Audio Conferencing add-on
B.Phone System add-on
C.Microsoft 365 Business Voice
D.Upgrade to Microsoft 365 Business Standard
AnswerA

Correct. The Audio Conferencing add-on is the specific Microsoft 365 license that provides a real PSTN phone number (with national and international dial-in numbers) that external participants can call to join a Teams meeting's audio. It is a per-user add-on that works directly with Business Basic, enabling the 50 users to host meetings that anyone can join by phone without installing an app or using a computer.

Why this answer

Audio Conferencing is the correct add-on because it provides dial-in (PSTN) access to Microsoft Teams meetings, allowing participants to join via phone when VoIP is unavailable. Since the company already has Microsoft 365 Business Basic licenses, which include Teams but not dial-in capabilities, purchasing the Audio Conferencing add-on per user is the most cost-effective way to enable this feature without upgrading the entire license.

Exam trap

The trap here is that candidates confuse the Phone System add-on (which handles internal call routing) with Audio Conferencing (which provides external dial-in to meetings), leading them to pick the wrong add-on for PSTN meeting access.

How to eliminate wrong answers

Option B (Phone System add-on) is wrong because Phone System provides PBX capabilities (call queues, auto attendants, and internal call routing) but does not include dial-in access to meetings; it requires additional calling plans or third-party trunking for PSTN connectivity. Option C (Microsoft 365 Business Voice) is wrong because it bundles Phone System and a calling plan for domestic calls, which is overkill and more expensive than just needing dial-in meeting access; it also requires a minimum of 5 users and includes features not needed here. Option D (Upgrade to Microsoft 365 Business Standard) is wrong because Business Standard does not include Audio Conferencing; it only adds desktop Office apps and additional cloud services, not PSTN dial-in for meetings, so it would not solve the requirement and costs more than the add-on.

538
MCQmedium

A company uses Infrastructure-as-a-Service (IaaS) from a cloud provider. They have deployed virtual machines running a custom application. The cloud provider supplies the physical hardware, networking, and storage. Who is responsible for patching the operating system of the virtual machines?

A.The cloud provider
B.The customer
C.Both the provider and the customer share equally
D.A third-party managed security service provider
AnswerB

The customer is the correct answer because IaaS delivers raw compute, storage, and networking, leaving the customer in full control of the guest OS, middleware, runtime, data, and applications. This means the customer must apply OS patches, configure firewalls, harden the system, manage user access, and protect workloads against malware and vulnerabilities. Under the shared responsibility model, this is a firm, non-transferable obligation for the IaaS consumer, even if some tasks are automated or delegated.

Why this answer

In an IaaS model, the cloud provider is responsible for the physical infrastructure (hardware, networking, storage), but the customer retains responsibility for the guest OS and application stack. Patching the operating system of virtual machines is a customer task because the customer controls the OS image and has full administrative access to the VM. This follows the shared responsibility model where the provider secures the hypervisor and physical layer, while the customer secures the OS and applications.

Exam trap

The trap here is that candidates confuse IaaS with PaaS or SaaS, assuming the cloud provider patches everything, but in IaaS the customer is explicitly responsible for the guest OS and applications.

How to eliminate wrong answers

Option A is wrong because the cloud provider patches only the hypervisor and physical infrastructure, not the guest OS inside the VM; the customer manages the OS. Option C is wrong because responsibility is not shared equally for OS patching—the provider handles the underlying platform, and the customer handles the OS and applications. Option D is wrong because a third-party MSSP is an optional service the customer could contract, but it is not the default responsibility assignment in the IaaS shared responsibility model.

539
MCQeasy

A department asks for the Microsoft 365 service best suited for enterprise video publishing and town hall recordings. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Purview Compliance Manager
B.Microsoft Stream on SharePoint
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Stream on SharePoint delivers enterprise video publishing and town hall recordings using the SharePoint platform already provisioned in Microsoft 365, so no custom operational scripts are needed. This satisfies the stem's constraint of avoiding bespoke automation.

Why this answer

Microsoft Stream on SharePoint is the correct service because it provides enterprise-grade video publishing and live event capabilities, including town hall recordings, directly integrated with SharePoint and Microsoft Teams. It leverages SharePoint's storage and permissions model, eliminating the need for custom operational scripts for video management.

Exam trap

The trap here is that candidates may confuse Microsoft Stream (classic) with the new Stream on SharePoint, or incorrectly associate video features with compliance or security services like Purview or Defender.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance and risk management tool for assessing regulatory compliance, not a video publishing or recording service. Option C is wrong because Microsoft Entra Privileged Identity Management manages just-in-time privileged access to Azure AD roles, not video content. Option D is wrong because Microsoft Defender for Endpoint is an endpoint security solution for threat detection and response, not a video platform.

540
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to review upcoming Microsoft 365 changes and recommended admin actions. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Whiteboard
D.Message center
AnswerD

The Message center in the Microsoft 365 admin center is the definitive hub for all tenant-relevant change announcements, including new features, retirement notices, and action-required requests. It allows administrators to filter by product and message type, share posts with colleagues, and set up email digests to stay informed. Its purpose is precisely to document and track Microsoft's planned changes and the related admin actions, making it the correct choice.

Why this answer

The Message center in the Microsoft 365 admin center is the dedicated hub for reviewing upcoming changes, new features, and recommended admin actions. It provides official communications from Microsoft about service updates, deprecations, and required administrative steps, making it the correct resource for a help desk lead documenting change management.

Exam trap

The trap here is that candidates confuse collaboration tools (Stream, Forms, Whiteboard) with administrative communication channels, failing to recognize that Message center is the only official source for Microsoft 365 change notifications and admin actions.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for recording, sharing, and managing videos, not a channel for reviewing Microsoft 365 changes or admin actions. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to service change notifications or admin recommendations. Option C is wrong because Microsoft Whiteboard is a digital canvas for collaboration, not a source for upcoming Microsoft 365 changes or admin guidance.

541
MCQmedium

A department head asks which Microsoft 365 option should be used to review uptime commitments for Microsoft cloud services. Cloud concept or benefit best matches this requirement?

A.Data Loss Prevention (DLP)
B.Microsoft Planner
C.Sensitivity labels
D.Service Level Agreement (SLA)
AnswerD

A Service Level Agreement formally documents Microsoft's uptime commitments for cloud services, giving the department head the guaranteed availability percentages and remedies. This matches the requirement to review uptime commitments rather than general reliability guidance.

Why this answer

The Service Level Agreement (SLA) is the correct choice because it is the formal document published by Microsoft that defines the uptime commitments, availability guarantees, and financial remedies for Microsoft cloud services. The department head needs to review uptime commitments, which is exactly what the SLA covers, not a security or project management feature.

Exam trap

The trap here is that candidates often confuse operational features (like DLP or sensitivity labels) with contractual documents, assuming any Microsoft 365 tool that 'protects' or 'manages' something could cover uptime, when only the SLA provides legally binding availability commitments.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is a security policy that prevents sensitive information from being shared or leaked, not a document that defines uptime commitments. Option B is wrong because Microsoft Planner is a task management and project planning tool within Microsoft 365, not a source of service availability guarantees. Option C is wrong because sensitivity labels are used to classify and protect data based on its sensitivity level, not to provide uptime or service-level commitments.

542
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to desktop Office apps plus Intune and enhanced security capabilities for a small or medium business. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Whiteboard
C.Microsoft 365 Business Premium
D.Microsoft Forms
AnswerC

Microsoft 365 Business Premium bundles desktop Office apps with Intune and Defender for Business, satisfying the stem's requirement for enhanced security alongside device management. Its 300-seat ceiling suits small and medium businesses, and it includes Microsoft Entra ID P1 for conditional access, unlike Business Standard, which omits Intune and advanced threat protection.

Why this answer

Microsoft 365 Business Premium is the correct answer because it bundles desktop Office apps, Microsoft Intune for mobile device management, and advanced security features like Microsoft Defender for Business and Azure AD Plan 1. This plan is specifically designed for small and medium businesses needing comprehensive productivity, management, and security capabilities under a single subscription.

Exam trap

The trap here is that candidates may confuse individual productivity apps (Stream, Whiteboard, Forms) with licensing plans, failing to recognize that only Business Premium bundles the required management and security components.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video sharing and recording service, not a licensing plan that includes desktop Office apps, Intune, or enhanced security. Option B is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a subscription that bundles management or security features. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, lacking any device management or advanced security capabilities.

543
MCQhard

A company needs to enforce that all documents marked as 'Confidential' are encrypted and cannot be printed. Which combination of Microsoft Purview features should they use?

A.Microsoft Entra ID Conditional Access and Intune app protection
B.Sensitivity labels with encryption and rights management
C.Data Loss Prevention (DLP) policies and retention labels
D.eDiscovery (Premium) and Audit (Premium)
AnswerB

Sensitivity labels apply persistent encryption through Azure Rights Management, and the label's protection settings can block printing while restricting copying or forwarding. This directly satisfies the stem's dual requirement: Confidential documents stay encrypted at rest and in transit, and print permissions are denied for all users regardless of device or location.

Why this answer

Sensitivity labels in Microsoft Purview can apply encryption and rights management (Azure Rights Management) directly to documents, and label policies can enforce protection settings such as 'do not print' and 'do not copy.' When a user labels a document 'Confidential,' the label can automatically encrypt it and restrict actions like printing, fulfilling both requirements in a single control.

Exam trap

MS-900 often tests the confusion between DLP (detection/blocking) and sensitivity labels (persistent protection) — candidates pick DLP thinking it encrypts, but only labels apply encryption and rights management.

How to eliminate wrong answers

Option A is wrong because Conditional Access and Intune app protection govern access to services and mobile apps, not the encryption or print restrictions of individual documents once they leave the managed context. Option C is wrong because DLP policies detect and block sharing of sensitive content but do not natively encrypt documents or prevent printing — retention labels manage lifecycle, not protection. Option D is wrong because eDiscovery and Audit are investigative and compliance tools for searching and reviewing content, not enforcement mechanisms for encryption or print blocking.

544
MCQhard

Refer to the exhibit. The JSON shows compliance scores from Microsoft Purview Compliance Manager. Which action should the organization prioritize to improve its HIPAA compliance score?

A.Deploy Microsoft Defender for Office 365.
B.Enable multifactor authentication for all users.
C.Implement retention labels for medical records.
D.Conduct a data privacy impact assessment.
AnswerB

Enabling multi-factor authentication for all users is correct because the JSON's compliance score indicates an open, high-impact improvement action that resolves several identity-control failures. MFA mitigates account compromise, directly maps to regulatory controls such as ISO 27001 A.9.4.2 or NIST IA-2(1), and requires minimal configuration to be marked as implemented in Compliance Manager. Since the compliance score reflects the percentage of controls met, MFA has a disproportionate positive effect on the overall score.

Why this answer

The recommended action 'Enable MFA for all users' is marked as high impact and open. Implementing MFA would significantly improve the HIPAA score, as it addresses a common control. Option B is correct.

545
MCQeasy

You are the IT administrator for a non-profit organization that uses Microsoft 365 Business Basic. The organization has 50 volunteers who use their own personal devices to access email and SharePoint Online. The board of directors wants to ensure that if a volunteer's device is lost or stolen, the organization's data on that device can be removed remotely. They also want to ensure that volunteers use multi-factor authentication (MFA) to access corporate resources. What should you do?

A.Deploy Microsoft Defender for Cloud Apps and configure session controls.
B.Use Microsoft Purview to label all corporate data and configure a policy to revoke access.
C.Implement a Data Loss Prevention (DLP) policy that blocks access from unmanaged devices.
D.Enroll devices in Microsoft Intune and configure a selective wipe policy. Set up a Conditional Access policy in Microsoft Entra ID to require MFA.
AnswerD

Intune can wipe corporate data; Conditional Access enforces MFA.

Why this answer

Microsoft Intune allows you to enroll devices and perform a selective wipe to remove only corporate data from personal devices. Conditional Access in Microsoft Entra ID can enforce MFA for accessing corporate resources. Option A is incorrect because Microsoft Defender for Cloud Apps provides cloud app security (e.g., session controls) but does not perform device wipe or manage device enrollment.

Option B is incorrect because Microsoft Purview is for data governance, compliance, and labeling, not for device management or selective wipe. Option C is incorrect because Data Loss Prevention (DLP) policies control data sharing but cannot block access from unmanaged devices; that would require Conditional Access policies with device compliance.

