Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 601–675

794 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
Multi-Selectmedium

Which THREE of the following are valid data subject rights under GDPR? (Choose three.)

Select 3 answers
A.Right to data portability
B.Right to erasure (right to be forgotten)
C.Right of access
D.Right to perpetual storage
E.Right to monetization of data
AnswersA, B, C

The right to data portability lets a data subject receive personal data they provided in a structured, commonly used, machine-readable format and transmit it to another controller. It is an enumerated GDPR right, satisfying the question's requirement.

Why this answer

Under GDPR, Article 20 grants the Right to data portability (A), allowing data subjects to receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller. Article 17 establishes the Right to erasure, also known as the right to be forgotten (B), enabling individuals to request deletion of personal data under specified conditions. Article 15 provides the Right of access (C), giving data subjects the ability to obtain confirmation of whether their data is processed and access to that data plus related information.

Options D and E are not GDPR rights: the regulation instead embodies storage limitation (Article 5(1)(e)), which discourages perpetual storage, and it does not grant a right to monetize one's data.

Exam trap

MS-900 often tests whether candidates confuse GDPR data-subject rights with general data-handling practices, luring them toward plausible-sounding but non-existent rights like 'perpetual storage' or 'monetization'.

602
MCQmedium

Your company has 50 users on Microsoft 365 Business Premium. You need to provide phone system and audio conferencing capabilities. What should you do?

A.Purchase Microsoft 365 Business Voice
B.Purchase a Microsoft 365 Calling Plan subscription for each user
C.Upgrade all users to Microsoft 365 E5
D.Add the Phone System and Audio Conferencing add-ons to the existing Business Premium licenses
AnswerD

For Microsoft 365 Business Premium, Phone System and Audio Conferencing are first-party per-user add-ons that can be directly attached to the tenant's existing base licenses. Phone System supplies the cloud PBX features for call control and routing, while Audio Conferencing enables external dial-in to Teams meetings, together satisfying the stated requirement without changing the base SKU or requiring any minimum seat upgrade.

Why this answer

Microsoft 365 Business Premium includes the rights to add Phone System and Audio Conferencing as add-ons. Option D is correct because you simply purchase the Phone System and Audio Conferencing add-on licenses for each user who needs those capabilities, without changing the base subscription. This is the most cost-effective and straightforward path to enable PSTN calling and dial-in conferencing for Business Premium users.

Exam trap

The trap here is that candidates often confuse the need for a Calling Plan with the Phone System and Audio Conferencing capabilities, or they mistakenly think Business Voice is still available, when in fact the correct path is to add the Phone System and Audio Conferencing add-ons to the existing Business Premium licenses.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Voice was a legacy bundle that has been retired; it is no longer available for purchase. Option B is wrong because a Calling Plan subscription is an add-on that requires the Phone System license first; you cannot purchase a Calling Plan alone without first having Phone System assigned. Option C is wrong because upgrading all users to Microsoft 365 E5 is unnecessary and more expensive; Business Premium already includes the rights to add Phone System and Audio Conferencing as add-ons, so a full E5 upgrade is overkill.

603
Multi-Selecthard

Which THREE Microsoft 365 services are part of the Microsoft Viva employee experience platform?

Select 3 answers
A.Viva Insights
B.Microsoft SharePoint
C.Viva Connections
D.Microsoft Teams
E.Viva Learning
AnswersA, C, E

Viva Insights is one of the Microsoft Viva modules, delivering productivity and wellbeing analytics to individuals, managers and leaders within Microsoft Teams and the Viva suite. It forms part of the employee experience platform alongside Connections, Learning and Topics.

Why this answer

Viva Insights (A) is a core Microsoft Viva module that uses Workplace Analytics and MyAnalytics data to surface productivity, wellbeing, and collaboration insights within Microsoft 365. Viva Connections (C) is the Viva gateway experience that surfaces company news, resources, and communities through a Teams app and SharePoint home site. Viva Learning (E) is the Viva module that aggregates learning content from LinkedIn Learning, Microsoft Learn, and third-party providers directly into the flow of work.

SharePoint (B) and Microsoft Teams (D) are underlying Microsoft 365 services that Viva builds upon and integrates with, but they are not themselves Viva modules.

Exam trap

MS-900 often tests whether candidates can distinguish Viva modules from the underlying Microsoft 365 services (Teams, SharePoint) that host or power them, causing them to select platform services instead of Viva-branded modules.

604
Multi-Selecteasy

Which two statements correctly describe SaaS in a cloud computing model? (Choose 2.)

Select 2 answers
A.Users access a complete application provided by the cloud service provider.
B.The provider manages the underlying infrastructure and application platform.
C.Customers manage the operating system patching.
D.Customers deploy their own runtime environment.
AnswersA, B

In SaaS, the cloud service provider delivers a finished, functional application to end users over the internet, typically through a web browser or thin client. Users do not install, deploy, or host the software on their own devices or servers; they simply consume the hosted application and its features. This is the defining characteristic of the SaaS model, as the customer sees only the application interface and data, not the underlying stack.

Why this answer

In the SaaS model, users access a complete application—such as Microsoft 365—that is hosted and managed entirely by the cloud service provider. The provider handles all aspects of the application, including availability, performance, and security, while the user simply consumes the software via a web browser or client. This aligns with the NIST definition of SaaS, where the consumer does not manage or control the underlying cloud infrastructure or even individual application capabilities.

Exam trap

The trap here is that candidates confuse SaaS with PaaS or IaaS, mistakenly thinking customers are responsible for OS patching (Option C) or deploying their own runtime (Option D), when in fact SaaS abstracts all underlying layers away from the consumer.

605
MCQmedium

A consulting firm needs a tool to allow customers to schedule appointments with specific consultants online. The tool must show available time slots, send confirmation emails, and allow customers to reschedule. Which Microsoft 365 app should they use?

A.Microsoft Bookings
B.Microsoft Forms
C.Microsoft To Do
D.Microsoft Planner
AnswerA

Microsoft Bookings is a Microsoft 365 scheduling tool that provides a customer-facing booking page where clients can choose from available time slots based on the consultant's calendar. It automatically manages appointment confirmations, rescheduling, and cancellations, and syncs with Exchange Online to prevent double-booking. Bookings also supports virtual appointments through Teams, making it the correct choice for a consulting firm's scheduling needs.

Why this answer

Microsoft Bookings is the correct app because it is specifically designed for scheduling appointments, showing real-time availability of staff, sending automated confirmation and reminder emails, and allowing customers to self-manage rescheduling or cancellations. It integrates with Exchange Online for calendar synchronization and Teams for virtual meetings, meeting all stated requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Bookings with Microsoft Forms or Planner, assuming any Microsoft 365 app with a calendar or task feature can handle scheduling, but only Bookings provides the dedicated customer-facing booking page and automated confirmation workflow required for external appointment management.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a scheduling system; it cannot show available time slots or send confirmation emails for appointments. Option C (Microsoft To Do) is wrong because it is a personal task management app focused on to-do lists and reminders, lacking any scheduling or customer-facing booking capabilities. Option D (Microsoft Planner) is wrong because it is a project management tool for team task boards and plans, not designed for external customer appointment scheduling or time slot management.

606
MCQmedium

A company wants to ensure that sensitive documents in Microsoft SharePoint Online are automatically classified and protected when they contain credit card numbers. Which Microsoft 365 service should they use?

A.Microsoft Purview Compliance Manager
B.Microsoft Purview Audit
C.Microsoft Purview Insider Risk Management
D.Microsoft Purview Information Protection
AnswerD

Microsoft Purview Information Protection delivers automatic classification by using content inspection and pattern detection to identify sensitive data types, such as credit card numbers or national identity numbers, and then applies sensitivity labels automatically without manual intervention. These labels can encrypt, restrict access, or add visual markings, ensuring that sensitive documents are consistently protected across the tenant. This is the correct solution because it directly addresses the requirement to ensure that sensitive documents are automatically classified.

Why this answer

Microsoft Purview Information Protection (D) enables organizations to automatically classify and protect sensitive documents based on data classification rules. By configuring a sensitive information type for credit card numbers, SharePoint Online can apply sensitivity labels or retention labels to documents containing that pattern, ensuring they are encrypted or restricted as defined by policy.

Exam trap

The trap here is that candidates may confuse Compliance Manager (a compliance posture dashboard) with the actual data classification and protection service, or assume Insider Risk Management handles content classification when it is actually focused on user behavior analytics.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance score tool, not a data classification or protection engine; it does not automatically classify or protect documents based on content. Option B is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities, not automated classification or protection of sensitive data. Option C is wrong because Microsoft Purview Insider Risk Management focuses on detecting risky user behaviors (e.g., data exfiltration) through analytics and policies, not on automatically classifying or protecting documents based on content patterns like credit card numbers.

607
MCQeasy

A healthcare organization stores patient records in SharePoint Online. They need to ensure that the data is encrypted at rest and in transit. Which statement is true regarding Microsoft 365 encryption?

A.Microsoft provides default encryption for data at rest and in transit.
B.Customers must enable encryption at rest manually for each workload.
C.Encryption only applies to Exchange Online, not SharePoint or OneDrive.
D.Encryption is optional and can be turned off if a customer chooses.
AnswerA

Microsoft applies encryption automatically, without requiring any customer configuration. Data at rest, including SharePoint patient records, is protected with BitLocker disk encryption and Storage Service Encryption, while data in transit is secured with industry-standard TLS 1.2+ protocols. These default protections cover every Microsoft 365 workload, so encryption is always on from the moment data is written.

Why this answer

Microsoft 365 provides default encryption for data at rest and in transit across all workloads, including SharePoint Online, Exchange Online, and OneDrive for Business. For data at rest, Microsoft uses BitLocker Drive Encryption and service-side encryption with per-file keys, while data in transit is secured using TLS 1.2+ and IPSec. This means the healthcare organization's patient records in SharePoint Online are automatically encrypted without any manual configuration.

Exam trap

The trap here is that candidates often assume encryption must be manually configured or is optional, but Microsoft 365 enforces encryption by default across all workloads, and customers cannot disable it.

How to eliminate wrong answers

Option B is wrong because encryption at rest is enabled by default for all Microsoft 365 workloads, including SharePoint Online, and does not require manual enablement per workload. Option C is wrong because encryption applies to all Microsoft 365 services, not just Exchange Online; SharePoint Online and OneDrive for Business also use BitLocker and service-side encryption for data at rest and TLS for data in transit. Option D is wrong because encryption is mandatory and cannot be turned off by customers; Microsoft enforces encryption as a core security feature to protect data.

608
Multi-Selectmedium

A company is planning to migrate its collaboration tools to Microsoft 365. They need a solution for real-time document co-authoring, instant messaging, and video conferencing, all in one integrated platform. Which two Microsoft 365 services should they use? (Choose two.)

Select 2 answers
A.Microsoft SharePoint
B.Microsoft Teams
C.Microsoft OneDrive
D.Microsoft Stream
AnswersA, B

Correct. Microsoft SharePoint provides cloud-based team sites that act as a central document repository, with version history, metadata, and permission controls. Real-time co-authoring in SharePoint allows multiple users to edit the same document simultaneously in a browser, making it a core collaboration workload rather than merely storage. For an organization migrating collaboration tools, SharePoint Online is the backbone for structured file sharing and intranet portals.

Why this answer

Microsoft SharePoint is correct because it provides the document storage and versioning infrastructure that enables real-time co-authoring of documents (e.g., Word, Excel, PowerPoint) via the Office Online Server integration. Microsoft Teams is correct because it integrates instant messaging, persistent chat, and video conferencing (using the underlying Skype for Business Online technology) with SharePoint and OneDrive for seamless file sharing and co-authoring within the same interface.

Exam trap

The trap here is that candidates often confuse OneDrive for Business (a personal sync tool) with SharePoint (a team-based document management platform), or they assume Microsoft Stream provides live video conferencing, when in fact Stream is for recorded video management and Teams handles live meetings.

609
MCQmedium

A user reports receiving a phishing email that bypassed Exchange Online Protection (EOP). You need to investigate the threat and automate a response across email, endpoints, and identities. Which Microsoft 365 security solution should you use?

A.Microsoft Sentinel
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Defender XDR
AnswerD

Microsoft Defender XDR (formerly Microsoft 365 Defender) unifies signals from Defender for Office 365, Defender for Endpoint, Defender for Identity, and Microsoft Purview into a single incident model. It automatically correlates a phishing email with subsequent endpoint compromises and identity anomalies, then executes built-in automated response actions such as quarantining email, isolating devices, or disabling accounts. This native cross-domain correlation and automated remediation make it the correct primary solution for a phishing email that bypassed email protection and may have impacted multiple domains.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that correlates signals across email, endpoints, and identities. When a phishing email bypasses Exchange Online Protection (EOP), Defender XDR can automatically trigger an investigation and response (e.g., remediating the email, isolating the affected endpoint, and resetting the compromised user's credentials) through its automated incident response and playbooks, leveraging data from Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID Protection.

Exam trap

The trap here is that candidates often pick Microsoft Defender for Office 365 (Option B) because the question mentions a phishing email, but they overlook the requirement to automate a response across email, endpoints, and identities, which only a cross-domain solution like Defender XDR can fulfill.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) solution that ingests logs from multiple sources for threat detection and manual response, but it does not natively provide automated, cross-domain response actions across email, endpoints, and identities without custom playbooks and connectors. Option B is wrong because Microsoft Defender for Office 365 focuses specifically on email and collaboration threats (e.g., phishing, malware in attachments) and can remediate email-level incidents, but it lacks native capabilities to automate responses across endpoints and identities. Option C is wrong because Microsoft Defender for Endpoint is designed for endpoint detection and response (EDR) on devices, handling malware, fileless attacks, and behavioral threats, but it does not extend automated response to email or identity domains.

