Courseiva

CCNA M365 Apps Services Questions

75 of 300 questions · Page 1/4 · M365 Apps Services topic · Answers revealed

1
MCQeasy

A user wants to schedule a meeting with colleagues and automatically find a time that works for everyone. Which Microsoft 365 app should they use?

A.Microsoft Bookings
B.Microsoft Teams
C.Microsoft Viva Insights
D.Microsoft Outlook
AnswerD

Microsoft Outlook's Scheduling Assistant is the central tool for planning internal meetings, as it consults Exchange Online free/busy data for all invitees and graphically displays overlapping availability. It can automatically propose times when attendees and meeting rooms are all available, and it integrates directly with the calendar and meeting invitation flow. This availability-based scheduling capability is why Outlook is the correct answer.

Why this answer

Microsoft Outlook includes the Scheduling Assistant feature, which uses free/busy data from the Exchange Online calendar to automatically suggest meeting times that work for all attendees. This is the correct app for scheduling meetings with colleagues because it directly integrates with the organization's calendar system to find mutual availability.

Exam trap

The trap here is that candidates often confuse Microsoft Teams' ability to schedule a meeting (which uses Outlook's backend) with the primary app for finding mutual availability, leading them to select Teams instead of Outlook.

How to eliminate wrong answers

Option A is wrong because Microsoft Bookings is a scheduling tool for external customers to book appointments with a business, not for internal colleague meeting coordination. Option B is wrong because Microsoft Teams provides a scheduling feature that leverages Outlook's Scheduling Assistant, but it is not the primary app for finding mutual availability; Teams relies on Outlook for the underlying calendar and free/busy logic. Option C is wrong because Microsoft Viva Insights focuses on personal productivity analytics, wellbeing, and focus time suggestions, not on scheduling meetings with multiple colleagues.

2
MCQmedium

A department asks for the Microsoft 365 service best suited for task tracking using boards and buckets. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Defender for Endpoint
B.Microsoft Planner
C.Microsoft Entra Privileged Identity Management
D.Microsoft Purview Compliance Manager
AnswerB

Microsoft Planner provides native boards and buckets for task tracking, directly satisfying the department's requirement without custom operational scripts. Its Kanban-style interface organises tasks into buckets and cards, and integrates with Microsoft 365 groups for collaboration. Unlike SharePoint lists or Power Automate workarounds, Planner delivers this capability out of the box.

Why this answer

Microsoft Planner is the correct service because it provides task tracking using boards and buckets, which are core features of its Kanban-style interface. It is designed for lightweight project management within Microsoft 365, allowing users to create plans, organize tasks into buckets, and track progress without requiring custom scripts or additional configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Planner with Microsoft Project or To Do, but the question specifically requires 'boards and buckets'—a hallmark of Planner's Kanban interface—and explicitly prohibits custom scripts, ruling out more complex or script-dependent solutions.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, not a task tracking service with boards and buckets. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring access to privileged roles in Azure AD, not for task management. Option D is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessing and managing regulatory compliance risks, not a task tracking service.

3
MCQmedium

Refer to the exhibit. The JSON shows Microsoft Entra ID role assignments using Privileged Identity Management (PIM). Which statement about user2@contoso.com is correct?

A.user2 is not assigned any administrative role
B.user2 cannot access any administrative features
C.user2 must activate the Global Administrator role before using it
D.user2 is permanently assigned the Global Administrator role
AnswerC

Correct. In Microsoft Entra ID (Azure AD) Privileged Identity Management, an 'Eligible' assignment does not confer active permissions. User2 must first activate the Global Administrator role—typically by performing MFA, providing business justification, and possibly receiving approval—before they can use any Global Administrator privileges. This time-bound activation is a core security feature that reduces standing admin access and enforces just-in-time access.

Why this answer

The JSON shows that user2@contoso.com has an eligible assignment for the Global Administrator role via Microsoft Entra ID PIM. In PIM, an eligible assignment means the user must activate the role (e.g., through the PIM portal or API) before gaining administrative privileges. The JSON snippet includes a property like "assignmentType": "Eligible" (implied by the context), which requires activation to elevate permissions temporarily.

Exam trap

The trap here is that candidates may confuse 'eligible assignment' with 'no assignment' or 'permanent assignment,' failing to recognize that PIM requires activation for eligible roles, which is a core concept tested in MS-900.

How to eliminate wrong answers

Option A is wrong because the JSON explicitly includes a role assignment for user2 with the Global Administrator role, so user2 is assigned an administrative role. Option B is wrong because user2 has an eligible assignment, meaning they can access administrative features after activating the role; they are not permanently blocked from administrative features. Option D is wrong because the assignment is eligible, not permanent (active); a permanent assignment would have an "assignmentType": "Active" or no activation requirement, which is not indicated in the exhibit.

4
MCQeasy

A user wants to access their work files from a personal laptop without installing any Microsoft 365 Apps. Which web-based service allows them to view and edit documents in a browser?

A.Microsoft OneDrive
B.Microsoft 365 for the web
C.Microsoft Teams
D.Microsoft SharePoint
AnswerB

Microsoft 365 for the web, formerly known as Office Online, delivers browser-based versions of Word, Excel, PowerPoint, and other Office applications. It allows users to view, create, and edit documents directly in a web browser without requiring any local installation, making it ideal for accessing work files from a personal laptop. As long as the user has an internet connection and appropriate licensing, they can use these web apps for full editing capability, which directly addresses the user's need.

Why this answer

Microsoft 365 for the web (formerly Office Web Apps) provides browser-based versions of Word, Excel, PowerPoint, and OneNote, enabling users to view and edit documents without installing any local applications. This service is accessed through a web browser on any device, including a personal laptop, and requires only an internet connection and a valid Microsoft 365 subscription.

Exam trap

Microsoft often tests the distinction between storage services (OneDrive, SharePoint) and the actual web-based editing service (Microsoft 365 for the web), causing candidates to mistakenly choose OneDrive because it is the most familiar file-access option.

How to eliminate wrong answers

Option A is wrong because Microsoft OneDrive is primarily a cloud storage and file synchronization service, not a web-based document editing suite; while it can launch documents in Microsoft 365 for the web, OneDrive itself does not provide the editing capabilities. Option C is wrong because Microsoft Teams is a collaboration platform focused on chat, meetings, and channel-based communication, not a dedicated web-based document editor; although it integrates with Office for the web for file previews, its primary function is not browser-based document creation and editing. Option D is wrong because Microsoft SharePoint is a web-based document management and collaboration platform that stores and organizes files, but it relies on Microsoft 365 for the web or desktop apps to actually edit documents; SharePoint itself does not provide the in-browser editing functionality.

5
MCQmedium

A project manager wants to create a visual dashboard that tracks project tasks, deadlines, and progress. The dashboard should pull data from a Microsoft List and update in real time. Which Microsoft 365 app is best suited for building this interactive dashboard?

A.Microsoft Lists
B.Power BI
C.SharePoint Online
D.Microsoft Forms
AnswerB

Power BI is a dedicated business analytics suite that directly connects to Microsoft Lists, SharePoint, and other data sources to build live, interactive dashboards. It lets you create custom visuals, apply cross-filtering, set up conditional formatting, and publish reports to the Microsoft 365 ecosystem, making it the only option here that natively delivers the requested task-deadline dashboard with rich user interactivity and scheduled data refreshes.

Why this answer

Power BI is the correct choice because it is designed to create interactive, real-time dashboards with live data connectivity. It can connect directly to a Microsoft List as a data source and refresh automatically, enabling real-time tracking of project tasks, deadlines, and progress with visualizations like charts and gauges.

Exam trap

The trap here is that candidates often confuse Microsoft Lists (a data source) with a dashboard tool, or assume SharePoint's built-in list views are sufficient for interactive, real-time dashboards, overlooking Power BI's specialized visualization and refresh capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data storage and tracking app, not a dashboard-building tool; it lacks native interactive visualization and real-time dashboard capabilities. Option C is wrong because SharePoint Online provides list and library functionality but does not offer the dedicated, interactive dashboard creation and real-time data refresh features of Power BI. Option D is wrong because Microsoft Forms is a survey and quiz tool for collecting responses, not for building dashboards or visualizing real-time data.

6
Multi-Selecthard

A marketing manager wants to create a mobile-friendly app that field sales representatives can use to submit expense reports with photos of receipts. The app should automatically save the data to a SharePoint list and send an email notification to the manager. Which two Microsoft 365 technologies should the developer use to build this solution? (Choose two.)

Select 2 answers
A.Microsoft Power Apps
B.Microsoft Power Automate
C.Microsoft SharePoint
D.Microsoft Power BI
AnswersA, B

Power Apps is the low-code platform purpose-built for creating custom mobile-friendly apps. You can design a canvas app with a responsive layout, add screens for capturing receipt photos and numeric data, and bind those controls directly to a SharePoint list through the SharePoint connector. This gives the marketing manager a real app interface without writing traditional code, making it the correct tool for the app-building requirement.

Why this answer

Microsoft Power Apps is correct because it enables rapid development of mobile-friendly apps with minimal code, allowing field sales representatives to capture expense data and receipt photos directly from their devices. It integrates seamlessly with SharePoint lists for data storage, making it the ideal low-code platform for this custom business app.

Exam trap

The trap here is that candidates often confuse SharePoint as a development tool for building apps, when in reality it is only a data storage service, while Power Apps and Power Automate are the actual low-code development and automation technologies required.

7
MCQmedium

An administrator is reviewing a request from users who need to host training videos securely for employees. Microsoft 365 app or service is the best fit?

A.Microsoft Purview Audit
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Stream
AnswerD

Microsoft Stream is Microsoft 365's enterprise video service, designed specifically for uploading, transcribing, searching, and playing videos across an organization with access controls. Stream integrates with Teams, SharePoint, and Viva and can handle training videos as part of a centralized, managed content library. With built-in support for permissions, captions, and analytics, it fully meets the requirement to host and share training videos.

Why this answer

Microsoft Stream is the correct choice because it is Microsoft 365's enterprise video service designed specifically for securely hosting, sharing, and managing training videos within an organization. It integrates with Azure AD for access control, supports permissions-based sharing, and provides features like transcripts, chapters, and engagement analytics, making it ideal for internal training content.

Exam trap

The trap here is that candidates may confuse Microsoft Stream with other Microsoft 365 apps that have 'video' or 'media' in their name or assume that any app with sharing capabilities (like Forms or Planner) can handle video, but only Stream is purpose-built for secure enterprise video hosting and management.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Audit is a compliance and auditing tool that logs user and admin activities across Microsoft 365, not a service for hosting or streaming video content. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, not designed for video hosting or secure streaming of training materials. Option C is wrong because Microsoft Planner is a task management and project planning application, lacking any video storage, streaming, or permission management capabilities.

8
MCQmedium

A project manager needs to create a detailed project schedule with a Gantt chart view, task dependencies, critical path analysis, and milestones. The schedule must be shared with team members who can update their tasks, and the manager wants to track progress against a baseline. Which Microsoft 365 app is specifically designed for this type of project management?

A.Microsoft Lists
B.Microsoft Project
C.Microsoft Planner
D.Microsoft Excel
AnswerB

Microsoft Project (including Project for the Web, Project Online, and Project desktop) is the M365 portfolio's dedicated project management application. It has native Gantt chart views, supports task dependencies with lead/lag, constraint types, resource assignments, and critical path analysis, and saves baselines for variance tracking. Because scheduling is algorithmic, changes to one task automatically recalculate downstream dates across the entire plan. This is the correct choice when the requirement is to 'create a detailed project schedule with a Gantt chart view.'

Why this answer

Microsoft Project is the correct answer because it is specifically designed for advanced project management, offering native support for Gantt charts, task dependencies, critical path analysis, milestones, baseline tracking, and collaborative task updates. Unlike simpler tools, Project provides the scheduling engine and analytical capabilities required for detailed, enterprise-grade project plans.

Exam trap

The trap here is that candidates confuse Microsoft Planner's Kanban-style task management with full project scheduling, overlooking that Planner lacks Gantt charts, dependency chains, critical path analysis, and baseline tracking—features that are exclusive to Microsoft Project in the Microsoft 365 ecosystem.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data-tracking and organization app for creating custom lists (e.g., issue trackers, inventories), not a project scheduling tool—it lacks Gantt charts, dependency modeling, critical path analysis, and baseline tracking. Option C is wrong because Microsoft Planner is a lightweight task management app for team collaboration with Kanban boards and basic due dates, but it does not support Gantt charts, task dependencies, critical path analysis, or baseline tracking. Option D is wrong because Microsoft Excel is a spreadsheet application that can manually simulate a Gantt chart or schedule, but it has no built-in project management engine for automatic dependency resolution, critical path calculation, or baseline comparison.

9
MCQeasy

A sales team needs to collaborate on documents in real time, track changes, and co-author using familiar desktop tools. Which Microsoft 365 app should they use?

A.Microsoft Teams
B.Microsoft OneNote
C.Microsoft Word
D.Microsoft Planner
AnswerC

Microsoft Word is the correct choice because it is a full-featured word processor with native real-time co-authoring support for .docx files stored in OneDrive or SharePoint. Multiple authors can work simultaneously in Word for the web or Word desktop, with presence indicators, inline comments, version history, and Track Changes showing every insertion, deletion, or formatting change for later accept/reject. This precisely meets the sales team's need to collaborate on documents in real time while preserving an auditable editing trail.

Why this answer

Microsoft Word is the correct choice because it is the desktop app that natively supports real-time co-authoring, change tracking, and simultaneous editing by multiple users. These features are built into Word for Microsoft 365, allowing teams to collaborate on documents using the familiar desktop interface without needing to switch to a web or mobile app.

Exam trap

The trap here is that candidates often confuse Microsoft Teams' file-sharing capability with actual document editing, assuming Teams itself provides co-authoring, when in fact it merely hosts the file and launches Word for editing.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and file sharing, but it does not provide native desktop co-authoring or change tracking within its interface; documents opened in Teams are edited in Word Online or the Word desktop app. Option B is wrong because Microsoft OneNote is a digital notebook for free-form note-taking and does not support structured document co-authoring with tracked changes like a word processor. Option D is wrong because Microsoft Planner is a task management and project planning tool that organizes work with boards and checklists, not a document editing or co-authoring application.

10
MCQhard

A company is deploying Microsoft Teams Rooms for its meeting rooms. They need to ensure that room calendars are automatically updated when a meeting is booked via Outlook. Which Microsoft 365 service enables this integration?

A.Microsoft Intune
B.Exchange Online
C.Microsoft Teams
D.SharePoint Online
AnswerB

Exchange Online is correct because it hosts the resource mailboxes that represent meeting rooms and runs the calendar processing logic for those mailboxes. When a Teams Rooms device displays availability or receives a booking, it is querying and updating the room mailbox in Exchange Online, which accepts or declines the invitation. This makes Exchange Online the component that manages calendars for Teams Rooms.

Why this answer

Exchange Online is the correct answer because it provides the mailbox and calendar infrastructure that Microsoft Teams Rooms relies on. When a meeting is booked via Outlook, the Exchange Online calendar processes the booking and automatically updates the room's calendar, enabling the Teams Rooms device to display the meeting details. This integration uses the Exchange Web Services (EWS) or REST APIs to synchronize calendar events between Outlook and the room resource mailbox.