546
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to protect corporate data inside mobile apps without enrolling the whole personal device. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.App protection policies / Mobile Application Management (MAM)
C.Microsoft Forms
D.Microsoft Stream
AnswerB

App protection policies (APP) under Mobile Application Management (MAM) are the correct solution because they apply security controls directly to supported Microsoft 365 mobile apps, like Outlook and Teams, without requiring full device enrollment (MDM). These policies can enforce PIN, encryption, copy/paste restrictions, and prevent data leakage to unmanaged apps, aligning with the need to protect corporate data on personal devices. This approach satisfies the requirement by putting the data protection boundary around the app itself, rather than the device.

Why this answer

App protection policies (APP), also known as Mobile Application Management (MAM), allow administrators to protect corporate data within mobile apps—such as enforcing encryption, preventing copy/paste, or requiring PIN—without enrolling the entire personal device into management. This is the correct capability because it separates data-level controls from device-level management, meeting the requirement to protect corporate data without full device enrollment.

Exam trap

The trap here is that candidates often confuse Mobile Device Management (MDM)—which requires full device enrollment—with Mobile Application Management (MAM), which protects data at the app level without enrolling the device, and they may incorrectly select a non-security tool like Planner or Forms because they see 'mobile' or 'app' in the question.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and collaboration tool, not a security or compliance capability; it cannot enforce data protection policies on mobile apps. Option C is wrong because Microsoft Forms is a survey and data collection tool, lacking any native ability to apply conditional access or data loss prevention controls to mobile app usage. Option D is wrong because Microsoft Stream is a video hosting and sharing service, not a security or identity solution; it does not provide app-level protection policies for mobile applications.

547
Multi-Selecthard

Which TWO Microsoft 365 services are primarily used for business process automation?

Select 2 answers
A.Power BI
B.Power Automate
C.Power Virtual Agents
D.Power Apps
E.Microsoft Lists
AnswersB, D

Power Automate delivers workflow automation through triggers, connectors and approval flows across Microsoft 365 and external systems. It satisfies the business process automation requirement by orchestrating repetitive tasks without code, whereas services such as Exchange Online or SharePoint Online provide messaging and storage rather than process orchestration.

Why this answer

Power Automate (B) is correct because it is Microsoft's dedicated workflow engine for business process automation, letting you build event-driven flows that connect hundreds of connectors to automate approvals, notifications, data sync, and repetitive tasks. Power Apps (D) is correct because it provides low-code canvas and model-driven apps that digitize and automate business processes such as forms, approvals, and data entry, often triggered or extended by Power Automate flows. Power BI (A) is a business intelligence and reporting tool for visualizing data, not for automating processes.

Power Virtual Agents (C) is for building conversational chatbots, which is a narrower automation use case rather than general business process automation. Microsoft Lists (E) is an information-tracking and list-management app, not a process automation service.

Exam trap

The trap here is that candidates might think only Power Automate qualifies for business process automation, forgetting that Power Apps also enables automating business processes through custom apps and logic. Both Power Automate (workflow automation) and Power Apps (app-based automation) are correct. Avoid selecting Power Virtual Agents (chatbots) or Power BI (analytics) as they are not primarily for business process automation.

548
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to identify risky user behaviour such as unusual downloads or policy violations. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Purview Insider Risk Management
C.Microsoft Stream
D.Microsoft Forms
AnswerB

Microsoft Purview Insider Risk Management is a compliance solution that uses behavioral analytics and machine learning to identify, triage, and investigate risky user activities aligned with data exfiltration, leaks, and policy violations. It integrates with the Microsoft 365 activity logs and provides alerts, case management, and contextual evidence for administrators to mitigate internal threats. This direct focus on risky behavior makes it the correct service for a Microsoft 365 adoption plan addressing security and compliance.

Why this answer

Microsoft Purview Insider Risk Management is the correct capability because it is specifically designed to identify, detect, and act on risky user behaviors such as unusual downloads, data leaks, and policy violations. It uses machine learning models and predefined indicators to correlate user activities (e.g., mass file downloads, unauthorized sharing) with risk signals, enabling organizations to investigate and mitigate insider threats. This aligns directly with the consultant's need to monitor and address risky behavior in a Microsoft 365 adoption plan.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Insider Risk Management with general compliance tools like Microsoft Purview Compliance Manager or DLP, but the question specifically targets risky user behavior detection, which is the unique domain of Insider Risk Management.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a project management and task-tracking tool, not a security or compliance solution; it cannot detect risky user behaviors like unusual downloads or policy violations. Option C is wrong because Microsoft Stream is a video hosting and sharing platform for enterprise content, lacking any built-in capabilities for monitoring user behavior or enforcing security policies. Option D is wrong because Microsoft Forms is a survey and form creation tool, designed for data collection and feedback, with no functionality to identify insider risks or policy violations.

549
MCQeasy

An organization needs to securely store and manage user identities for Microsoft 365. Which Microsoft service should they use?

A.Microsoft Entra ID
B.Microsoft Purview
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerA

Microsoft Entra ID is the cloud identity provider that authenticates users and issues tokens for Microsoft 365 services, enforcing conditional access and multifactor authentication. It satisfies the requirement to securely store and manage user identities, unlike Exchange Online or SharePoint Online, which consume identities rather than host them.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the correct choice because it is Microsoft's cloud-based identity and access management service, specifically designed to store and manage user identities for Microsoft 365. It provides authentication, single sign-on (SSO), and conditional access policies, ensuring secure access to Microsoft 365 resources. Other options focus on data protection, security monitoring, or device management, not identity storage.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (data compliance) or Defender for Cloud Apps (security monitoring) with identity management, but only Microsoft Entra ID provides the core directory service for storing and authenticating user identities in Microsoft 365.

How to eliminate wrong answers

Option B (Microsoft Purview) is wrong because it is a data governance and compliance solution for managing sensitive data across environments, not for storing or managing user identities. Option C (Microsoft Defender for Cloud Apps) is wrong because it is a cloud access security broker (CASB) that monitors and controls cloud app usage, not an identity store. Option D (Microsoft Intune) is wrong because it is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for identity management.

550
MCQhard

A company uses Microsoft 365 E5 and wants to automatically classify sensitive emails containing credit card numbers and then apply encryption. Which solution should they use in combination with Microsoft Purview?

A.Microsoft 365 Copilot
B.Microsoft Intune
C.Microsoft Purview Information Protection
D.Microsoft Defender for Office 365
AnswerC

Microsoft Purview Information Protection provides sensitivity labels with auto-labeling policies that automatically classify and encrypt documents and emails based on sensitive information types or trainable classifiers. Once triggered, it applies encryption via Azure Rights Management, visual markings, and access restrictions to ensure only authorized users can view or modify the data. This directly satisfies the need for automatic, content-triggered compliance protection, making it the correct choice for the scenario.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) enables automatic classification of sensitive data, such as credit card numbers, using built-in sensitive information types and exact data match (EDM) classifiers. When combined with sensitivity labels, it can automatically apply encryption (e.g., via Azure Rights Management) to emails containing that data, meeting the requirement without additional services.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection with Microsoft Defender for Office 365, assuming threat protection includes data classification, when in fact Defender focuses on inbound/outbound threats and not on content-based sensitivity labels or encryption policies.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Copilot is an AI-powered productivity assistant that helps with content generation and summarization, not with data classification or encryption policies. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution focused on device compliance and app protection, not on email content classification or encryption. Option D is wrong because Microsoft Defender for Office 365 is a security solution that protects against threats like phishing, malware, and spam, but it does not provide native automatic classification or encryption of sensitive content based on data patterns like credit card numbers.

551
MCQeasy

A company currently has Microsoft 365 E3 licenses for all users. They need to retain all Exchange Online mailbox data for 10 years and place legal holds for litigation. Which add-on license provides these retention and eDiscovery capabilities?

A.Microsoft 365 E5 Compliance
B.Microsoft 365 E5 Security
C.Microsoft 365 E5
D.Office 365 E5
AnswerA

Microsoft 365 E5 Compliance is the precise add-on for a company already on Microsoft 365 E3 that needs advanced legal and regulatory requirements. It unlocks the full compliance suite—including advanced data lifecycle management, retention policies, legal hold, and eDiscovery—without forcing an upgrade to full E5. Because the company only needs compliance capabilities, this add-on provides the required features in the most cost-efficient manner.

Why this answer

Microsoft 365 E5 Compliance is the correct add-on because it includes advanced eDiscovery (e.g., eDiscovery Premium) and retention capabilities such as Preservation Lock and 10-year retention policies via Microsoft Purview. The base E3 license only provides basic retention and eDiscovery, lacking the extended 10-year retention and litigation hold features required for this scenario.

Exam trap

The trap here is that candidates often confuse the full Microsoft 365 E5 suite (which includes compliance) with the add-on license, or mistakenly think E5 Security provides retention and eDiscovery, when in fact only the Compliance add-on specifically unlocks those capabilities for existing E3 tenants.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 E5 Security focuses on security features like Microsoft Defender for Office 365 and Azure Active Directory Premium P2, not on compliance, retention, or eDiscovery capabilities. Option C is wrong because Microsoft 365 E5 is a full suite that includes both security and compliance, but the question asks for an add-on license to existing E3 licenses, and E5 is not an add-on but a full upgrade. Option D is wrong because Office 365 E5 is a legacy plan that includes compliance features, but it is not an add-on to Microsoft 365 E3; it is a separate suite, and the question specifies an add-on license for existing E3 users.

552
MCQmedium

A company deploys Microsoft 365 Business Premium. The IT team wants to enable employees to sign in using a mobile app without passwords. Which app should they configure?

A.Microsoft Intune
B.Microsoft Entra ID
C.Microsoft Copilot
D.Microsoft Authenticator
AnswerD

Microsoft Authenticator is the mobile app specifically designed to handle sign-in verification for Microsoft 365. It enables passwordless sign-in and multi-factor authentication via push notification, number matching, or a rotating one-time code. When deploying Microsoft 365 Business Premium, users are expected to install and register Authenticator with their work account in Entra ID, making it the correct tool for user sign-in in this scenario.

Why this answer

Microsoft Authenticator is the correct app because it enables passwordless sign-in for Microsoft 365 Business Premium users via FIDO2-based phone sign-in or number matching. It allows employees to authenticate using biometrics or a PIN, eliminating the need for a password during sign-in.

Exam trap

The trap here is that candidates may confuse Microsoft Entra ID (the identity provider that enables passwordless authentication) with the actual user-facing app (Microsoft Authenticator) that performs the sign-in, leading them to select Entra ID instead of the correct app.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, not an authentication app; it does not directly provide passwordless sign-in capabilities. Option B is wrong because Microsoft Entra ID (formerly Azure AD) is the identity and access management service that supports passwordless authentication methods, but it is not the app employees use to sign in; the app that facilitates the actual sign-in process is Microsoft Authenticator. Option C is wrong because Microsoft Copilot is an AI-powered productivity assistant integrated into Microsoft 365 apps, not an authentication app; it has no role in passwordless sign-in.

553
MCQhard

An organization needs to enforce that all external emails are automatically encrypted before delivery to recipients. Which feature should they configure in Microsoft 365?

A.S/MIME
B.Microsoft Purview Data Loss Prevention
C.Exchange Online mail flow rules
D.Microsoft Purview sensitivity labels
AnswerC

Exchange Online mail flow rules (transport rules) can be configured with a condition like 'The recipient is outside the organization' and an action to apply Microsoft Purview Message Encryption, which automatically encrypts all outbound messages without requiring end-user action. This makes it the correct native mechanism for enforcing encryption on every email sent to external recipients, as it operates at the transport layer and applies uniformly.

Why this answer

Exchange Online mail flow rules (also known as transport rules) can be configured to automatically encrypt all external emails by applying Office 365 Message Encryption (OME) based on conditions such as recipient domain or sender address. This allows the organization to enforce encryption for all outbound messages without requiring user intervention, meeting the stated requirement.

Exam trap

The trap here is that candidates often confuse Microsoft Purview sensitivity labels or DLP policies as the direct mechanism for automatic encryption, when in fact mail flow rules are the correct transport-level feature to enforce encryption on all external emails without relying on user action or client-side configuration.