610
MCQmedium

A business stakeholder asks how Microsoft 365 can help them allow sign-in using biometrics or FIDO2 security keys. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Entra ID passwordless authentication
C.Microsoft Stream
D.Microsoft Forms
AnswerB

Microsoft Entra ID passwordless authentication directly satisfies the biometrics and FIDO2 requirement. It supports Windows Hello biometrics and FIDO2 security keys through the WebAuthn standard, replacing passwords entirely. This maps precisely to the stakeholder's stated sign-in methods, unlike other Microsoft 365 capabilities that address different security or compliance concerns.

Why this answer

Microsoft Entra ID passwordless authentication (Option B) is the correct capability because it directly supports sign-in using biometrics (Windows Hello, Microsoft Authenticator) and FIDO2 security keys. This feature eliminates the need for passwords by leveraging public-key cryptography and the WebAuthn standard, aligning with the stakeholder's request for passwordless sign-in methods.

Exam trap

The trap here is that candidates may confuse productivity tools (Planner, Stream, Forms) with identity and access management capabilities, failing to recognize that passwordless authentication is a core feature of Microsoft Entra ID, not a standalone app.

How to eliminate wrong answers

Option A (Microsoft Planner) is wrong because it is a task management and project planning tool, not an identity or authentication service. Option C (Microsoft Stream) is wrong because it is a video sharing and management platform, unrelated to authentication mechanisms. Option D (Microsoft Forms) is wrong because it is a survey and data collection tool, with no capability to handle biometric or FIDO2 sign-in.

611
Multi-Selectmedium

Which TWO Microsoft 365 services can be used to create and manage corporate training content and track employee completion?

Select 2 answers
A.Microsoft Viva Learning
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft To Do
E.SharePoint Online
AnswersA, E

Microsoft Viva Learning is a centralized learning hub integrated directly into Microsoft Teams and the Viva suite. It aggregates content from LinkedIn Learning, Microsoft Learn, and custom organizational materials, allowing L&D administrators to create learning paths, assign courses, and track employee completion. This makes it a purpose-built service for creating and managing structured training programs across the organization.

Why this answer

Microsoft Viva Learning (A) is a centralized learning hub within Microsoft Teams that allows organizations to create, assign, and track corporate training content from internal sources (like SharePoint) and external providers (like LinkedIn Learning). SharePoint Online (E) enables the creation and management of training materials as documents, pages, or custom learning portals, and can integrate with Viva Learning to track employee completion via list-based progress tracking or Power Automate workflows.

Exam trap

The trap here is that candidates often confuse Microsoft Forms (a simple quiz tool) or Microsoft Stream (a video platform) with having built-in training management capabilities, when in fact they lack the assignment and completion tracking features required for corporate training.

612
MCQeasy

A cloud provider allows customers to provision virtual machines, storage, and other resources through a web portal without requiring human interaction with the provider's staff. Which cloud computing characteristic does this best illustrate?

A.Rapid elasticity
B.Measured service
C.Resource pooling
D.On-demand self-service
AnswerD

On-demand self-service is the cloud characteristic that lets a consumer unilaterally provision computing capabilities—such as virtual machines, storage, and databases—automatically, using a self-service interface like a web portal, CLI, or REST API, with no human interaction with the cloud provider. In the question's scenario, the customer directly requests and configures a VM and receives it without waiting for an administrator, which is precisely the definition of this capability. It is a foundational trait that distinguishes cloud computing from traditional IT operations, where provisioning requires a service desk ticket and human approval.

Why this answer

The scenario describes a user provisioning resources through a web portal without any human interaction from the provider. This directly matches the NIST SP 800-145 definition of on-demand self-service, where a consumer can unilaterally provision computing capabilities as needed automatically without requiring human interaction with each service provider.

Exam trap

The trap here is that candidates confuse the 'self-service' aspect of provisioning with 'rapid elasticity' because both involve speed, but the question specifically highlights the lack of human interaction, which is the defining feature of on-demand self-service, not the scaling behavior.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to quickly scale resources up or down, often automatically, not the method of provisioning without human contact. Option B is wrong because measured service involves monitoring, controlling, and reporting resource usage for billing and optimization, not the self-provisioning capability. Option C is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple consumers, not the consumer's ability to provision without staff interaction.

613
Multi-Selecteasy

Which TWO Microsoft 365 apps are part of the Microsoft Viva suite?

Select 2 answers
A.Microsoft Viva Insights
B.Microsoft Teams
C.Microsoft SharePoint
D.Microsoft Viva Connections
E.Microsoft Power BI
AnswersA, D

Microsoft Viva Insights is a productivity and wellbeing app that uses Microsoft 365 data (calendar, email, chats, and meetings) to give employees personalized recommendations for focus time, meeting habits, and work-life balance. It is one of the core experiences in the Viva platform, alongside Viva Connections, Topics, Learning, and Goals. Unlike Teams or SharePoint, it is explicitly branded and sold as a Viva module and does not exist as a standalone collaboration or content service.

Why this answer

Microsoft Viva Insights is correct because it is a core component of the Microsoft Viva employee experience platform, providing personalized wellbeing, productivity, and collaboration analytics derived from Microsoft 365 data. It uses signals from emails, meetings, and chats to deliver actionable insights to individuals, managers, and leaders.

Exam trap

The trap here is that candidates often confuse the host platform (Microsoft Teams) or supporting services (SharePoint, Power BI) with the actual Viva suite components, leading them to select those as Viva apps instead of the dedicated Viva modules.

614
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to view usage reports without changing configuration. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Microsoft Forms
D.Reports Reader
AnswerD

The Reports Reader role grants read-only access to Microsoft 365 usage and activity reports in the admin centre, satisfying the constraint of viewing reports without altering tenant configuration. It carries no write permissions, so the help desk lead can inspect adoption data while configuration remains untouched.

Why this answer

The Reports Reader role in Microsoft 365 is specifically designed to allow users to view usage reports and adoption metrics without requiring any administrative permissions or configuration changes. This role provides read-only access to the Reports section in the Microsoft 365 admin center, enabling help desk leads to monitor usage data without altering settings or licensing. The other options (Whiteboard, Stream, Forms) are unrelated to viewing usage reports.

Exam trap

The trap here is that candidates may confuse the Reports Reader role with other Microsoft 365 services (like Stream or Forms) that have 'reporting' features in their own context, but only the Reports Reader role provides tenant-wide usage report access without configuration changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a reporting or admin role, and it does not provide access to usage reports. Option B is wrong because Microsoft Stream is a video service for recording and sharing videos, and it lacks any built-in capability to view Microsoft 365 usage reports without additional configuration. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, and it cannot be used to access or view tenant-level usage reports from the admin center.

615
Multi-Selectmedium

A healthcare organization must encrypt outbound email automatically when a message contains passport numbers. Which two Microsoft Purview capabilities are commonly combined? (Choose two.)

Select 2 answers
A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.Microsoft Purview Message Encryption
D.Microsoft Viva Engage
AnswersB, C

Data Loss Prevention (DLP) is the foundational capability for identifying sensitive information, such as passport numbers, within outbound email. DLP policies are precisely configured to automatically detect these specific content types using built-in or custom sensitive information types. Upon detection, a pre-defined action, such as applying encryption to the email, is automatically triggered. This directly satisfies the requirement to encrypt outbound email when a message contains passport numbers.

Why this answer

Data Loss Prevention (DLP) is the correct answer because it provides the policy engine that detects sensitive information, such as passport numbers, in outbound email. When a DLP rule matches, it can trigger automatic encryption of the message using Microsoft Purview Message Encryption, ensuring the email is protected before leaving the organization.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Message Encryption as a standalone solution, forgetting that it requires a DLP policy to automatically detect and trigger the encryption action.

616
MCQmedium

A department asks for the Microsoft 365 service best suited for task tracking using boards and buckets. Which service should they use?

A.Microsoft Defender for Endpoint
B.Microsoft Planner
C.Microsoft Entra Privileged Identity Management
D.Microsoft Purview Compliance Manager
AnswerB

Microsoft Planner provides task tracking through boards, buckets and cards, matching the department's stated requirement exactly. It is included with most Microsoft 365 licences, so no additional purchase is needed for planning work visually across a team.

Why this answer

Microsoft Planner is the correct service because it provides task tracking using boards and buckets, which are core features of its Kanban-style project management interface. This aligns directly with the department's request for organizing tasks visually, making it the appropriate Microsoft 365 app for lightweight project coordination.

Exam trap

The trap here is that candidates may confuse Microsoft Planner with Microsoft To Do or Microsoft Project, but Planner is specifically designed for team-based task tracking with boards and buckets, whereas To Do is for personal task lists and Project is for complex project management.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, not a task management tool. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring access to privileged roles in Azure AD, not for task tracking. Option D is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessing and managing regulatory compliance risks, not for organizing tasks with boards and buckets.

617
MCQmedium

A company needs to ensure that their cloud data and applications remain available even if an entire Azure region experiences an outage. They also want to minimize latency by hosting resources in multiple geographic locations. Which cloud concept addresses these requirements?

A.Scalability
B.Geo-redundancy
C.Measured service
D.Resource pooling
AnswerB

Geo-redundancy stores synchronous or asynchronous copies of data in a secondary Azure region, commonly a paired region, and automatically fails over or permits customer-triggered failover when the primary region becomes unavailable. Azure Storage geo-redundant storage (GRS) and geo-zone-redundant storage (GZRS) maintain a second copy hundreds of miles away, while read-access geo-redundant storage (RA-GRS) additionally lets applications read from the secondary region, improving availability and lowering latency for nearby users.

Why this answer

Geo-redundancy (Option B) is correct because it specifically addresses the requirement for data and application availability during an entire Azure region outage by replicating resources across multiple geographically separated regions, such as Azure paired regions (e.g., East US and West US). This also minimizes latency by allowing traffic to be routed to the nearest available region, leveraging Azure Traffic Manager or Azure Front Door for global load balancing.

Exam trap

The trap here is that candidates often confuse geo-redundancy with high availability within a single region (e.g., Availability Zones) or mistakenly think scalability or resource pooling can provide region-level disaster recovery, but only geo-redundancy ensures data and app availability across entire regions.

How to eliminate wrong answers

Option A is wrong because scalability refers to the ability to increase or decrease resources (e.g., compute or storage) to handle demand, not to maintain availability during a region-wide outage or to reduce latency across geographic locations. Option C is wrong because measured service is a cloud characteristic where usage is metered and billed (e.g., pay-as-you-go), which does not address disaster recovery or geographic latency. Option D is wrong because resource pooling describes the multi-tenant model where provider resources are shared among customers (e.g., Azure's hypervisor isolation), not the replication of data across regions for high availability.

618
MCQmedium

A business stakeholder asks how Microsoft 365 can help them desktop Office apps plus business email and collaboration services without advanced security management. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft 365 Business Standard
D.Microsoft Whiteboard
AnswerC

Microsoft 365 Business Standard bundles the desktop Office apps with Exchange Online business email and Teams collaboration, matching the stated requirement. It deliberately omits advanced security management capabilities such as Defender for Office 365 P2 and Entra ID P1, so it satisfies the constraint without over-provisioning.

Why this answer

Microsoft 365 Business Standard is the correct licensing plan because it includes desktop versions of Office apps (e.g., Word, Excel, PowerPoint), business-class email via Exchange Online, and collaboration services like Microsoft Teams and SharePoint—all without requiring advanced security management features such as Microsoft Defender for Office 365 or Azure Information Protection. This plan is designed for businesses that need core productivity and communication tools without the complexity of enterprise-grade security controls.

Exam trap

The trap here is that candidates may confuse individual service names (like Stream, Forms, or Whiteboard) with licensing plans, failing to recognize that only a subscription plan like Business Standard bundles desktop Office apps, email, and collaboration services together.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing service within Microsoft 365, not a licensing plan that provides desktop Office apps, email, or collaboration services. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, not a licensing plan that bundles desktop Office apps, email, or collaboration services. Option D is wrong because Microsoft Whiteboard is a digital canvas for collaboration, not a licensing plan that includes desktop Office apps, business email, or collaboration services.

619
MCQeasy

A small marketing agency uses Microsoft 365 Business Basic. They want to enable real-time co-authoring of Word, Excel, and PowerPoint documents stored in SharePoint Online and OneDrive for Business, and ensure that multiple users can edit the same document simultaneously. Which Microsoft 365 service should they use?

A.OneDrive for Business
B.Microsoft Teams
C.Office for the web
D.SharePoint Online
AnswerC

Office for the web (formerly Office Online) provides browser-based versions of Word, Excel, and PowerPoint that support real-time co-authoring. Users can edit documents stored in SharePoint Online and OneDrive for Business simultaneously, seeing each other's changes in real time. This is included in Microsoft 365 Business Basic and meets the requirement without requiring desktop app installations.

Why this answer

Office for the web provides browser-based Word, Excel, and PowerPoint with real-time co-authoring capabilities, included in Microsoft 365 Business Basic. Teams, SharePoint, and OneDrive are collaboration and storage services that integrate with Office but do not themselves provide the document editing experience required for simultaneous editing.

Exam trap

The trap here is thinking that SharePoint Online or OneDrive for Business enables co-authoring directly, when they are storage platforms and the actual editing is done through Office for the web or desktop apps.

620
MCQhard

An organization wants to prevent employees from sharing sensitive files with external users via SharePoint Online, but they need to allow sharing with a specific external partner for a single project. What is the most efficient configuration?

A.Disable external sharing at the tenant level and enable it only for the specific project site
B.Change the default sharing link type to 'Specific people' and add the partner's domain to an allow list
C.Apply sensitivity labels with encryption to all files
D.Configure a DLP policy to block external sharing except for the partner domain
AnswerA

Disabling external sharing at the tenant level in the SharePoint admin center (under Policies > Sharing) establishes a baseline that blocks all external sharing by default. Enabling it only for the specific project site via site-level sharing settings grants a granular exception, so the partner can access that site while all other sites remain locked down. This layered configuration directly enforces the requirement, as tenant settings are inherited unless explicitly overridden for the chosen site collection.

