Courseiva

CCNA M365 Apps Services Questions

75 of 300 questions · Page 3/4 · M365 Apps Services topic · Answers revealed

151
MCQeasy

A training manager needs to create a simple video that includes screen recordings, webcam overlay, and transitions to announce a new compliance policy. The manager wants to use a Microsoft 365 app that is designed for video creation and editing. Which Microsoft 365 app should the manager use?

A.Microsoft Clipchamp
B.Microsoft Stream
C.Microsoft Teams
D.Microsoft PowerPoint
AnswerA

Clipchamp is Microsoft's web-based video editor included with Microsoft 365 consumer and commercial plans. Its timeline-based editor combines screen recordings, webcam footage, imported images, and audio, then lets you trim clips, add transitions, text overlays, filters, and captions before exporting or publishing. That makes it the appropriate tool for creating a simple training video, because you can produce and polish a finished MP4 in one workflow.

Why this answer

Microsoft Clipchamp is the correct app because it is a dedicated video creation and editing tool included with Microsoft 365, specifically designed for tasks like combining screen recordings, webcam overlays, and transitions. Unlike other Microsoft 365 apps, Clipchamp provides a full timeline-based editor with built-in support for these features, making it ideal for producing a polished compliance policy announcement video.

Exam trap

The trap here is that candidates often confuse Microsoft Stream (a video hosting service) with a video editor, or assume PowerPoint's recording features are sufficient for multi-track video editing, when Clipchamp is the only Microsoft 365 app purpose-built for creating and editing videos with screen recordings, webcam overlays, and transitions.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because Stream is a video hosting and sharing platform, not a video creation or editing tool; it lacks features like screen recording, webcam overlay, and transition editing. Option C (Microsoft Teams) is wrong because Teams is a collaboration and communication app focused on chat, meetings, and file sharing, not a video editor; while it can record meetings, it cannot edit or add transitions to existing recordings. Option D (Microsoft PowerPoint) is wrong because PowerPoint is a presentation software that can record slides with narration and webcam, but it does not support multi-track video editing, screen recording with overlay, or custom transitions between video clips; its video export is limited to slide-based recordings.

152
MCQeasy

A sales team needs to create a shared list of customer contact information with custom fields like company, email, phone, and deal stage. The list should be accessible from within Outlook and allow real-time updates by multiple users. Which Microsoft 365 app should they use?

A.Microsoft Lists
B.Microsoft To Do
C.Microsoft Planner
D.Microsoft Dynamics 365
AnswerA

Microsoft Lists is a SharePoint-backed data-tracking app in Microsoft 365 that lets you build a tailored customer contact list with custom columns for name, email, phone, and other fields. It supports real-time multi-user editing, version history, and sorting or filtering, and it appears in Outlook via the "My Lists" entry point or direct list sharing. Because it is built on SharePoint, it can be embedded in Teams and automated with Power Automate, making it the correct fit for a shared, structured list.

Why this answer

Microsoft Lists is the correct choice because it provides a customizable, shared list that supports custom columns (e.g., company, email, phone, deal stage) and real-time collaboration. It integrates directly with Outlook via the Lists app or by adding a list as a tab in Outlook, allowing the sales team to access and update the list without leaving their email client.

Exam trap

The trap here is that candidates may confuse Microsoft Lists with Microsoft To Do or Planner because both involve task tracking, but Lists is the only one that supports custom columns and real-time multi-user editing for structured data like contacts.

How to eliminate wrong answers

Option B is wrong because Microsoft To Do is a personal task management app that does not support custom fields or real-time multi-user editing of shared lists; it lacks the column customization and collaborative features needed. Option C is wrong because Microsoft Planner is designed for team task management with boards and buckets, not for creating a shared list of contacts with custom fields, and it does not integrate directly into Outlook for inline access. Option D is wrong because Microsoft Dynamics 365 is a full Customer Relationship Management (CRM) platform that is far more complex and costly than needed; it is not a simple list app and does not provide the lightweight, Outlook-integrated shared list functionality required.

153
MCQmedium

An organization wants to monitor and respond to security incidents across their Microsoft 365 environment, including email, endpoints, and cloud apps. Which solution should they deploy?

A.Microsoft Intune
B.Microsoft Defender XDR
C.Microsoft Sentinel
D.Microsoft Defender for Office 365
AnswerB

Microsoft Defender XDR (formerly Microsoft 365 Defender) is an integrated XDR service that natively aggregates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. It uses AI and automated response actions to investigate and remediate incidents in a single console, covering email, endpoints, identities, and applications. This exactly matches the requirement to monitor and respond to security incidents across the full Microsoft 365 environment, making it the correct choice.

Why this answer

Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified extended detection and response solution that correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps (Defender for Cloud Apps). It provides a single portal for monitoring and responding to security incidents across the Microsoft 365 environment, making it the correct choice.

Exam trap

MS-900 often tests the difference between XDR (Defender XDR) and SIEM (Sentinel) — candidates may choose Sentinel thinking it covers all Microsoft 365 workloads, but the question specifically asks for integrated monitoring and response across email, endpoints, and cloud apps, which is Defender XDR's role.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device and application management (MDM/MAM) service, not a security incident monitoring and response solution. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution that ingests data from many sources, but it is not specifically the integrated XDR solution for Microsoft 365 workloads; Sentinel is broader and often used alongside Defender XDR. Option D is wrong because Microsoft Defender for Office 365 only covers email and collaboration threats, not endpoints or cloud apps, so it is not the comprehensive cross-domain solution required.

154
Multi-Selectmedium

A company uses Microsoft 365 E3 and wants to implement a collaboration solution that allows multiple users to co-author documents in real time, track version history, and set permissions at the document level. Which THREE Microsoft 365 services can fulfill these requirements?