How to eliminate wrong answers

Option A is wrong because S/MIME is a client-side encryption method that requires manual certificate management and configuration on each user's device, and it cannot be enforced automatically for all external emails at the transport level. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to detect and prevent the sharing of sensitive information, but it does not natively encrypt emails; it can trigger encryption via a mail flow rule, but the DLP policy itself does not perform encryption. Option D is wrong because Microsoft Purview sensitivity labels apply classification and protection (including encryption) to content, but they require user or automated labeling and are not designed to automatically encrypt all external emails based solely on the recipient being external; they are typically applied at the client or via auto-labeling policies, not as a blanket transport rule for all external messages.

554
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to track compliance assessments and improvement actions. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Forms
C.Microsoft Purview Compliance Manager
D.Microsoft Stream
AnswerC

Microsoft Purview Compliance Manager is a purpose-built solution for managing compliance activities across an organization. It offers pre-built assessments for regulations like GDPR, ISO 27001, and CMMC, along with a compliance score, improvement actions, and evidence collection capabilities. This makes it the correct tool for a help desk lead to document compliance requirements, track remediation steps, and report on audit readiness.

Why this answer

Microsoft Purview Compliance Manager is the correct tool because it provides a centralized dashboard for tracking compliance assessments, managing improvement actions, and monitoring regulatory compliance posture. It integrates with Microsoft 365 services to automate risk assessments and generate detailed reports for standards like ISO 27001, SOC 2, and GDPR.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task assignment features with compliance action tracking, but Planner lacks the regulatory framework integration, automated scoring, and audit-ready reporting that Compliance Manager provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing team work and projects, not designed for compliance tracking or assessment management. Option B is wrong because Microsoft Forms is a survey and data collection tool, lacking the compliance-specific features like automated scoring, improvement action tracking, and regulatory framework mapping. Option D is wrong because Microsoft Stream is a video hosting and sharing platform, with no capabilities for compliance assessments or improvement action tracking.

555
MCQmedium

A company wants to run a critical application that requires dedicated hardware to comply with regulatory isolation requirements. However, they want to avoid the upfront cost of building their own data center. Which cloud deployment model meets these needs?

A.Private cloud
B.Public cloud
C.Hybrid cloud
D.Community cloud
AnswerA

A private cloud delivers a single-tenant environment on dedicated physical hardware, giving the organization exclusive access to compute, storage, and networking. This fully satisfies the requirement for dedicated hardware while still providing cloud-like self-service and scalability. If hosted by a third-party, it also eliminates capital expenditure and can be tailored to meet regulatory or compliance constraints.

Why this answer

A private cloud is the correct deployment model because it provides dedicated hardware and infrastructure for a single organization, ensuring regulatory isolation without requiring the company to build and maintain its own on-premises data center. In Azure, a private cloud can be implemented via Azure Stack Hub or Azure VMware Solution, which run in the customer's own environment or a dedicated hosted environment, meeting compliance needs while avoiding upfront capital expenditure.

Exam trap

The trap here is that candidates often confuse 'private cloud' with 'on-premises only,' forgetting that a private cloud can be hosted by a third-party provider like Azure Stack Hub, which offers dedicated hardware without the upfront cost of building a data center.

How to eliminate wrong answers

Option B (Public cloud) is wrong because it uses shared multi-tenant infrastructure that cannot guarantee the dedicated hardware isolation required for strict regulatory compliance. Option C (Hybrid cloud) is wrong because it combines public and private clouds but does not inherently provide dedicated hardware; the public cloud portion still lacks isolation. Option D (Community cloud) is wrong because it is shared among several organizations with common concerns, not dedicated to a single company, and thus cannot meet the requirement for exclusive hardware isolation.

556
MCQmedium

A company with 500 users is planning to adopt Microsoft 365. They need to ensure that all users have access to Microsoft Teams, Exchange Online, and SharePoint Online, as well as the latest desktop versions of Office apps. They also require advanced compliance features such as litigation hold and eDiscovery. Which Microsoft 365 licensing plan best meets these requirements?

A.Microsoft 365 E3
B.Microsoft 365 Business Basic
C.Microsoft 365 Business Premium
D.Microsoft 365 E5
AnswerA

For a 500-user organization, Microsoft 365 E3 provides the full productivity suite including desktop Office apps, Exchange Online, SharePoint, and Teams, with no seat limit unlike Business plans. It includes core compliance features such as Litigation Hold and eDiscovery (Standard), which are essential for legal holds and content searches. E3 delivers enterprise-grade functionality at a lower cost than E5 while meeting the stated requirements.

Why this answer

Microsoft 365 E3 is the correct choice because it includes all required services: Microsoft Teams, Exchange Online, SharePoint Online, and the latest desktop versions of Office apps (Office 365 ProPlus). It also provides advanced compliance features such as litigation hold and eDiscovery (via the Microsoft Purview compliance portal), which are not available in lower-tier plans like Business Basic or Business Premium.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Premium with E3, assuming Business Premium includes all E3 features for smaller organizations, but Business Premium has a 300-user limit and lacks the full advanced compliance and eDiscovery capabilities of E3, making it unsuitable for a 500-user company with specific compliance needs.

How to eliminate wrong answers

Option B (Microsoft 365 Business Basic) is wrong because it does not include the desktop versions of Office apps; it only provides web and mobile versions, and it lacks advanced compliance features like litigation hold and eDiscovery. Option C (Microsoft 365 Business Premium) is wrong because while it includes desktop Office apps and some compliance capabilities, it is designed for organizations with up to 300 users, not 500, and its compliance features are limited compared to E3 (e.g., no advanced eDiscovery or litigation hold at the same level). Option D (Microsoft 365 E5) is wrong because it exceeds the requirements; it includes all E3 features plus advanced security and analytics (e.g., Microsoft Defender for Office 365, Power BI Pro), which are not needed, making it a more expensive overprovisioning for the stated needs.

557
MCQeasy

A business stakeholder asks how Microsoft 365 can help them create a short-term test environment and delete it after the pilot. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Agility
C.Data Loss Prevention (DLP)
D.Microsoft Planner
AnswerB

Cloud agility lets the business provision a short-term test environment on demand and tear it down once the pilot ends, paying only for what is used. This directly satisfies the stem's requirement to create and delete a temporary pilot environment quickly without long procurement cycles.

Why this answer

Agility is the correct answer because it refers to the ability to rapidly provision and deprovision resources, such as creating a short-term test environment and deleting it after a pilot. Microsoft 365's cloud-based infrastructure enables on-demand scaling and resource lifecycle management, allowing organizations to spin up environments quickly and tear them down without long-term commitments or hardware procurement delays.

Exam trap

The trap here is that candidates confuse agility with data protection features (sensitivity labels or DLP) or productivity tools (Planner), because the question mentions 'test environment' and 'delete' which superficially sounds like data management or task tracking, but the core cloud concept is rapid provisioning and deprovisioning.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data based on sensitivity (e.g., confidential or restricted), not to manage temporary environments. Option C is wrong because Data Loss Prevention (DLP) policies prevent unauthorized sharing or leakage of sensitive data, not environment lifecycle management. Option D is wrong because Microsoft Planner is a task management and collaboration tool for organizing work, not for provisioning or deleting cloud test environments.

558
MCQmedium

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What will this policy do?

A.Allows access but logs the sign-in risk
B.Requires multi-factor authentication for high-risk sign-ins
C.Blocks access to all cloud apps when sign-in risk is high
D.Blocks access to Office 365 apps when the sign-in risk is high
AnswerD

The policy correctly matches the exhibit: assigned to the 'Office 365' cloud app, condition set to 'High' sign-in risk, and grant control configured to 'Block access'. When a sign-in for any Office 365 app (like OneDrive, Exchange, etc.) is evaluated as high risk, Azure AD blocks the authentication and prevents the user from gaining access. This is an effective way to protect against compromised credentials without locking out legitimate low-risk sign-ins.

Why this answer

The exhibit shows a Conditional Access policy configured with the condition 'Sign-in risk: High' and the control 'Block access'. This combination means that when Microsoft Entra ID detects a high-risk sign-in (e.g., from an anonymous IP address or compromised credentials), access to the targeted cloud apps is denied. The policy specifically targets Office 365 apps (as indicated in the 'Cloud apps or actions' assignment), so it blocks access to those apps when the sign-in risk is high.

Exam trap

The trap here is that candidates often confuse 'Block access' with 'Require MFA' or assume the policy applies to all cloud apps, when the exhibit clearly shows the scope is limited to Office 365 apps.

How to eliminate wrong answers

Option A is wrong because the policy is set to 'Block access', not 'Grant access' with a session control to log risk; logging sign-in risk alone does not block access. Option B is wrong because the policy uses 'Block access' as the control, not 'Require multi-factor authentication'; MFA would be a grant control, not a block. Option C is wrong because the policy targets 'Office 365' apps specifically, not 'All cloud apps'; the scope is limited to the selected apps.

559
MCQeasy

A business stakeholder asks how Microsoft 365 can help them use hosted email without managing mail servers. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Community cloud
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerC

Software as a Service (SaaS) is a cloud service model where the provider operates the complete application, including the underlying infrastructure, platform, and application code, and delivers it to users over the internet. Microsoft 365 exemplifies SaaS with services such as Exchange Online, Microsoft Teams, and Word Web App, which Microsoft patches and updates centrally. This matches the stakeholder's goal of using business tools immediately without managing servers or software installations, making it the correct answer.

Why this answer

Microsoft 365 delivers hosted email (Exchange Online) as a Software as a Service (SaaS) offering, where Microsoft manages the mail servers, patches, and infrastructure. The stakeholder simply uses the service via a web browser or client without any server administration. This aligns with the SaaS model, which provides ready-to-use applications over the internet.

Exam trap

The trap here is that candidates confuse PaaS with SaaS because both involve managed services, but PaaS still requires the customer to deploy and manage the application code (e.g., a custom email server), whereas SaaS delivers the fully functional application itself.

How to eliminate wrong answers

Option A is wrong because PaaS provides a platform (runtime, database, middleware) for developers to build and deploy custom applications, not a ready-to-use hosted email service. Option B is wrong because a community cloud is a deployment model shared by several organizations with common concerns (e.g., compliance), not a service model that delivers hosted email without server management. Option D is wrong because IaaS provides virtualized computing resources (VMs, storage, networking) that still require the customer to manage operating systems and mail server software, contradicting the requirement to avoid managing mail servers.

560
Multi-Selecteasy

Which TWO of the following are examples of security defaults in Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Require multifactor authentication for all users
B.Allow legacy authentication protocols
C.Disable self-service password reset
D.Enable guest user access
E.Block legacy authentication
AnswersA, E

Security defaults require every user to register for and use multifactor authentication, satisfying the question's demand for a security default example. This baseline applies tenant-wide, blocking sign-ins until MFA registration completes, which is precisely the mechanism the stem describes.

Why this answer

Security defaults in Microsoft Entra ID are a preconfigured set of baseline protections that Microsoft enables for tenants that have not purchased Entra ID P1/P2 licenses. Option A is correct because security defaults require all users to register for and use multifactor authentication (MFA) via the Microsoft Authenticator app when necessary, protecting against credential-stuffing and password-spray attacks. Option E is correct because security defaults block legacy authentication protocols (such as POP, IMAP, SMTP AUTH, and older Office clients) that cannot enforce MFA, thereby closing a common MFA-bypass vector.

Option B is incorrect because allowing legacy authentication is the opposite of what security defaults do — they block it. Option C is incorrect because security defaults do not disable self-service password reset; SSPR is a separate feature configured independently. Option D is incorrect because enabling guest user access is not part of security defaults; guest access is governed by external collaboration settings, and security defaults actually restrict guest actions such as Azure portal access.

Exam trap

MS-900 often tests the misconception that security defaults are configurable per-user or that they include features like SSPR or guest access — in reality they are a fixed, tenant-wide baseline that only enforces MFA and blocks legacy auth.

561
MCQeasy

A company runs a virtual machine in Azure that hosts a web application. The company is responsible for configuring the operating system, installing web server software, and managing application updates. The cloud provider is responsible for the physical hardware, networking, and data center security. Which cloud service model does this represent?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerC

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, where the cloud provider supplies the physical hardware, virtualization, networking, and storage, but you are responsible for installing and managing the guest OS, middleware, and applications. For a VM hosting a web app, IaaS matches because you manage the OS, apply patches, configure the web server, and maintain the app itself. Azure Virtual Machines is a classic IaaS offering that gives you full administrative control.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer manages the operating system, web server software, and application updates, while the cloud provider handles the physical hardware, networking, and data center security. In IaaS, the provider offers virtualized computing resources over the internet, and the customer retains control over the guest OS and installed software, which matches the responsibilities outlined.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve deploying applications, but the key differentiator is whether the customer manages the OS and installed software—PaaS abstracts the OS, while IaaS does not.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) would have the provider manage the entire application stack, including the OS and software, leaving the customer only to use the application—here the customer configures the OS and installs web server software. Option B is wrong because Platform as a Service (PaaS) abstracts the OS and runtime, with the provider managing the underlying OS and middleware, but the customer is responsible for configuring the OS and installing web server software, which is not typical for PaaS. Option D is wrong because Function as a Service (FaaS) is a serverless compute model where the provider manages all infrastructure and the customer only deploys individual functions, not a full VM with OS and web server management.