Why this answer

It allows the organization to disable external sharing globally at the tenant level via the SharePoint admin center, which prevents all users from sharing with external users by default. Then, by enabling external sharing only for the specific project site (site-level override), the organization can grant the necessary access to the external partner while maintaining the broad restriction. This is the most efficient approach because it uses a single configuration change at the tenant level and a targeted exception at the site level, avoiding complex policies or labels.

Exam trap

The trap here is that candidates often confuse DLP policies or sensitivity labels as the primary method to control sharing, when in fact SharePoint sharing settings at the tenant and site level are the direct and most efficient configuration for this scenario.

How to eliminate wrong answers

Option B is wrong because changing the default sharing link type to 'Specific people' does not block external sharing; it only changes the default link behavior, and adding the partner's domain to an allow list (via cross-tenant access settings) still permits external sharing broadly, not just for the single project. Option C is wrong because applying sensitivity labels with encryption protects files but does not prevent sharing; users can still share encrypted files with external users, and encryption does not enforce sharing restrictions. Option D is wrong because configuring a DLP policy to block external sharing except for the partner domain is overly complex and less efficient; DLP policies are designed for data loss prevention (e.g., blocking sensitive info in emails or documents) and are not the primary tool for controlling SharePoint sharing settings, which are managed via sharing permissions.

621
MCQmedium

A helpdesk team needs to provide remote assistance to users by viewing and controlling their Windows devices. Which Microsoft 365 service enables this?

A.Microsoft Teams screen sharing
B.Windows 365
C.Microsoft Quick Assist
D.Microsoft Intune Remote Help
AnswerD

Intune Remote Help is the correct solution because it provides secure, policy-compliant remote view and full control capabilities specifically for devices enrolled in Microsoft Intune. It uses Azure AD for authentication and supports role-based access control, session auditing, and elevated privilege prompts, giving the helpdesk the management integration and oversight required for enterprise remote assistance.

Why this answer

Remote Help via Intune allows support personnel to remotely view and control devices. Teams screen sharing is less secure. Quick Assist is not integrated.

Windows 365 is a cloud PC.

622
MCQmedium

Contoso has Microsoft 365 E3 and a hybrid identity environment with Microsoft Entra Connect. Security policy requires that when a user's on-premises Active Directory account is disabled, their Microsoft 365 access must stop within minutes without an administrator manually touching the cloud account. Which Microsoft 365 capability should you rely on to meet this requirement?

A.Microsoft Entra ID Protection risk-based sign-in policies
B.Microsoft Entra Connect sync of the on-premises accountEnabled attribute
C.Microsoft 365 Apps sign-in restrictions configured by using Group Policy
D.Conditional Access policies requiring compliant devices
AnswerB

Microsoft Entra Connect synchronizes the on-premises userAccountControl/accountEnabled state to Microsoft Entra ID, so disabling the on-premises account marks the cloud account as blocked for sign-in on the next sync cycle. Because default sync runs every 30 minutes, access stops within minutes rather than requiring manual cloud changes, which is exactly what the policy demands.

Why this answer

The requirement is that disabling the authoritative on-premises account must propagate to the cloud quickly. Microsoft Entra Connect continuously synchronizes the accountEnabled state from Active Directory to Microsoft Entra ID, so the next delta sync blocks cloud sign-in without administrator intervention. Controls such as risk policies, device compliance, or client-side Group Policy evaluate other signals and never look at the source AD account status.

Exam trap

The trap here is assuming that disabling an account in on-premises Active Directory immediately blocks every Microsoft 365 service, when the effect actually depends on the directory synchronization cycle.

623
MCQmedium

A hospital uses Microsoft 365 and wants to enable secure messaging between doctors and nurses that supports compliance with health data regulations. Which Microsoft 365 service provides encrypted, compliant messaging?

A.Microsoft Yammer
B.Microsoft Teams
C.Microsoft Viva
D.Microsoft Bookings
AnswerB

Microsoft Teams is the correct choice because it provides secure, persistent chat in both one-on-one and channel contexts, with all messages encrypted in transit (TLS) and at rest (AES-256). Its conversation history is stored in Exchange Online mailboxes and SharePoint, enabling compliance features like retention, legal hold, eDiscovery, and communication compliance through Microsoft Purview. For healthcare scenarios, Teams can be configured with DLP policies and sensitivity labels to help meet HIPAA requirements, making it a robust secure messaging solution that Yammer, Viva, and Bookings cannot match.

Why this answer

Microsoft Teams supports encrypted messaging and compliance with health data regulations like HIPAA through features such as data encryption at rest and in transit, Data Loss Prevention (DLP) policies, and eDiscovery. It provides secure communication channels for healthcare professionals while meeting regulatory requirements for protected health information (PHI).

Exam trap

The trap here is that candidates may confuse Microsoft Teams with Yammer as both are communication tools, but Yammer lacks the compliance and encryption features required for regulated health data messaging.

How to eliminate wrong answers

Option A is wrong because Microsoft Yammer is an enterprise social network focused on broad organizational communication and lacks the granular compliance controls (e.g., DLP, eDiscovery, retention policies) needed for secure, regulated messaging in healthcare. Option C is wrong because Microsoft Viva is an employee experience platform that integrates with Microsoft 365 and third-party tools for insights, learning, and wellbeing, but it does not provide native messaging or encrypted communication capabilities. Option D is wrong because Microsoft Bookings is a scheduling and appointment management tool, not a messaging service, and does not offer encrypted, compliant messaging features.

624
Multi-Selecteasy

A company uses a cloud service where they pay only for the compute hours their virtual machines run. They can increase or decrease the number of VMs instantly based on demand. Which two cloud computing characteristics are demonstrated? (Choose two.)

Select 2 answers
A.On-demand self-service
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswersB, C

Rapid elasticity is the cloud characteristic that enables resources to be provisioned and released elastically, often automatically, to scale outward and inward commensurate with demand. In this scenario, the company's ability to increase or decrease the number of virtual machines based on demand is a textbook example of rapid elasticity, as it directly addresses the agility and scalability of resource allocation. This elasticity is what allows the company to align its resource usage with actual workload, rather than over-provisioning for peak demand.

Why this answer

B is correct because rapid elasticity allows the company to instantly increase or decrease the number of virtual machines based on demand, scaling resources up or down automatically. C is correct because measured service ensures that the company pays only for the compute hours their VMs run, with usage metered and billed accordingly.

Exam trap

The trap here is that candidates often confuse 'on-demand self-service' with the ability to instantly scale resources, but on-demand self-service specifically refers to the user's ability to provision resources without provider intervention, not the elasticity of scaling.

625
MCQeasy

A marketing team needs to create a slide-based presentation that includes charts copied from an Excel spreadsheet and animated transitions. They also require the ability to collaborate in real-time with remote colleagues. Which Microsoft 365 app should they use?

A.Word
B.Excel
C.PowerPoint
D.Sway
AnswerC

Microsoft PowerPoint is the purpose-built presentation application in Microsoft 365, offering a slide-based canvas with slide masters, layouts, themes, and tools for embedding charts, images, video, and tables. It includes advanced animation and transition controls, rehearsal and presenter-coach features, and real-time co-authoring via OneDrive or SharePoint. This makes PowerPoint the correct tool for creating and delivering a traditional slide-based presentation, as it directly supports the team's need.

Why this answer

PowerPoint is the correct choice because it is specifically designed for creating slide-based presentations with rich media, including charts copied from Excel and animated transitions. It also supports real-time co-authoring via OneDrive or SharePoint, enabling multiple remote colleagues to edit simultaneously.

Exam trap

The trap here is that candidates may confuse Sway as a presentation tool because it can create visually rich content, but it is not a slide-based presentation app and lacks the specific features (animated transitions, real-time co-authoring) that PowerPoint provides for this scenario.

How to eliminate wrong answers

Option A is wrong because Word is a word-processing app for documents, not slide-based presentations, and lacks native support for animated transitions between slides. Option B is wrong because Excel is a spreadsheet app for data analysis and charting, but it cannot create slide-based presentations or apply slide transitions. Option D is wrong because Sway is a digital storytelling app for interactive web-based reports, not traditional slide-based presentations, and it does not support animated transitions or real-time co-authoring in the same way as PowerPoint.

626
MCQeasy

An administrator is reviewing a request from users who need to avoid buying servers upfront and pay monthly based on usage. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Operational expenditure (OpEx) model
D.Microsoft Planner
AnswerC

The operational expenditure (OpEx) model charges for cloud solutions on a subscription or pay-as-you-go basis, so organizations pay a recurring fee for capacity instead of making a large upfront capital investment in hardware. Microsoft 365, for example, typically costs per user per month, covering licensing, maintenance, and infrastructure. This approach directly aligns with the users' need to avoid buying servers because it converts fixed capital expenditure into variable operating expenses that scale with actual usage.

Why this answer

The requirement to avoid upfront server purchases and pay monthly based on usage directly aligns with the operational expenditure (OpEx) model, a key cloud computing benefit. In cloud services, OpEx shifts costs from capital expenditure (CapEx) to a pay-as-you-go or subscription-based model, eliminating the need for large upfront hardware investments. This is a fundamental concept in Microsoft Azure and other cloud platforms, where resources like virtual machines are billed monthly based on actual consumption.

Exam trap

The trap here is that candidates often confuse OpEx with other cloud benefits like scalability or elasticity, but the question specifically tests the financial distinction between paying upfront (CapEx) versus paying monthly based on usage (OpEx).

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity (e.g., confidential, public), not a financial or deployment model. Option B is wrong because Data Loss Prevention (DLP) is a security policy mechanism that detects and prevents unauthorized sharing of sensitive data, unrelated to cost models or server procurement. Option D is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, designed for organizing work, not for financial planning or infrastructure purchasing.

627
Multi-Selecthard

Which THREE Microsoft 365 services are included in Microsoft 365 E3 that are NOT in Microsoft 365 Business Basic?

Select 3 answers
A.Exchange Online
B.Microsoft Purview Information Protection
C.Microsoft Teams
D.Desktop versions of Office apps
E.Microsoft Intune
AnswersB, D, E

Microsoft Purview Information Protection (formerly Azure Information Protection) delivers persistent data classification and protection through sensitivity labels and encryption. These capabilities are embedded in the E3 security and compliance suite, whereas Business Basic only includes minimal eDiscovery and retention features without full information protection. Since this is a premium compliance feature absent from Business Basic, it is a valid selection.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) is included in Microsoft 365 E3 but not in Microsoft 365 Business Basic. Business Basic only includes Exchange Online, Teams, and web/mobile versions of Office apps, with no data classification or rights management capabilities. E3 adds full Purview features like sensitivity labels and encryption for compliance and data loss prevention.

Exam trap

The trap here is that candidates assume all 'Business' plans lack advanced security features, but the question specifically asks for services included in E3 that are NOT in Business Basic, and Exchange Online and Teams are common to both, while desktop Office apps and Intune are also exclusive to E3.

628
MCQmedium

During requirements gathering, an IT manager says the organization must create an approval workflow between SharePoint and Teams without writing code. Microsoft 365 app or service is the best fit?

A.Power Automate
B.Microsoft Purview Audit
C.Microsoft Forms
D.Microsoft Planner
AnswerA

Power Automate is a low-code/no-code automation platform included with Microsoft 365, designed to create cloud flows that connect apps and services via hundreds of connectors. It uses triggers and actions to orchestrate tasks like document approvals, email notifications, and data synchronization, directly fulfilling a requirement to automate a business process. For an IT manager specifying a collaboration or workflow need, this is the precise service.

Why this answer

Power Automate is the correct choice because it provides a low-code/no-code platform for creating automated workflows that integrate SharePoint and Teams. It allows you to trigger actions based on events in SharePoint (e.g., a new item added to a list) and then perform subsequent actions in Teams (e.g., posting an approval request in a channel). This directly meets the requirement to build an approval workflow without writing code.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task assignment features with workflow automation, but Planner lacks the cross-service orchestration and approval action types that Power Automate provides.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit is a compliance and auditing tool that logs user and admin activities across Microsoft 365; it cannot create or execute approval workflows. Option C is wrong because Microsoft Forms is used to create surveys, quizzes, and polls, not to build multi-step approval workflows between SharePoint and Teams. Option D is wrong because Microsoft Planner is a task management and project tracking tool that lacks the workflow automation capabilities needed to orchestrate an approval process across different services.

629
MCQmedium

A marketing team wants to create a visual task board to track campaign activities, assign owners, and set deadlines. They do not need subtasks or dependencies. Which Microsoft 365 app is most suitable?

A.Microsoft Planner
B.Microsoft Project
C.Microsoft To Do
D.Microsoft Lists
AnswerA

Microsoft Planner is the correct choice because it provides a purpose-built Kanban-style board with customizable buckets for stages (e.g., To Do, Doing, Done), cards for each task, and built-in fields for assignments, due dates, and progress tracking. This visual board view is immediately available without configuration, and Planner integrates natively with Microsoft Teams channels so the entire marketing team can collaborate in real time. Planner is included with most Microsoft 365 enterprise and business plans, making it a low-friction, cost-effective solution for a team needing a lightweight visual task board.

Why this answer

Microsoft Planner is the most suitable app because it provides a visual Kanban-style task board specifically designed for team collaboration, allowing users to create tasks, assign owners, set deadlines, and track progress without requiring subtasks or dependencies. It integrates seamlessly with Microsoft Teams and other Microsoft 365 services, making it ideal for lightweight project management like campaign tracking.

Exam trap

The trap here is that candidates often confuse Microsoft Planner with Microsoft To Do or Microsoft Lists, assuming any task-related app can handle team boards, but only Planner provides the specific visual Kanban board with team assignment and deadline tracking without dependencies.

How to eliminate wrong answers

Option B (Microsoft Project) is wrong because it is a full-featured project management tool designed for complex projects with dependencies, subtasks, resource management, and Gantt charts, which is overkill for a simple visual task board and not intended for lightweight team collaboration. Option C (Microsoft To Do) is wrong because it is a personal task management app focused on individual productivity, lacking team assignment, shared boards, and deadline tracking for group activities. Option D (Microsoft Lists) is wrong because it is a data-tracking and list management app for creating custom lists, forms, and workflows, but it does not provide a native Kanban board view or built-in task assignment features like Planner does.