Exam trap

The trap here is that candidates often assume Microsoft Teams directly manages room calendars because Teams Rooms is a Teams feature, but in reality, the calendar integration is entirely dependent on Exchange Online's resource mailbox and calendar processing capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service used for managing devices and apps, not for calendar synchronization or room mailbox updates. Option C is wrong because Microsoft Teams is the collaboration platform that provides the meeting experience, but it does not directly manage room calendars; it relies on Exchange Online for calendar data. Option D is wrong because SharePoint Online is a document management and collaboration platform focused on content storage and sharing, with no native capability to process room bookings or update room calendars.

11
MCQmedium

A sales team uses Microsoft Teams for collaboration. They need to securely share large files (up to 15 GB) with external partners without requiring the partners to sign in. Which Microsoft 365 service should they use?

A.OneDrive for Business
B.Microsoft Lists
C.Microsoft Stream
D.SharePoint Online
AnswerA

OneDrive for Business is a personal cloud library in Microsoft 365 that supports sharing large files via 'Anyone with the link' anonymous sharing, allowing external recipients to download without a Microsoft account or sign-in. This makes it the most direct solution for a sales team needing to send sizable files to outside parties. The default maximum file size is 250 GB, and you can set expiration dates and passwords for extra security.

Why this answer

OneDrive for Business allows users to share files with external partners via a secure link that does not require the partner to sign in, and supports file sizes up to 250 GB (including the 15 GB requirement). This meets the need for large file sharing without authentication, leveraging OneDrive's external sharing capabilities with anonymous guest links.

Exam trap

The trap here is that candidates may choose SharePoint Online because it is a general-purpose collaboration platform, but they overlook the specific requirement of 'without requiring the partners to sign in,' which is more natively and commonly achieved via OneDrive for Business anonymous links, whereas SharePoint Online typically enforces authentication or a verification code by default.

How to eliminate wrong answers

Option B is wrong because Microsoft Lists is a data-tracking and organization app for creating lists, not designed for file sharing or external collaboration with large files. Option C is wrong because Microsoft Stream is a video hosting and management service, not intended for sharing arbitrary large files like documents or archives. Option D is wrong because SharePoint Online supports external sharing but, by default, requires recipients to sign in or verify their identity via a one-time code; anonymous sharing without sign-in is possible only if explicitly enabled by the admin, and the question specifies 'without requiring the partners to sign in,' making OneDrive for Business the more straightforward and commonly used solution for this scenario.

12
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Defender for Cloud Apps access policy configuration. What does this policy do?

A.Allows access but prevents downloads from the specified IP range
B.Allows access to the SharePoint site only from the specified IP range
C.Blocks access from the specified IP range to the SharePoint site and prevents downloads
D.Disables the policy for the SharePoint site
AnswerC

This is the correct description. The policy's access rule is set to 'Block', which denies all access to the SharePoint site from the specified IP range. Independently, the download rule is also set to 'Block', so even if access were permitted by another policy, downloads would be prevented. Together, the policy imposes both an access block and a download block for that IP range.

Why this answer

This policy is configured with an action of 'Block' and a 'Download (including printing)' control set to 'Block' for the specified IP range. When both access and download are blocked, the result is that users from that IP range are completely denied access to the SharePoint site and cannot download any files. Option C correctly describes this combined blocking behavior.

Exam trap

The trap here is that candidates often focus on the 'Download' control and assume the policy only restricts downloads (Option A), overlooking that the 'Access' action is set to 'Block', which completely denies access from the specified IP range.

How to eliminate wrong answers

Option A is wrong because the policy blocks access entirely, not just downloads; the 'Access' action is set to 'Block', not 'Allow'. Option B is wrong because the policy blocks access from the specified IP range, rather than allowing it only from that range; the action is 'Block', not 'Allow only'. Option D is wrong because the policy is enabled and actively blocking, not disabled; the policy state is not set to 'Disabled'.

13
MCQmedium

A marketing team needs to create a professional-looking newsletter that includes embedded videos, images, and links to documents. The newsletter should be viewable on any device and allow team members to collaborate on the content. Which Microsoft 365 app is best suited for this purpose?

A.Word Online
B.Sway
C.Publisher
D.OneNote
AnswerB

Sway is Microsoft's digital storytelling app designed specifically for creating visually engaging, interactive newsletters that automatically adapt to any screen size. Its card-based canvas lets users mix text, images, videos, and embed content from social media or the web, with a built-in design engine that applies consistent styling. Sway supports real-time collaboration and sharing via a unique URL, making it ideal for a marketing team that needs a professional-looking, device-friendly newsletter without requiring coding or design expertise. Unlike static documents, Sway's responsive layout and interactive elements (e.g., clickable slideshows, embedded media) differentiate it as the right choice.

Why this answer

Sway is the correct choice because it is specifically designed for creating interactive, web-based reports and newsletters that can embed videos, images, and links to documents. It provides responsive design that automatically adapts to any device, and it supports real-time collaboration through sharing a link, allowing team members to co-author content.

Exam trap

The trap here is that candidates often confuse Sway with Word Online or Publisher because they associate newsletters with traditional document creation, but Sway is the only Microsoft 365 app that combines rich media embedding, responsive web output, and real-time collaboration in a single tool.

How to eliminate wrong answers

Option A is wrong because Word Online is primarily a word processor for creating text-heavy documents; while it can embed images and links, it lacks native support for embedded videos and its layout is not optimized for responsive, device-agnostic newsletters. Option C is wrong because Publisher is a desktop publishing app focused on print layouts (e.g., brochures, flyers) and does not support embedded videos or responsive web viewing; it also lacks real-time collaboration features. Option D is wrong because OneNote is a digital notebook for capturing notes and ideas, not designed for creating polished, professional newsletters with embedded media and collaborative editing in a presentation-style format.

14
MCQmedium

A company uses Microsoft 365 Business Premium. All users have Microsoft 365 E3 licenses, but the IT team wants to enforce conditional access policies to require multifactor authentication (MFA) for all external access to SharePoint Online. Which service should they use to create and manage these policies?

A.Microsoft Defender XDR
B.Microsoft Intune
C.Microsoft Entra ID
D.Microsoft Purview
AnswerC

Microsoft Entra ID (formerly Azure Active Directory) is the identity and access management service in Microsoft 365, and its Conditional Access engine is the correct place to enforce MFA for all users. Conditional Access policies evaluate sign-in signals such as user risk, device state, location, and application, and then require MFA or block access. Administrators would create a policy in Entra ID to require MFA for all users or specific conditions, which is exactly what this scenario demands.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the identity and access management service that provides Conditional Access policies, which can require MFA for external access to SharePoint Online. These policies are evaluated at authentication time based on signals like user location, device state, and application, and they are independent of the underlying Microsoft 365 license (E3 or Business Premium).

Exam trap

The trap here is that candidates confuse Microsoft Intune's device compliance policies with Conditional Access policies, but Intune only provides the compliance state signal, while Entra ID is the service that evaluates and enforces the access decision.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is a security analytics and threat response platform that correlates signals across endpoints, email, and identities, but it does not create or manage Conditional Access policies. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service that enforces device compliance and app protection policies, but it does not handle Conditional Access policy creation. Option D is wrong because Microsoft Purview is a data governance, compliance, and risk management solution that focuses on data classification, retention, and eDiscovery, not on identity-based access controls like Conditional Access.

15
Multi-Selecthard

Which TWO Microsoft 365 apps use AI to assist users with content creation?

Select 2 answers
A.Microsoft PowerPoint with Copilot
B.Microsoft Word with Copilot
C.Microsoft Viva Insights
D.Microsoft Excel with Copilot
E.Microsoft Teams with Copilot
AnswersA, B

Copilot in PowerPoint uses natural language prompts to generate full presentation decks, including slide layouts, images, and speaker notes, directly from a user's intent. This is a content-creation feature because it produces original presentation assets, not merely analyzes existing data or surfaces productivity insights. It also supports one-click summarization and restructuring of existing decks, further reinforcing its role in creating and refining presentation content.

Why this answer

Microsoft PowerPoint with Copilot and Microsoft Word with Copilot are correct because Copilot in these apps leverages large language models (LLMs) integrated with the Microsoft Graph to generate, summarize, and refine content directly within the document or presentation. In PowerPoint, Copilot can create entire slide decks from a prompt or natural language outline, while in Word, it can draft text, rewrite paragraphs, or summarize documents, both using AI to assist users in content creation.

Exam trap

The trap here is that candidates may assume any Copilot-enabled app (like Excel or Teams) qualifies as 'content creation,' but the MS-900 exam specifically distinguishes between AI for content generation (Word, PowerPoint) and AI for data analysis or meeting summarization (Excel, Teams), so you must identify which apps focus on creating new textual or visual content.

16
MCQhard

A multinational corporation uses Microsoft 365 E5 and wants to implement a retention policy that automatically deletes emails in users' mailboxes after 7 years, except for emails from the legal department which must be retained indefinitely. Which approach should the admin use?

A.Apply a litigation hold to all mailboxes and a retention policy to delete after 7 years
B.Configure Exchange Online archive policies to move emails after 7 years
C.Create a default retention policy for 7 years and use auto-labeling for legal department emails
D.Use Microsoft Purview eDiscovery to manually delete emails after 7 years
AnswerC

This approach separates retention behaviors by scope: a default Microsoft 365 retention policy enforces deletion of all general mailbox content after 7 years, satisfying systematic destruction. Auto-labeling then identifies legal department emails—using sensitive info types, trainable classifiers, or keywords—and applies a retention label with indefinite retention, which overrides the default deletion policy. The result is a compliant dual outcome: non-legal email is purged on schedule, while legal correspondence is preserved permanently.

Why this answer

It uses a retention policy with a 7-year deletion period for all content, then overrides that for legal department emails via auto-labeling with a 'retain indefinitely' label. This ensures that only legal emails are preserved forever while all other emails are automatically purged after 7 years, meeting the compliance requirement without manual intervention.

Exam trap

The trap here is that candidates confuse litigation hold (which preserves everything indefinitely) with a retention label that allows indefinite retention for a subset of items, leading them to choose Option A instead of understanding that litigation hold blocks deletion for all content.

How to eliminate wrong answers

Option A is wrong because a litigation hold preserves all mailbox content indefinitely, preventing the 7-year deletion policy from taking effect on any emails, including non-legal ones. Option B is wrong because Exchange Online archive policies only move emails to the archive mailbox after a specified period; they do not delete emails, so they cannot meet the deletion requirement. Option D is wrong because eDiscovery is a search and export tool, not a retention or deletion mechanism; manually deleting emails after 7 years is impractical, error-prone, and violates the automated compliance requirement.

17
MCQeasy

A marketing team needs to collaborate on a campaign document in real time and track changes. Which Microsoft 365 app should they use?

A.Teams
B.Word
C.OneNote
D.SharePoint
AnswerB

Word supports real-time co-authoring and built-in tracked changes, directly meeting the marketing team's need to collaborate simultaneously on the campaign document while recording revisions. Unlike SharePoint or Teams, which host and share files, Word provides the document editing and change-tracking functionality the scenario requires.

Why this answer

Microsoft Word is the application designed for creating and editing documents with real-time co-authoring and built-in track changes, which is exactly what the marketing team needs for a campaign document. Word supports simultaneous editing by multiple users and provides a full revision history with accept/reject change tracking. This makes it the correct choice for document collaboration with change tracking.

Exam trap

MS-900 often tests the confusion between the collaboration platform (Teams, SharePoint) and the authoring application (Word), so candidates pick Teams or SharePoint thinking they handle document editing and track changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and file sharing — it hosts the document but is not the app used to author and track changes in it. Option C is wrong because OneNote is a note-taking application optimized for free-form notes and notebooks, not for formal document editing with track changes. Option D is wrong because SharePoint is a document management and storage platform — it stores and versions files but does not itself provide the rich document editing and track-changes experience that Word does.

18
MCQmedium

A sales team wants to build a custom inventory tracking application with minimal code. They need a cloud-based database that can securely store structured data and integrate with the low-code app builder. Which Microsoft 365 service should they use as the database backend?

A.Microsoft Lists
B.Power Apps
C.Microsoft Dataverse
D.Power Automate
AnswerC

Microsoft Dataverse is the correct choice because it is a fully managed, low-code data platform that provides relational tables, rich metadata, role-based security, and built-in auditing for structured business data. It is tightly integrated with Power Apps and the Power Platform, enabling the sales team to model inventory items, relationships, and business rules without writing custom code, all within a scalable, secure cloud database.

Why this answer

Microsoft Dataverse is the correct choice because it provides a scalable, cloud-based relational database that securely stores structured data and integrates natively with Power Apps, the low-code app builder. Unlike simpler list-based storage, Dataverse supports rich data types, relationships, business logic, and role-based security, making it ideal for custom inventory tracking applications built with minimal code.

Exam trap

The trap here is that candidates often confuse Microsoft Lists (a simple list tool) with a proper database backend, or mistakenly think Power Apps or Power Automate can serve as data storage, when in fact they are application and automation layers that require a separate data source like Dataverse.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a list-based data storage service designed for simple tracking and collaboration, not a full relational database with support for complex relationships, business rules, and integration with low-code app builders like Power Apps. Option B is wrong because Power Apps is the low-code app builder itself, not a database backend; it requires a data source such as Dataverse, SharePoint, or SQL to store and retrieve data. Option D is wrong because Power Automate is a workflow automation service for creating automated processes, not a database; it can trigger actions based on data but does not provide persistent storage for structured inventory data.

19
Multi-Selectmedium

Which TWO Microsoft 365 apps can be used to create and share forms for surveys? (Select exactly 2.)

Select 2 answers
A.Microsoft Forms
B.Microsoft Teams
C.Microsoft Outlook
D.OneNote
E.Microsoft Excel
AnswersA, E

Microsoft Forms is the dedicated web-based application for creating surveys, quizzes, and polls in Microsoft 365. It provides a rich authoring environment with question types, branching logic, and real-time response analytics, and it lets you share forms via links, QR codes, or email. While it integrates with Excel to export responses, the form creation itself occurs exclusively within Forms, making it the correct answer.

Why this answer

Microsoft Forms is a dedicated survey and quiz creation tool within Microsoft 365, allowing users to design forms, collect responses, and export data to Excel. It integrates with Teams and SharePoint for sharing, but the core creation and sharing capability for surveys is native to Forms itself. Microsoft Excel can also be used to create forms via the 'Insert > Forms' option, which leverages the same underlying Forms service to generate and share surveys directly from a spreadsheet.

Exam trap

The trap here is that candidates often mistake Microsoft Teams as a form creation tool because they see forms shared within Teams channels, but Teams is merely a distribution platform, not a creation app.

20
MCQeasy

A marketing team wants to quickly create a visually appealing report from data stored in Excel and share it with stakeholders via a web browser. Which Microsoft 365 app should they use?

A.Microsoft Forms
B.Microsoft Stream
C.Microsoft Excel
D.Microsoft Power BI
AnswerD

Power BI is Microsoft's dedicated business intelligence tool for turning data into interactive, visually rich reports. Users can connect to dozens of data sources, build cross-filtering visuals, add drilldowns, and publish to the Power BI service, where colleagues access the report in a browser or mobile app. This directly matches the team's need to quickly create and share an appealing, interactive report.