562
MCQmedium

A project team uses Microsoft Teams and wants to create a shared space where they can track tasks, deadlines, and assign work items without leaving Teams. Which Microsoft 365 app should be integrated into Teams for this purpose?

A.Microsoft Planner
B.Microsoft Project Online
C.Microsoft To Do
D.Microsoft Lists
AnswerA

Microsoft Planner is a collaborative task management service in Microsoft 365 that creates shared plans, assigns tasks to individuals with due dates, and tracks progress via charts and board views. It can be added directly as a tab in Microsoft Teams, letting all team members view and update the same task list without leaving the Teams interface. Because it is purpose-built for team-level task assignment and status tracking, it fully satisfies the need for a shared, collaborative task list.

Why this answer

Microsoft Planner is the correct choice because it provides a lightweight, Kanban-style task management solution that integrates directly into Microsoft Teams via the Planner tab. This allows the project team to create, assign, and track tasks with deadlines and progress indicators without leaving the Teams interface, fulfilling the requirement for a shared workspace for work items.

Exam trap

The trap here is that candidates often confuse Microsoft To Do (personal tasks) with Planner (team tasks) or assume Microsoft Lists can handle task tracking without realizing it lacks native assignment and Kanban features, leading them to choose an app that does not meet the shared task management requirement.

How to eliminate wrong answers

Option B is wrong because Microsoft Project Online is a full-scale project management tool for complex scheduling, resource management, and Gantt charts, which is overkill for simple task tracking and requires additional licensing and a separate web interface, not a native Teams tab. Option C is wrong because Microsoft To Do is a personal task management app designed for individual productivity and lacks shared team views, assignment capabilities, and deadline tracking across multiple users. Option D is wrong because Microsoft Lists is a data-tracking and information-management app for creating custom lists (e.g., issue trackers, inventories), but it does not provide built-in task assignment, Kanban boards, or deadline tracking out of the box without additional customization.

563
MCQmedium

A company with 75 users needs desktop Office apps and cloud services but has no advanced security requirement. Which option best matches the requirement?

A.Microsoft 365 Business Standard
B.Microsoft Defender for Cloud only
C.Azure Virtual Desktop only
D.A free personal Microsoft account only
AnswerA

Microsoft 365 Business Standard delivers the desktop Office applications plus cloud services for up to 300 users, comfortably covering 75. It omits advanced security tooling, matching the stated absence of advanced security requirements without over-licensing the organisation.

Why this answer

Microsoft 365 Business Standard is designed for small to medium businesses (up to 300 users) and includes desktop Office apps (Word, Excel, PowerPoint, Outlook) plus cloud services like Exchange Online, SharePoint, Teams, and OneDrive. It meets the requirement of 75 users needing desktop apps and cloud services without advanced security. Other options either lack desktop apps or are not full productivity suites.

Exam trap

MS-900 often tests the distinction between Microsoft 365 Business Standard and Business Premium, where candidates may incorrectly assume that Business Standard includes advanced security features like Conditional Access or Intune.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Cloud is a security posture management and threat protection service, not a productivity suite with desktop Office apps. Option C is wrong because Azure Virtual Desktop is a virtualization service for running Windows desktops and apps in the cloud, but it does not include Office licenses or cloud productivity services by itself. Option D is wrong because a free personal Microsoft account provides only basic consumer services and no commercial Office desktop apps or business cloud services.

564
MCQhard

A multinational company must comply with the General Data Protection Regulation (GDPR). They need to be able to search for and delete personal data of a user upon request (right to erasure). Which Microsoft Purview solution should they use?

A.Microsoft Purview eDiscovery (Premium)
B.Microsoft Purview Audit (Standard)
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Insider Risk Management
AnswerA

eDiscovery Premium can search, collect, and export data, and supports deletion.

Why this answer

Microsoft Purview eDiscovery (Premium) supports searching across Microsoft 365 workloads for personal data and applying holds or deletions to satisfy data subject requests, including the GDPR right to erasure. It provides case management, review sets, and the ability to purge content, which are the capabilities needed to locate and delete a user's personal data on request.

Exam trap

MS-900 often tests whether candidates can match GDPR obligations to the correct Purview solution — many pick Audit or Communication Compliance because they sound compliance-related, missing that only eDiscovery supports content search and deletion.

How to eliminate wrong answers

Option B is wrong because Audit (Standard) only records and searches audit log events; it cannot search content or delete data. Option C is wrong because Communication Compliance monitors communications for policy violations; it does not perform content search or deletion for data subject requests. Option D is wrong because Insider Risk Management detects risky user behavior; it is not a tool for locating and erasing personal data.

565
MCQeasy

A user reports that they cannot access their Microsoft 365 email on their mobile device. The user can access Outlook on the web. Which Microsoft 365 app should the administrator check to verify the user's mobile device is compliant?

A.Microsoft Intune
B.Microsoft Defender for Office 365
C.Microsoft Entra ID
D.Microsoft Purview
AnswerA

Microsoft Intune is the cloud-based MDM/MAM service that creates and enforces device compliance policies, such as requiring BitLocker encryption, a minimum OS build, or a passcode. In this scenario, the user’s device is likely non-compliant, so Intune’s compliance state is consumed by Conditional Access in Entra ID, which blocks the user’s session to Microsoft 365 Exchange Online. Thus Intune is the component that determines whether the device meets access requirements.

Why this answer

Microsoft Intune is the correct answer because it is the mobile device management (MDM) and mobile application management (MAM) component within Microsoft 365. When a user cannot access email on a mobile device but can via Outlook on the web, the issue is likely a device compliance policy blocking access. Intune enforces conditional access policies by checking device compliance (e.g., encryption, jailbreak status, minimum OS version) before allowing Exchange Online connectivity.

Exam trap

The trap here is that candidates confuse Microsoft Entra ID (which handles conditional access policies) with Intune (which actually performs the device compliance check and reports the status to Entra ID).

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Office 365 is a security service focused on protecting against email threats like phishing, malware, and spam, not on device compliance or mobile access policies. Option C is wrong because Microsoft Entra ID (formerly Azure AD) provides identity and access management, including conditional access policies, but it does not directly verify device compliance; it relies on Intune to report device compliance status. Option D is wrong because Microsoft Purview is a compliance and data governance solution covering data loss prevention, eDiscovery, and auditing, not device management or compliance enforcement.

566
Multi-Selecthard

Contoso Ltd. is a medium-sized company with 2,000 users. They use Microsoft 365 E5 and have recently deployed Microsoft Teams for collaboration. The IT department has received complaints that external partners (guests) can see internal team names and member lists in the Teams directory. The compliance team requires that external guests must only see teams they are directly added to, and they must not be able to search for other teams or see internal team members who are not members of the same team. Additionally, the HR team wants to use a custom app in Teams that allows employees to submit leave requests, and this app must be available to all employees without requiring them to install anything manually. The IT admin needs to configure Teams settings to meet these requirements. Which two actions should the admin take? (Choose two. Each correct answer is part of the solution.)

Select 2 answers
A.Disable 'Show all teams' in the Teams admin center to prevent guests from seeing teams they are not members of.
B.Create a Teams app setup policy that pins the leave request app for all users.
C.Block all external access in Teams admin center to prevent guests from joining.
D.Configure external sharing settings in SharePoint admin center to limit guest access.
E.Enable external access in Teams admin center to allow guests to communicate with internal users.
AnswersA, B

Disabling the 'Show all teams' tenant-wide setting in the Teams admin center controls whether users, including guests, can browse all teams in the organization and request to join them. When this setting is off, guests only see the specific teams they have been added to, which directly satisfies the security requirement. Unlike external access or SharePoint sharing, this setting specifically targets team discovery and visibility.

Why this answer

Disabling 'Show all teams' in the Teams admin center (under Teams settings) prevents guests from seeing teams they are not members of in the Teams directory. This directly addresses the compliance requirement that external guests must only see teams they are directly added to and cannot search for other teams or see internal team members outside their own team.

Exam trap

The trap here is confusing 'external access' (federation for chat/calling) with 'guest access' (B2B collaboration for team membership), leading candidates to select options that manage federation settings instead of the specific Teams directory visibility control.

567
MCQhard

A compliance officer needs to set up a policy that automatically monitors and detects activities related to accessing sensitive data from outside the corporate network. When a user from a foreign country accesses a confidential file, the policy should trigger an alert and require additional authentication. Which combination of Microsoft 365 solutions achieves this?

A.Microsoft Purview Data Loss Prevention and Conditional Access
B.Microsoft Purview Audit (Standard) and Microsoft Entra ID Identity Protection
C.Microsoft Purview Insider Risk Management and Microsoft Cloud App Security
D.Microsoft Purview eDiscovery and Privileged Identity Management
AnswerA

Microsoft Purview Data Loss Prevention (DLP) continuously inspects content in Exchange, SharePoint, OneDrive, and endpoints to detect sensitive data patterns and automatically trigger alerts or protective actions. Conditional Access in Microsoft Entra ID evaluates signals such as user location, device compliance, and risk level to require additional authentication (e.g., MFA) before access is granted. Together, they satisfy both the monitoring-and-alerting requirement and the adaptive authentication requirement, making them the correct pairing.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) monitors and detects sensitive data access from outside the corporate network, while Conditional Access enforces additional authentication (e.g., MFA) when such access is detected. Together, they meet the requirement for automatic alerting and step-up authentication based on location and data sensitivity.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Insider Risk Management with external access detection, but it is specifically for internal user risk, not foreign country access scenarios.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit (Standard) only logs user activities for forensic review, not real-time detection or policy-driven alerts, and Microsoft Entra ID Identity Protection focuses on user risk (e.g., compromised credentials) rather than data access policies. Option C is wrong because Microsoft Purview Insider Risk Management is designed for internal user behavior analytics (e.g., data exfiltration by employees), not external access detection, and Microsoft Cloud App Security provides cloud app visibility but lacks native DLP policy enforcement for on-premises file access. Option D is wrong because Microsoft Purview eDiscovery is for legal discovery and content search, not real-time monitoring, and Privileged Identity Management (PIM) manages just-in-time admin roles, not data access policies.

568
Matchingmedium

Match each Microsoft 365 service to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Email and calendaring

Document management and intranet

Chat, meetings, and collaboration

Personal cloud storage and file sync

Why these pairings

Microsoft Teams is for chat and collaboration, SharePoint for document management and intranets, Exchange Online for email, and OneDrive for personal file storage. Common confusions include mixing Teams with SharePoint or Exchange with SharePoint.

569
MCQeasy

A team of financial analysts needs to collaboratively build a complex budget model that includes data from multiple sources. They require real-time co-authoring, advanced formulas, and the ability to create custom charts. Which Microsoft 365 app is best suited for this task?

A.Microsoft Word
B.Microsoft Excel
C.Microsoft PowerPoint
D.Microsoft OneNote
AnswerB

Microsoft Excel is the correct choice because it is a spreadsheet application built around a powerful calculation engine that supports financial formulas, functions, PivotTables, and a wide range of chart types. Excel's real-time co-authoring via OneDrive and SharePoint enables multiple analysts to edit the same workbook simultaneously, with AutoSave and version history ensuring no work is lost. Its ability to model complex budget scenarios through cells, named ranges, and data tables directly supports the analytical workflow the team needs.

Why this answer

Microsoft Excel is the correct choice because it is designed for complex numerical modeling with advanced formulas, real-time co-authoring via OneDrive or SharePoint, and custom chart creation. The team's requirements for multi-source data integration, collaborative editing, and analytical visualization align directly with Excel's core capabilities, unlike the other apps which lack these features.

Exam trap

The trap here is that candidates may confuse the collaborative editing features of Word or OneNote with the specialized data analysis and formula capabilities required for budget modeling, overlooking Excel's unique strength in handling complex numerical computations and real-time co-authoring for spreadsheets.