630
MCQeasy

A security administrator needs to review all sign-in attempts and identify suspicious login patterns for the past 30 days. Which Microsoft 365 portal should they use to access this information?

A.Microsoft Purview compliance portal
B.Microsoft 365 admin center
C.Microsoft Entra ID sign-in logs
D.Microsoft Defender for Cloud Apps
AnswerC

Microsoft Entra ID sign-in logs are the authoritative record of every authentication attempt against your Microsoft 365 tenant, captured by the identity provider that issued the token. Each entry includes timestamps, user principal name, application, client IP, device details, conditional access policies applied, MFA requirements, and sign-in error codes—sufficient for correlating suspicious patterns. Investigators can access these logs in the Entra admin center, Azure portal, or via Microsoft Graph APIs, making them the primary tool for this review.

Why this answer

Microsoft Entra ID sign-in logs provide a detailed record of all sign-in attempts, including successful and failed logins, IP addresses, applications used, and risk detections. This data can be filtered and analyzed to identify suspicious patterns such as multiple failed attempts or sign-ins from unusual locations over the past 30 days, making it the correct choice for a security administrator.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 admin center (which shows basic sign-in activity under 'Health' > 'Sign-in logs') with the full-featured Microsoft Entra ID sign-in logs, but the admin center only provides a limited view and lacks the detailed filtering, risk analysis, and 30-day retention needed for security investigations.

How to eliminate wrong answers

Option A is wrong because the Microsoft Purview compliance portal focuses on data governance, retention, eDiscovery, and compliance management, not on real-time sign-in logs or authentication patterns. Option B is wrong because the Microsoft 365 admin center is used for managing users, licenses, and service settings, but it does not provide detailed sign-in logs or security analysis of login attempts. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility into cloud app usage and anomalies, but the primary source for raw sign-in logs and authentication events is Microsoft Entra ID sign-in logs.

631
MCQmedium

A development team wants to build a custom web application. They choose a cloud service that provides the runtime environment, operating system, and middleware, but the team is responsible for writing and deploying their own code. The provider automatically applies patches to the underlying infrastructure. Which cloud service model best describes this approach?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerB

Platform as a Service (PaaS) is correct because it provides a fully managed hosting environment that includes the operating system, language runtime, web server, and middleware, along with built-in deployment and scaling features. In a service like Azure App Service, the development team simply deploys its custom code and configuration, and the platform handles patching, load balancing, and high availability. This allows the team to focus on building the application rather than maintaining the underlying infrastructure.

Why this answer

Platform as a Service (PaaS) provides the runtime environment, operating system, and middleware, allowing developers to focus on writing and deploying their own code while the cloud provider manages the underlying infrastructure, including automatic patching. This model abstracts the hardware and OS layer, giving the team full control over application code but not the platform stack.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve deploying custom code, but IaaS requires the team to manage the OS and middleware patching, whereas PaaS automates that responsibility.

How to eliminate wrong answers

Option A (IaaS) is wrong because it provides virtualized computing resources (e.g., VMs, storage, networking) where the team is responsible for managing the operating system, middleware, and runtime, including patching, which contradicts the automatic patching described. Option C (SaaS) is wrong because it delivers fully functional software applications over the internet, where the provider manages everything, and the team would not write or deploy their own code. Option D (FaaS) is wrong because it is a serverless compute model where code runs in response to events, and the provider manages the runtime environment, but it does not include middleware or a full runtime environment like a web server; it is a subset of PaaS focused on individual functions.

632
Multi-Selectmedium

Which TWO Microsoft 365 services can be used to create and manage chatbots that use AI to answer user questions?

Select 2 answers
A.Microsoft Copilot Studio
B.Microsoft Forms
C.Microsoft Viva Topics
D.Microsoft Bot Framework
E.Microsoft Power Automate
AnswersA, D

Microsoft Copilot Studio is a low-code platform that lets you build AI-powered chatbots and custom copilots without writing code. It provides a graphical conversation designer, natural language understanding, and connectors to Microsoft 365 services like SharePoint, Teams, and Dataverse, enabling you to create, publish, and manage intelligent bots that can be embedded in websites or Teams. This is the only out-of-the-box, no-code chatbot builder in the Microsoft 365 ecosystem.

Why this answer

Microsoft Copilot Studio (formerly Power Virtual Agents) is a low-code platform for creating conversational AI chatbots that can answer user questions using natural language processing and generative AI. It integrates with Microsoft 365 and allows you to build, test, and deploy chatbots without extensive coding.

Exam trap

The trap here is that candidates confuse Microsoft Copilot Studio (a low-code chatbot builder) with Microsoft Power Automate (a workflow tool) or Microsoft Viva Topics (a knowledge management service), not realizing that only Copilot Studio and Bot Framework directly create and manage AI-powered conversational chatbots.

633
Multi-Selectmedium

An e-commerce company hosts its website on a public cloud IaaS platform. The site experiences varying traffic throughout the year. The cloud provider automatically adds more virtual servers during peak traffic and removes them when demand drops. The company only pays for the resources used during each period. Which two cloud characteristics are demonstrated? (Choose two.)

Select 2 answers
A.Rapid elasticity
B.Measured service
C.On-demand self-service
D.Resource pooling
AnswersA, B

Rapid elasticity is a core NIST characteristic of cloud computing where resources can be provisioned and released automatically, often in response to demand, to scale outward and inward rapidly. In this IaaS scenario, the automatic addition and removal of VMs based on traffic levels directly demonstrates this capability, making it the correct answer.

Why this answer

Rapid elasticity is demonstrated because the cloud provider automatically scales virtual servers up or down in response to varying traffic, which is a key characteristic of cloud computing where resources can be provisioned and released elastically to match demand. Measured service is demonstrated because the company only pays for the resources used during each period, meaning the provider meters resource usage (e.g., CPU hours, memory, bandwidth) and bills accordingly, which is a core attribute of cloud services.

Exam trap

The trap here is that candidates often confuse 'on-demand self-service' with automatic scaling, but on-demand self-service is about manual provisioning without provider interaction, not about the system's ability to scale automatically based on load.

634
MCQmedium

During requirements gathering, an IT manager says the organization must make document protection persist after a file is downloaded or emailed. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Forms
C.Microsoft Stream
D.Sensitivity labels with encryption
AnswerD

Sensitivity labels with encryption are the correct mechanism because they provide persistent information protection across Microsoft 365 services. Labels can classify content and apply encryption, restricting access based on identity, permissions, or business rules even after the file leaves the organization. This meets the requirement for granular security and compliance control during requirements gathering.

Why this answer

Sensitivity labels with encryption (via Microsoft Purview Information Protection) apply persistent protection that travels with the file — even after download or email — because the encryption and usage rights are embedded in the document itself. This ensures that protection persists regardless of where the file goes, satisfying the requirement.

Exam trap

MS-900 often tests the difference between tools that manage documents (Planner, Forms, Stream) and those that protect them — candidates must recognize that only sensitivity labels with encryption provide persistent, file-level protection.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool with no document protection capabilities. Option B is wrong because Microsoft Forms is a survey/quiz tool unrelated to document security. Option C is wrong because Microsoft Stream is a video hosting service and does not provide document encryption or persistent protection.

635
MCQeasy

A marketing team needs to create a printed newsletter that includes custom graphics, text boxes, and precise layout control. Which Microsoft 365 app is specifically designed for desktop publishing tasks like this?

A.Microsoft Word
B.Microsoft Publisher
C.Microsoft Sway
D.Microsoft PowerPoint
AnswerB

Microsoft Publisher is a dedicated desktop publishing application engineered for creating print-ready documents, including newsletters, brochures, and flyers. It offers precise control over text boxes, graphics, and page composition through master pages, ruler guides, and linked text frames, allowing consistent multi-page layouts. Publisher also supports commercial printing specifications such as CMYK color separation and bleeds, making it the correct tool for a professional printed newsletter.

Why this answer

Microsoft Publisher is the correct answer because it is specifically designed for desktop publishing (DTP) tasks such as creating printed newsletters with custom graphics, text boxes, and precise layout control. Unlike general-purpose word processors or presentation tools, Publisher provides advanced page layout features, including master pages, typography controls, and fine-grained object positioning, making it the appropriate choice for this scenario.

Exam trap

The trap here is that candidates often confuse Microsoft Word's basic layout capabilities (like text boxes and images) with the dedicated desktop publishing features of Publisher, leading them to choose Word for tasks that require precise print layout control.

How to eliminate wrong answers

Option A is wrong because Microsoft Word is a word processing application optimized for document creation and text editing, not for precise desktop publishing layout control, and it lacks dedicated DTP features like advanced text wrapping and object layering. Option C is wrong because Microsoft Sway is a web-based presentation and storytelling app designed for interactive, responsive content, not for print-ready desktop publishing with fixed layouts. Option D is wrong because Microsoft PowerPoint is a presentation application focused on slideshows and screen-based delivery, lacking the print-oriented layout tools and page size flexibility required for a printed newsletter.

636
MCQmedium

A tenant administrator is advising a department that wants to co-author a Word document with colleagues in real time from a browser. Microsoft 365 app or service is the best fit?

A.Microsoft Forms
B.Microsoft Purview Audit
C.Microsoft 365 web apps with OneDrive or SharePoint
D.Microsoft Planner
AnswerC

Microsoft 365 web apps built into OneDrive and SharePoint give users the ability to co-author Word, Excel, and PowerPoint files directly in a browser. Changes are saved automatically and merged in near real time, with presence indicators showing who is editing, while version history allows recovery of earlier drafts. Because the files live in OneDrive or SharePoint, the tenant admin can manage sharing links and permissions to support both internal and external collaborators.

Why this answer

Microsoft 365 web apps (Word, Excel, PowerPoint) combined with OneDrive or SharePoint enable real-time co-authoring from a browser. This allows multiple users to edit the same document simultaneously, with changes synced instantly via the cloud, which directly meets the department's requirement.

Exam trap

The trap here is that candidates may confuse Microsoft Forms or Planner as collaboration tools, but they are designed for data collection and task management, not real-time document co-authoring, which specifically requires web apps with OneDrive or SharePoint.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz tool, not a document co-authoring solution; it does not support real-time editing of Word documents. Option B is wrong because Microsoft Purview Audit is a compliance and auditing service for tracking user activities, not a tool for collaborative document editing. Option D is wrong because Microsoft Planner is a task and project management app for organizing work, not a document co-authoring platform.

637
Drag & Dropmedium

Drag and drop the steps to configure a data loss prevention (DLP) policy in the Microsoft 365 compliance center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DLP policies are created in the compliance center by selecting a template, locations, and rules.

638
MCQeasy

A non-profit organization, NPO Global, uses Microsoft 365 Nonprofit Business Basic. The organization has 200 users and is growing. They need to: 1. Create a central repository for storing and sharing documents with external partners. 2. Allow multiple users to co-author documents in real time. 3. Provide a secure way for external partners to access only specific folders. 4. Maintain version history for all documents. Which Microsoft 365 app should the organization primarily use?

A.Microsoft SharePoint
B.Microsoft Teams
C.Microsoft Power Apps
D.Microsoft OneDrive
AnswerA

Microsoft SharePoint provides team sites and document libraries that serve as a centralized, structured repository for organizational content. It supports granular permission management, version history, metadata columns, content types, co-authoring, and external sharing, making it the appropriate platform for a non-profit to store and collaborate on shared documents at scale.

Why this answer

Microsoft SharePoint is the correct primary app because it provides a centralized document repository with granular permission controls, enabling external sharing of specific folders via secure links. It supports real-time co-authoring through Office Online integration and maintains version history for all documents, meeting all four requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a document management tool because it integrates with SharePoint, but Teams lacks the granular folder-level external sharing and centralized repository focus that SharePoint provides natively.

How to eliminate wrong answers

Option B (Microsoft Teams) is wrong because while Teams includes SharePoint-backed file storage and co-authoring, its primary focus is persistent chat and collaboration channels, not a dedicated central repository with folder-level external sharing; managing external access to specific folders is more complex and less granular than SharePoint. Option C (Microsoft Power Apps) is wrong because it is a low-code application development platform for building custom apps, not a document management or sharing solution; it lacks native document storage, co-authoring, and version history features. Option D (Microsoft OneDrive) is wrong because it is designed for individual file storage and sharing, not as a central repository for an organization; it does not support folder-level external sharing with granular permissions for multiple external partners, and its version history is per-user, not centrally managed for collaboration.

639
MCQmedium

A healthcare company must keep patient records in a specific country and wants Microsoft to guarantee that data remains within that geography. The company also needs to know which Microsoft 365 services are available in that region. Which Microsoft 365 capability should the company review?

A.Microsoft 365 network connectivity principles
B.Microsoft 365 service health dashboard
C.Microsoft 365 data residency commitments
D.Microsoft 365 backup and restore
AnswerC

Microsoft 365 data residency commitments define where customer data at rest is stored for core workloads and which geographies support those workloads. Reviewing these commitments lets the healthcare company verify that patient records remain in the required country and understand service availability by region. This directly addresses the compliance and location requirements described in the scenario.

Why this answer

Data residency commitments specify the geographic locations where Microsoft stores customer data at rest and which services are available in each geography. The healthcare company needs that contractual and architectural assurance to keep patient records in the required country. Backup, network connectivity, and service health features address recovery, performance, and incidents, but none of them establish or document where data resides.

Exam trap

The trap here is assuming any Microsoft 365 operational or security feature automatically guarantees where customer data is stored.

640
Multi-Selecthard

Which THREE Microsoft 365 services are part of Microsoft Viva, the employee experience platform?

Select 3 answers
A.Viva Learning
B.Viva Insights
C.Viva Connections
D.Microsoft Teams
E.Microsoft Stream
AnswersA, B, C

Viva Learning is one of the four core Viva modules, delivering aggregated training content from LinkedIn Learning, Microsoft Learn and organisational sources directly within Microsoft Teams. It satisfies the stem's requirement for a genuine employee-experience service, alongside Connections, Insights and Topics.