Why this answer

Microsoft Power BI is the correct choice because it is designed specifically for creating interactive, visually appealing reports and dashboards from data sources like Excel. It allows users to publish these reports to the Power BI service, where stakeholders can access them via a web browser without needing to install any software.

Exam trap

The trap here is that candidates may choose Microsoft Excel because they think it can create charts and share them via OneDrive or SharePoint, but they overlook that Power BI is the dedicated tool for interactive, browser-based reporting with advanced visualization and sharing capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz tool, not a data visualization or reporting app; it cannot create reports from Excel data. Option B is wrong because Microsoft Stream is a video hosting and sharing platform, not designed for data analysis or report creation. Option C is wrong because while Microsoft Excel can create charts and graphs, it lacks the native capability to publish interactive, browser-accessible reports with the same level of visual interactivity and sharing controls as Power BI.

21
Multi-Selectmedium

Which TWO Microsoft 365 services provide real-time co-authoring in documents?

Select 2 answers
A.Microsoft Teams
B.SharePoint Online
C.Microsoft Lists
D.Exchange Online
E.OneDrive for Business
AnswersB, E

SharePoint Online stores documents in document libraries and natively supports real-time co-authoring via the Office Web Apps and desktop applications, allowing multiple users to edit a document simultaneously with presence indicators and automatic versioning. Because SharePoint is a first-class document management service, it is one of the two correct services.

Why this answer

SharePoint Online is correct because it supports real-time co-authoring in Word, Excel, and PowerPoint documents stored in SharePoint document libraries, leveraging the Office Online server infrastructure and the WebDAV protocol for simultaneous edits by multiple users.

Exam trap

The trap here is that candidates may confuse Microsoft Teams' file-sharing and preview capabilities with actual real-time co-authoring, but Teams merely surfaces files from SharePoint or OneDrive and does not host the co-authoring engine itself.

22
Multi-Selectmedium

Which TWO Microsoft 365 apps are primarily used for business process automation and workflow? (Select two.)

Select 2 answers
A.Microsoft Planner
B.Microsoft To Do
C.Microsoft Forms
D.Microsoft Power Apps
E.Microsoft Power Automate
AnswersD, E

Power Apps is a low-code development platform for building custom business applications that can pull from Microsoft Dataverse, SharePoint, and hundreds of data connectors. Users create canvas, model-driven, or portal apps with responsive UI and business rules, enabling organizations to solve specific operational problems without writing traditional code. Because it is designed to digitize and customize end-to-end business processes, it is one of the two Microsoft/Power Platform apps primarily used for business.

Why this answer

Microsoft Power Apps is a low-code application development platform that enables users to build custom business apps for process automation, while Microsoft Power Automate (formerly Flow) is a cloud-based service for creating automated workflows between apps and services. Together, they form the core of Microsoft's Power Platform for business process automation and workflow orchestration.

Exam trap

The trap here is that candidates often confuse task management tools (Planner, To Do) with workflow automation platforms, or mistake data collection tools (Forms) for process automation, because all involve 'tasks' or 'forms' but lack the underlying workflow engine and integration capabilities.

23
Multi-Selecthard

Which THREE Microsoft 365 compliance features are available in Microsoft Purview to help organizations manage data lifecycle and retention?

Select 3 answers
A.Sensitivity Labels
B.Records Management
C.Data Lifecycle Management
D.Retention Policies
E.Data Loss Prevention
AnswersB, C, D

Records Management is a dedicated Microsoft Purview solution that lets organizations declare content as records, meaning it is retained and disposed of according to defined rules, and users cannot alter or delete it. It uses retention labels with event-based or manual disposition reviews to manage records from declaration through final disposition. This directly addresses compliance requirements for legal and regulatory retention, making it one of the correct features for lifecycle governance.

Why this answer

Records Management (B) is correct because it enables organizations to declare records, apply retention labels, and manage the disposition of content in a defensible manner. It is a core Purview feature for managing the data lifecycle, ensuring that records are retained for the required period and then disposed of appropriately.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels with retention features because both are part of Purview, but Sensitivity Labels control access and protection, not the lifecycle or retention duration of data.

24
Multi-Selecteasy

Which TWO Microsoft 365 services can be used to create and manage tasks?

Select 2 answers
A.Power Automate
B.Microsoft Planner
C.Microsoft Word
D.Microsoft To Do
E.SharePoint
AnswersB, D

Microsoft Planner is a team-based task management service in Microsoft 365, part of the Power Platform and Teams. Each plan is a shared board with buckets, tasks, due dates, checklists, labels, and assignments, enabling groups to organize work visually. It directly satisfies the rubric of creating and managing tasks within a shared team context.

Why this answer

Microsoft Planner (B) is a dedicated Microsoft 365 task-management service where teams create plans, buckets, and tasks with assignments, due dates, checklists, and progress tracking, so it directly satisfies the requirement to create and manage tasks. Microsoft To Do (D) is the personal task-management app in Microsoft 365 that lets users create task lists, set reminders, due dates, steps, and sync tasks (including flagged Outlook items and assigned Planner tasks), so it also directly creates and manages tasks. Power Automate (A) is a workflow/automation service that triggers actions across services rather than a task-management tool itself, so it does not belong.

Microsoft Word (C) is a document-authoring application with no native task-management capability, and SharePoint (E) is a collaboration and content platform whose lists can store task-like items but it is not one of the two designated task creation/management services here.

Exam trap

The trap here is that candidates may confuse SharePoint's ability to create custom task lists with being a dedicated task management service, but SharePoint lacks the native Kanban boards, assignment workflows, and integration with To Do that define Planner and To Do as the correct answers.

25
MCQmedium

A financial services company uses Microsoft 365 E5 and wants to implement a data loss prevention (DLP) policy that blocks users from sharing credit card numbers via email and Teams messages. The compliance team also wants to generate reports on policy violations. They are considering using Microsoft Purview. Which approach should they take to meet these requirements with minimum administrative overhead?

A.Create separate DLP policies in Exchange admin center and Teams admin center.
B.Create a unified DLP policy in the Microsoft Purview compliance portal that covers Exchange and Teams.
C.Use Microsoft Sentinel to create analytics rules that detect sharing of credit card numbers.
D.Use Microsoft Defender for Cloud Apps to create session policies for email and Teams.
AnswerB

A single unified DLP policy in Microsoft Purview applies across Exchange and Teams, blocking credit card numbers in both and generating violation reports. This meets both requirements with minimum administrative overhead, avoiding separate per-workload policies.

Why this answer

A unified DLP policy in Microsoft Purview covers Exchange Online, Teams, SharePoint, and OneDrive from a single policy definition, so credit card numbers (a built-in sensitive information type) can be blocked across both email and Teams chat with one configuration. This minimizes administrative overhead because there is no need to duplicate rules across separate admin centers, and violation reports are consolidated in the Purview compliance portal.

Exam trap

MS-900 often tests the misconception that DLP must be configured separately per workload (Exchange vs Teams), when Microsoft Purview provides a single unified policy engine across Microsoft 365 workloads.

How to eliminate wrong answers

Option A is wrong because creating separate DLP policies in the Exchange admin center and Teams admin center duplicates configuration, increases maintenance overhead, and does not provide a single unified reporting view. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR platform for detection and investigation of security events, not a preventive DLP control that blocks sharing of sensitive data in real time. Option D is wrong because Defender for Cloud Apps session policies apply to cloud app access via Conditional Access App Control (typically for unsanctioned or third-party SaaS apps), not to native Exchange and Teams DLP enforcement.

26
MCQmedium

A project team needs to create a shared workspace to manage tasks, share files, track project milestones, and communicate through conversation threads. They want a single app that integrates with other Microsoft 365 services like Outlook and Teams. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft Planner
B.Microsoft To Do
C.Microsoft Project for the web
D.Microsoft Lists
AnswerA

Microsoft Planner is correct because it provides a shared Kanban-style task board within Microsoft 365, where team members can create buckets, assign tasks, set due dates, attach files, and add checklists. Each task includes a comments section for threaded, collaborative conversations, and the board offers real-time progress charts. Planner integrates natively as a tab in Microsoft Teams and syncs with Outlook tasks, making it purpose-built for lightweight team project management and milestone tracking.

Why this answer

Microsoft Planner is best suited because it provides a shared workspace with buckets and cards for task management, file attachments, milestone tracking via checklists and due dates, and conversation threads on each task. It integrates natively with Outlook for task visibility and with Teams via the Planner tab, meeting the requirement for a single app that combines these capabilities.

Exam trap

The trap here is that candidates confuse Microsoft To Do as a team tool because of its integration with Outlook tasks, but it lacks shared workspaces and team collaboration features, which are core to Planner.

How to eliminate wrong answers

Option B (Microsoft To Do) is wrong because it is a personal task management app focused on individual to-do lists and lacks shared workspaces, file sharing, milestone tracking, and conversation threads for team collaboration. Option C (Microsoft Project for the web) is wrong because it is designed for complex project portfolio management with Gantt charts and resource allocation, not for lightweight task management with conversation threads and file sharing in a single app. Option D (Microsoft Lists) is wrong because it is a data tracking app for creating custom lists (e.g., inventory, issues) and does not include built-in task management features like buckets, checklists, or conversation threads.

27
Multi-Selectmedium

Which of the following are included as part of Microsoft 365 E3 or E5 subscriptions? Choose all that apply. (There are four correct answers.)

Select 4 answers
.Microsoft Teams
.Exchange Online with 100 GB mailbox and unlimited storage via archiving
.Windows 10/11 Enterprise E3
.Microsoft Defender for Office 365
.Azure Active Directory Premium P1 only (not P2)
.Microsoft 365 Personal (single user) license

Why this answer

Microsoft 365 E3 and E5 subscriptions include Microsoft Teams as a core collaboration service, Exchange Online with a 100 GB mailbox and unlimited archive storage via auto-expanding archiving, Windows 10/11 Enterprise E3 for device management and security, and Microsoft Defender for Office 365 (in E5, and as an add-on for E3 but included in the E5 suite). These are standard components of the enterprise-grade plans.

Exam trap

Microsoft often tests the misconception that Azure AD Premium P1 is the only identity tier in E3/E5, but E5 actually includes P2, and that Microsoft 365 Personal is a valid enterprise license, when it is a consumer-only product.

28
Multi-Selecteasy

Which TWO apps are included in Microsoft Viva?

Select 2 answers
A.Microsoft Stream
B.Microsoft Teams
C.Viva Connections
D.Microsoft Power Automate
E.Viva Insights
AnswersC, E

Viva Connections is a core Microsoft Viva app that serves as a personalized gateway to company resources, news, tasks, and tools within Teams. It aggregates internal communications and common actions into a single, curated employee experience. This makes it directly part of the Viva suite, fulfilling the requirement for an app included in Microsoft Viva.

Why this answer

Viva Connections is a core app within Microsoft Viva that provides a personalized employee experience dashboard, integrating company news, resources, and tasks directly into Microsoft Teams. Viva Insights is another core app that offers data-driven privacy-protected insights to help employees improve productivity and well-being. Both are explicitly part of the Microsoft Viva employee experience platform.

Exam trap

The trap here is that candidates confuse the platform (Microsoft Teams) with the apps that run on it (Viva Connections, Viva Insights), leading them to select Teams as a Viva app instead of recognizing it as the host environment.

29
MCQmedium

A company needs to provide external partners with access to a specific SharePoint Online site without granting them access to the entire tenant. Which approach should the administrator use?

A.Configure SharePoint Online external sharing and invite partners as authenticated users
B.Create an Azure AD B2C tenant for partners
C.Use anonymous sharing links for the site
D.Add partners as guests in Microsoft Teams and share the site from Teams
AnswerA

Configuring SharePoint Online external sharing with authenticated guests is the appropriate Microsoft 365 pattern. This leverages Azure AD Business-to-Business (B2B) collaboration, generating a one-time invitation that creates a guest identity in the tenant. Administrators can then grant granular permissions to specific SharePoint sites, document libraries, or files, ensuring partners are authenticated and access is auditable. External sharing must be enabled at the tenant and site collection level, and partners receive the SharePoint site link to access resources.

Why this answer

SharePoint Online external sharing allows administrators to invite external users as authenticated guests who can access only the specific site they are invited to, without gaining access to the entire tenant. This is achieved by configuring site-level sharing settings to 'New and existing guests' and sending an invitation that requires the external partner to authenticate with a Microsoft account or Azure AD credentials, ensuring granular access control.

Exam trap

The trap here is that candidates often confuse Azure AD B2B (guest users) with Azure AD B2C, or assume that anonymous sharing is the simplest way to share externally, overlooking the authentication and access control requirements specified in the question.

How to eliminate wrong answers

Option B is wrong because creating an Azure AD B2C tenant is designed for consumer-facing identity management in custom applications, not for granting external partners access to SharePoint Online sites; it would introduce unnecessary complexity and does not integrate directly with SharePoint Online sharing. Option C is wrong because anonymous sharing links provide access to anyone with the link without authentication, which violates the requirement to grant access only to specific external partners and poses a security risk. Option D is wrong because adding partners as guests in Microsoft Teams and sharing the site from Teams still requires the partners to be invited as Azure AD guests, which grants them access to the entire tenant's Azure AD directory and potentially other resources, not just the specific SharePoint site.

30
MCQeasy

A sales team uses Microsoft 365 and wants to track customer interactions and manage leads from within Outlook. Which app should they use?

A.Microsoft Lists
B.Microsoft Bookings
C.Microsoft Forms
D.Microsoft Dynamics 365 Sales
AnswerD

Microsoft Dynamics 365 Sales is a full-featured CRM application that provides lead and opportunity management, sales pipelines, and customer activity tracking, all deeply integrated with Outlook. It enables sales teams to view communication history, schedule follow-ups, and manage accounts from a single interface, making it the correct choice for tracking customers in a structured, relationship-centric way.

Why this answer

Microsoft Dynamics 365 Sales is a customer relationship management (CRM) application that integrates directly with Outlook to track customer interactions, manage leads, and automate sales processes. It provides a unified interface within Outlook for viewing contact history, logging emails, and managing opportunities, making it the correct choice for the sales team's requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Lists or Bookings as CRM tools due to their data-tracking or scheduling features, but they lack the lead management, pipeline tracking, and customer interaction history that Dynamics 365 Sales provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data-tracking app for creating and sharing lists (e.g., issue trackers, inventory) but lacks CRM capabilities like lead management or customer interaction tracking within Outlook. Option B is wrong because Microsoft Bookings is a scheduling and appointment management tool, not designed for tracking customer interactions or managing sales leads. Option C is wrong because Microsoft Forms is used for creating surveys, quizzes, and polls, and does not provide lead management or customer interaction tracking features.

31
MCQhard

Refer to the exhibit. An IT administrator is using Microsoft Intune to assign Microsoft 365 Apps for Enterprise to a group called Contoso-Sales. The exhibit shows a JSON snippet from the Intune deployment configuration. Based on the snippet, what is the most likely outcome?

A.The app will be automatically installed on all devices in the Contoso-Sales group.
B.The app will be excluded from installation for the Contoso-Sales group.
C.The app will be available for users in the group to install from Company Portal.
D.The app will be assigned but requires user approval before installation.
AnswerA

AutoAssignment is functionally equivalent to a Required assignment in Microsoft Intune. When an app is configured with AutoAssignment for a group, Intune automatically installs it on every enrolled device that belongs to that group, without requiring any user interaction. The device receives the deployment policy at its next check-in and the installation runs in the background.