How to eliminate wrong answers

Option A is wrong because Microsoft Word is a word processor optimized for document creation and text formatting, not for numerical analysis, advanced formulas, or custom charting. Option C is wrong because Microsoft PowerPoint is a presentation tool for slideshows, lacking the formula engine and data manipulation features needed for budget modeling. Option D is wrong because Microsoft OneNote is a digital note-taking app with limited formula support and no native charting or real-time co-authoring for complex spreadsheets.

570
MCQmedium

A tenant administrator is advising a department that wants to keep services available during a hardware failure. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.High availability
D.Sensitivity labels
AnswerC

High availability keeps services reachable during hardware failure by using redundancy such as multiple nodes, load balancing, and failover, so no single component outage causes downtime. This matches the department's requirement to maintain continuous service availability.

Why this answer

High availability (C) is the correct answer because it directly addresses the requirement to keep services available during a hardware failure. High availability refers to a system's ability to remain operational and accessible despite component failures, typically achieved through redundancy, failover clustering, and load balancing. In Microsoft 365, this is implemented via redundant infrastructure across multiple datacenters and automatic failover mechanisms, ensuring service continuity without manual intervention.

Exam trap

The trap here is that candidates confuse high availability with disaster recovery or data protection features like DLP, but high availability specifically focuses on minimizing downtime during failures, not on preventing data loss or classifying data.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management application, not a cloud concept or benefit; it does not provide infrastructure-level availability during hardware failures. Option B is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive information from being shared inappropriately, but it has no role in maintaining service availability during hardware outages. Option D is wrong because sensitivity labels are used for data classification and protection (e.g., encryption, marking), not for ensuring uptime or resilience against hardware failures.

571
MCQeasy

An HR manager needs to collect feedback from employees about a new wellness program. The manager wants to create a simple survey with multiple-choice questions and have the responses automatically visualized in charts. Which Microsoft 365 app is best suited for this task?

A.Microsoft Excel
B.Microsoft Forms
C.Microsoft Word
D.Microsoft Teams
AnswerB

Microsoft Forms is the correct choice because it is purpose-built for creating surveys with multiple question types, branching logic, and validation rules. After distribution, it automatically compiles responses and presents them in real-time charts, and administrators can export the dataset to Excel if further statistical analysis is needed. This streamlined workflow makes Forms the ideal tool for an HR manager collecting employee feedback.

Why this answer

Microsoft Forms is specifically designed for creating surveys, quizzes, and polls with automatic response collection and built-in chart visualization. It allows the HR manager to quickly add multiple-choice questions and instantly see aggregated results as charts without any manual setup.

Exam trap

The trap here is that candidates may confuse Microsoft Teams as the correct answer because they know surveys can be created within Teams, but the question asks for the app best suited for the task, which is Microsoft Forms—the dedicated survey tool that Teams integrates with.

How to eliminate wrong answers

Option A is wrong because Microsoft Excel is a spreadsheet application for data analysis and manual chart creation, not a survey tool; it lacks native survey creation and automatic response visualization. Option C is wrong because Microsoft Word is a word processing application for document creation, not for building interactive surveys or generating charts. Option D is wrong because Microsoft Teams is a collaboration platform that can host a Forms tab or use the Forms app, but it is not the primary survey creation tool; the best-suited app for creating the survey itself is Microsoft Forms.

572
MCQeasy

Your organization wants to ensure that data sent to Microsoft 365 is encrypted in transit. Which protocol should you enforce for all client connections?

A.IPsec
B.TLS 1.2
C.HTTPS
D.SSH
AnswerB

TLS 1.2 is the encryption protocol Microsoft 365 requires for inbound client connections; Microsoft disabled TLS 1.0 and 1.1 for these services. It authenticates the server using digital certificates, negotiates a symmetric session key, and then encrypts the application data flowing between the client and cloud. This satisfies the confidentiality and integrity needs for data sent to Microsoft 365.

Why this answer

TLS 1.2 is the correct protocol because Microsoft 365 enforces TLS 1.2 or later for all client-to-service connections to ensure data is encrypted in transit. TLS provides end-to-end encryption for HTTP-based traffic (including HTTPS) and is the standard protocol used by Microsoft 365 services like Exchange Online, SharePoint Online, and Teams. Enforcing TLS 1.2 ensures that older, less secure versions like TLS 1.0 and 1.1 are blocked, meeting the organization's encryption requirement.

Exam trap

The trap here is that candidates often confuse HTTPS (the URL scheme) with the underlying encryption protocol TLS, leading them to select HTTPS instead of TLS 1.2, even though HTTPS is merely the application-layer wrapper that relies on TLS for actual encryption.

How to eliminate wrong answers

Option A (IPsec) is wrong because IPsec is a network-layer protocol used for VPN tunnels or site-to-site connections, not for encrypting individual client-to-Microsoft 365 connections over the internet. Option C (HTTPS) is wrong because HTTPS is not a protocol itself but an application-layer scheme that uses TLS (or SSL) underneath; the question asks for the specific protocol to enforce, which is TLS 1.2. Option D (SSH) is wrong because SSH is used for secure remote administration of servers (e.g., command-line access), not for encrypting HTTP-based traffic to Microsoft 365 services.

573
MCQmedium

A marketing department uses Microsoft 365 Copilot to generate content. The compliance officer is concerned about data leakage when users interact with Copilot. Which Microsoft Purview feature should the admin implement to prevent sensitive data from being used in Copilot prompts?

A.Microsoft Purview Data Loss Prevention (DLP) for Copilot
B.Microsoft Purview Audit (Standard)
C.Microsoft Purview Information Rights Management (IRM)
D.Microsoft Purview Sensitivity labels
AnswerA

Microsoft Purview DLP for Copilot inspects both the Copilot prompt and the generated response for sensitive content types, such as credit card numbers, personal data, or confidential keyword patterns, using the same policy engine as classic DLP. When a violation is detected, it can block the interaction, restrict sharing, and raise an incident in Microsoft Defender, which is why it is the control that actually prevents leakage. This is a preventive, in-line control rather than a retrospective or classification-only measure.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) for Copilot is the correct feature because it specifically inspects and blocks sensitive data (e.g., credit card numbers, PII) from being included in Copilot prompts or generated content. DLP policies can be applied to Copilot interactions to prevent data leakage by evaluating the content in real time against sensitive information types and enforcing actions like blocking or warning the user.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect static content) with DLP (which actively monitors and blocks data in motion), leading them to choose Option D instead of the correct preventive control.

How to eliminate wrong answers

Option B (Microsoft Purview Audit (Standard)) is wrong because it only logs user activities for compliance review but does not actively prevent sensitive data from being used in prompts; it is a detective control, not a preventive one. Option C (Microsoft Purview Information Rights Management (IRM)) is wrong because it protects content after it is created by restricting access and usage rights (e.g., preventing forwarding or printing), but it does not inspect or block data at the point of prompt entry in Copilot. Option D (Microsoft Purview Sensitivity labels) is wrong because they classify and protect data by applying encryption or markings, but they do not provide real-time inspection or blocking of sensitive data in Copilot prompts; labels are applied to documents and emails, not to dynamic prompt content.

574
MCQmedium

A company must comply with a regulation that requires all data stored in Microsoft 365 to remain within the European Union. Which Microsoft 365 feature should an administrator configure to enforce this geographic restriction?

A.Data Loss Prevention (DLP)
B.Information Rights Management (IRM)
C.Data Residency policies
D.Customer Lockbox
AnswerC

Data Residency policies are designed specifically to ensure customer data is stored at rest within a defined geographic region. In Microsoft 365, administrators can leverage features like Multi-Geo in Exchange Online, SharePoint, and OneDrive to provision storage in specific datacenters, or rely on regional commitments such as the EU Data Boundary. These policies directly enforce where data resides, meeting regulatory requirements for storage location, making this the correct answer.

Why this answer

Data Residency policies in Microsoft 365 allow administrators to define the geographic location where data at rest is stored. By configuring a Data Residency policy for the European Union, the administrator ensures that all data remains within EU data centers, meeting regulatory requirements.

Exam trap

The trap here is that candidates often confuse Data Residency policies with Data Loss Prevention (DLP) or Information Rights Management (IRM), mistakenly thinking those features control data location rather than focusing on data protection or access control.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is designed to prevent sensitive information from being shared or leaked, not to control where data is stored geographically. Option B is wrong because Information Rights Management (IRM) protects data through encryption and usage restrictions, but does not enforce data residency or storage location constraints. Option D is wrong because Customer Lockbox provides customer approval control over Microsoft engineer access to data during support scenarios, but does not determine or enforce the geographic storage location of data.

575
MCQmedium

A company wants to ensure that only IT administrators can install browser extensions in Microsoft Edge. Which Microsoft 365 security feature should be used?

A.Conditional Access
B.Microsoft Intune
C.Microsoft Defender for Cloud Apps
D.Microsoft Entra ID Identity Protection
AnswerB

Microsoft Intune is a cloud-based endpoint management service (MDM/MAM) that can deploy device configuration profiles to Windows, macOS, iOS, and Android devices. For instance, an Intune configuration profile can apply a Policy CSP to set the "Configure ExtensionSettings" policy for Microsoft Edge, blocking extension installations or allowlisting only approved extensions. Intune also integrates with Entra ID so that Conditional Access can require device compliance, but the actual endpoint restriction is enforced by Intune's policy delivery.

Why this answer

Microsoft Intune is the correct choice because it provides mobile device management (MDM) and mobile application management (MAM) capabilities that allow administrators to configure Microsoft Edge settings via configuration profiles. Specifically, Intune can enforce the 'Installation of browser extensions' policy to restrict extension installation to IT administrators only, using the Administrative Templates for Edge within the Settings Catalog.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access to resources) with device management policies (which control software behavior on the device), leading them to incorrectly select Conditional Access instead of Intune.

How to eliminate wrong answers

Option A is wrong because Conditional Access is an identity-driven access control feature that enforces policies based on user, device, location, or risk signals at authentication time, but it cannot directly manage or restrict browser extension installation within Edge. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on discovering and controlling cloud app usage, data protection, and threat detection, not on configuring local browser policies like extension installation. Option D is wrong because Microsoft Entra ID Identity Protection is a risk-based protection feature that detects and responds to identity threats (e.g., leaked credentials, sign-in anomalies), but it does not have the capability to enforce device-level configuration policies for browser extensions.

576
MCQeasy

A sales team needs to create a shared workspace where they can store customer documents, collaborate on a lead list, track follow-ups on a shared calendar, and hold video meetings with customers. Which Microsoft 365 service provides all these capabilities in a single, integrated experience?

A.Microsoft Viva Engage
B.Microsoft Teams
C.SharePoint Online
D.OneNote
AnswerB

Microsoft Teams is a comprehensive collaboration hub in Microsoft 365 that brings together persistent chat, channel-based discussions, shared document storage (backed by SharePoint Online), and co-authoring capabilities. It also includes a team calendar synced with Exchange Online and native integration with Microsoft Teams Meetings for video conferencing, enabling a sales team to manage files, schedules, and virtual meetings in one place. This integrated combination of chat, documents, calendar, and video meetings makes Teams the ideal shared workspace for a sales team's daily operations.

Why this answer

Microsoft Teams is the correct answer because it provides a single, integrated workspace that combines persistent chat, file storage (via SharePoint), collaborative editing on lists (via SharePoint or Planner), a shared calendar, and built-in video meetings. This eliminates the need to switch between separate apps for each task, fulfilling all the sales team's requirements in one experience.

Exam trap

The trap here is that candidates often pick SharePoint Online because they associate it with document storage and lists, forgetting that Teams integrates those features with video meetings and a shared calendar, making it the single, integrated solution the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Engage is primarily a social networking and employee engagement tool (formerly Yammer), not designed for document storage, lead list collaboration, shared calendars, or video meetings. Option C is wrong because SharePoint Online provides document storage and list collaboration, but lacks native video meeting capabilities and a shared calendar for tracking follow-ups without additional integration. Option D is wrong because OneNote is a digital note-taking app that supports collaboration on notes but does not offer document storage, lead list management, a shared calendar, or video meeting functionality.

577
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to troubleshoot why a licensed user cannot access a specific app. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.The assigned license and enabled service plans
C.Microsoft Stream
D.Microsoft Whiteboard
AnswerB

The assigned license and enabled service plans are the authoritative control for user access to Microsoft 365 services. Each user license is a SKU containing multiple service-plan switches (for example, Exchange Online, SharePoint Online, Teams), and an administrator can enable or disable those switches per user. Access is evaluated against this license state plus the user's tenant membership, not by which app is installed or used.