Why this answer

Viva Learning (A) is a core Microsoft Viva module that aggregates training content from LinkedIn Learning, Microsoft Learn, and other providers directly into the flow of work, so it is correctly part of the employee experience platform. Viva Insights (B) is also a Viva module, delivering productivity and wellbeing analytics, personal insights, and manager/leader insights derived from Microsoft Graph and collaboration data. Viva Connections (C) is the Viva gateway/experience app that surfaces company news, resources, and communities through a customizable dashboard in Microsoft Teams, making it a genuine Viva service.

Microsoft Teams (D) is not part of Viva; it is the collaboration platform that hosts Viva Connections and other apps, but it is a separate Microsoft 365 service. Microsoft Stream (E) is likewise not a Viva module; it is Microsoft 365's enterprise video service, and while video content may appear within Viva Learning or Connections, Stream itself is not one of the Viva services.

Exam trap

The trap here is that candidates confuse the underlying Microsoft 365 services (like Teams or Stream) with the Viva modules that run on top of them, leading them to select Teams as a Viva component instead of recognizing that Viva is a separate employee experience platform with distinct modules.

641
MCQhard

A company runs a legacy application that requires a fixed amount of dedicated hardware resources for compliance reasons. However, they want to benefit from cloud-based backup and disaster recovery to reduce on-premises hardware costs. Which cloud deployment model best aligns with this requirement?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

Hybrid cloud combines a private or on-premises environment with public cloud services, typically over a secure VPN or dedicated connection like Azure ExpressRoute. This lets the legacy application continue running in a dedicated private space with fixed resources, while backup, disaster recovery, or scale-out workloads are offloaded to the public cloud, decreasing the on-premises footprint. The resulting reduction in physical infrastructure, energy, and maintenance directly lowers on-premises cost while preserving the application's required isolation.

Why this answer

Hybrid cloud is correct because it allows the company to keep the legacy application on dedicated on-premises hardware for compliance, while leveraging cloud-based backup and disaster recovery services (e.g., Azure Backup and Azure Site Recovery) to reduce on-premises hardware costs. This model combines private cloud (or on-premises infrastructure) with public cloud resources, enabling data replication and failover to the cloud without migrating the application itself.

Exam trap

The trap here is that candidates often confuse 'hybrid cloud' with 'private cloud' because both involve on-premises resources, but the key differentiator is the use of public cloud services for backup/DR to reduce hardware costs, which only hybrid cloud enables.

How to eliminate wrong answers

Option A is wrong because public cloud would require running the legacy application entirely on shared cloud infrastructure, which cannot guarantee the fixed amount of dedicated hardware resources needed for compliance. Option B is wrong because private cloud, while providing dedicated resources, does not inherently reduce on-premises hardware costs as it still requires maintaining all hardware on-site or in a dedicated data center. Option D is wrong because community cloud is designed for organizations with shared compliance concerns (e.g., government or healthcare), but it does not specifically address the need for dedicated hardware for a single company's legacy application while also reducing on-premises costs via cloud backup.

642
MCQmedium

A company has 500 users and is considering moving to Microsoft 365. They need to ensure that all users have access to Exchange Online, SharePoint Online, and Teams, and they want to use Microsoft Entra ID P1 for identity management. Which Microsoft 365 subscription should they choose?

A.Microsoft 365 E5
B.Microsoft 365 E3
C.Microsoft 365 Business Basic
D.Microsoft 365 Business Premium
AnswerB

Microsoft 365 E3 is an enterprise-level plan with no seat cap, making it suitable for 500 users. It includes Exchange Online, SharePoint Online, Teams, and Microsoft Entra ID P1 (Azure AD Premium P1), which provides the required identity and access management features. This plan delivers all necessary services at a lower cost than E5, making it the correct and most cost-effective choice for the scenario.

Why this answer

Microsoft 365 E3 includes Exchange Online, SharePoint Online, Teams, and Microsoft Entra ID P1, meeting all stated requirements. Unlike Business Premium, E3 has no user limit, making it suitable for 500 users.

Exam trap

Candidates often overlook the 300-user limit on Microsoft 365 Business plans and assume Business Premium is sufficient for any organization size. In this scenario, the company has 500 users, so an Enterprise plan (E3) is required.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 E5 includes advanced security and compliance features (e.g., Microsoft Defender for Office 365, eDiscovery) that are not required, and it is more expensive than necessary. Option B is wrong because Microsoft 365 E3 includes Exchange Online, SharePoint Online, and Teams, but it only provides Microsoft Entra ID P1 as an add-on or through a separate license; it is not included by default in the E3 subscription. Option C is wrong because Microsoft 365 Business Basic includes Exchange Online, SharePoint Online, and Teams, but it does not include Microsoft Entra ID P1; it only provides Microsoft Entra ID Free, which lacks advanced identity management features.

643
MCQmedium

A department asks for the Microsoft 365 service best suited for custom low-code business apps. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Defender for Endpoint
B.Microsoft Entra Privileged Identity Management
C.Microsoft Purview Compliance Manager
D.Power Apps
AnswerD

Power Apps is Microsoft 365's low-code application platform, letting makers build custom business apps through visual designers and connectors rather than operational scripts. It satisfies the requirement to avoid custom operational scripting, unlike Power Automate, which targets workflow automation instead of app creation.

Why this answer

Power Apps is the correct choice because it is a low-code application development platform within Microsoft 365 that enables users to build custom business apps without writing traditional code. It provides pre-built templates, connectors to Microsoft and third-party services, and a visual drag-and-drop designer, allowing departments to create tailored solutions without custom operational scripts.

Exam trap

The trap here is that candidates may confuse security or compliance tools (like Defender, PIM, or Compliance Manager) with app development platforms, failing to recognize that Power Apps is the designated low-code solution in the Microsoft 365 ecosystem.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, not a platform for building custom low-code business apps. Option B is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring privileged access within Azure AD, not for app development. Option C is wrong because Microsoft Purview Compliance Manager is a compliance management solution that helps organizations assess and manage regulatory compliance, not a low-code app development service.

644
MCQhard

A global company needs to ensure that only employees in the 'HR' security group can access a specific set of HR documents stored in SharePoint. If a user outside the group attempts to view or copy the content, it must be blocked. The protection must persist even if someone downloads the files and shares them externally, or if the files are saved to a personal device. Which Microsoft Purview solution should be used?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels with encryption and permission settings
C.Microsoft Entra ID Conditional Access
D.Microsoft Defender for Cloud Apps session policy
AnswerB

Sensitivity labels, when configured with encryption, use Azure Information Protection (AIP) to encrypt the file content and apply usage rights based on the authenticated identity. The encryption is embedded into the file itself, so the protection persists everywhere—whether the file is downloaded, attached to email, or saved to a USB drive. By setting the permission to require the HR group, only their Entra ID accounts gain the rights to decrypt and read the file, making this the only option that enforces persistent, identity-based access control.

Why this answer

Sensitivity labels with encryption and permission settings are the correct solution because they allow you to apply persistent protection that travels with the file, regardless of where it is stored or shared. By configuring a sensitivity label to restrict access to only members of the 'HR' security group and enabling encryption, the protection remains intact even if the file is downloaded, saved to a personal device, or shared externally. This meets the requirement for persistent access control that blocks unauthorized viewing or copying.

Exam trap

The trap here is that candidates often confuse DLP policies (which only monitor and block sharing at the transport layer) with sensitivity labels (which provide persistent encryption and access control that stays with the file), leading them to choose DLP when the question explicitly requires protection that persists after download or external sharing.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies are designed to detect and prevent accidental sharing of sensitive information based on content inspection, but they do not apply persistent encryption or access control that travels with the file after it is downloaded or saved to a personal device. Option C is wrong because Microsoft Entra ID Conditional Access controls access at the authentication and session level for cloud apps, but it does not provide persistent protection that remains with the file once it is downloaded or shared outside the controlled environment. Option D is wrong because Microsoft Defender for Cloud Apps session policies can monitor and control access in real-time within the browser session, but they cannot enforce persistent encryption or access restrictions on files that have been downloaded or saved locally.

645
MCQmedium

During requirements gathering, an IT manager says the organization must track assets using columns such as owner, status, purchase date, and location. Microsoft 365 app or service is the best fit?

A.Microsoft Forms
B.Microsoft Planner
C.Microsoft Lists
D.Microsoft Purview Audit
AnswerC

Microsoft Lists provides structured, column-based tracking with owner, status, purchase date and location fields, matching the asset-tracking requirement directly. It is included in Microsoft 365, so no separate asset-management platform or custom database build is needed.

Why this answer

Microsoft Lists is the best fit because it provides a structured, customizable data-tracking solution with columns for metadata like owner, status, purchase date, and location. Unlike simple task or form tools, Lists supports rich column types (e.g., choice, date, person), views, and integration with SharePoint, making it ideal for asset tracking.

Exam trap

The trap here is that candidates confuse Microsoft Planner (a task board) with a data tracking tool, overlooking that Lists is the correct choice for structured column-based asset management.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is designed for creating surveys and quizzes, not for tracking assets with structured columns and ongoing data management. Option B is wrong because Microsoft Planner is a task management tool for organizing work with buckets and checklists, not a data repository for asset metadata like purchase date and location. Option D is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user and admin activities in Microsoft 365, not for creating and managing asset tracking lists.

646
MCQeasy

A user wants to quickly set up a website for their team to share news and resources. Which Microsoft 365 app should they use?

A.Microsoft Teams
B.Microsoft Viva
C.Yammer
D.SharePoint
AnswerD

SharePoint is the correct choice because SharePoint communication sites are built specifically to create team-oriented web pages for sharing news, documents, and resources. Through modern web parts, flexible layouts, and granular site-level permissions, a user can quickly build a polished website without writing code. SharePoint Online supports both internal sharing and external sharing with appropriate configuration, making it the Microsoft 365 workload that actually delivers a website experience.

Why this answer

SharePoint is the correct choice because it is specifically designed for creating team sites that serve as centralized hubs for sharing news, documents, and resources. With SharePoint, users can quickly provision a modern team site using pre-built templates, add web parts for news feeds and document libraries, and manage permissions for team members. This directly meets the requirement for a website to share news and resources.

Exam trap

The trap here is that candidates often confuse Microsoft Teams with a website creation tool because Teams includes tabs for SharePoint pages and files, but Teams itself is not a website platform—SharePoint is the underlying service for site creation and content management.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration workspace, not a website creation tool; while it integrates with SharePoint for file storage, it does not provide a standalone website for sharing news and resources. Option B is wrong because Microsoft Viva is an employee experience platform that focuses on insights, learning, and wellbeing, not on creating team websites or resource hubs. Option C is wrong because Yammer is an enterprise social networking tool for broad organizational communication, not a site for a specific team to share news and resources in a structured website format.

647
MCQmedium

Refer to the exhibit. A Teams administrator runs the PowerShell commands to enable meeting transcription and recording for all users. After running the commands, users still cannot start transcription in their meetings. What is the most likely cause?

A.Users may have a custom meeting policy that overrides the global policy.
B.The admin does not have the correct permissions.
C.The admin forgot to run a Grant-CsTeamsMeetingPolicy command.
D.The AllowTranscription property is misnamed.
AnswerA

Users may have a custom meeting policy that overrides the global policy. In Teams, the global policy is the default, but if a user has been assigned a per-user meeting policy via Grant-CsTeamsMeetingPolicy, that explicit assignment takes precedence. Modifying the global policy only affects users who are not assigned a custom policy. To verify, the admin should run Get-CsTeamsMeetingPolicy with the user's identity to see which policy is actually effective.

Why this answer

In Microsoft Teams, meeting policies are applied hierarchically: a custom policy assigned directly to a user overrides the global policy. Even if the global policy has transcription enabled, users with a custom meeting policy that has AllowTranscription set to False will not be able to start transcription. The admin must either modify the custom policy or assign the global policy to those users.

Exam trap

The trap here is that candidates assume modifying the global policy affects all users, forgetting that a user-assigned custom policy takes precedence and must be explicitly updated or removed.

How to eliminate wrong answers

Option B is wrong because the admin successfully ran the PowerShell commands, which indicates they have the necessary permissions (e.g., Teams Administrator or Global Administrator role) to modify meeting policies. Option C is wrong because the Grant-CsTeamsMeetingPolicy cmdlet is used to assign a specific policy to a user; if the admin intended to modify the global policy, no Grant command is needed—the Set-CsTeamsMeetingPolicy cmdlet directly updates the global policy. Option D is wrong because the AllowTranscription property is correctly named; it is a valid parameter in the Set-CsTeamsMeetingPolicy cmdlet, and any typo would have caused an error when running the command.

648
MCQmedium

During requirements gathering, an IT manager says the organization must keep services available during a hardware failure. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.High availability
D.Sensitivity labels
AnswerC

High availability is the cloud characteristic that keeps services operational and user-accessible even when specific components, such as servers, disks, or network paths, fail. It is implemented through redundant design, automatic failover, load balancing, and continuous health monitoring that routes traffic away from unhealthy nodes. Microsoft 365 contractually guarantees a monthly uptime percentage through its Service Level Agreement, which is typically expressed in 'nines' (e.g., 99.9%), directly matching an IT manager's expectation that 'this needs to be available no matter what.'

Why this answer

High availability (C) is the correct cloud concept because it directly addresses the requirement to keep services operational during hardware failure. In Microsoft 365, high availability is achieved through redundant infrastructure, such as multiple server instances across different Azure availability zones, and automatic failover mechanisms that ensure service continuity without manual intervention.

Exam trap

The trap here is that candidates may confuse high availability with disaster recovery, but the question specifically asks about keeping services available during a hardware failure, which is the definition of high availability, not the broader recovery from a major outage.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management application within Microsoft 365, not a cloud concept or benefit related to service availability during hardware failure. Option B is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive information from being shared or leaked, focusing on data protection rather than infrastructure resilience. Option D is wrong because Sensitivity labels are classification and protection tools for data governance, used to apply encryption and access restrictions, not to maintain service uptime during hardware failures.