Why this answer

The JSON snippet shows an assignment with 'intent' set to 'Required' and 'targetGroupId' pointing to the Contoso-Sales group. In Microsoft Intune, a 'Required' assignment for a mobile app (like Microsoft 365 Apps for Enterprise) triggers automatic installation on all targeted devices without user intervention, making option A correct.

Exam trap

The trap here is that candidates confuse 'Required' intent with 'Available' intent, assuming all assignments require user action, but 'Required' in Intune means mandatory, silent installation, not optional installation from Company Portal.

How to eliminate wrong answers

Option B is wrong because the JSON shows an assignment with 'intent' set to 'Required', not 'Excluded' — exclusion would require a separate 'Exclude' group assignment or an 'excludedGroupIds' property. Option C is wrong because 'Required' intent forces installation silently; making the app available for user-initiated install from Company Portal requires 'Available' intent. Option D is wrong because 'Required' intent does not require user approval — it installs automatically; user approval is only relevant for 'Available' intent or when using 'User must accept license' settings, which are not indicated here.

32
MCQmedium

A department head asks which Microsoft 365 option should be used to reduce email attachments by storing shared team documents in one place and collaborating from conversations. Microsoft 365 app or service is the best fit?

A.Microsoft Teams with SharePoint Online
B.Microsoft Purview Audit
C.Microsoft Planner
D.Microsoft Forms
AnswerA

This combination is correct because Teams provides a hub for chat, meetings, and channel-based collaboration, while every file shared in a channel is stored in that team's SharePoint Online document library. SharePoint adds native version history, co-authoring, metadata, and permission inheritance, which together meet the department head's need for a shared, persistent file workspace.

Why this answer

Microsoft Teams integrates with SharePoint Online to provide a centralized document repository where team files are stored and managed. This allows users to collaborate on documents directly within Teams conversations, eliminating the need for email attachments. The combination of Teams for chat-based collaboration and SharePoint for file storage and versioning directly addresses the requirement.

Exam trap

The trap here is that candidates might confuse Microsoft Teams as a standalone chat app, overlooking its deep integration with SharePoint Online for file storage and collaboration, or mistakenly think Planner or Forms can serve as document repositories.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit is a compliance and auditing solution that tracks user activities and events, not a tool for storing shared documents or collaborating from conversations. Option C is wrong because Microsoft Planner is a task management and project planning tool that organizes work into boards and tasks, not a document storage or conversation collaboration platform. Option D is wrong because Microsoft Forms is a survey and quiz creation tool for collecting data, not designed for document storage or team collaboration within conversations.

33
MCQhard

A healthcare organization uses Microsoft 365 E5 and must comply with HIPAA. They need to ensure that all emails containing protected health information (PHI) are encrypted both in transit and at rest. They also need to prevent users from accidentally sending PHI to external recipients. What should they implement?

A.Use Microsoft Entra ID Conditional Access to require MFA for all email access.
B.Implement Microsoft Purview Message Encryption and create DLP policies to detect and block PHI sent externally.
C.Configure Microsoft Defender for Office 365 Safe Attachments and Safe Links policies.
D.Deploy Microsoft Purview Compliance Manager to assess compliance with HIPAA.
AnswerB

Implementing Microsoft Purview Message Encryption (OME) encrypts email messages and attachments, ensuring protected health information (PHI) is unreadable to unauthorized recipients, while DLP policies detect sensitive patterns such as medical record numbers or diagnosis codes and automatically block or warn before such content is sent externally. Together, these controls enforce both confidentiality and controlled sharing, which are core HIPAA safeguards. Unlike other options, this combination directly addresses the specific requirement to secure PHI in email.

Why this answer

Microsoft Purview Message Encryption (MPME) provides the necessary encryption for PHI in transit and at rest by using Azure Rights Management (RMS) to protect emails. Data Loss Prevention (DLP) policies in Microsoft Purview can be configured to detect patterns like social security numbers or medical record numbers and automatically block or warn users before sending such emails externally, preventing accidental PHI exposure.

Exam trap

The trap here is that candidates often confuse DLP with encryption, thinking that encryption alone prevents accidental sharing, or they mistake security features like MFA or Safe Attachments for data protection controls that address content-based compliance requirements.

How to eliminate wrong answers

Option A is wrong because Conditional Access with MFA only enforces multi-factor authentication for access, it does not encrypt email content or prevent accidental sending of PHI. Option C is wrong because Safe Attachments and Safe Links protect against malicious attachments and URLs in email, they do not provide encryption or DLP-based content blocking for PHI. Option D is wrong because Compliance Manager is a risk assessment and reporting tool that helps evaluate compliance posture but does not actively encrypt emails or block PHI in transit.

34
MCQhard

An organization uses Microsoft 365 and wants to implement a retention policy for all Exchange Online mailboxes that automatically deletes emails older than 7 years, except for emails from the legal department which must be kept for 10 years. What should the administrator configure?

A.Create a single retention policy with 7-year retention and apply preservation lock.
B.Configure retention tags in Exchange Online for each mailbox.
C.Place the legal department mailboxes on litigation hold and set a 7-year retention for others.
D.Create two retention policies: one for all mailboxes with 7-year retention, and another for the legal department with 10-year retention using adaptive scopes.
AnswerD

Creating two retention policies allows you to apply a 7-year retention to all mailboxes and a separate 10-year retention to the legal department, using adaptive scopes to dynamically include mailboxes based on the department attribute. Adaptive scopes let you target users by Azure AD properties, such as Department = 'Legal', so the policy automatically applies to current and future legal staff without manual maintenance. When both policies apply to a legal mailbox, Microsoft 365 retains content for the longer period (10 years), satisfying the legal department's requirement while still enforcing the 7-year baseline for everyone else.

Why this answer

Microsoft 365 retention policies can be scoped using adaptive scopes to apply different retention settings to different groups of users. By creating two policies—one with a 7-year deletion rule for all mailboxes and another with a 10-year deletion rule for the legal department—the administrator meets the requirement without conflicting settings. Adaptive scopes allow dynamic membership based on attributes like department, ensuring the legal department's emails are kept longer while others are deleted after 7 years.

Exam trap

The trap here is that candidates often confuse litigation hold or preservation lock with retention policies, thinking they can be used to set different retention periods for different groups, when in fact they are designed for preservation (preventing deletion) rather than scheduled deletion with varying durations.

How to eliminate wrong answers

Option A is wrong because a single retention policy with preservation lock would prevent any changes or deletions, not selectively keep legal emails for 10 years while deleting others after 7; preservation lock is used for regulatory compliance to make the policy immutable, not for differential retention. Option B is wrong because retention tags in Exchange Online are part of the Messaging Records Management (MRM) feature, which is separate from Microsoft 365 retention policies and cannot be used to create a unified organization-wide retention policy that applies to all mailboxes consistently; MRM tags are per-mailbox and require manual assignment or default policies, making them less suitable for this requirement. Option C is wrong because litigation hold places a hold on all content in the mailbox, preventing deletion entirely, which would conflict with the 7-year deletion requirement for other mailboxes; it does not allow a 10-year retention period for legal department emails while still allowing deletion after 7 years for others.

35
MCQhard

Contoso Ltd. is a medium-sized company with 500 employees using Microsoft 365 E5. They have a mixed environment: 300 Windows 10 devices are managed by Microsoft Intune, and 200 are unmanaged but Azure AD joined. The company uses Microsoft Teams for collaboration and SharePoint Online for document storage. The security team wants to implement the following: restrict access to company data from unmanaged devices, require multi-factor authentication (MFA) for all external users accessing SharePoint, and ensure that sensitive documents labeled 'Highly Confidential' are automatically encrypted when shared via email. Currently, the company has no conditional access policies, no MFA enforced, and no data classification policies. The administrator needs to design a solution using Microsoft 365 built-in capabilities without purchasing additional licenses. What should the administrator do?

A.Configure SharePoint to block access from unmanaged devices, enable MFA for all users, and use Microsoft Purview Data Loss Prevention (DLP) to encrypt sensitive emails.
B.Use Intune app protection policies to restrict data access, enable MFA for SharePoint, and use Microsoft Purview auto-labeling for encryption.
C.Create a conditional access policy to require MFA for all users, use Intune compliance policies to mark devices as compliant, and create a sensitivity label to encrypt documents.
D.Create a conditional access policy to grant access from compliant devices, require MFA for external users, and configure a sensitivity label with auto-labeling for 'Highly Confidential' documents.
AnswerD

This solution precisely maps each requirement to the correct Microsoft 365 capability: a Conditional Access policy can require both device compliance (based on Intune compliance policies) and MFA for external users, ensuring only approved, managed devices gain access while external identities are verified. The sensitivity label configured with auto-labeling for 'Highly Confidential' content automatically applies encryption and permissions when documents match the label's pattern, eliminating user error. By combining these two policy layers, the organization enforces least-privilege access and protects sensitive data at the file level, which fully addresses the stated scenario.

Why this answer

It uses Conditional Access policies to require compliant devices for access (addressing unmanaged devices), requires MFA specifically for external users (not all users, aligning with the requirement), and uses a sensitivity label with auto-labeling to automatically encrypt 'Highly Confidential' documents when shared via email. This leverages built-in Microsoft 365 capabilities without additional licenses.

Exam trap

The trap here is that candidates often assume MFA must be enforced for all users or that DLP policies can encrypt emails, but the scenario specifically requires MFA only for external users and encryption via sensitivity labels, not DLP.

How to eliminate wrong answers

Option A is wrong because blocking access from unmanaged devices via SharePoint alone is not granular enough and does not leverage Conditional Access; enabling MFA for all users is overkill and not required by the scenario; DLP policies do not automatically encrypt emails—they block or warn, not encrypt. Option B is wrong because Intune app protection policies require devices to be enrolled in Intune, which the 200 unmanaged Azure AD-joined devices are not; enabling MFA for SharePoint only does not cover external users accessing SharePoint via other apps; auto-labeling in Purview requires a subscription like Microsoft 365 E5 Compliance, which is not explicitly stated as available. Option C is wrong because requiring MFA for all users is unnecessary and does not specifically target external users; Intune compliance policies alone do not grant access—they require a Conditional Access policy to enforce; creating a sensitivity label to encrypt documents does not include auto-labeling, so manual application would be needed.

36
MCQhard

Contoso Ltd. is a global manufacturing company with 10,000 users. They are deploying Microsoft 365 E5 and require: (1) All Microsoft 365 data must be encrypted at rest and in transit using customer-managed keys; (2) Email must be archived for 10 years; (3) Users must be able to access files offline on mobile devices and sync changes when online; (4) The IT team must monitor and respond to threats across email, endpoints, and identities from a single console. You need to recommend the appropriate Microsoft 365 services. Which combination should you choose?

A.Microsoft Purview Double Key Encryption, Exchange Online Archiving, SharePoint Online, Microsoft Sentinel
B.Microsoft Purview Customer Key, Exchange Online Archiving, OneDrive, Microsoft Defender XDR
C.Azure Information Protection, Exchange Online Archiving, Windows 365, Microsoft Defender for Endpoint
D.Microsoft Purview Customer Key, Exchange Online In-Place Hold, OneDrive, Microsoft 365 Defender for Cloud Apps
AnswerB

Microsoft Purview Customer Key gives the tenant control over the root encryption keys that encrypt data at rest across Microsoft 365 services, meeting a strict encryption-at-rest requirement. Exchange Online Archiving provides unlimited archiving and supports retention policies with Preservation Lock that can be configured for 10 years, satisfying long-term regulatory retention. OneDrive for Business offers automatic offline synchronization for user files without manual per-library configuration. Microsoft Defender XDR unifies signals from endpoints, email, identity, and cloud apps into a single incident queue, providing the needed unified threat response and monitoring.

Why this answer

Microsoft Purview Customer Key provides customer-managed encryption keys for data at rest in Microsoft 365, meeting the first requirement. Exchange Online Archiving with a 10-year retention policy satisfies the email archiving requirement. OneDrive enables offline file access on mobile devices with sync capabilities.

Microsoft Defender XDR (Extended Detection and Response) offers a unified console to monitor and respond to threats across email, endpoints, and identities.

Exam trap

The trap here is confusing Microsoft Purview Customer Key (which encrypts all data at rest with customer-managed keys) with Double Key Encryption (which only protects a subset of data) or Azure Information Protection (which is a labeling solution, not encryption at rest).

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Double Key Encryption (DKE) protects only specific sensitive data with two keys, not all Microsoft 365 data, and Microsoft Sentinel is a SIEM/SOAR tool, not a single console for threat response across email, endpoints, and identities. Option C is wrong because Azure Information Protection is a classification and labeling solution, not a customer-managed encryption key service, and Windows 365 is a cloud PC service, not a file sync solution for offline mobile access. Option D is wrong because Exchange Online In-Place Hold is a litigation hold feature, not a 10-year archiving solution, and Microsoft 365 Defender for Cloud Apps is a CASB, not the unified XDR console that covers email, endpoints, and identities.

37
Multi-Selectmedium

Which three of the following are key capabilities of Microsoft 365 Apps for enterprise (formerly Office 365 ProPlus)? (Choose three.)

Select 3 answers
.Always-up-to-date versions of Word, Excel, PowerPoint, and Outlook
.Installation on up to 5 PCs or Macs per user
.Real-time co-authoring in Word, Excel, and PowerPoint
.Unlimited cloud storage per user in OneDrive
.Built-in video conferencing with unlimited meeting duration
.On-premises deployment with perpetual licensing

Why this answer

Microsoft 365 Apps for enterprise provides always-up-to-date versions of core Office applications like Word, Excel, PowerPoint, and Outlook, with updates delivered via the Click-to-Run technology from the cloud. It allows installation on up to 5 PCs or Macs per user, enabling productivity across multiple devices. Real-time co-authoring in Word, Excel, and PowerPoint is a key capability, leveraging OneDrive or SharePoint to allow multiple users to edit the same document simultaneously.

Exam trap

Microsoft often tests the distinction between cloud-based subscription services and perpetual on-premises licensing, leading candidates to incorrectly select on-premises deployment as a capability of Microsoft 365 Apps for enterprise.

38
MCQhard

A company uses Microsoft 365 E5 and wants to implement a zero-trust security model. They need to ensure that all external file sharing requires multi-factor authentication (MFA) and that sensitive documents are automatically labeled. Which combination of services should they use?

A.Microsoft Defender XDR and Microsoft Purview Audit
B.Microsoft Intune and Microsoft Defender for Cloud Apps
C.Microsoft Defender for Cloud Apps and Microsoft Purview Data Lifecycle Management
D.Microsoft Entra Conditional Access and Microsoft Purview Information Protection
AnswerD

Microsoft Entra Conditional Access provides identity-driven policy enforcement, such as requiring MFA during sign-in based on user, location, device, or risk signals, which directly satisfies the MFA requirement. Microsoft Purview Information Protection automatically classifies emails and documents by applying sensitivity labels based on content detection and user-defined policies, thereby meeting the auto-labeling requirement. Together these two services form the correct combination: one governs access at the authentication boundary, the other governs data classification and protection at the content level.