Why this answer

When a licensed user cannot access a specific app, the most relevant concept is the assigned license and its enabled service plans. In Microsoft 365, each license (e.g., Microsoft 365 E3) includes multiple service plans (e.g., Exchange Online, SharePoint, Teams), and an admin can disable individual plans. If the required service plan for the app is disabled in the user's license, the user will be blocked from accessing that app despite having a valid license.

This is a core licensing troubleshooting step in the 'Describe Microsoft 365 pricing and support' domain.

Exam trap

The trap here is that candidates confuse the specific app names (Forms, Stream, Whiteboard) with the underlying licensing concept, failing to recognize that the question asks for the 'concept' most relevant to troubleshooting access, not the app itself.

How to eliminate wrong answers

Option A (Microsoft Forms) is wrong because it is a specific application, not a licensing, admin, or support concept; it would be the app the user cannot access, not the troubleshooting approach. Option C (Microsoft Stream) is wrong because it is also a specific application (for video) and not a licensing or support concept; it does not address why a licensed user might be blocked from an app. Option D (Microsoft Whiteboard) is wrong because it is another specific application, not a licensing or admin concept; it would be the target app, not the root cause of access issues.

578
MCQeasy

A company with 200 employees needs to deploy Microsoft 365 Apps for Enterprise. They want to pay monthly and have no annual commitment. Which licensing program should they use?

A.Microsoft 365 Enterprise Agreement
B.Microsoft 365 Business Basic
C.Microsoft 365 Business Premium
D.Microsoft 365 E3
AnswerC

Microsoft 365 Business Premium is the correct choice because it includes the full Microsoft 365 Apps for Enterprise desktop applications, hosted Exchange, Teams, SharePoint, and advanced security features like Microsoft Defender for Office 365 and Intune, and it can be licensed on a true monthly basis with no annual commitment—making it a flexible, comprehensive solution for 200 employees.

Why this answer

Microsoft 365 Business Premium is the correct choice because it includes Microsoft 365 Apps for Enterprise (e.g., Word, Excel, PowerPoint) and is available as a monthly subscription with no annual commitment for organizations with up to 300 users. This aligns with the company's requirement of 200 employees and the desire for flexible, month-to-month billing.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Premium with Microsoft 365 E3, assuming E3 is the only option for desktop Office apps, but Business Premium also includes Microsoft 365 Apps for Enterprise and is designed for smaller organizations with flexible monthly billing.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 Enterprise Agreement (EA) is a volume licensing program designed for large organizations (typically 250+ users) that requires a 3-year commitment, not monthly billing with no annual commitment. Option B is wrong because Microsoft 365 Business Basic does not include the desktop versions of Microsoft 365 Apps for Enterprise; it only provides web and mobile app access plus cloud services like Exchange Online. Option D is wrong because Microsoft 365 E3 is an enterprise-grade plan that includes Microsoft 365 Apps for Enterprise, but it is typically sold through Enterprise Agreement or CSP with annual commitments, and it is not the most straightforward option for a company of 200 employees seeking a simple monthly subscription without commitment.

579
MCQmedium

A healthcare organization must ensure that electronic protected health information (ePHI) in Microsoft 365 is encrypted both at rest and in transit. Which Microsoft 365 feature provides encryption for data in transit?

A.Azure Information Protection
B.TLS/SSL encryption
C.BitLocker Drive Encryption
D.Microsoft Purview Information Protection
AnswerB

TLS/SSL encrypts data while it moves between clients and Microsoft 365 services, directly satisfying the in-transit requirement. Unlike BitLocker or service-side encryption, which protect stored data at rest, TLS secures the network channel itself, preventing interception of ePHI during transmission.

Why this answer

TLS/SSL encryption is the Microsoft 365 feature that protects data in transit — all Microsoft 365 services use TLS by default for client-to-service and service-to-service communication, and TLS 1.2+ is enforced for modern clients. This directly satisfies the requirement to encrypt ePHI in transit, complementing at-rest encryption provided by BitLocker and service-side encryption.

Exam trap

MS-900 often tests the confusion between encryption at rest (BitLocker, service encryption) and encryption in transit (TLS/SSL) — candidates pick data-classification tools like Azure Information Protection for transit questions.

How to eliminate wrong answers

Option A is wrong because Azure Information Protection (now part of Microsoft Purview Information Protection) is a data classification and labeling service that encrypts content at the document level — it protects data at rest and in use, not the transport channel. Option C is wrong because BitLocker Drive Encryption protects data at rest on disk — it has no role in encrypting network traffic. Option D is wrong because Microsoft Purview Information Protection provides sensitivity labels and encryption for stored content, not the TLS channel used for data in transit.

580
MCQhard

Your organization, Contoso Ltd., uses Microsoft 365 E5 licenses and has 10,000 users. The company is planning to deploy Microsoft Copilot for Microsoft 365 to all users. The IT department has identified the following requirements: 1. Users must be able to use Copilot across Microsoft Teams, Word, Excel, PowerPoint, and Outlook. 2. Copilot must be able to access user data from Exchange Online, SharePoint Online, and Microsoft Graph. 3. The deployment must comply with the company's data residency policy, which requires that all data processed by Copilot remains within the European Union (EU). 4. The company wants to use a phased rollout, starting with a pilot group of 500 users. Which configuration should the IT administrator implement to meet these requirements?

A.Assign Microsoft Copilot for Microsoft 365 licenses to the pilot group, and in Microsoft Purview, create a data residency policy that restricts data to the EU.
B.Enable Microsoft Copilot for Microsoft 365 in the Microsoft 365 admin center for all users, then ask each user to customize their Copilot permissions in Graph.
C.Assign Microsoft Copilot for Microsoft 365 licenses to the pilot group, and in the Microsoft 365 admin center, configure the data storage location to 'EU'.
D.Create a separate Microsoft 365 tenant in the EU region, move pilot users to that tenant, and assign Copilot licenses there.
AnswerC

This is the correct approach because it combines the right licensing strategy (assign the Copilot add-on license to a pilot group for phased rollout) with the correct data-residency configuration. The tenant's data storage location is set in the Microsoft 365 admin center under Settings > Org settings > Security & privacy > Data location, and choosing 'EU' ensures that core data, including Copilot-related data, is stored at rest in Microsoft's European datacenters. Because this setting is at the tenant level, it applies to all users, which is exactly what a pilot rollout needs before broader deployment.

Why this answer

The Microsoft 365 admin center provides a tenant-level setting to configure the data storage location for Microsoft Copilot for Microsoft 365, ensuring all processed data remains within the EU. Assigning licenses to the pilot group enables the phased rollout, while the data residency setting satisfies the compliance requirement without needing a separate tenant or manual user configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Purview's compliance features with the Copilot-specific data residency setting in the Microsoft 365 admin center, or assume that a separate tenant is required for regional data residency, when in fact a single tenant can enforce EU data residency via the admin center configuration.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview does not offer a data residency policy for Copilot; data residency for Copilot is configured in the Microsoft 365 admin center, not Purview. Option B is wrong because enabling Copilot for all users violates the phased rollout requirement, and asking users to customize permissions in Graph is impractical and not how Copilot data access is controlled—access is managed via Microsoft Graph permissions at the tenant level. Option D is wrong because creating a separate tenant is unnecessary and overly complex; the data residency requirement can be met within the existing tenant by configuring the storage location in the admin center, and moving users to a new tenant disrupts operations and licensing.

581
Multi-Selecthard

Which THREE Microsoft 365 services can be used to enforce data classification and protection?

Select 3 answers
A.Microsoft Defender for Cloud Apps
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Information Protection
D.Microsoft Intune
E.Microsoft Entra ID
AnswersA, B, C

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that enforces data protection policies across SaaS apps by inspecting content in real time. It integrates with Microsoft Purview Information Protection to apply sensitivity labels and trigger DLP actions such as blocking downloads, uploads, or sharing of sensitive files via conditional access app control. This makes it a correct answer because it actively enforces data loss prevention rules in cloud environments, not merely classifying data at rest.

Why this answer

Microsoft Defender for Cloud Apps (A) is correct because it acts as a Cloud Access Security Broker (CASB) that can enforce data classification and protection by applying policies to control data in transit and at rest across cloud applications. It can automatically classify sensitive data using built-in DLP engines and enforce actions like blocking downloads or applying encryption based on content inspection.

Exam trap

The trap here is that candidates often confuse Microsoft Intune's device compliance policies with data classification and protection, or mistakenly think Entra ID's conditional access policies enforce data protection directly, when in fact they only control access based on identity and device state.

582
MCQmedium

A compliance officer needs to automatically retain all SharePoint documents that contain a specific project code for exactly 5 years. The retention must be applied automatically when the document is uploaded, without any user interaction. Which Microsoft Purview feature should they configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels
C.Retention labels with an auto-apply policy
D.eDiscovery (Premium)
AnswerC

Retention labels with an auto-apply policy are purpose-built for this scenario: a Microsoft Purview auto-label policy runs a query to match keywords, sensitive info types, or trainable classifiers, and automatically assigns the retention label to each matching item. The label then enforces the configured retention period and disposition action—such as delete after 7 years or keep forever—without requiring any user effort. This content-triggered, hands-free lifecycle management makes it the only option that fully satisfies the compliance officer's need for automatic retention.

Why this answer

Retention labels with an auto-apply policy are the correct choice because they allow you to automatically assign a retention label to SharePoint documents based on specific conditions, such as the presence of a project code, and enforce a fixed retention period (e.g., 5 years) without any user interaction. This feature is designed for automated, policy-driven retention based on content properties or sensitive information types.

Exam trap

The trap here is that candidates often confuse retention labels (which enforce retention actions) with sensitivity labels (which focus on classification and protection), leading them to choose Option B when the requirement is purely about automated retention duration.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies are designed to prevent unauthorized sharing or leakage of sensitive data, not to enforce retention or deletion schedules. Option B is wrong because sensitivity labels primarily classify and protect data with encryption or visual markings, and while they can trigger retention, they require manual application or user interaction unless combined with auto-labeling, which is not the primary mechanism for automated retention based on a project code. Option D is wrong because eDiscovery (Premium) is used for searching, holding, and exporting data for legal or investigative purposes, not for automatically retaining documents for a fixed period upon upload.

583
MCQhard

Your company is deploying Microsoft 365 Copilot and wants to ensure that sensitive data in emails and documents is not inadvertently exposed via Copilot responses. Which Microsoft 365 capability should you implement?

A.Microsoft Purview Sensitivity Labels
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview Customer Lockbox
D.Microsoft Purview Data Loss Prevention
AnswerD

Microsoft Purview Data Loss Prevention (DLP) is the correct control because it can identify sensitive data types (e.g., credit card numbers, passport IDs) in Copilot interactions and apply enforcement actions like blocking the response or restricting sharing. DLP policies attach to specific data sources, including Microsoft 365 Copilot endpoints, and can evaluate prompts and responses against sensitive info types or trainable classifiers. This gives administrators a direct way to prevent Copilot from returning confidential content to unauthorized users.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct choice because it is specifically designed to identify, monitor, and automatically protect sensitive data (e.g., credit card numbers, PII, or custom patterns) across Microsoft 365 services, including emails and documents. When integrated with Microsoft 365 Copilot, DLP policies can prevent Copilot from including sensitive information in its responses by enforcing real-time content checks and blocking or warning users before exposure occurs.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels (which apply persistent protection) with DLP (which enforces real-time actions), leading them to choose A, even though labels alone cannot block Copilot from surfacing sensitive data in responses.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Sensitivity Labels classify and protect data with encryption and visual markings, but they do not actively monitor or block data in Copilot responses—they require user or automated labeling, not real-time content inspection. Option B is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on shadow IT discovery, app permissions, and session controls for third-party cloud apps, not on preventing data leakage within Microsoft 365 Copilot responses. Option C is wrong because Microsoft Purview Customer Lockbox provides a controlled access approval process for Microsoft support engineers to access your data, but it has no role in scanning or blocking sensitive content in Copilot outputs.

584
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to maintain a personal checklist that syncs across devices and integrates with Outlook tasks. Microsoft 365 app or service is the best fit?