649
MCQmedium

Refer to the exhibit. A Microsoft 365 admin configures an update policy for Microsoft 365 Apps for enterprise. The channel is set to 'CurrentChannel'. What is the expected behavior for users?

A.Users receive feature updates monthly.
B.Users receive feature updates twice a year.
C.Users receive feature updates as soon as they are released.
D.Users receive updates only after the deadline.
AnswerC

CurrentChannel delivers feature updates as soon as Microsoft releases them, with no fixed deferral. Devices on this channel therefore receive new features immediately rather than after the scheduled delays applied to Monthly Enterprise Channel or Semi-Annual Channel.

Why this answer

The Current Channel in Microsoft 365 Apps for enterprise provides feature updates as soon as they are released, typically monthly, but the key is that users receive them as soon as they are available, without a fixed delay. This channel is designed for users who want the latest features immediately. The expected behavior is that users receive feature updates as soon as they are released, which aligns with option C.

Exam trap

The trap is confusing Current Channel with Monthly Enterprise Channel; both provide monthly updates, but Current Channel delivers features as soon as they are released, while Monthly Enterprise Channel follows a more predictable monthly schedule with a slight delay.

How to eliminate wrong answers

Option A is wrong because while Current Channel does receive monthly feature updates, the statement 'monthly' is not precise; the channel delivers updates as soon as they are released, which is typically monthly but can vary. Option B is wrong because twice-a-year feature updates correspond to the Semi-Annual Enterprise Channel, not Current Channel. Option D is wrong because updates are not held until a deadline; that behavior is associated with deadlines set for updates, but the channel itself does not delay updates until a deadline.

650
MCQmedium

A tenant administrator is advising a department that wants to automatically apply a label when sensitive customer identifiers are detected. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Auto-labeling for sensitivity labels
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Auto-labeling for sensitivity labels in Microsoft Purview automatically assigns a sensitivity label to documents, emails, or other content when it matches conditions such as sensitive information types, keywords, or trainable classifiers. This cloud-based capability can apply the label at the time content is created, edited, or uploaded, and it can also enforce protections like encryption or headers/footers when configured. By using auto-labeling, the tenant administrator can implement a compliance control that scans content and classifies it without requiring manual user intervention. This directly meets the department's need for automatic labeling based on content conditions.

Why this answer

Auto-labeling for sensitivity labels in Microsoft Purview (formerly Microsoft 365 Compliance) can automatically apply a sensitivity label when sensitive customer identifiers are detected. It uses trainable classifiers or sensitive information types to identify content and then applies the label based on policies. This helps organizations protect data without manual intervention.

Exam trap

MS-900 often tests the confusion between different Microsoft 365 services; candidates might pick Planner or Forms thinking they handle data, but only Purview's auto-labeling applies sensitivity labels.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool, not a compliance or labeling service. Option C is wrong because Microsoft Forms is for creating surveys and quizzes, not for data classification. Option D is wrong because Microsoft Stream is a video sharing service, unrelated to sensitivity labeling.

651
MCQmedium

A compliance officer needs to automatically detect when employees share customers' personal data (e.g., social security numbers) via email and block such sharing. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Audit
AnswerA

DLP policies are content-aware and use built-in sensitive information types, such as regex patterns for Social Security numbers, to scan emails, documents, and chats across Exchange Online, SharePoint, and Teams. When a match occurs, DLP can automatically block the message from being sent or the file from being shared, while also showing a policy tip to the user and alerting the compliance officer. This provides real-time, automated detection and remediation of sensitive data sharing, which is exactly the requirement.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to identify, monitor, and automatically protect sensitive data—such as social security numbers—across Microsoft 365 services, including Exchange Online. DLP policies can be configured with conditions that detect sensitive information types (e.g., U.S. Social Security Number) in email messages and apply actions like blocking the email from being sent.

This directly meets the compliance officer's requirement to automatically detect and block sharing of customers' personal data via email.

Exam trap

The trap here is that candidates often confuse Communication Compliance (which reviews communications for policy violations) with DLP (which actively blocks sensitive data), leading them to select option C because they think 'compliance' implies blocking, but Communication Compliance only detects and flags, not blocks.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Insider Risk Management focuses on identifying, analyzing, and remediating internal risks (e.g., data theft, policy violations) by correlating signals from various sources, but it does not provide real-time blocking of sensitive data in email. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect and review inappropriate or policy-violating communications (e.g., harassment, insider trading) but does not have the capability to automatically block data sharing based on sensitive content like social security numbers. Option D is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities, but it is a passive auditing tool that cannot automatically detect or block data sharing in real time.

652
MCQmedium

A compliance administrator needs to block sharing of documents containing credit card numbers. Which Microsoft 365 capability is the best fit?

A.Data Loss Prevention policies
B.Microsoft Teams live events
C.Microsoft Bookings
D.OneDrive sync client
AnswerA

Data Loss Prevention policies inspect content for sensitive information types such as credit card numbers and block or restrict sharing when detected. This directly satisfies the requirement to prevent documents containing card numbers from being shared, unlike retention or sensitivity labelling alone.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft 365 are specifically designed to identify, monitor, and automatically protect sensitive information—such as credit card numbers—across Exchange Online, SharePoint, OneDrive, and Teams. By configuring a DLP policy with a built-in sensitive info type for credit card numbers, the administrator can block users from sharing documents containing that data, either by preventing the action or triggering a notification. This directly addresses the compliance requirement to block sharing of documents with credit card numbers.

Exam trap

The trap here is that candidates may confuse the OneDrive sync client with the OneDrive cloud service, thinking the sync client can enforce DLP policies locally, when in fact DLP policies are applied at the cloud service layer and the sync client simply replicates cloud-side restrictions.

How to eliminate wrong answers

Option B is wrong because Microsoft Teams live events is a broadcast and meeting feature for streaming video to large audiences; it has no capability to scan or block documents based on sensitive content like credit card numbers. Option C is wrong because Microsoft Bookings is a scheduling and appointment management tool; it does not include any data classification or policy enforcement to block sharing of sensitive information. Option D is wrong because the OneDrive sync client is a desktop application that synchronizes files between a local device and OneDrive; it does not natively enforce DLP policies or block sharing of documents containing credit card numbers—DLP policies are enforced at the cloud service level, not by the sync client.

653
MCQmedium

A department asks for the Microsoft 365 service best suited for custom low-code business apps. Which service should they use?

A.Microsoft Defender for Endpoint
B.Microsoft Entra Privileged Identity Management
C.Microsoft Purview Compliance Manager
D.Power Apps
AnswerD

Power Apps provides a low-code canvas and model-driven environment for building custom business applications with minimal hand-written code. It directly satisfies the department's requirement for a Microsoft 365 service suited to custom low-code business apps, unlike Power Automate or Power BI.

Why this answer

Power Apps is the correct choice because it is a low-code application development platform within Microsoft 365 that enables users to build custom business apps without extensive coding. It provides pre-built templates, connectors to Microsoft and third-party services, and a drag-and-drop interface, making it ideal for department-level custom app needs.

Exam trap

The trap here is that candidates may confuse security or compliance services (like Defender, PIM, or Compliance Manager) with development tools, failing to recognize that Power Apps is the dedicated low-code platform for custom business applications.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, not a low-code app development tool. Option B is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring privileged access within Azure AD, not for building custom apps. Option C is wrong because Microsoft Purview Compliance Manager is a compliance management solution that helps organizations assess and manage regulatory compliance risks, not a low-code app builder.

654
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to create dashboards showing sales and operational trends from multiple data sources. Microsoft 365 app or service is the best fit?

A.Power BI
B.Microsoft Purview Audit
C.Microsoft Planner
D.Microsoft Forms
AnswerA

Power BI connects to multiple data sources and builds interactive dashboards visualising sales and operational trends. It directly satisfies the requirement for a Microsoft 365 capability producing multi-source dashboards, whereas Power Apps builds apps and Power Automate orchestrates workflows.

Why this answer

Power BI is the correct choice because it is a business analytics service that enables users to create interactive dashboards and reports by connecting to multiple data sources, including Excel, SQL databases, and cloud services. It provides built-in data transformation, visualization, and sharing capabilities, making it ideal for aggregating sales and operational trends into a single dashboard.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Audit with Power BI due to both involving data, but Purview is strictly for compliance logging and not for analytical dashboard creation.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit is a compliance and auditing solution that logs user and admin activities across Microsoft 365, not a tool for creating dashboards or analyzing trends from multiple data sources. Option C is wrong because Microsoft Planner is a task management and collaboration tool for organizing work with boards and checklists, lacking data integration and visualization features for dashboards. Option D is wrong because Microsoft Forms is a survey and form creation tool for collecting responses, not designed for aggregating data from multiple sources or building analytical dashboards.

655
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to require MFA only for sign-ins from outside trusted locations. Microsoft security, identity, or compliance capability should it use?

A.Conditional Access
B.Microsoft Stream
C.Microsoft Planner
D.Microsoft Forms
AnswerA

Conditional Access is the correct choice because it is the identity-driven policy engine in Entra ID (formerly Azure AD) that evaluates real-time signals—such as user risk, location, device compliance, and application sensitivity—to enforce granular access controls like requiring MFA or blocking access entirely. For a compliance-focused administrator, this directly supports regulatory requirements by enabling policies that restrict access to sensitive resources based on contextual conditions, rather than granting static permissions.

Why this answer

Conditional Access is the correct Microsoft 365 capability because it allows administrators to create policies that enforce MFA based on specific conditions, such as sign-in location. By configuring a Conditional Access policy with a 'location' condition that includes trusted IP ranges (defined via named locations), you can require MFA only when users sign in from outside those trusted locations. This directly addresses the requirement for location-aware MFA enforcement without affecting sign-ins from trusted networks.

Exam trap

Microsoft often tests the misconception that any Microsoft 365 workload can enforce MFA, but only Conditional Access (an Azure AD feature) provides the granular, location-based policy control needed for this scenario.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because it is a video management and sharing service, not a security or identity capability; it cannot enforce MFA or evaluate sign-in locations. Option C (Microsoft Planner) is wrong because it is a task management and planning tool within Microsoft 365, lacking any identity or access control features to require MFA based on location. Option D (Microsoft Forms) is wrong because it is a survey and data collection tool; it has no mechanism to enforce authentication policies or evaluate sign-in locations.

656
MCQeasy

A small accounting firm wants its staff to work from home using Microsoft 365. The partners want to avoid buying new servers and want predictable monthly costs instead of large upfront hardware purchases. Which cloud benefit does this describe?

A.CapEx to OpEx shift
B.High availability
C.Disaster recovery
D.Elasticity
AnswerA

Moving from on-premises servers to Microsoft 365 replaces large upfront capital expenditure on hardware with ongoing operational expenditure in the form of subscription fees. The firm avoids buying servers and gains predictable monthly costs, which is exactly the CapEx-to-OpEx benefit of cloud services. This matches the partners' stated financial goal.

Why this answer

Cloud services replace upfront capital purchases with subscription-based operating expenses, which is the CapEx-to-OpEx shift. The accounting firm avoids buying servers and pays predictable monthly fees, directly matching that benefit. High availability, elasticity, and disaster recovery are real cloud advantages, but they address uptime, scaling, and recovery rather than the financial model the partners want.

Exam trap

The trap here is confusing any cloud benefit with the specific financial benefit of replacing upfront hardware purchases with recurring subscription costs.

657
Multi-Selectmedium

Which three of the following are Microsoft 365 apps and services that are primarily designed for productivity and collaboration? (Choose three.)

Select 3 answers
.Microsoft Teams
.Microsoft Exchange Online
.Microsoft SharePoint Online
.Microsoft Intune
.Microsoft Azure Active Directory
.Microsoft Defender for Office 365

Why this answer

Microsoft Teams, Exchange Online, and SharePoint Online are core Microsoft 365 workloads designed to enhance productivity and collaboration. Teams provides a unified communication platform with chat, meetings, and file sharing; Exchange Online delivers enterprise-grade email and calendaring; SharePoint Online enables document management, intranet portals, and team sites for collaborative content creation.

Exam trap

The trap here is that candidates often confuse security or identity services (like Intune, Azure AD, or Defender) with productivity tools, because they are part of the Microsoft 365 ecosystem, but the question specifically asks for apps and services 'primarily designed for productivity and collaboration.'

658
MCQeasy

A marketing team at Contoso Ltd. needs a cloud-based workspace where they can create and share interactive dashboards, reports, and datasets with colleagues without setting up any on-premises servers. Which Microsoft 365 service should they use?

A.Microsoft Sway
B.Microsoft Viva Insights
C.Microsoft Stream
D.Microsoft Power BI
AnswerD

Power BI is Microsoft 365's cloud business analytics service that lets users build interactive dashboards, reports, and datasets and share them across the organization. It requires no on-premises infrastructure and supports natural-language queries, making it the right fit for a marketing team that needs to visualize and distribute data insights quickly and collaboratively.

Why this answer

Power BI is the Microsoft 365 service specifically designed for cloud-based business analytics, enabling users to create interactive dashboards, reports, and datasets and share them with colleagues. Viva Insights, Stream, and Sway serve different purposes—employee productivity analytics, enterprise video, and visual storytelling—and none provide the data modeling and dashboard-sharing capabilities the marketing team needs.

Exam trap

The trap here is assuming that any Microsoft 365 app that displays information visually can serve as a reporting and dashboard platform, which leads to selecting presentation or video tools instead of the dedicated analytics service.

659
MCQmedium

A marketing manager wants to create a central repository for project documents, announcements, and a shared calendar. The solution must be accessible from Microsoft Teams and allow team members to co-author documents in real time. Which Microsoft 365 service should be used?

A.SharePoint Online (team site)
B.Microsoft Lists
C.Power Automate
D.Microsoft Planner
AnswerA

SharePoint Online team sites function as true central collaboration repositories, providing document libraries with co-authoring, version history, list apps, and a shared team calendar through the site's built-in Calendar list. Because a team site can be added as a tab in Microsoft Teams, it consolidates files, announcements, and events in one managed, permission-controlled location. This makes it the only option that simultaneously satisfies the marketing manager's requirement for a central repository with calendar and document management.