Why this answer

Microsoft Entra Conditional Access can enforce MFA for external file sharing by requiring MFA as a condition for accessing SharePoint/OneDrive resources. Microsoft Purview Information Protection provides automatic sensitivity labeling for documents based on content or context, ensuring sensitive data is labeled without manual intervention. Together, these services directly address the zero-trust requirements of MFA for external sharing and automatic document labeling.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud Apps (a CASB) with Entra Conditional Access for MFA enforcement, or assume Purview Data Lifecycle Management handles labeling instead of Information Protection, leading them to select options that address only one requirement or use the wrong service for the task.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR focuses on threat detection and response across endpoints, email, and identities, not on enforcing MFA for external sharing or automatic labeling; Microsoft Purview Audit only provides logging and auditing of activities, not labeling or access control. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, not designed to enforce MFA on external file sharing or apply sensitivity labels; Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that can apply session policies but does not natively handle automatic labeling of documents. Option C is wrong because while Microsoft Defender for Cloud Apps can enforce access policies, it does not directly integrate with MFA enforcement for external sharing as a primary function; Microsoft Purview Data Lifecycle Management manages retention and deletion policies, not automatic sensitivity labeling.

39
Matchingmedium

Match each Microsoft 365 workload to its associated AI feature.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Intelligent recap and meeting transcripts

Microsoft Editor for grammar and style suggestions

Designer for slide layout recommendations

Focused Inbox and suggested replies

Why these pairings

AI features in Microsoft 365 enhance productivity: Word uses Editor, Excel uses Ideas, Outlook uses Focused Inbox, PowerPoint uses Designer, and Teams uses Live Captions. Common confusions arise from swapping features across workloads.

40
MCQmedium

A company is deploying Microsoft 365 Apps for Enterprise to 500 users. The IT team wants to minimize network traffic during installation by downloading only the apps that users need, instead of the full Office suite. Which deployment tool should they use?

A.Microsoft Store for Business
B.Microsoft Configuration Manager
C.Microsoft Intune
D.Office Deployment Tool (ODT)
AnswerD

The Office Deployment Tool (ODT) is the correct choice because it uses a configuration.xml file to specify exactly which Microsoft 365 Apps applications (e.g., Word, Excel, PowerPoint) to download or install, along with architecture, language, and update channel settings. During the /download mode, it retrieves only the selected apps and their dependencies from the Office Content Delivery Network, significantly reducing bandwidth compared to pulling down the entire suite. This granular control makes ODT ideal for creating a custom deployment with specified apps, and it supports both online and offline installation scenarios.

Why this answer

The Office Deployment Tool (ODT) allows IT administrators to download and deploy only the specific Microsoft 365 Apps (e.g., Word, Excel) needed by users, using an XML configuration file to control which products and languages are installed. This minimizes network traffic by avoiding the download of the full suite, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates may confuse the ODT with broader management tools like Intune or Configuration Manager, but the question specifically asks for the tool that directly controls which apps are downloaded, which is the ODT.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business is designed for purchasing and distributing apps from the Store, not for customizing or selectively deploying Microsoft 365 Apps components. Option B is wrong because Microsoft Configuration Manager (formerly SCCM) can deploy Office, but it relies on the ODT under the hood for customization; it is a broader management tool and not the specific tool for minimizing traffic by selecting only needed apps. Option C is wrong because Microsoft Intune is a cloud-based MDM/MAM service that can deploy Office apps, but it also uses the ODT for customization; it is not the direct tool for granular control over which apps are downloaded during installation.

41
MCQhard

Your organization uses Microsoft 365 E5 and wants to implement a solution that automatically detects and protects sensitive data in SharePoint Online, OneDrive, and Exchange Online. Which Microsoft 365 service should you configure?

A.Microsoft Defender for Cloud Apps
B.Microsoft 365 Copilot
C.Microsoft Intune
D.Microsoft Purview Information Protection
AnswerD

Microsoft Purview Information Protection applies sensitivity labels with encryption, and its auto-labelling policies detect sensitive data across SharePoint Online, OneDrive and Exchange Online. This satisfies the requirement for automatic detection and protection in those three workloads, whereas Defender for Cloud Apps governs access rather than labelling content.

Why this answer

Microsoft Purview Information Protection is the service within Microsoft 365 E5 that provides sensitivity labels and data loss prevention (DLP) to automatically detect and protect sensitive data across SharePoint Online, OneDrive, and Exchange Online. It allows you to classify and encrypt data based on sensitive information types.

Exam trap

MS-900 often tests the distinction between Purview Information Protection and Defender for Cloud Apps; candidates may confuse the two, but only Purview provides automatic labeling and protection for Microsoft 365 data.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud apps, but it does not automatically label and protect data in Microsoft 365 services; it focuses on threat protection and governance. Option B is wrong because Microsoft 365 Copilot is an AI assistant, not a data protection service. Option C is wrong because Microsoft Intune is for mobile device and application management, not for data classification and protection in Microsoft 365 workloads.

42
MCQhard

A company uses Microsoft Forms to collect customer feedback. They want to automatically analyze sentiment from the responses using AI. Which Microsoft 365 service can integrate with Forms for this purpose?

A.Power BI
B.SharePoint Online
C.Azure Logic Apps
D.Power Automate
AnswerD

Power Automate is a Microsoft 365 cloud automation service that can trigger on new Forms responses and use AI Builder to analyze sentiment. AI Builder provides a prebuilt sentiment analysis model that can classify text as positive, negative, or neutral without extra custom code. You can create a flow that reads each response, applies the model, and then stores the result or sends an alert, making it the correct and efficient choice.

Why this answer

Power Automate (D) is the correct service because it can connect Microsoft Forms to Azure AI services (e.g., Azure Cognitive Services Text Analytics) to automatically analyze sentiment from form responses. When a new response is submitted, a Power Automate flow triggers, sends the response text to the AI sentiment analysis API, and stores or reports the result—all without manual intervention.

Exam trap

The trap here is that candidates may confuse Power Automate with Azure Logic Apps, but the question explicitly asks for a 'Microsoft 365 service,' and Power Automate is the correct Microsoft 365 offering, while Azure Logic Apps is an Azure service.

How to eliminate wrong answers

Option A is wrong because Power BI is a data visualization and business analytics tool, not a workflow automation or AI integration service; it can display sentiment data but cannot directly trigger AI analysis from a Forms submission. Option B is wrong because SharePoint Online is a document management and collaboration platform; it can store form responses but lacks built-in AI sentiment analysis or workflow triggers to process them automatically. Option C is wrong because Azure Logic Apps is a cloud-based integration service that could technically perform this task, but it is not a Microsoft 365 service—it is an Azure service—and the question specifically asks for a Microsoft 365 service that integrates with Forms; Power Automate is the correct Microsoft 365 service for this purpose.

43
MCQmedium

Your company has deployed Microsoft Defender XDR. A security analyst needs to investigate a suspicious email that was reported by a user. Which Microsoft 365 service should the analyst use to view the email's details and analyze threats?

A.Microsoft Sentinel
B.Microsoft Defender XDR
C.Microsoft Intune
D.Microsoft Purview
AnswerB

Microsoft Defender XDR is the unified security operations platform that correlates signals from emails, endpoints, identities, and collaboration tools into a single incident queue, enabling teams to investigate the full attack story of email threats such as phishing and malware. It natively relies on Defender for Office 365 for mail-flow protection, URL and attachment detonation, campaign views, and automated investigation and response for email incidents. Therefore, Defender XDR is the correct service for investigating email security incidents in a Microsoft 365 deployment.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct service because it provides a unified investigation and response experience across email, endpoints, identities, and cloud apps. The security analyst can use the Microsoft Defender portal (security.microsoft.com) to view the full email details, including headers, attachments, URLs, and threat analysis results from automated investigation and advanced hunting queries.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR solution), not realizing that email investigation is a core function of Defender for Office 365 within Defender XDR, not Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that aggregates logs and alerts from multiple sources, but it is not the primary tool for investigating individual suspicious emails within Microsoft 365; that function belongs to Defender XDR. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service focused on managing devices and apps, not on email threat investigation. Option D is wrong because Microsoft Purview is a compliance and data governance solution (including data loss prevention, eDiscovery, and insider risk management), not a tool for analyzing email threats; email threat analysis is handled by Defender for Office 365, which is part of Defender XDR.

44
MCQeasy

Your organization has 500 users and uses Microsoft 365 Business Basic. The sales team frequently works remotely and needs to access their work files on mobile devices. They also need to conduct video meetings with customers. The IT department has been asked to recommend additional Microsoft 365 services to meet these needs without upgrading the existing plan if possible. Which action should the IT department take?

A.Subscribe to a Microsoft Teams Rooms license for each user.
B.Upgrade all users to Microsoft 365 Business Standard to get desktop Office and additional features.
C.Deploy a third-party VPN solution to secure remote access to files.
D.Use the existing OneDrive and SharePoint mobile apps for file access and use Microsoft Teams for video meetings.
AnswerD

With Microsoft 365 Business Basic, users can access and collaborate on files through the native OneDrive and SharePoint mobile apps, which sync and share documents securely from any device. Microsoft Teams, also included in Business Basic, provides robust video meeting capabilities without requiring any additional licenses. This solution directly satisfies both requirements using existing subscriptions, avoiding extra costs and complexity.

Why this answer

Microsoft 365 Business Basic already includes OneDrive and SharePoint for mobile file access via their respective apps, and Microsoft Teams for video meetings. These services meet the sales team's requirements without any additional licensing or plan upgrade, as Teams supports video conferencing and OneDrive/SharePoint provide secure remote file access on mobile devices.

Exam trap

The trap here is that candidates often assume remote file access requires a VPN or that video meetings need a higher-tier plan like Business Standard, overlooking that Business Basic already includes Teams and OneDrive/SharePoint mobile apps for these exact scenarios.

How to eliminate wrong answers

Option A is wrong because a Microsoft Teams Rooms license is designed for dedicated meeting room hardware (e.g., cameras, microphones, displays), not for individual users' mobile devices or remote work scenarios; it would be an unnecessary cost and does not address file access. Option B is wrong because upgrading to Business Standard is not required; the existing Business Basic plan already includes Teams for video meetings and OneDrive/SharePoint for file access via mobile apps, and the question explicitly asks to avoid upgrading if possible. Option C is wrong because a third-party VPN is unnecessary; OneDrive and SharePoint already provide secure remote access to files using HTTPS and Azure AD authentication, and deploying a VPN adds complexity and cost without addressing the video meeting requirement.

45
MCQhard

Your organization uses Microsoft Teams and wants to allow external partners to participate in shared channels without giving them full tenant access. Which identity solution should you configure?

A.Microsoft Teams guest access
B.Microsoft Entra External ID
C.Active Directory Federation Services
D.Microsoft Entra ID B2C
AnswerB

Microsoft Entra External ID is the correct service for enabling collaboration with external partners using their own identities, such as another Microsoft Entra tenant or Microsoft account. It offers B2B collaboration for guest users and B2B direct connect for shared channels, allowing controlled access to resources without requiring a guest object in your directory for every partner. This service provides fine-grained conditional access policies and governance for each partner relationship, making it ideal for Teams shared channels and other partner scenarios.

Why this answer

Microsoft Entra External ID (formerly Azure AD External Identities) is the correct solution because it allows external partners to authenticate and access shared Teams channels without granting them full tenant access. Unlike guest access, which creates a B2B collaboration user object in the tenant, External ID enables cross-tenant access policies that limit partner identities to specific resources like shared channels, preserving tenant isolation.

Exam trap

The trap here is that candidates often confuse Microsoft Teams guest access (which creates a guest user in the tenant) with the more restrictive B2B direct connect for shared channels, leading them to select guest access when the question explicitly requires 'without giving them full tenant access.'

How to eliminate wrong answers

Option A is wrong because Microsoft Teams guest access creates a guest user object in your tenant, which grants broader directory access and is not scoped solely to shared channels. Option C is wrong because Active Directory Federation Services (AD FS) is an on-premises identity federation solution for internal users, not designed for external partner access to Microsoft 365 shared channels. Option D is wrong because Microsoft Entra ID B2C is a customer-facing identity service for consumer applications, not for business-to-business partner collaboration in Teams.

46
MCQmedium

A manager needs to create a custom dashboard that visualizes sales data from multiple data sources in real-time. Which service should they use?

A.Excel
B.Power Apps
C.Power BI
D.SharePoint
AnswerC

Power BI is a dedicated business analytics service that connects to a wide variety of on-premises and cloud data sources, such as SQL Server, Azure, Salesforce, and SharePoint. It enables real-time data refreshes, interactive visuals with cross-filtering and drill-downs, and secure sharing via the Power BI service. Its robust data modeling with DAX, row-level security, and integration with Microsoft Teams and SharePoint make it the correct choice for a custom, live sales dashboard.

Why this answer

Power BI is the correct choice because it is specifically designed for creating interactive, real-time dashboards that aggregate data from multiple sources, including databases, cloud services, and streaming data. It provides live tile updates and direct query capabilities, enabling real-time visualization of sales data without manual refresh.

Exam trap

The trap here is that candidates often confuse Power Apps with Power BI, assuming both are for dashboards, but Power Apps is for building apps, not for data visualization or real-time analytics.

How to eliminate wrong answers

Option A is wrong because Excel is a spreadsheet application for static data analysis and lacks native real-time data connectivity and live dashboard capabilities. Option B is wrong because Power Apps is a low-code platform for building custom business applications, not for data visualization or real-time dashboards. Option D is wrong because SharePoint is a document management and collaboration platform that does not support real-time data aggregation or interactive dashboard creation from multiple sources.

47
MCQmedium

A department asks for the Microsoft 365 service best suited for interactive business dashboards. Which service should they use?

A.Microsoft Purview Compliance Manager
B.Power BI
C.Microsoft Defender for Endpoint
D.Microsoft Entra Privileged Identity Management
AnswerB

Power BI is Microsoft's dedicated business intelligence service, delivering interactive dashboards and reports from varied data sources. It directly satisfies the department's requirement for interactive business dashboards, unlike productivity or collaboration tools. Its visualisation engine supports drill-downs, filtering and real-time refresh, matching the stated scenario precisely.

Why this answer

Power BI is the correct choice because it is Microsoft's dedicated business analytics service that enables users to create interactive dashboards and reports from various data sources. It provides real-time data visualization, drill-down capabilities, and natural language querying, making it ideal for business intelligence needs within Microsoft 365.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's dashboard-like compliance score interface with a business dashboard, but it is strictly for compliance posture assessment, not interactive business analytics.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that helps organizations assess and manage regulatory compliance, not for building interactive dashboards. Option C is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, unrelated to dashboard creation. Option D is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring privileged access to Azure AD resources, not for data visualization or dashboards.

48
MCQeasy

An organization wants to provide employees with a personalized news feed from internal and external sources. Which Microsoft 365 app should they use?

A.Microsoft Viva Insights
B.Microsoft Viva Engage
C.Microsoft Stream
D.Microsoft SharePoint
AnswerB

Microsoft Viva Engage is the correct answer because it provides an employee experience platform with a social news feed that aggregates posts, stories, and updates from internal communities and external sources. Built on Yammer, it delivers a personalized feed of relevant news, conversations, and leadership messages directly within Microsoft 365. This matches the organization's need to provide employees with personalized news.