A.Microsoft Forms
B.Microsoft To Do
C.Microsoft Purview Audit
D.Microsoft Planner
AnswerB

Microsoft To Do provides a personal task list that synchronises across devices and surfaces in Outlook's Tasks view, letting the service owner maintain one checklist everywhere. This directly satisfies the stated need for cross-device sync plus Outlook task integration.

Why this answer

Microsoft To Do is the best fit because it provides a personal checklist that syncs across devices via Exchange Online and integrates natively with Outlook tasks. This allows the service owner to manage tasks from any device and see them directly within the Outlook task pane, fulfilling both requirements precisely.

Exam trap

The trap here is that candidates often confuse Microsoft Planner with Microsoft To Do because both involve tasks, but Planner is designed for team collaboration and lacks personal checklist sync with Outlook tasks, while To Do is the correct personal task management tool with direct Outlook integration.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz creation tool, not a task management or checklist app; it lacks sync with Outlook tasks. Option C is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user and admin activities, not a personal task or checklist tool. Option D is wrong because Microsoft Planner is a team-based project management app that organizes work into plans and buckets, but it does not provide a personal checklist that syncs with Outlook tasks; it focuses on collaborative assignments rather than individual task lists.

585
MCQmedium

A department head asks which Microsoft 365 option should be used to desktop Office apps plus Intune and enhanced security capabilities for a small or medium business. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Whiteboard
C.Microsoft 365 Business Premium
D.Microsoft Forms
AnswerC

Microsoft 365 Business Premium is the advanced small-business subscription that bundles Office apps with Azure Active Directory Premium P1, Microsoft Intune, and Microsoft Defender for Office 365, enabling conditional access, device compliance, and threat protection. It directly addresses the department head's need for licensing and support by providing a unified plan that enforces security policies and manages user access across endpoints. This makes it the correct choice when the ask is for a full licensing solution, not a single app.

Why this answer

Microsoft 365 Business Premium is the correct choice because it bundles desktop Office apps (e.g., Word, Excel, PowerPoint) with Microsoft Intune for mobile device and app management, plus advanced security features like Microsoft Defender for Office 365, Azure Information Protection, and Conditional Access. This plan is specifically designed for small and medium businesses (up to 300 users) that need enterprise-grade security and management without requiring Enterprise-level licensing.

Exam trap

The trap here is that candidates confuse individual Microsoft 365 apps (like Stream, Whiteboard, Forms) with licensing plans, assuming any app can provide the bundled capabilities of desktop Office, Intune, and security, when only Business Premium (or Enterprise plans) offers that combination.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing service within Microsoft 365, not a licensing plan that includes desktop Office apps, Intune, or enhanced security. Option B is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a licensing plan that provides desktop Office apps, Intune, or security capabilities. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, not a licensing plan that offers desktop Office apps, Intune, or enhanced security features.

586
MCQeasy

A colleague says, 'The public cloud is cheaper because you only pay for the resources you use, like compute hours or storage space.' Which cloud computing characteristic directly supports this pay-as-you-go model?

A.Rapid elasticity
B.Broad network access
C.Measured service
D.On-demand self-service
AnswerC

Measured service is the cloud feature that automates the metering of resource usage, such as CPU time, storage GBs, and network bandwidth, at a granular level. It is this metering capability that enables the pay-as-you-go model, where customers are billed only for the actual consumption, and it allows providers to offer variable pricing that can be lower for sporadic workloads compared to on-premises fixed capacity. This direct linkage between usage and billing is why measured service, not elasticity or self-service, is the correct answer.

Why this answer

Measured service is the cloud computing characteristic that enables a pay-as-you-go model by metering resource usage (e.g., compute hours, storage GB-months, outbound data transfer) and providing transparent billing based on actual consumption. This allows providers like Azure to charge only for what is used, directly supporting the colleague's statement that the public cloud is cheaper because you pay only for resources consumed.

Exam trap

The trap here is that candidates often confuse on-demand self-service (the ability to provision resources without waiting) with the billing model, but on-demand self-service does not inherently include usage metering or pay-as-you-go pricing.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly based on demand, not to the metering or billing mechanism that supports pay-as-you-go. Option B is wrong because broad network access describes the ability to access cloud services over the network via standard protocols (e.g., HTTPS, SSH), which enables connectivity but does not involve usage tracking or cost allocation. Option D is wrong because on-demand self-service allows users to provision resources without human interaction (e.g., via the Azure portal or CLI), but it does not inherently include the metering or billing logic that makes pay-as-you-go possible.

587
MCQhard

A multinational corporation needs to design a cloud strategy that allows them to keep sensitive financial data on-premises while using public cloud for customer-facing apps. Which deployment model should they adopt?

A.Hybrid cloud
B.Private cloud
C.Public cloud
D.Multi-cloud
AnswerA

Hybrid cloud combines on-premises infrastructure with public cloud services, letting the corporation retain sensitive financial data in its own datacentre while hosting customer-facing apps in the public cloud. This directly satisfies the stem's split requirement, unlike pure public or private models. Microsoft Entra ID can broker identity across both environments.

Why this answer

A hybrid cloud combines on-premises infrastructure with public cloud services, connected so workloads and data can span both environments. Keeping sensitive financial data on-premises for compliance while running customer-facing apps in the public cloud is the textbook hybrid scenario, since it preserves data residency and control where required while gaining public cloud elasticity elsewhere.

Exam trap

MS-900 often tests the confusion between hybrid and multi-cloud — candidates pick multi-cloud because it sounds more flexible, forgetting that multi-cloud means multiple public providers, not on-prem plus public.

How to eliminate wrong answers

Option B is wrong because a private cloud is dedicated solely to one organization and does not include public cloud for customer-facing apps — it addresses control but not the requirement to use public cloud. Option C is wrong because a pure public cloud cannot keep sensitive financial data on-premises, violating the stated data residency requirement. Option D is wrong because multi-cloud means using two or more public cloud providers (e.g., Azure and AWS) and says nothing about on-premises integration, so it does not satisfy the on-prem data requirement.

588
MCQeasy

Your organization uses Microsoft 365 Copilot and wants to ensure that sensitive data is not exposed through AI-powered features. Which Microsoft Purview capability should be configured?

A.Microsoft Intune app protection policies
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview Data Loss Prevention policies for Copilot
D.Microsoft Entra Conditional Access
AnswerC

DLP policies for Copilot inspect prompts and responses in Microsoft 365 Copilot, blocking or auditing sensitive content as it is processed. This directly satisfies the requirement to prevent exposure of sensitive data through AI features, unlike sensitivity labels or retention policies, which classify or retain rather than block.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can be scoped specifically to Microsoft 365 Copilot, allowing organizations to detect and prevent sensitive data from being processed or surfaced by Copilot. This is the direct Purview control for governing data exposure through AI-powered features. Configuring a DLP policy with Copilot as the workload ensures that prompts and responses involving sensitive content are blocked or warned.

Exam trap

MS-900 often tests the misconception that Defender for Cloud Apps or Conditional Access governs Copilot data — the correct Purview workload for AI data governance is DLP scoped to Microsoft 365 Copilot.

How to eliminate wrong answers

Option A is wrong because Intune app protection policies govern mobile app data access (e.g., copy/paste restrictions in managed apps), not AI feature data exposure in Copilot. Option B is wrong because Defender for Cloud Apps is a CASB for shadow IT discovery and SaaS session control — it does not natively govern Copilot prompt/response data. Option D is wrong because Entra Conditional Access controls sign-in conditions (device, location, risk), not the content flowing through Copilot.

589
MCQhard

A security administrator at Contoso wants to ensure that sensitive documents in SharePoint Online are automatically encrypted and access is restricted to specific users, even if the document is shared externally. Which Microsoft 365 feature should the administrator use?

A.SharePoint Online site-level permissions
B.Microsoft Defender for Cloud Apps file policies
C.Sensitivity labels in Microsoft Purview Information Protection
D.Exchange Online transport rules
AnswerC

Sensitivity labels can automatically apply encryption and access restrictions to documents based on the label's configuration. When applied to SharePoint Online, labels can enforce encryption and permissions that persist even when the document is shared externally. This meets the requirement for automatic encryption and restricted access.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection can automatically apply encryption and access restrictions to documents. When configured, labels can enforce encryption that travels with the document, ensuring that access is restricted even when shared externally. This directly addresses the requirement for automatic encryption and persistent access control.

Exam trap

The trap here is assuming that SharePoint permissions alone provide encryption, when they only control access within SharePoint and do not persist externally.

590
MCQhard

A hospital uses Microsoft 365 E5. They need to archive patient emails for 7 years and enable legal hold for ongoing litigation. Which two Microsoft Purview features should they use? (Select TWO.)

A.Sensitivity labels
B.Retention policies
C.Litigation hold
D.Data Lifecycle Management
E.eDiscovery
AnswerB, C

Retention policies in the Microsoft Purview compliance portal let administrators define how long content must be kept, such as retaining all Exchange mailbox items for 7 years before automatic deletion. These policies are centrally managed, can be scoped to specific users or groups, and can be configured to either keep content indefinitely, keep for a set period, or delete after the retention period expires. For the hospital's requirement to archive patient emails for 7 years, a retention policy is the precise and flexible solution.

Why this answer

Retention policies (B) are correct because they allow the organization to define rules that preserve patient emails for a specific duration, such as 7 years, to meet regulatory compliance requirements. Litigation hold (C) is correct because it preserves all mailbox content, including deleted items, in its original state for the duration of ongoing litigation, preventing any alteration or deletion.

Exam trap

The trap here is that candidates often confuse 'Litigation hold' with 'eDiscovery hold' or think that 'Data Lifecycle Management' is a standalone feature in Microsoft Purview, when in fact the correct feature for time-based retention is 'Retention policies' and for legal preservation is 'Litigation hold'.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data based on sensitivity (e.g., confidentiality), not to enforce time-based retention or legal holds. Option D is wrong because Data Lifecycle Management is a broader concept that includes retention and deletion policies, but in Microsoft 365, the specific feature for setting retention durations is 'Retention policies' (part of Microsoft Purview), not a separate feature named 'Data Lifecycle Management'. Option E is wrong because eDiscovery is used to search, hold, and export content for legal or investigative purposes, but it does not itself enforce a fixed 7-year retention period; it relies on holds and retention policies to preserve data.

591
MCQmedium

Your company is moving to Microsoft 365 and wants to reduce capital expenditure (CapEx) on hardware and software licenses. Which cloud benefit is most directly related to this goal?

A.Scalability
B.Consumption-based pricing
C.Agility
D.Security
AnswerB

Consumption-based pricing converts upfront hardware and licence purchases into operating expenditure, billed only for resources actually used. This directly satisfies the stem's CapEx reduction goal, since Microsoft 365 subscriptions remove large initial capital outlays and shift spending to predictable monthly operational costs.

Why this answer

Consumption-based pricing (also called pay-as-you-go) directly reduces capital expenditure because organizations no longer purchase hardware or perpetual software licenses upfront; instead they pay only for the resources and licenses they consume. This shifts spending from CapEx to OpEx, which is the core financial benefit the company is seeking. Scalability, agility, and security are cloud benefits but do not directly address the CapEx reduction goal.

Exam trap

MS-900 often tests the CapEx vs. OpEx distinction, and candidates may confuse 'scalability' or 'agility' with the financial benefit — the key is recognizing that consumption-based pricing is the specific cloud characteristic that eliminates upfront capital spending.

How to eliminate wrong answers

Option A is wrong because scalability refers to the ability to grow or shrink resources on demand; while valuable, it does not by itself eliminate upfront hardware or license purchases. Option C is wrong because agility describes the speed at which an organization can deploy and adapt services, not the financial model that reduces CapEx. Option D is wrong because security is a cloud benefit related to protection and compliance, not to the capital-expenditure reduction the company wants.

592
MCQhard

A legal firm needs to automatically encrypt and apply access restrictions to all documents that contain case numbers considered highly confidential. The protection must remain enforced even if the document is emailed to external parties or saved to a personal device. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP)
B.Sensitivity Labels with encryption
C.Microsoft Purview Audit
D.Customer Lockbox
AnswerB

Sensitivity labels with encryption use Azure Rights Management to automatically encrypt a document when a label is applied, and the encryption remains attached to the file wherever it travels, including outside the tenant. The label can be configured to require automatic classification based on content conditions, so the legal firm's files are encrypted without user intervention, and the same label enforces usage restrictions like read-only or no-copy. This persistent, automatic protection directly meets the requirement for securing legal documents.