Why this answer

SharePoint Online team sites provide a centralized document library, announcements, and shared calendar that can be integrated directly into Microsoft Teams via the SharePoint tab. Team members can co-author documents in real time using Office Online integration, which supports simultaneous editing with auto-save. This makes SharePoint the correct choice for a central repository with real-time collaboration accessible from Teams.

Exam trap

The trap here is that candidates often confuse Microsoft Planner (task management) or Microsoft Lists (data tracking) with a full document and calendar repository, overlooking that SharePoint Online is the underlying service that provides the document library, calendar, and announcements that can be surfaced in Teams.

How to eliminate wrong answers

Option B (Microsoft Lists) is wrong because it is a data-tracking application for creating lists and tables, not a document repository or calendar; it lacks native real-time co-authoring for documents. Option C (Power Automate) is wrong because it is a workflow automation tool that orchestrates actions across services, not a storage or collaboration platform for documents and calendars. Option D (Microsoft Planner) is wrong because it is a task management and planning tool focused on Kanban boards and assignments, not a document repository or shared calendar with real-time co-authoring.

660
MCQeasy

A company uses a cloud provider that charges them based solely on the exact number of gigabytes of storage used and the number of virtual machine hours consumed. They can increase or decrease usage at any time without any upfront commitment. Which essential characteristic of cloud computing does this billing model demonstrate?

A.Measured service
B.Rapid elasticity
C.Resource pooling
D.On-demand self-service
AnswerA

Measured service is the cloud characteristic where a provider meters resource usage — such as compute hours, storage capacity, and network bandwidth — and bills customers based solely on that measured consumption. This pay-per-use model directly matches the scenario of being charged based on actual resource utilization, not on flat fees or other factors.

Why this answer

The billing model charges based on exact gigabytes of storage used and virtual machine hours consumed, which directly aligns with the 'measured service' characteristic of cloud computing. Measured service means cloud providers meter and bill customers precisely for the resources they consume, often using a pay-as-you-go model. This allows the company to pay only for what they use without upfront commitments, as described in the scenario.

Exam trap

The trap here is that candidates often confuse 'measured service' with 'on-demand self-service' because both involve user control and flexibility, but measured service specifically focuses on the metering and billing aspect, not the ability to provision resources without human interaction.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly in response to demand, not to the billing or metering of those resources. Option C (Resource pooling) is wrong because resource pooling describes how the provider's computing resources are pooled to serve multiple customers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to consumer demand; it does not directly relate to billing granularity. Option D (On-demand self-service) is wrong because on-demand self-service allows a consumer to provision computing capabilities automatically without requiring human interaction with each service provider; while the scenario mentions the ability to increase or decrease usage at any time, the key billing aspect of 'pay per exact usage' is specifically measured service, not the provisioning mechanism.

661
MCQmedium

Wide World Importers is a retail company with 2,000 users. They use Microsoft 365 E3. They need to: (1) Deploy a new employee experience platform that integrates with Microsoft 365 and provides personalized news, tasks, and learning; (2) Enable employees to create low-code apps to automate approvals and workflows without custom development; (3) Provide a secure way for employees to store and share company files with granular permissions; (4) Allow IT to manage mobile devices and applications centrally. Which Microsoft 365 services should they use?

A.Viva Connections, Power Apps and Power Automate, SharePoint Online, Microsoft Intune
B.Viva Insights, Power Apps and Power Automate, SharePoint Online, Microsoft 365 Defender
C.Microsoft Teams, Power Apps and Power Automate, OneDrive, Microsoft Entra ID
D.Viva Connections, Power BI, OneDrive, Microsoft Intune
AnswerA

This option is correct because it combines the four required services. Viva Connections delivers a personalized employee experience portal within Teams and SharePoint, Power Apps and Power Automate enable low-code custom business apps and automated workflows, SharePoint Online provides centralized document storage with granular permission controls, and Microsoft Intune enforces mobile device management (MDM) and mobile application management (MAM) policies for company-owned and BYOD devices.

Why this answer

Viva Connections delivers the employee experience platform with personalized news, tasks, and learning integrated into Microsoft 365; Power Apps and Power Automate enable low-code app creation and workflow automation; SharePoint Online provides secure file storage and sharing with granular permissions; and Microsoft Intune delivers centralized mobile device and application management (MDM/MAM). All four requirements map exactly to these services, which are included in or available with Microsoft 365 E3.

Exam trap

MS-900 often tests service-to-requirement mapping — the trap is confusing Viva Connections with Viva Insights, SharePoint with OneDrive, and Intune with Defender, so candidates must match each requirement to the precise service name.

How to eliminate wrong answers

Option B is wrong because Viva Insights is an analytics/productivity tool (not the employee experience hub — that's Viva Connections), and Microsoft 365 Defender is a security suite, not a device management solution (Intune is required for MDM/MAM). Option C is wrong because Microsoft Teams is a collaboration tool, not the personalized employee experience platform (Viva Connections), OneDrive is personal file storage rather than the granular-permission team file platform (SharePoint Online), and Microsoft Entra ID is identity management, not device management. Option D is wrong because Power BI is a business analytics tool, not a low-code app/workflow platform (Power Apps/Power Automate), and OneDrive lacks the granular team-level permission model of SharePoint Online.

662
MCQmedium

A user in your organization receives an email from an unknown sender with a link to a fake login page. The user reports it. You need to analyze the threat and check if other users received similar emails. Which Microsoft 365 Defender feature should you use?

A.Threat analytics
B.Threat Explorer (Explorer)
C.Attack simulation training
D.Automated investigation and response (AIR)
AnswerB

Threat Explorer in Defender for Office 365 is a real-time investigation tool that lets security teams search and filter email records by attributes such as threat type, sender, recipient, subject, message ID, and delivery action. In this scenario, an administrator could use Explorer to locate the exact unknown email, inspect its threat verdicts, and view the mail flow or delivery action. It is the correct option because it is explicitly designed for manual, forensic analysis of email threats in a Microsoft 365 tenant.

Why this answer

Threat Explorer (Explorer) is the correct tool because it provides a real-time, interactive view of email threats, allowing you to search for and analyze specific messages (like the phishing link) across all users. You can use filters such as sender, recipient, or URL to determine if other users received the same malicious email, enabling rapid threat hunting and response.

Exam trap

The trap here is that candidates confuse Threat Explorer (a manual hunting and analysis tool) with Automated investigation and response (AIR), which is an automated reaction system, leading them to pick D because they think 'investigation' implies manual analysis, but AIR is fully automated and not designed for ad-hoc email searches.

How to eliminate wrong answers

Option A is wrong because Threat analytics is a feature that provides intelligence about active threats, vulnerabilities, and attack campaigns, but it does not allow you to search for specific emails or check if other users received a particular message. Option C is wrong because Attack simulation training is used to create and run simulated phishing attacks for user training and awareness, not for analyzing real threats or checking email delivery. Option D is wrong because Automated investigation and response (AIR) automatically triggers investigations and remediation actions after a threat is detected, but it is not the tool you use to manually search and analyze whether other users received a similar email.

663
MCQeasy

A sales team needs a centralized repository for customer proposals that multiple team members can edit simultaneously and that maintains version history. Which Microsoft 365 service should they use?

A.OneDrive for Business
B.SharePoint Online
C.Microsoft Teams
D.Exchange Online
AnswerB

SharePoint Online is the correct choice because it provides team-specific document libraries with granular permission controls, content types, and managed metadata that support a shared repository. Multiple users can co-author the same document simultaneously while version history records every change, and workflows or retention policies can be applied at the site or library level. For a centralized customer repository, SharePoint gives the sales team a governed, collaborative home rather than a personal drive or a communication tool.

Why this answer

SharePoint Online is the correct choice because it provides a centralized document library where multiple users can co-author documents simultaneously, with built-in version history to track changes over time. This aligns directly with the requirement for a shared repository with real-time collaboration and versioning, which OneDrive for Business lacks for team-wide access.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the file storage solution, but Teams relies on SharePoint Online for its Files tab, so the underlying service providing version history and simultaneous editing is SharePoint Online, not Teams itself.

How to eliminate wrong answers

Option A is wrong because OneDrive for Business is designed for personal storage and sharing with individuals, not as a centralized team repository; it does not support simultaneous editing by multiple team members in a shared workspace. Option C is wrong because Microsoft Teams is a collaboration platform that uses SharePoint Online for file storage; Teams itself does not provide the document library or version history features required. Option D is wrong because Exchange Online is an email and calendaring service, not a document management or collaboration tool, and cannot store or version customer proposals.

664
Drag & Dropmedium

Drag and drop the steps to enable Microsoft 365 audit logging in the compliance center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to enable Microsoft 365 audit logging in the compliance center is: first sign in to the Microsoft 365 Compliance center, then navigate to the Audit solution, click 'Start recording user and admin activity' to enable auditing, and finally wait for the audit log to become active (which may take up to 24 hours). This order ensures that all prerequisites are met and the feature is properly activated.

665
MCQeasy

A user receives a suspicious email with a link. They report it using the built-in Microsoft 365 reporting tool. Which service will analyze the reported message?

A.Microsoft Defender for Office 365
B.Microsoft Sentinel
C.Microsoft Purview
D.Microsoft Defender XDR
AnswerA

Microsoft Defender for Office 365 is the dedicated email security workload that receives user-reported phishing or malware reports. It uses threat intelligence, URL and attachment detonation, and automated investigation/response to analyze the message and remediate threats. In this scenario, the reported suspicious link is exactly what MDO's Safe Links and anti-phishing policies are built to evaluate.

Why this answer

Microsoft Defender for Office 365 (MDO) includes the built-in reporting tool that allows users to report suspicious emails directly from Outlook. When a user submits a message via this tool, it is automatically routed to the Microsoft 365 Defender portal's Submissions page, where it is analyzed by MDO's threat protection engines, including detonation in the sandbox environment for URLs and attachments. This analysis determines whether the message is malicious, spam, or a false positive, and updates the tenant's filtering policies accordingly.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Office 365 (which handles email-specific threat analysis and user submissions) with Microsoft Defender XDR (which is the broader correlation engine that ingests alerts from Defender for Office 365 and other sources, but does not itself perform the initial analysis of user-reported messages).

How to eliminate wrong answers

Option B (Microsoft Sentinel) is wrong because Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests logs and alerts from multiple sources for enterprise-wide threat detection, not a tool for analyzing user-reported emails from the built-in reporting tool. Option C (Microsoft Purview) is wrong because Purview focuses on data governance, compliance, and information protection (e.g., data loss prevention, records management, eDiscovery), not on email threat analysis or sandboxing. Option D (Microsoft Defender XDR) is wrong because Defender XDR is a cross-domain extended detection and response solution that correlates alerts across endpoints, identities, email, and cloud apps, but the actual analysis of user-reported messages is performed by Defender for Office 365's specific threat engines, not by the XDR correlation layer.

666
MCQeasy

A project team needs a centralized location to store, share, and co-author documents while maintaining version history. Which Microsoft 365 service should they use?

A.SharePoint Online
B.OneDrive for Business
C.Microsoft Teams
D.Microsoft Viva Topics
AnswerA

SharePoint Online is the correct choice because it is a cloud-based team collaboration platform designed to be a centralized repository for project files. It provides team sites with configurable document libraries, version history, co-authoring, rich metadata, and granular permission controls, making it the default document management service in Microsoft 365 for shared team content.

Why this answer

SharePoint Online is the correct choice because it is designed as a centralized document management and storage platform that supports co-authoring, version history, and granular permission controls. Unlike personal storage services, SharePoint Online provides team-oriented libraries where multiple users can simultaneously edit documents while automatically tracking changes through versioning. This aligns directly with the requirement for a shared, collaborative repository with version history.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint Online, assuming both are equivalent for team collaboration, but OneDrive for Business is designed for individual use and lacks the centralized team site structure and advanced permission management that SharePoint Online provides.

How to eliminate wrong answers

Option B (OneDrive for Business) is wrong because it is primarily a personal cloud storage service for an individual user's files, not a centralized team repository; while it supports co-authoring and version history, it lacks the team-level sharing and management features required for a project team. Option C (Microsoft Teams) is wrong because it is a collaboration hub that integrates chat, meetings, and apps, but its file storage relies on underlying SharePoint Online or OneDrive for Business; Teams itself is not a dedicated document storage service. Option D (Microsoft Viva Topics) is wrong because it is a knowledge discovery and AI-powered topic experience service that surfaces information from across Microsoft 365, not a document storage or co-authoring platform.

667
MCQeasy

A department asks for the Microsoft 365 service best suited for workflow approvals between Microsoft 365 and Dynamics 365. Which service should they use?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Defender for Endpoint
C.Power Automate
D.Microsoft Purview Compliance Manager
AnswerC

Power Automate provides the workflow engine that connects Microsoft 365 services with Dynamics 365 through hundreds of connectors, enabling automated approval flows without custom code. This directly satisfies the department's requirement for cross-platform workflow approvals, unlike Power Apps, which builds apps, or Power BI, which only visualises data.

Why this answer

Power Automate (Option C) is the correct service because it provides a low-code, workflow automation platform that integrates directly with both Microsoft 365 (e.g., SharePoint, Teams) and Dynamics 365. It enables users to create automated approval workflows using prebuilt templates and connectors, making it the ideal choice for cross-service approval processes.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager (a compliance tool) with workflow automation, or think that Privileged Identity Management can handle approvals, but PIM only manages role activation approvals, not general business workflow approvals between Microsoft 365 and Dynamics 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management (PIM) is an identity governance tool for managing, controlling, and monitoring privileged role assignments in Azure AD, not for building workflow approvals between Microsoft 365 and Dynamics 365. Option B is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response, and has no capability to create or manage workflow approvals. Option D is wrong because Microsoft Purview Compliance Manager is a compliance management tool that helps assess and manage regulatory compliance risks, not a workflow automation service.