Why this answer

Microsoft Viva Engage (formerly Yammer) is the correct app because it provides a personalized news feed that aggregates content from both internal sources (e.g., company announcements, community posts) and external sources (e.g., RSS feeds, external news). It enables employees to discover relevant updates in a social-style feed, aligning with the requirement for a unified internal and external news experience.

Exam trap

The trap here is that candidates often confuse Microsoft Viva Insights (which sounds like it provides personalized content) with Viva Engage, or they assume SharePoint’s news web part can aggregate external sources, but SharePoint lacks the social feed and external aggregation capabilities that Viva Engage offers.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Insights focuses on personal productivity and well-being analytics (e.g., focus time, meeting habits), not on delivering a personalized news feed from internal and external sources. Option C is wrong because Microsoft Stream is a video hosting and sharing platform for enterprise video content, not a news aggregation feed. Option D is wrong because Microsoft SharePoint is a document management and collaboration platform that can display news via web parts, but it lacks the built-in social feed and external source aggregation that Viva Engage provides for a personalized news experience.

49
MCQmedium

A project team needs a centralized workspace that includes a shared calendar for deadlines, a document library for storing deliverables, and a task list with assignments. They also want threaded discussions about each item. Which Microsoft 365 service provides this integrated experience out of the box?

A.Microsoft Teams
B.SharePoint Online
C.Microsoft 365 Groups
D.Microsoft Outlook
AnswerC

A Microsoft 365 Group is the correct answer because it is the underlying identity and membership container that automatically provisions a complete set of collaboration services: a shared Outlook inbox and calendar, a SharePoint Online document library, a Planner plan for task management, and a shared workspace for threaded conversations. Everything is bound to the same group ID, so membership and permissions propagate consistently across all services. This meets the requirement of a centralized workspace with a calendar and tasks out of the box, without requiring manual assembly of separate tools.

Why this answer

Microsoft 365 Groups is the correct answer because it provides a unified, out-of-the-box workspace that includes a shared calendar, document library (via connected SharePoint), task list (via Planner or To Do), and a group mailbox with threaded conversations. Unlike standalone services, a Microsoft 365 Group bundles these resources together automatically when created, offering the integrated experience described without requiring manual configuration.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the integrated workspace, but Teams is actually a client that surfaces the underlying Microsoft 365 Group resources, not the service that provides them out of the box.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration hub that relies on a Microsoft 365 Group for its underlying calendar, document library, and task list; Teams itself does not natively provide a shared calendar or threaded discussions about each item without the group's resources. Option B is wrong because SharePoint Online provides document libraries and lists but lacks a built-in shared calendar and threaded discussions; it requires integration with other services like Outlook or Teams to achieve the full integrated experience. Option D is wrong because Microsoft Outlook is an email and calendar client that can display group resources but does not natively create or manage the document library, task list, or threaded discussions as a centralized workspace; it consumes the group's resources rather than providing them.

50
MCQmedium

A sales representative needs to quickly create a professional-looking price quote that includes dynamic pricing from a company database and send it as a PDF to a customer. Which Microsoft 365 app is best suited for this?

A.Microsoft Word
B.Microsoft Excel
C.Microsoft Sway
D.Microsoft SharePoint Online
AnswerA

Word is a full-featured word processor that supports precise page layout, rich typography, tables, headers/footers, and embedded objects, all essential for a polished, branded sales quote. It can pull live data from Excel or external databases via linked content and mail merge fields, then export to a fixed-layout PDF via Save As, guaranteeing the recipient sees an identical professional document.

Why this answer

Microsoft Word is best suited because it supports mail merge and dynamic content from external data sources like a company database. Using Word's 'Insert Quick Parts' or mail merge features, a sales rep can pull live pricing data into a professional quote template and then export the document as a PDF directly from Word.

Exam trap

The trap here is that candidates often confuse Excel's data calculation capabilities with document creation, assuming a spreadsheet can produce a professional quote, but Word is the correct app for formatted, PDF-ready documents with dynamic content.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel is a spreadsheet app optimized for data analysis and calculations, not for creating professional-looking documents with dynamic text and images; it lacks the rich layout and PDF export capabilities needed for a polished quote. Option C is wrong because Microsoft Sway is a presentation and storytelling app for interactive web-based content, not for generating static PDF documents with dynamic database-driven pricing. Option D is wrong because Microsoft SharePoint Online is a collaboration and document management platform, not a content creation app; it cannot directly create a formatted quote with dynamic pricing from a database.

51
Multi-Selecteasy

Which TWO Microsoft 365 services can be used to create and manage custom forms for data collection and surveys?

Select 2 answers
A.Microsoft Lists
B.Microsoft Forms
C.Excel Online
D.Power Apps
E.SharePoint Lists
AnswersB, D

Microsoft Forms is the dedicated service for building surveys, quizzes, and polls, providing a question editor, branching rules, and automatic result charts. It supports real-time response collection and can be embedded easily in Teams or SharePoint, making it the obvious choice for form creation. This service is purpose-built for the task described in the question.

Why this answer

Microsoft Forms is purpose-built for creating custom forms, surveys, and quizzes with automatic data collection into Excel Online. It provides a simple interface for designing forms, distributing them, and analyzing responses in real time, making it the primary tool for this task in Microsoft 365.

Exam trap

The trap here is that candidates often confuse Microsoft Lists or SharePoint Lists with form creation tools because they can display data in a form-like view, but they lack the native survey and data collection functionality that Microsoft Forms provides.

52
MCQeasy

A tenant administrator applies the above configuration for Microsoft 365 Copilot. What is the result of this configuration?

A.Copilot will be enabled but will only use data from SharePoint and OneDrive; Exchange and Teams data are excluded.
B.Copilot will be enabled for all users and will access data from all Microsoft 365 services.
C.Copilot will be disabled because GraphConnectors is empty.
D.Copilot will only work for users in the European Union.
AnswerA

The configuration explicitly sets RestrictedContentSources to include only SharePoint and OneDrive, so Copilot remains enabled but its grounding data is limited to these two workloads. Exchange and Teams are not listed in the restricted sources, meaning their data cannot be retrieved or used by Copilot. The empty GraphConnectors list is irrelevant here because native Microsoft 365 sources are still available; it simply means no third-party or custom connectors were added.

Why this answer

The configuration shows that the 'Copilot' toggle is enabled, but the 'Data sources' section explicitly lists only SharePoint and OneDrive, with Exchange and Teams unchecked. This means Copilot will be active for users but will only index and retrieve data from SharePoint and OneDrive, excluding emails and Teams messages. The empty GraphConnectors list further confirms no external data sources are connected, but this does not disable Copilot itself.

Exam trap

The trap here is that candidates often assume an empty GraphConnectors list disables Copilot entirely, but in reality, Copilot remains enabled and functional with the internal Microsoft 365 data sources that are explicitly selected.

How to eliminate wrong answers

Option B is wrong because the configuration does not enable all data sources; Exchange and Teams are explicitly excluded, so Copilot will not access data from those services. Option C is wrong because an empty GraphConnectors list only means no external (third-party) data sources are connected; it does not disable Copilot, which still works with the selected Microsoft 365 data sources (SharePoint and OneDrive). Option D is wrong because there is no indication of any geographic restriction in the configuration; Copilot's availability is determined by licensing and tenant settings, not by a region-specific toggle in this UI.

53
MCQeasy

A non-profit organization uses Microsoft 365 Business Basic. They have 50 staff members who need to collaborate on documents in real time. The executive director wants to set up a centralized repository for all organizational policies that can be accessed by staff both online and offline on their mobile devices. Which solution should the organization use?

A.Create a SharePoint Online document library with versioning and enable offline sync.
B.Store documents in Exchange Online mailboxes as attachments.
C.Create a Microsoft Teams team with a channel for policies and use the Files tab.
D.Use OneDrive for Business shared folders for each policy document.
AnswerA

A SharePoint Online document library is purpose-built for centralized policy management: it stores files in a secure, standards-based library with configurable major/minor versioning that retains a complete history of each change. Enabling offline sync via the OneDrive sync client or SharePoint mobile app ensures staff can access the latest approved versions even without connectivity. Because the library is a single source of truth in the Microsoft 365 Business Basic tenant, it meets both the version-control and offline-access requirements directly.

Why this answer

SharePoint Online document libraries support versioning, granular permissions, and offline sync via the OneDrive sync client or mobile app, making them ideal for a centralized, always-accessible policy repository. This meets the requirements for real-time collaboration and offline access on mobile devices.

Exam trap

The trap here is that candidates may confuse OneDrive for Business (personal storage) with SharePoint (organizational storage), or assume Teams' Files tab is a separate storage system rather than a SharePoint interface.

How to eliminate wrong answers

Option B is wrong because Exchange Online mailboxes are designed for email and calendar, not document storage; attachments are not versioned, cannot be synced offline, and lack centralized access controls. Option C is wrong because while Teams uses SharePoint for file storage, the Files tab in a channel is a front-end to a SharePoint library; however, the question asks for a centralized repository, and Teams channels are team-specific, not a single repository for all staff. Option D is wrong because OneDrive for Business is intended for individual file storage and sharing, not as a centralized organizational repository; shared folders require manual sharing and lack the governance features of a SharePoint library.

54
MCQhard

A sales team uses Microsoft Lists to track leads. They want to create a real-time dashboard that shows the number of leads by stage, the total deal value, and the win rate. The dashboard must update automatically when the list is changed. Which Microsoft 365 app should they use to build this dashboard?

A.Microsoft Power BI
B.Microsoft Excel
C.Microsoft SharePoint
D.Microsoft Power Automate
AnswerA

Microsoft Power BI is correct because Power BI includes a native Microsoft Lists (SharePoint Online) connector that can pull list data into a data model via Power Query. It supports scheduled refresh (up to 8 times per day with a Pro license, or via a gateway in Power BI Report Server) so dashboards can display near-live data without manual intervention. With DAX measures, you can aggregate leads by stage, owner, or time, and build interactive visualizations that update on refresh, making it the only option that combines connectivity, computational analytics, and automatic data refresh.

Why this answer

Microsoft Power BI is the correct choice because it is designed to create real-time, interactive dashboards that can connect directly to Microsoft Lists via the Power BI service or Power BI Desktop. It supports automatic data refresh when the underlying list changes, enabling live tracking of leads by stage, total deal value, and win rate without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Power Automate with a dashboarding tool because it can respond to list changes, but it cannot visualize data; the correct answer requires recognizing that Power BI is the dedicated analytics and visualization app for real-time dashboards.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel, while capable of creating charts and dashboards, does not natively support real-time automatic updates from Microsoft Lists without manual refresh or complex VBA scripting, and it lacks the robust data modeling and live dashboard capabilities of Power BI. Option C is wrong because Microsoft SharePoint is a content management and collaboration platform, not a dashboarding tool; it can host lists but cannot build real-time analytical dashboards with automatic updates. Option D is wrong because Microsoft Power Automate is a workflow automation tool that can trigger actions based on list changes but cannot create or display dashboards; it would need to integrate with Power BI for visualization.

55
MCQhard

A company with Microsoft 365 E5 wants to use AI to summarize email threads and draft replies automatically. Which Microsoft 365 service provides this capability?

A.Microsoft Viva Insights
B.Microsoft 365 Copilot
C.Microsoft Search
D.Microsoft Editor
AnswerB

Microsoft 365 Copilot is a generative AI assistant embedded across Word, Outlook, Teams, and other M365 apps that uses large language models and your organizational data from Microsoft Graph to understand context. It can summarize a lengthy email thread, synthesize a meeting's key points, or draft a response in Outlook, making it the proper choice for AI-driven summarization.

Why this answer

Microsoft 365 Copilot integrates with Outlook and other Microsoft 365 apps to provide AI-powered email thread summarization and draft reply generation. It uses large language models (LLMs) combined with your Microsoft Graph data to understand context and produce relevant, personalized responses. This capability is not available in other Microsoft 365 services like Viva Insights or Microsoft Editor.

Exam trap

The trap here is that candidates may confuse Microsoft Viva Insights (which provides 'insights' and 'suggestions' about work patterns) with AI-powered content generation, or assume Microsoft Editor's grammar suggestions include drafting capabilities, when in fact only Copilot uses generative AI for these tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Insights focuses on personal productivity analytics, wellbeing, and work patterns (e.g., meeting time, focus hours), not on generating email summaries or drafts. Option C is wrong because Microsoft Search provides enterprise search across files, messages, and sites using the Microsoft Graph, but it does not generate AI summaries or draft replies. Option D is wrong because Microsoft Editor is a writing assistant that checks spelling, grammar, and style in documents and emails, but it lacks the generative AI capabilities to summarize threads or draft replies from scratch.

56
MCQeasy

A department needs a shared document library with version history, permissions, and co-authoring for team files. Which service should they primarily use?

A.SharePoint Online.
B.OneDrive for Business.
C.Microsoft Forms.
D.Microsoft Planner.
AnswerA

SharePoint Online is Microsoft 365's dedicated content-management service, offering team document libraries with built-in version history, co-authoring, metadata columns, and granular permissions. Versioning in SharePoint retains previous versions of files and allows restore or compare, which directly meets the department's need for a shared, versioned document repository. It is the standard backend for shared files in Teams, Outlook, and many other M365 workloads.

Why this answer

SharePoint Online is the correct choice because it provides a centralized, team-based document library with built-in version history, granular permission management, and real-time co-authoring. Unlike OneDrive for Business, which is designed for personal file storage, SharePoint Online supports shared workspaces where multiple users can collaborate simultaneously on the same documents while maintaining full audit trails and access controls.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint Online, assuming OneDrive can serve as a team library, but OneDrive lacks the centralized permission management and team-level version history that SharePoint provides for departmental collaboration.

How to eliminate wrong answers

Option B (OneDrive for Business) is wrong because it is primarily a personal cloud storage service for individual users, not designed for team-based shared libraries with centralized permissions and version history across a department. Option C (Microsoft Forms) is wrong because it is a survey and quiz creation tool, not a document storage or collaboration platform. Option D (Microsoft Planner) is wrong because it is a task management and project planning tool, lacking document library, versioning, and co-authoring capabilities.

57
MCQhard

An organization wants to use AI to summarize long email threads and suggest replies in Outlook. Which Microsoft 365 feature provides this capability?

A.Microsoft Copilot for Microsoft 365
B.Microsoft Editor
C.Microsoft Search
D.Microsoft Viva Insights
AnswerA

Microsoft Copilot for Microsoft 365 is embedded in Outlook and uses the Microsoft Graph plus large language models to summarise lengthy email threads and draft suggested replies directly within the mailbox, matching the stated requirement.

Why this answer

Microsoft Copilot for Microsoft 365 integrates AI directly into Outlook to summarize long email threads and generate suggested replies. It uses large language models and the Microsoft Graph to analyze conversation context, extract key points, and draft responses, all within the user's mailbox. This is the only Microsoft 365 feature designed specifically for these natural language processing tasks in Outlook.

Exam trap

The trap here is that candidates often confuse Microsoft Editor's basic AI writing assistance with Copilot's advanced generative AI capabilities, assuming Editor can handle complex tasks like summarization and reply generation, but Editor lacks the underlying large language model and Graph integration required for those features.