Why this answer

Sensitivity Labels with encryption are the correct solution because they allow the legal firm to classify documents containing confidential case numbers and enforce persistent protection (encryption and access restrictions) that travels with the document, even when emailed externally or saved to a personal device. This is achieved by applying Azure Rights Management (Azure RMS) encryption directly to the file, ensuring the protection is embedded in the document itself, not just at the network or service boundary.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with persistent protection, mistakenly thinking DLP can encrypt documents and enforce access controls after they leave the organization, when in fact DLP only monitors and blocks data in transit or at rest within the tenant, not after it is shared externally.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies can detect and block the sharing of sensitive data (like case numbers) but do not automatically encrypt or apply persistent access restrictions to documents; DLP operates at the transport and endpoint level to prevent data exfiltration, not to enforce ongoing protection after the document leaves the organization. Option C is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities, not automatic encryption or access control on documents. Option D is wrong because Customer Lockbox is a control that requires explicit approval for Microsoft support engineers to access customer data, and it does not provide document-level encryption or access restrictions.

593
Drag & Dropmedium

Drag and drop the steps to perform an eDiscovery content search in the Microsoft 365 compliance center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

eDiscovery content search involves creating a search, specifying locations, query, and reviewing results.

594
Multi-Selecteasy

A business wants to use a cloud solution where they can scale computing resources up or down automatically based on demand and only pay for what they use. The cloud provider manages the underlying hardware. Which two cloud characteristics are being described? (Choose two.)

Select 2 answers
A.Elasticity
B.Measured service
C.Scalability
D.High availability
AnswersA, B

Elasticity is the cloud computing characteristic that allows resources to be automatically scaled up or down in response to real-time demand. In the scenario, the business can dynamically adjust resource consumption without manual intervention, ensuring they only provision what is needed. This automatic provisioning and deprovisioning directly aligns with the definition of elasticity, which is distinct from mere scalability because it responds to fluctuations in workload instantaneously.

Why this answer

Elasticity is correct because it describes the ability to automatically scale computing resources up or down based on demand, which is a key characteristic of cloud computing. The scenario explicitly states that resources scale automatically, which aligns with elasticity rather than just the ability to scale (scalability). Measured service is correct because the business pays only for what they use, which is the pay-per-use billing model enabled by metering resource consumption.

Exam trap

The trap here is that candidates confuse scalability (the ability to scale) with elasticity (automatic scaling based on demand), and they overlook measured service as a distinct characteristic because they focus only on the scaling aspect rather than the pay-per-use billing model explicitly stated in the question.

595
MCQmedium

An organization uses Microsoft Viva Learning to provide training content. They want to ensure that only employees in the Sales department see sales-specific courses. Which feature should they use?

A.Set permissions on the SharePoint site hosting the courses.
B.Configure Viva Connections dashboard to show only Sales courses.
C.Create learning paths and assign them to the Sales department group in Viva Learning.
D.Use Viva Topics to tag courses and let users discover them.
AnswerC

Viva Learning administrators create learning paths that include the relevant courses and then assign those paths directly to the Sales department group, which is a Microsoft Entra ID security or distribution group. The assignment enforces enrollment for all members of the group, tracks progress and completion, and provides reporting for administrators, directly satisfying the requirement to deliver targeted training to the Sales department.

Why this answer

Viva Learning allows administrators to create learning paths and assign them to specific Microsoft 365 groups, such as the Sales department group. This ensures that only members of that group see the assigned sales-specific courses, providing targeted content delivery without affecting other users' views.

Exam trap

The trap here is that candidates often confuse SharePoint permissions (Option A) with Viva Learning's group-based targeting, not realizing that Viva Learning controls visibility through learning path assignments rather than underlying site permissions.

How to eliminate wrong answers

Option A is wrong because setting permissions on the SharePoint site hosting the courses would control access to the site itself, but Viva Learning aggregates content from multiple sources and permissions on the underlying SharePoint site do not directly control visibility within the Viva Learning interface; users could still see the courses listed but be denied access when trying to open them, which is not the same as controlling visibility. Option B is wrong because the Viva Connections dashboard is a personalized entry point to employee resources and news, but it does not have the capability to filter or restrict which courses appear in Viva Learning; it can surface links but cannot enforce course visibility by department. Option D is wrong because Viva Topics uses AI to automatically tag and surface knowledge content, but it is designed for discovery and knowledge management, not for controlling visibility or access to training courses; it cannot restrict who sees specific courses based on department membership.

596
MCQhard

Refer to the exhibit. An admin creates a Microsoft Purview Data Loss Prevention (DLP) policy rule as shown. When will the rule block access?

A.When a credit card number is detected with high confidence
B.When the document is shared externally
C.When any sensitive information type is detected
D.Never, because the rule is not applied to any location
AnswerA

The rule's condition evaluates the content of the inspected document and requires the Credit Card Number sensitive information type (SIT) to be matched at the High confidence level. Content that is merely similar to a card number or detected at low or medium confidence will not satisfy this threshold. Because the exhibit shows this exact condition, a high-confidence credit card number match is the only outcome that would trigger the configured DLP action.

Why this answer

The rule is configured with a condition that triggers when a credit card number is detected with a confidence level of 'high'. The action 'Block access' is set to execute when this condition is met. Therefore, the rule blocks access specifically when a credit card number is detected with high confidence, making option A correct.

Exam trap

The trap here is that candidates may assume the rule blocks access whenever a sensitive information type is detected, overlooking the specific confidence level requirement, or they might think the rule is not applied to any location without verifying the exhibit's location configuration.

How to eliminate wrong answers

Option B is wrong because the rule does not include a condition for external sharing; the condition is solely based on detecting a credit card number, not on the sharing context. Option C is wrong because the rule specifies a particular sensitive information type (credit card number) with a high confidence level, not 'any sensitive information type'. Option D is wrong because the rule is applied to locations (as indicated by the 'Locations' section in the exhibit, which is assumed to be configured, even if not fully shown), and the question states the admin creates the rule, implying it is applied to at least one location.

597
MCQmedium

A company with 500 users currently has Microsoft 365 Business Basic licenses. They need to provide all users with the desktop versions of Office apps and increase email storage to 100 GB per user. What is the most cost-effective licensing upgrade from the options below?

A.Upgrade all users to Microsoft 365 Business Standard
B.Upgrade all users to Microsoft 365 Business Premium
C.Keep Business Basic and purchase Exchange Online Plan 2 add-on for each user
D.Upgrade to Microsoft 365 E3
AnswerD

Microsoft 365 E3 is an enterprise offering that includes the full desktop Office suite (e.g., Word, Excel, PowerPoint) as well as Exchange Online Plan 2, which provides per-user mailboxes with a 100 GB storage limit. This single license simultaneously satisfies the desktop applications requirement and the 100 GB mailbox requirement for all 500 users. As such, upgrading to Microsoft 365 E3 is the correct and most straightforward solution.

Why this answer

Microsoft 365 Business Basic provides only web and mobile versions of Office apps and 50 GB of email storage. The requirement for desktop Office apps and 100 GB email storage per user is met by Microsoft 365 E3, which includes both the full desktop Office suite and Exchange Online Plan 2 (100 GB mailbox). Among the options, E3 is the most cost-effective upgrade because it bundles these features without the additional security and device management costs of Business Premium or the inefficiency of stacking add-ons on Business Basic.

Exam trap

The trap here is that candidates often assume Business Standard or Business Premium already includes 100 GB mailboxes, but they only include Exchange Online Plan 1 (50 GB), and the question specifically requires 100 GB per user, which forces the upgrade to an Enterprise plan like E3.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Standard includes desktop Office apps but only provides 50 GB of email storage per user (Exchange Online Plan 1), not the required 100 GB. Option B is wrong because Microsoft 365 Business Premium also includes only 50 GB email storage per user and adds unnecessary security and device management features that increase cost without addressing the 100 GB requirement. Option C is wrong because keeping Business Basic and adding Exchange Online Plan 2 per user would provide the 100 GB storage but still lacks desktop Office apps, requiring an additional purchase (e.g., Office 365 E1 or separate Office licenses), making it less cost-effective than a single E3 license that bundles both.

598
MCQmedium

A company wants to provide employees with a personal cloud storage solution that syncs files across devices and allows sharing with external partners. Which Microsoft 365 service should they use?

A.Exchange Online
B.OneDrive for Business
C.Microsoft Teams
D.SharePoint Online
AnswerB

OneDrive for Business provides each user with a dedicated personal library in the cloud, enabling file sync via the OneDrive client, Files On-Demand to conserve local storage, and granular sharing with individuals or groups. It supports version history, co-authoring in Office apps, and integration with Teams and SharePoint. This matches the requirement for personal cloud storage.

Why this answer

OneDrive for Business provides personal cloud storage that syncs files across devices via the OneDrive sync client and enables secure sharing with external partners through granular permission controls. This directly meets the requirement for individual file storage, cross-device synchronization, and external sharing.

Exam trap

The trap here is that candidates often confuse SharePoint Online's team-based document libraries with OneDrive for Business's personal storage, overlooking that the question explicitly asks for 'personal cloud storage' and 'syncs files across devices'—features unique to OneDrive for Business.

How to eliminate wrong answers

Option A is wrong because Exchange Online is an email and calendaring service, not a cloud storage solution; it lacks file sync and external file-sharing capabilities. Option C is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and channels, not a personal storage service; while files can be shared in Teams, it does not provide per-user personal sync storage. Option D is wrong because SharePoint Online is a document management and collaboration platform for team sites, not a personal cloud storage solution; it is designed for shared team libraries rather than individual file sync across devices.

599
MCQeasy

A help desk lead is documenting the correct Microsoft 365 approach to use hosted email without managing mail servers. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Community cloud
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerC

SaaS delivers fully hosted applications where the provider manages servers, patching and availability. Microsoft 365 email is consumed directly, so the help desk needs no mail server administration. This matches the requirement of hosted email without managing infrastructure.

Why this answer

Microsoft 365's Exchange Online delivers hosted email as a Software as a Service (SaaS) offering. This means Microsoft manages the mail servers, software updates, and infrastructure, while the help desk lead simply configures user mailboxes and policies via the admin center. SaaS is the cloud model where the provider hosts and manages the entire application, aligning perfectly with the requirement to avoid managing mail servers.

Exam trap

The trap here is that candidates confuse PaaS with SaaS because both involve managed services, but PaaS requires you to manage the application code and runtime, whereas SaaS delivers a fully finished application like Exchange Online, eliminating all server management tasks.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) provides a runtime environment for deploying custom applications, not a ready-to-use hosted email service; you would still need to build and manage the email application code. Option B is wrong because Community cloud is a deployment model where infrastructure is shared among several organizations with common concerns (e.g., compliance), not a service model that delivers hosted email without server management. Option D is wrong because Infrastructure as a Service (IaaS) provides virtualized servers, storage, and networking, requiring the customer to install, configure, and manage the email server software (e.g., Exchange Server) themselves, which contradicts the 'without managing mail servers' requirement.

600
MCQmedium

An HR manager needs to collect employee feedback on a new policy. They want to create a short survey that anonymizes responses and provides automatic charts summarizing the results. Which Microsoft 365 app is best suited for this task?

A.Microsoft Lists
B.Microsoft Forms
C.Microsoft Sway
D.Microsoft Excel
AnswerB

Microsoft Forms is purpose-built for creating surveys and questionnaires with multiple question types (choice, rating, text), branching, and anonymous response options. It automatically compiles responses into real-time summary charts, supports exporting results to Excel, and can be embedded in Teams or SharePoint, making it the ideal tool for an HR manager to efficiently gather and analyze feedback.

Why this answer

Microsoft Forms is the correct choice because it is specifically designed for creating surveys and quizzes with built-in anonymous response settings and automatic chart generation. The HR manager can enable 'Record name' to be off for anonymity, and Forms automatically visualizes results with pie charts, bar graphs, and summary data without manual setup.

Exam trap

The trap here is that candidates may confuse Microsoft Lists as a survey tool because it can collect data via forms, but Lists lacks anonymous response settings and automatic charting, which are core to Forms.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data tracking and organization app for managing structured information like inventory or issues, not for creating surveys with automatic chart summaries. Option C is wrong because Microsoft Sway is a digital storytelling and presentation tool for interactive reports and newsletters, lacking survey creation and anonymous response collection. Option D is wrong because Microsoft Excel is a spreadsheet application that requires manual data entry and chart creation, and it does not natively support anonymous survey distribution or automatic result visualization.

Page 7

Page 8 of 11

Page 9

All pages