668
MCQeasy

A small business with 15 employees needs Microsoft 365 subscriptions that include desktop versions of Office apps and business-class email. They have a limited budget. Which is the most cost-effective plan that meets these requirements?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Business Premium
D.Office 365 E1
AnswerB

Microsoft 365 Business Standard includes desktop Office apps and business-class email, satisfying both stated requirements. It costs less than Business Premium, which adds Microsoft Entra ID P1 and Intune features the 15-employee business does not need. Business Basic would fail the desktop-apps constraint, so Standard is the cheapest qualifying plan.

Why this answer

Microsoft 365 Business Standard is the most cost-effective plan that includes both desktop versions of Office apps (e.g., Word, Excel, PowerPoint) and business-class email (Exchange Online with a 50 GB mailbox and custom domain). Business Basic only provides web and mobile Office apps without desktop installations, while Business Premium adds advanced security and device management features that exceed the small business's limited budget and stated requirements. Office 365 E1 is an enterprise plan that lacks desktop Office apps entirely.

Exam trap

The trap here is that candidates often confuse 'Business Basic' (which lacks desktop Office apps) with 'Business Standard' (which includes them), or they assume 'Business Premium' is the only plan with desktop apps and email, overlooking the cost-benefit trade-off that Business Standard is the correct minimum plan for these exact requirements.

How to eliminate wrong answers

Option A (Microsoft 365 Business Basic) is wrong because it includes only web and mobile versions of Office apps with no desktop installation rights, failing the requirement for desktop Office apps. Option C (Microsoft 365 Business Premium) is wrong because while it includes desktop Office apps and email, its additional cost (approximately $22/user/month vs. $12.50/user/month for Business Standard) is driven by advanced security, compliance, and device management features (e.g., Microsoft Defender for Office 365, Intune) that are unnecessary for a small business with a limited budget. Option D (Office 365 E1) is wrong because it is an enterprise plan that provides Exchange Online email but does not include any version of the Office desktop apps, only web and mobile access.

669
MCQmedium

An administrator is reviewing a request from users who need to explain why a newly licensed user may not access an app immediately. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.License provisioning may need time after assignment
C.Microsoft Stream
D.Microsoft Forms
AnswerB

After a Microsoft 365 license is assigned, activation is not instantaneous; the service tenant must sync the license and create the necessary user objects and permissions across Exchange Online, SharePoint Online, and Teams. This provisioning process typically takes anywhere from a few minutes to up to 24 hours, depending on the workload and service health. Therefore, the correct explanation for the user's issue is that the newly assigned license needs time to fully propagate before the expected features appear.

Why this answer

When a Microsoft 365 license is assigned to a user, the provisioning of the associated services (e.g., Exchange Online, SharePoint Online) is not instantaneous. It typically takes from a few minutes up to 24 hours for the license to fully propagate and for the user to be able to access the licensed apps. This delay is a standard behavior in Microsoft 365's licensing and provisioning system, not a sign of a problem.

Exam trap

The trap here is that candidates may confuse the specific app names (Whiteboard, Stream, Forms) with the underlying licensing provisioning concept, thinking that the question is about which app is most relevant, rather than recognizing that the delay is a general licensing behavior.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a specific application, not a licensing, admin, or support concept that explains why a newly licensed user cannot access an app immediately. Option C is wrong because Microsoft Stream is a video service, and its availability depends on the license provisioning process, but it is not the core concept explaining the delay. Option D is wrong because Microsoft Forms is a survey tool, and like Whiteboard and Stream, it is an app that becomes available only after the license provisioning completes, not the reason for the delay.

670
MCQeasy

A user reports receiving a phishing email in their Outlook inbox. The organization uses Microsoft Defender for Office 365. Which feature should the user use to report the email to the security team?

A.Use the Report Message add-in in Outlook
B.Block the sender in Outlook
C.Submit the email to the Microsoft 365 Defender portal
D.Enable Safe Links in Outlook
AnswerA

The Report Message add-in submits the phishing email directly to Microsoft Defender for Office 365, letting the security team triage and tune filters. It satisfies the stem's requirement to report from within Outlook, unlike forwarding manually, which loses metadata and delays automated analysis.

Why this answer

The Report Message add-in in Outlook is the user-facing tool that lets users report suspicious emails directly to the security team with a single click. Reported messages are sent to Microsoft for analysis and can be routed to the organization's security operations team via the Microsoft 365 Defender portal's user-reported settings. This is the intended workflow for phishing reports in Defender for Office 365 environments.

Exam trap

MS-900 often tests the misconception that users should submit phishing emails through the Defender portal — the correct end-user action is the Report Message add-in, while portal submission is an admin function.

How to eliminate wrong answers

Option B is wrong because blocking the sender only affects that user's mailbox and does not notify the security team or contribute to tenant-wide threat intelligence. Option C is wrong because submitting via the Defender portal is an admin/security-team action, not the end-user reporting mechanism — users are expected to use the add-in. Option D is wrong because Safe Links is a protection feature that rewrites and scans URLs at click time; it does not report phishing emails to the security team.

671
MCQmedium

Refer to the exhibit. A Microsoft Graph PowerShell command is run. What does this command retrieve about user jdoe?

A.Only the user's display name and email.
B.All properties of the user.
C.Display name, user principal name, assigned licenses, and usage location.
D.Only the user's display name.
AnswerC

This is correct because the exhibit's command specifies Select-Object -Property DisplayName, UserPrincipalName, AssignedLicenses, UsageLocation (or equivalent -Select parameter in Get-MgUser). These four properties map exactly to the output shown: display name, user principal name, assigned licenses (as a collection of service plan identifiers), and usage location (the ISO 3166-1 alpha-2 country code). No other properties are projected, so the selected list precisely matches the stated result.

Why this answer

The command `Get-MgUser -UserId jdoe -Property DisplayName, UserPrincipalName, AssignedLicenses, UsageLocation` explicitly specifies only those four properties in the `-Property` parameter. Microsoft Graph PowerShell by default returns a subset of properties, but when you list specific properties, it retrieves only those requested. Therefore, the output includes exactly the display name, user principal name, assigned licenses, and usage location.

Exam trap

The trap here is that candidates assume the `Get-MgUser` cmdlet returns all user properties by default, but the explicit `-Property` parameter restricts the output to only the listed fields, making it a selective retrieval rather than a full one.

How to eliminate wrong answers

Option A is wrong because it claims only display name and email are retrieved, but the command explicitly requests UserPrincipalName, AssignedLicenses, and UsageLocation in addition to DisplayName, and does not request the email property (which is a separate attribute). Option B is wrong because the `-Property` parameter restricts the output to only the listed properties; without it, all default properties would be returned, but here the explicit list overrides that behavior. Option D is wrong because it states only the display name is retrieved, ignoring the other three properties explicitly specified in the command.

672
MCQmedium

A communications manager wants to create an interactive monthly newsletter that includes embedded videos, images, and links to SharePoint documents. The newsletter should be viewable on any device without needing to install an app. Which Microsoft 365 app is best suited for this?

A.Microsoft Sway
B.Microsoft PowerPoint
C.Microsoft SharePoint
D.Microsoft Stream
AnswerA

Microsoft Sway is the correct choice because it is a digital storytelling application within Microsoft 365 built specifically for creating interactive, web-based content such as newsletters. Its card-based canvas allows you to combine text, images, videos, and embedded content, and the design engine automatically generates a responsive layout that adapts to any device, which is ideal for a monthly interactive newsletter that must be visually engaging and easily shared via a link.

Why this answer

Microsoft Sway is a presentation and newsletter tool in Microsoft 365 designed specifically for creating interactive, web-based content such as newsletters, reports, and presentations. It natively supports embedding videos, images, and links, and renders responsively in any browser without requiring an installed app. This matches the communications manager's requirements exactly.

Exam trap

MS-900 often tests the distinction between content creation tools (Sway, PowerPoint) and content hosting/collaboration platforms (SharePoint, Stream), so candidates must match the specific requirement of an interactive, app-free newsletter to Sway rather than assuming SharePoint or PowerPoint can fulfill it.

How to eliminate wrong answers

Option B is wrong because PowerPoint is a slide-based presentation tool; while it can be shared online, it is not optimized for interactive newsletter-style content and typically requires the PowerPoint app or viewer for full fidelity. Option C is wrong because SharePoint is a collaboration and document management platform, not a newsletter authoring tool — it can host content but does not provide the interactive newsletter creation experience described. Option D is wrong because Microsoft Stream is a video hosting and streaming service, not a multi-format newsletter authoring tool; it cannot embed images and links in an interactive newsletter format.

673
MCQmedium

During a Microsoft 365 planning workshop, explain why Microsoft 365 is cloud-based despite local Office apps. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Cloud-hosted service backend
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerB

The correct explanation is Microsoft 365's cloud-hosted service backend: Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, and Microsoft Entra ID run on Microsoft's multi-tenant cloud infrastructure, not on local servers. Local Office apps connect to these services through HTTPS and Microsoft Graph to deliver mail, files, identity, and policy, enabling centralized management, automatic updates, and global availability. This backend is the foundational reason M365 behaves as a cloud service.

Why this answer

Microsoft 365 is considered cloud-based because its core services—such as Exchange Online, SharePoint Online, and the Microsoft 365 admin portal—are hosted and managed in Microsoft's cloud datacenters. Even though local Office apps (e.g., Word, Excel) run on the client device, they rely on a cloud-hosted service backend for licensing validation, data synchronization, and feature updates. This backend enables centralized management, automatic updates, and seamless integration with cloud services like OneDrive and Teams, which is the defining characteristic of a cloud-based platform.

Exam trap

The trap here is that candidates mistakenly think local Office apps mean the solution is not cloud-based, but Microsoft 365 is defined by its cloud-hosted backend that manages licensing, data, and updates, not by where the application code executes.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a specific cloud-based task management application within Microsoft 365, not a general cloud concept or benefit that explains why the platform is cloud-based despite local apps. Option C is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive data from being shared inappropriately, but it does not address the foundational cloud architecture or the reason local apps still qualify as cloud-based. Option D is wrong because sensitivity labels are classification and protection tools for data, not a cloud concept that describes the backend infrastructure enabling local apps to function as part of a cloud service.

674
MCQhard

Refer to the exhibit. You are reviewing a role definition in Microsoft Purview compliance portal. Which actions can a user assigned this role perform?

A.Manage compliance and data governance tasks in Microsoft Purview
B.Manage user accounts in Microsoft Entra ID
C.Manage security settings in Microsoft Defender XDR
D.View only compliance reports without making changes
AnswerA

This role definition grants the 'allTasks' permission, which provides full control across the Security & Compliance Center and Protection Center interfaces now consolidated in Microsoft Purview. With full management capability, the holder can configure retention policies, data loss prevention rules, eDiscovery cases, and other compliance data governance workloads. Because the role includes every task rather than a read-only scope, it is correctly identified as managing compliance and data governance tasks.

Why this answer

The question refers to a role definition in the Microsoft Purview compliance portal. The Compliance Administrator role (or a custom role with equivalent permissions) is designed specifically to manage compliance and data governance tasks, such as data classification, data loss prevention (DLP), eDiscovery, and retention policies. Option A correctly identifies this scope, as Purview roles do not extend to identity management or security operations in other portals.

Exam trap

The trap here is that candidates often confuse the scopes of Microsoft Purview, Microsoft Entra ID, and Microsoft Defender XDR, assuming a single admin role covers all security and compliance tasks, when in fact each portal has its own distinct RBAC model and role assignments.

How to eliminate wrong answers

Option B is wrong because managing user accounts in Microsoft Entra ID requires roles like User Administrator or Global Administrator, which are assigned in the Microsoft Entra admin center, not in the Microsoft Purview compliance portal. Option C is wrong because managing security settings in Microsoft Defender XDR requires roles like Security Administrator or Security Operator, which are assigned in the Microsoft 365 Defender portal, not in Purview. Option D is wrong because a user assigned a role in Purview can perform actions beyond viewing reports, such as creating and managing compliance policies, unless they are assigned a read-only role like Compliance Reader.

675
MCQeasy

A company has 50 users with Microsoft 365 Business Basic licenses. They need desktop versions of Office apps (Word, Excel, PowerPoint) and 1 TB of cloud storage per user. They do not need advanced security, device management, or analytics features. Which licensing upgrade is the most cost-effective?

A.Microsoft 365 Business Standard
B.Microsoft 365 Business Premium
C.Microsoft 365 E3
D.Add an Office desktop apps add-on to Business Basic
AnswerA

Microsoft 365 Business Standard is the correct upgrade because it directly addresses the gap in Business Basic: it includes the full desktop versions of Office apps (Word, Excel, PowerPoint, Outlook, and more) in addition to the 1 TB OneDrive storage, Exchange Online, Teams, and SharePoint that users already have. This gives the 50 users the locally installed productivity tools they need without paying for extra security or compliance features that are irrelevant to their stated requirement.

Why this answer

Microsoft 365 Business Standard includes desktop versions of Office apps (Word, Excel, PowerPoint) and provides 1 TB of OneDrive cloud storage per user, meeting the stated requirements exactly. It is the most cost-effective upgrade from Business Basic because it adds these features without the advanced security, device management, or analytics capabilities found in higher-tier plans.

Exam trap

The trap here is that candidates may think an add-on license exists for desktop Office apps on Business Basic, but Microsoft does not offer such an add-on; the only path is a plan upgrade, and Business Standard is the cheapest option that includes all required features without over-provisioning security or management capabilities.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Business Premium includes advanced security features (e.g., Microsoft Defender for Office 365, Conditional Access) and device management (Intune) that the company does not need, making it unnecessarily expensive. Option C is wrong because Microsoft 365 E3 is an enterprise plan designed for larger organizations with compliance and advanced analytics (e.g., eDiscovery, Power BI Pro), which exceeds the requirements and costs significantly more than Business Standard. Option D is wrong because there is no standalone 'Office desktop apps add-on' for Business Basic; the only way to get desktop Office apps is to upgrade to a plan that includes them, such as Business Standard or higher.

Page 8

Page 9 of 11

Page 10

All pages