How to eliminate wrong answers

Option B is wrong because Microsoft Editor is a writing assistant that provides grammar, spelling, and style suggestions, but it cannot summarize email threads or generate suggested replies. Option C is wrong because Microsoft Search helps users find content across Microsoft 365 (e.g., emails, files, people) via a search index, but it does not perform AI-driven summarization or reply generation. Option D is wrong because Microsoft Viva Insights focuses on productivity and wellbeing analytics (e.g., focus time, meeting habits) and does not include capabilities for summarizing conversations or suggesting replies.

58
MCQmedium

A field service team needs a mobile-friendly app that allows technicians to view customer information from a central database, log completed tasks, and capture photos on-site. The IT department has limited development resources and wants to build this app quickly without writing extensive code. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft Power Apps
B.Microsoft Forms
C.Microsoft Power Automate
D.Microsoft Power BI
AnswerA

Power Apps provides a low-code canvas and model-driven builder, letting technicians view central data, log tasks and capture photos through a mobile app with minimal hand-written code. This directly satisfies the stem's limited development resource and rapid delivery constraint.

Why this answer

Microsoft Power Apps is the correct choice because it enables rapid development of custom mobile-friendly apps with minimal code, allowing the field service team to view customer data from a central database (e.g., Dataverse or SharePoint), log completed tasks, and capture photos on-site. Its low-code platform provides pre-built connectors and templates that directly address the need for a data-driven, mobile-first application without extensive development resources.

Exam trap

The trap here is that candidates often confuse Power Automate with Power Apps, thinking that automation alone can build an app, but Power Automate only orchestrates workflows and cannot provide the interactive user interface required for field technicians to view data, log tasks, and capture photos.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is designed for creating surveys and forms for data collection, not for building a multi-functional mobile app that integrates with a central database and supports task logging and photo capture. Option C (Microsoft Power Automate) is wrong because it focuses on workflow automation and process orchestration, not on creating a user-facing mobile application with custom UI and data interaction. Option D (Microsoft Power BI) is wrong because it is a business analytics and visualization tool, not an app development platform; it cannot provide the interactive, data-entry functionality required for field technicians.

59
MCQmedium

Refer to the exhibit. An admin runs the PowerShell command shown. What is the implication for the user's mailbox?

A.The retention policy is not effective
B.The mailbox has no retention policy applied
C.The mailbox is on litigation hold
D.The mailbox will automatically delete items after 30 days
AnswerC

The mailbox is correctly identified as being on litigation hold because the LitigationHoldEnabled property returns True. A litigation hold preserves all mailbox content indefinitely, including deleted items and previous versions, and prevents any permanent deletion or expiry. This is the direct and accurate interpretation of the output.

Why this answer

The PowerShell command `Set-Mailbox -LitigationHoldEnabled $true` places the user's mailbox on litigation hold. This preserves all mailbox content, including deleted items and original versions of modified items, for eDiscovery purposes. The hold overrides any retention policy that would otherwise delete or archive items, ensuring data is retained indefinitely until the hold is removed.

Exam trap

The trap here is that candidates confuse litigation hold with a retention policy or assume the command removes the policy, when in fact litigation hold is a separate preservation mechanism that overrides deletion behavior without altering the applied retention policy.

How to eliminate wrong answers

Option A is wrong because litigation hold overrides retention policies, making the retention policy temporarily ineffective for deletion or archiving, but the policy itself remains applied and will take effect once the hold is removed. Option B is wrong because the command does not remove or prevent a retention policy from being applied; it only enables litigation hold, which coexists with any existing policy. Option D is wrong because litigation hold prevents automatic deletion of items after any period, including 30 days; items are retained indefinitely regardless of retention tags or settings.

60
MCQhard

An organization uses Microsoft 365 and wants to automatically detect and remediate security incidents across identities, endpoints, and cloud apps. Which Microsoft 365 service should they deploy?

A.Microsoft Sentinel
B.Microsoft Purview
C.Microsoft Defender for Office 365
D.Microsoft Defender XDR
AnswerD

Microsoft Defender XDR (formerly Microsoft 365 Defender) unifies telemetry from Defender for Identity, Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps into a single incident queue, automatically correlating suspicious activities across identities, endpoints, email, and cloud applications. It leverages built-in hunting and automated response playbooks to remediate threats with actions like isolating endpoints, pausing user accounts, or rolling back email messages. This integrated, portfolio-wide automation is exactly the native XDR capability that the organization needs.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically detects and remediates security incidents across identities, endpoints, and cloud apps. It correlates signals from Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps to deliver automated investigation and response, aligning directly with the scenario's requirement for holistic incident management.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel requires manual configuration for automated remediation across domains, whereas Defender XDR provides built-in, cross-domain automated response out of the box.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests logs from multiple sources for threat detection and response, but it does not natively provide automated cross-domain remediation across identities, endpoints, and cloud apps without custom playbooks and integrations. Option B is wrong because Microsoft Purview is a data governance, compliance, and risk management solution focused on data classification, labeling, and protection, not on detecting and remediating security incidents across identities, endpoints, and cloud apps. Option C is wrong because Microsoft Defender for Office 365 is specifically designed to protect against threats in email, SharePoint, OneDrive, and Teams, and does not cover identity or endpoint security incidents, making it too narrow for the described requirement.

61
MCQhard

A global enterprise uses Microsoft 365 E5 and has users in Europe, Asia, and North America. They need to ensure that user data in Exchange Online and SharePoint Online remains within the European Union for EU users. They also want to apply a retention policy to keep all data for at least 7 years. Which combination of Microsoft 365 features should an administrator use?

A.Enforce data residency using Multi-Geo capabilities in Exchange Online and SharePoint Online, and apply a retention policy via Microsoft Purview Data Lifecycle Management.
B.Use Microsoft Purview Compliance Manager to configure data residency and retention settings.
C.Use Data Location for Exchange Online and a SharePoint multi-geo tenant, then create a retention policy in Purview for 7 years.
D.Configure Microsoft Entra ID Conditional Access policies to restrict data access based on location.
AnswerA

Multi-Geo in Microsoft 365 lets you designate satellite geographies for data-at-rest while keeping a single tenant; Exchange Online and SharePoint Online (including OneDrive) honor the user’s PreferredDataLocation to store content in the assigned EU region. Purview Data Lifecycle Management then applies a seven-year retention policy to that content, ensuring regulatory compliance without altering access controls. This is the direct, correct way to meet both residency and retention requirements in an E5 tenant.

Why this answer

Multi-Geo capabilities in Exchange Online and SharePoint Online allow the administrator to pin user data at the tenant level to a specific geographic location (e.g., the EU), ensuring data residency. A retention policy configured via Microsoft Purview Data Lifecycle Management can then be applied to retain all data for a minimum of 7 years, meeting both compliance requirements.

Exam trap

The trap here is confusing data residency enforcement (which requires Multi-Geo) with access control (Conditional Access) or compliance scoring (Compliance Manager), leading candidates to pick options that address only part of the requirement or use the wrong tool entirely.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Compliance Manager is a risk-assessment and compliance-scoring tool, not a feature for configuring data residency or retention policies; it does not enforce data location or set retention durations. Option C is wrong because 'Data Location for Exchange Online' is not a standalone feature—Multi-Geo is the correct mechanism for Exchange Online data residency, and the phrase 'SharePoint multi-geo tenant' is redundant and imprecise; the retention policy in Purview is correctly described, but the data residency part is misstated. Option D is wrong because Microsoft Entra ID Conditional Access policies control access based on location (e.g., blocking sign-ins from outside the EU), but they do not enforce where data is stored or apply retention; they are an identity and access control feature, not a data residency or lifecycle management tool.

62
MCQmedium

You need to provide external partners access to a single document without giving them access to your entire SharePoint site. What should you do?

A.Add the partners as guests to the SharePoint site
B.Email the document as an attachment
C.Create a Microsoft 365 group and add them
D.Share a direct link to the document with specific permissions
AnswerD

Sharing a direct link to the document with specific permissions (for example, 'Specific people' or 'Anyone with the link' with view or edit rights) scopes access to exactly that file, while allowing you to set an expiration date, require sign-in, or disable downloading. This uses SharePoint's granular sharing engine, which stores the link in the file's access control list, gives you the ability to revoke access at any time, and generates audit events in Microsoft Purview. It is the recommended method for granting external partners limited, document-specific access because it balances collaboration with security and least privilege.

Why this answer

Sharing a direct link with specific permissions allows you to grant external partners access to a single document without giving them broader access to the entire SharePoint site. This method uses SharePoint's granular permission model, where you can set the link to 'Specific people' and restrict permissions to 'View' or 'Edit' only on that document, ensuring no unintended access to other site content.

Exam trap

The trap here is that candidates often confuse 'guest access' (which grants site-level access) with 'document-level sharing' (which is granular), leading them to incorrectly choose Option A, assuming guest access can be scoped to a single document.

How to eliminate wrong answers

Option A is wrong because adding partners as guests to the SharePoint site grants them access to the entire site, including all documents, lists, and pages, which violates the requirement to restrict access to a single document. Option B is wrong because emailing the document as an attachment creates a separate copy outside SharePoint, losing version control, permissions management, and audit trails, and does not provide controlled access to the original document. Option C is wrong because creating a Microsoft 365 group and adding partners gives them access to all resources associated with that group (e.g., SharePoint site, Teams, Planner), which again exposes the entire site, not just the single document.

63
MCQhard

A hospital uses Microsoft 365 and needs to comply with HIPAA by ensuring that patient health information in emails is encrypted both in transit and at rest. Which Microsoft 365 feature should they enable?

A.Microsoft Defender for Office 365
B.Microsoft Intune
C.Microsoft Purview Data Lifecycle Management
D.Office 365 Message Encryption
AnswerD

Office 365 Message Encryption is exactly the service for HIPAA because it uses Azure Rights Management to encrypt messages in transit and at rest for authorized recipients both inside and outside the organization. It supports configurable encrypted email templates and can be integrated with data loss prevention rules to automatically protect ePHI. This directly fulfills the HIPAA Security Rule's requirement to encrypt email containing protected health information.

Why this answer

Office 365 Message Encryption (OME) is the correct feature because it provides built-in encryption for emails both in transit (via TLS) and at rest (via Azure Rights Management), ensuring that patient health information (PHI) remains protected and compliant with HIPAA requirements. OME integrates with Azure Information Protection to apply persistent encryption that travels with the email, regardless of where it is stored.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (a threat protection tool) with email encryption, because both are security-related, but Defender does not provide the persistent encryption required for HIPAA compliance.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 is a security service focused on threat protection (anti-phishing, anti-malware, safe attachments/links), not on encrypting email content at rest or in transit for compliance. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) tool that manages devices and apps, but it does not directly encrypt email messages themselves. Option C is wrong because Microsoft Purview Data Lifecycle Management (formerly known as Microsoft 365 retention policies) manages data retention and deletion, not encryption of email content.

64
MCQmedium

A legal team needs to store documents with strict retention policies and eDiscovery capabilities. Which Microsoft 365 workload should they primarily use?

A.Power BI
B.Microsoft Bookings
C.Microsoft Teams
D.SharePoint Online
AnswerD

SharePoint Online provides document libraries governed by retention labels and holds, and its content is indexed for Microsoft Purview eDiscovery searches and cases. This directly satisfies the legal team's strict retention and eDiscovery requirements, unlike Teams or Exchange, which lack equivalent document lifecycle management.

Why this answer

SharePoint Online is the Microsoft 365 workload that provides document libraries, retention labels, retention policies, and native eDiscovery (Content Search, eDiscovery cases, legal hold) capabilities. It is purpose-built for document storage and compliance, making it the correct primary workload for a legal team with strict retention and eDiscovery requirements. Retention policies configured in the Microsoft 365 compliance center apply directly to SharePoint sites and their document libraries.

Exam trap

The trap is that Microsoft Teams also stores files and supports compliance, so candidates pick Teams — but the question asks for the primary workload for document retention and eDiscovery, which is SharePoint Online (Teams files are actually stored in SharePoint behind the scenes).

How to eliminate wrong answers

Option A is wrong because Power BI is a business intelligence and data visualization service — it has no document storage, retention policy, or eDiscovery functionality. Option B is wrong because Microsoft Bookings is an appointment scheduling tool for service-based businesses; it does not store documents or support compliance workflows. Option C is wrong because while Microsoft Teams can host files (backed by SharePoint) and supports some compliance features, it is a collaboration and communication hub, not the primary workload for document retention and eDiscovery — the underlying storage and compliance engine is SharePoint Online.

65
MCQmedium

A mid-sized company, Fabrikam, uses Microsoft 365 Business Premium. The company has 500 users and wants to implement a solution to protect against phishing attacks that target user credentials. The solution must: 1. Automatically detect and block malicious links in emails and Teams messages. 2. Provide real-time protection when users click on links in emails. 3. Allow users to report suspicious emails to the security team. 4. Integrate with Microsoft Entra ID to enforce conditional access policies based on user risk. Which combination of Microsoft 365 services should Fabrikam deploy?

A.Deploy Microsoft Intune and enforce conditional access policies that require compliant devices.
B.Deploy Microsoft Sentinel and configure analytics rules for phishing.
C.Deploy Microsoft Purview Data Loss Prevention and set up an email policy.
D.Deploy Microsoft Defender for Office 365 and enable Microsoft Defender XDR.
AnswerD

Microsoft Defender for Office 365 is the correct choice because it provides comprehensive, pre-delivery and post-delivery protection against phishing through Safe Links (URL detonation and block-time verification), Safe Attachments, and anti-phishing policies that detect impersonation and spoofing. Additionally, enabling Microsoft Defender XDR aggregates signals from Defender for Office 365, Defender for Endpoint, and Defender for Identity, enabling automated investigation and response across the entire kill chain. This also integrates with Microsoft Entra ID to inform conditional access and identity risk policies, closing the loop between email threat detection and access control.

Why this answer

Microsoft Defender for Office 365 (formerly Office 365 ATP) provides Safe Links and Safe Attachments to automatically detect and block malicious links in email and Teams messages, and offers real-time protection when users click links. Microsoft Defender XDR (Extended Detection and Response) correlates signals across Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID to enforce conditional access policies based on user risk, fulfilling all four requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (compliance/DLP) with email security, or think Intune's compliance policies can replace dedicated phishing protection, but only Defender for Office 365 provides the required link scanning and click-time protection for email and Teams.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune focuses on device management and compliance, not on detecting phishing links in emails or Teams messages, and it cannot automatically block malicious links in those channels. Option B is wrong because Microsoft Sentinel is a SIEM/SOAR tool for aggregating and analyzing security logs, not a real-time email/Teams phishing protection service; it lacks built-in Safe Links or click-time protection. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data, not to detect or block phishing links in emails or Teams messages.

66
MCQhard

An organization decides to implement Microsoft 365 Business Premium. The security team wants to ensure that all devices accessing company data are compliant with security policies. Which service should they use?

A.Microsoft Defender for Office 365
B.Microsoft Entra ID
C.Microsoft Intune
D.Microsoft Purview
AnswerC

Microsoft Intune enforces compliance policies, configuration profiles and conditional access on enrolled devices, so only devices meeting security baselines reach company data. It directly satisfies the stem's requirement that all devices accessing organisational data comply with security policies.

Why this answer

Microsoft Intune is the mobile device management (MDM) and mobile application management (MAM) service within Microsoft 365 that enforces compliance policies on devices accessing corporate data. It allows administrators to define security requirements such as PIN, encryption, OS version, and jailbreak/root detection, and then conditionally grant access only to compliant devices. Intune integrates with Microsoft Entra ID to evaluate device compliance during authentication, ensuring that only devices meeting security policies can access company resources.

Exam trap

MS-900 often tests the confusion between identity management (Entra ID) and device management (Intune), leading candidates to choose Entra ID for device compliance when Intune is the actual enforcement tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 protects against threats in email, collaboration tools, and Office apps (e.g., phishing, malware) but does not manage device compliance. Option B is wrong because Microsoft Entra ID provides identity and access management, including conditional access, but it relies on Intune (or another MDM) to define and report device compliance; it does not itself enforce device security policies. Option D is wrong because Microsoft Purview focuses on data governance, compliance, and risk management (e.g., data classification, DLP), not on device compliance enforcement.

67
MCQmedium

A company uses Microsoft 365 E5. The security team wants to automatically investigate and remediate advanced threats across email, endpoints, and identities. Which Microsoft 365 Defender workload should they enable?

A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Defender XDR
AnswerD

Microsoft Defender XDR is the correct solution because it is a unified, cross-domain security platform that aggregates and correlates alerts across identities, endpoints, email, collaboration, and cloud apps. Through the Microsoft 365 Defender portal, security teams can investigate a single incident timeline, automatically respond with AI-driven remediation, and leverage shared threat intelligence across all domains.

Why this answer

Microsoft Defender XDR (option D) is the correct answer because it is the unified, cross-domain security solution that correlates signals across email, endpoints, identities, and cloud apps to automatically investigate and remediate advanced threats. Unlike the individual Defender workloads, Defender XDR provides integrated incident response and automated actions across all these domains, which directly matches the requirement for automatic investigation and remediation across email, endpoints, and identities.

Exam trap

The trap here is that candidates often confuse the individual Defender workloads (Identity, Endpoint, Office 365) with the integrated cross-domain solution (Defender XDR), mistakenly thinking one of the single-domain tools can automatically investigate and remediate across all three domains simultaneously.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Identity focuses solely on on-premises Active Directory and hybrid identity threats using behavioral analytics and alerts, but it does not cover email or endpoint investigation and remediation. Option B is wrong because Microsoft Defender for Endpoint is limited to endpoint devices (Windows, macOS, Linux, Android, iOS) and does not include email or identity threat investigation and remediation. Option C is wrong because Microsoft Defender for Office 365 protects only email and collaboration workloads (Exchange Online, SharePoint, Teams) and does not extend to endpoint or identity threat investigation and remediation.

68
MCQeasy

A department asks for the Microsoft 365 service best suited for enterprise video publishing and town hall recordings. Which service should they use?

A.Microsoft Purview Compliance Manager
B.Microsoft Stream on SharePoint
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Stream on SharePoint delivers enterprise video publishing, town hall recordings, transcripts and channel organisation within Microsoft 365. This satisfies the department's requirement for a service purpose-built for enterprise video publishing and town hall recordings.

Why this answer

Microsoft Stream on SharePoint is the correct service because it is designed for enterprise video publishing, including town hall recordings, live events, and on-demand video. It leverages SharePoint's storage and permissions model, allowing videos to be stored as files in document libraries with metadata, retention policies, and granular access controls, making it ideal for internal communications.

Exam trap

The trap here is that candidates may confuse Microsoft Stream (classic) with Stream on SharePoint, or think that Microsoft Purview Compliance Manager or Defender for Endpoint could handle video content due to their broad names, but the question specifically requires a service for enterprise video publishing and town hall recordings.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management solution that provides risk assessments and controls for regulatory standards (e.g., GDPR, ISO 27001), not a video publishing or recording service. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, monitoring, and auditing privileged roles and just-in-time access, not for video content. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint detection and response (EDR), antivirus, and threat hunting, not for video publishing or town hall recordings.

69
MCQhard

A multinational company needs to ensure that its Microsoft 365 tenant meets regional data residency requirements by storing data only in specific geographic locations. Which Microsoft 365 feature should they use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Intune
C.Microsoft Entra ID Conditional Access
D.Multi-Geo Capabilities
AnswerD

Multi-Geo Capabilities is a Microsoft 365 feature that enables organizations to provision and store data for specific users and workloads, such as Exchange Online, OneDrive for Business, and SharePoint Online, in designated satellite regions. This directly addresses data residency requirements by ensuring that data at rest resides in approved geographic locations, independent of the default tenant location, making it the correct solution for the company's needs.

Why this answer

Multi-Geo Capabilities in Microsoft 365 allow organizations to provision and store data at rest in specific geographic locations (geo regions) to meet data residency requirements. This feature enables a single tenant to span multiple countries/regions, with user data (Exchange Online, SharePoint, OneDrive, Teams) stored in the chosen geo location, ensuring compliance with regional regulations.

Exam trap

The trap here is that candidates often confuse data residency (where data is stored) with data access control (Conditional Access) or data lifecycle management, leading them to pick a security or governance feature instead of the dedicated geo-location feature.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management is a solution for governing data retention, deletion, and classification, not for controlling the geographic storage location of data. Option B is wrong because Microsoft Intune is a cloud-based endpoint management and mobile device management (MDM) service, not a tool for defining data residency or geo-location storage. Option C is wrong because Microsoft Entra ID Conditional Access is an identity-driven policy engine that controls access based on conditions like location, device, or risk, but it does not determine where data is stored at rest.

70
MCQeasy

A sales manager wants to streamline the process of generating follow-up emails after customer meetings. Which Microsoft 365 app allows them to automatically create email drafts based on meeting notes using AI?

A.SharePoint Online
B.Copilot in Outlook
C.Microsoft Viva Insights
D.Microsoft Teams Premium
AnswerB

Copilot in Outlook is the correct choice because it uses AI grounded in the Microsoft Graph to turn meeting notes, conversation context, and previous threads into a polished email draft. A user can simply say "draft an email to the attendees summarizing these meeting notes" and set tone or length, and Copilot generates the message in the Outlook compose window. This is the only listed option whose purpose is directly to streamline the process of generating email correspondence.

Why this answer

Copilot in Outlook leverages AI to automatically generate email drafts based on meeting notes, transcripts, or summaries, directly within the Outlook interface. This allows the sales manager to streamline follow-up emails without manual composition, using natural language processing to extract key points and action items from the meeting context.

Exam trap

The trap here is that candidates may confuse Microsoft Teams Premium's intelligent recap feature (which summarizes meetings) with the AI email drafting capability, but Teams Premium does not generate email drafts; that is a distinct function of Copilot in Outlook.

How to eliminate wrong answers

Option A is wrong because SharePoint Online is a document management and collaboration platform, not an AI-powered email drafting tool; it lacks the integrated AI capabilities to generate email drafts from meeting notes. Option C is wrong because Microsoft Viva Insights focuses on personal productivity analytics, wellbeing, and meeting effectiveness insights, not on generating email content or drafts. Option D is wrong because Microsoft Teams Premium provides enhanced meeting features like intelligent recap, custom backgrounds, and advanced security, but it does not include AI-driven email draft generation; that capability is specific to Copilot in Outlook.

71
MCQmedium

A marketing team wants to create a centralized repository for brand assets, such as logos and templates, that can be accessed by all employees. Which Microsoft 365 service should they use?

A.SharePoint Online
B.Microsoft Stream
C.OneDrive for Business
D.Microsoft Lists
AnswerA

SharePoint Online is the correct choice because it provides team sites with document libraries designed for centralized file storage and collaboration. The default 'Documents' library in a SharePoint team site supports versioning, co-authoring, metadata, and permission-based access, making it an ideal repository for marketing assets. Unlike personal or video-specific tools, SharePoint is purpose-built for organizational content management and team-wide sharing.

Why this answer

SharePoint Online is the correct choice because it is designed as a cloud-based document management and storage platform that supports centralized repositories with granular permission controls. It allows the marketing team to create a dedicated site or document library for brand assets, enabling all employees to access, share, and collaborate on logos and templates while maintaining version history and compliance policies.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint Online, assuming OneDrive can serve as a team repository, but OneDrive is designed for personal storage and lacks the centralized management, site hierarchy, and enterprise-level sharing controls that SharePoint provides.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because it is a video management service for storing, streaming, and sharing recorded content, not a repository for static brand assets like logos and templates. Option C (OneDrive for Business) is wrong because it is a personal cloud storage solution intended for individual file storage and sharing, lacking the centralized, team-wide access controls and site structure needed for a company-wide brand asset repository. Option D (Microsoft Lists) is wrong because it is a data-tracking application for creating lists of items (e.g., issues, contacts) with metadata and views, not a file storage system for binary assets like images and documents.

72
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to improve employee experience through learning, insights, goals, and engagement experiences. Microsoft 365 app or service is the best fit?

A.Microsoft Viva
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Purview Audit
AnswerA

Microsoft Viva bundles the employee experience modules — Learning, Insights, Goals and Engage — directly inside Microsoft 365 and Teams, matching the stem's requirement for learning, insights, goals and engagement in one platform rather than separate standalone services.

Why this answer

Microsoft Viva is the correct answer because it is an integrated employee experience platform (EXP) within Microsoft 365 that explicitly combines learning (Viva Learning), insights (Viva Insights), goals (Viva Goals), and engagement (Viva Engage). This directly matches the help desk lead's requirement to improve employee experience through those four pillars, whereas the other options are single-purpose tools that do not cover the full scope.

Exam trap

The trap here is that candidates may confuse Microsoft Viva with a single-feature app like Planner or Forms, failing to recognize that Viva is the only option designed as a comprehensive employee experience platform covering all four specified areas.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a platform for learning, insights, goals, or engagement experiences. Option C (Microsoft Planner) is wrong because it is a lightweight project management and task assignment tool, lacking any capabilities for learning analytics, goal tracking, or employee engagement. Option D (Microsoft Purview Audit) is wrong because it is a compliance and auditing solution for tracking user and admin activities, unrelated to improving employee experience through learning, insights, goals, or engagement.

73
MCQmedium

An enterprise wants to allow employees to access corporate resources (emails, files, intranet) from unmanaged personal devices while ensuring that corporate data cannot be copied to personal apps. Which Microsoft 365 technology should be configured?

A.Microsoft Intune Mobile Device Management (MDM)
B.Microsoft Intune Mobile Application Management (MAM)
C.Microsoft Entra ID Conditional Access
D.Microsoft Baseline Protection
AnswerB

Microsoft Intune MAM allows administrators to apply data protection policies directly to apps such as Outlook, without requiring the user's device to be enrolled. These policies can restrict copy/paste, screen capture, and data saving to personal cloud services, while also enforcing an app-level PIN or managed access to corporate email. This provides a granular separation between corporate and personal data, making it ideal for allowing employees to access corporate resources on their personal devices.

Why this answer

Microsoft Intune Mobile Application Management (MAM) allows administrators to apply data protection policies directly to applications, such as Outlook and SharePoint, without enrolling the device itself. This enables employees to access corporate resources from unmanaged personal devices while preventing data from being copied or transferred to personal apps through features like multi-identity management and app-level PIN policies.

Exam trap

The trap here is that candidates often confuse MDM (device-level management) with MAM (app-level management), assuming that any data protection requires full device enrollment, when MAM provides the exact capability needed for unmanaged devices.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune MDM requires device enrollment, which gives the organization control over the entire device, conflicting with the requirement to keep personal devices unmanaged. Option C is wrong because Microsoft Entra ID Conditional Access controls access based on conditions like device compliance or location but does not provide the granular data-loss prevention controls within apps needed to block copying corporate data to personal apps. Option D is wrong because Microsoft Baseline Protection is not a real Microsoft 365 technology; it is a distractor that does not exist in the Microsoft 365 security portfolio.

74
MCQmedium

Your organization uses Microsoft 365 E5 licenses and wants to implement a data loss prevention (DLP) policy that blocks sharing of credit card numbers in email. Which Microsoft 365 admin center should you use to create and manage this DLP policy?

A.Microsoft Security Center
B.Microsoft Entra admin center
C.Microsoft Purview compliance portal
D.Microsoft 365 admin center
AnswerC

The Microsoft Purview compliance portal is the centralized hub for managing compliance and information-protection solutions, including Data Loss Prevention (DLP). In this portal, you can create and manage DLP policies that identify, monitor, and automatically protect sensitive data across Exchange, SharePoint, OneDrive, Teams, and endpoints. It provides unified policy management, integration with sensitivity labels, and detailed activity reports, making it the correct location for this task.

Why this answer

The Microsoft Purview compliance portal is the correct admin center for creating and managing Data Loss Prevention (DLP) policies because it provides the unified compliance management interface for data protection, including DLP for Exchange Online email. DLP policies that block sharing of sensitive information like credit card numbers are configured under the 'Data loss prevention' section within the Purview portal, which leverages built-in sensitive information types and rules to enforce actions such as blocking email transmission.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 admin center (general admin tasks) with the Purview compliance portal (compliance-specific tasks), leading them to select the wrong portal for DLP policy management.

How to eliminate wrong answers

Option A is wrong because the Microsoft Security Center focuses on threat protection, security posture management, and incident response (e.g., Microsoft Defender for Cloud), not on compliance-based data loss prevention policies for email. Option B is wrong because the Microsoft Entra admin center is used for identity and access management (e.g., user accounts, groups, conditional access policies), not for configuring DLP rules that govern data in transit. Option D is wrong because the Microsoft 365 admin center is for general tenant administration (e.g., user licensing, service health, billing) and does not include the compliance-specific tools needed to create or manage DLP policies.

75
MCQeasy

A company wants to enable employees to securely access work files and collaborate in real-time from any device. Which Microsoft 365 service should the company use?

A.Microsoft Teams
B.Exchange Online
C.SharePoint Online
D.OneDrive for Business
AnswerA

Microsoft Teams is a comprehensive collaboration hub that integrates persistent chat, video meetings, file storage, and real-time co-authoring within a single interface. It uses SharePoint and OneDrive for backend file storage while providing a unified workspace for team communication and project management. With Azure Active Directory integration, it enables secure access to organizational resources, making it the ideal solution for secure work collaboration.

Why this answer

Microsoft Teams is the correct choice because it provides a unified platform for real-time collaboration, including chat, video conferencing, and file sharing, with integrated security and compliance features. It allows employees to access and co-author work files from any device while leveraging Azure Active Directory for conditional access and data encryption in transit and at rest.

Exam trap

The trap here is that candidates often confuse SharePoint Online's document management capabilities with real-time collaboration, overlooking that Teams is the primary service for synchronous teamwork and integrated file access from any device.

How to eliminate wrong answers

Option B (Exchange Online) is wrong because it is primarily an email and calendaring service, not designed for real-time file collaboration or secure file access from any device. Option C (SharePoint Online) is wrong because while it enables file storage and sharing, it lacks native real-time collaboration features like persistent chat and video meetings that Teams provides. Option D (OneDrive for Business) is wrong because it is a personal cloud storage service for individual file sync and sharing, not a team-based collaboration hub with integrated real-time communication.

Page 1 of 4 · 300 questions totalNext →

Ready to test yourself?

Try a timed practice session using only M365 Apps Services questions.