Select 3 answers
A.SharePoint Online
B.OneDrive for Business
C.Microsoft Teams
D.Exchange Online
E.Yammer
AnswersA, B, C

SharePoint Online satisfies the co-authoring, version history and document-level permission requirements through its document libraries, which store files in OneDrive-backed storage and enforce item-level permissions via Microsoft Entra ID security groups. Real-time co-authoring uses the Office co-authoring service, while version history retains prior copies within each library.

Why this answer

SharePoint Online (A) is correct because it provides document libraries with real-time co-authoring in Office apps, built-in version history, and item-level (document-level) permissions via SharePoint groups and unique permission inheritance breaks. OneDrive for Business (B) is correct because it is built on the same SharePoint document library engine, so it also supports real-time co-authoring, version history, and per-file sharing permissions for individual users. Microsoft Teams (C) is correct because its Files tab is backed by SharePoint Online or OneDrive, enabling real-time co-authoring, version tracking, and document-level permission management directly within team and channel contexts.

Exchange Online (D) is incorrect because it is a mail, calendaring, and messaging service, not a document collaboration or permission platform. Yammer (E) is incorrect because it is an enterprise social networking service for conversations and communities, not a document co-authoring or version-control solution.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a separate collaboration tool, but Teams relies on SharePoint Online and OneDrive for its file storage and co-authoring capabilities, making it a valid answer when the question explicitly asks for services that fulfill the requirements directly.

155
MCQeasy

A project team needs a central location to store and collaborate on project documents, with version history, co-authoring, and the ability to share files securely with external partners. Which Microsoft 365 service provides these capabilities?

A.Exchange Online
B.SharePoint Online
C.Microsoft Stream
D.Microsoft Viva Engage
AnswerB

SharePoint Online provides managed document libraries designed for persistent team collaboration. It supports versioning, real-time co-authoring, metadata, workflows, and external sharing controls, all on a single secure platform. Site permissions can be scoped by site, library, folder, or item, making it the appropriate central location for the project team's content.

Why this answer

SharePoint Online is the correct choice because it provides a centralized document library with version history, real-time co-authoring via Office Online integration, and granular external sharing controls through secure links or direct invitations. These capabilities align directly with the project team's need for collaborative document management and secure external partner access.

Exam trap

The trap here is that candidates confuse Exchange Online's file attachments (which lack version history and co-authoring) with a proper document management system, or mistakenly think Microsoft Stream's sharing features equate to collaborative document editing.

How to eliminate wrong answers

Option A is wrong because Exchange Online is an email and calendaring service based on the MAPI/HTTP protocol, not a document storage or collaboration platform; it lacks version history and co-authoring for files. Option C is wrong because Microsoft Stream is a video hosting and sharing service for enterprise video content, not designed for document collaboration or version control. Option D is wrong because Microsoft Viva Engage (formerly Yammer) is a social networking and employee engagement tool focused on communities and conversations, not structured document management or secure external file sharing.

156
MCQhard

A company wants to automate approval workflows for expense reports. Which Microsoft 365 service should they use?

A.Microsoft Planner
B.Microsoft Forms
C.SharePoint
D.Power Automate
AnswerD

Power Automate is the correct service because it provides a dedicated workflow automation platform with a built-in approval action that supports multiple approvers, conditional routing, and integration with Microsoft 365 services like Outlook, Teams, and SharePoint. Using the 'When a new expense report is submitted' trigger (e.g., from Forms or SharePoint), you can create a flow that sends an approval request, waits for the approver's response, and then updates a status or sends a notification — all without requiring custom code. This directly fulfills the requirement to automate approval workflows for expense reports.

Why this answer

Power Automate is the correct service because it provides workflow automation capabilities, including the ability to create approval workflows for expense reports. It integrates with various Microsoft 365 services and third-party apps, allowing users to design automated processes that trigger approvals based on specific conditions, such as submission of an expense report via email or SharePoint.

Exam trap

The trap here is that candidates may confuse SharePoint's ability to host documents and trigger workflows with being the actual automation engine, but SharePoint requires Power Automate (or legacy SharePoint Designer) to execute the approval logic.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing work among teams, not a workflow automation service; it lacks the ability to create automated approval processes. Option B is wrong because Microsoft Forms is used for creating surveys and quizzes, not for automating workflows; it can collect data but cannot initiate or manage approval workflows. Option C is wrong because SharePoint is a document management and collaboration platform that can store expense reports and trigger workflows via Power Automate, but it does not natively provide the automation engine itself; SharePoint alone cannot create or run approval workflows without Power Automate or SharePoint Designer.

157
Multi-Selecthard

Which THREE Microsoft 365 services are part of Microsoft Defender XDR (Extended Detection and Response)? (Select three.)

Select 3 answers
A.Microsoft Defender for Endpoint
B.Microsoft Purview
C.Microsoft Defender for Identity
D.Microsoft Sentinel
E.Microsoft Defender for Office 365
AnswersA, C, E

Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution that provides antivirus, attack surface reduction, endpoint detection and response (EDR), and vulnerability management for Windows, macOS, Linux, iOS, and Android devices. It is one of the core signal suppliers to Microsoft Defender XDR, whose unified incident engine correlates device telemetry with identity and email alerts. In this question it is correct because it represents the device-protection workload of Microsoft 365 Defender.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is a unified security suite that correlates signals across endpoints, identities, and email/collaboration. Microsoft Defender for Endpoint is correct because it provides endpoint detection and response (EDR) capabilities, collecting telemetry from Windows, macOS, Linux, Android, and iOS devices to detect and remediate advanced threats.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with a component of Defender XDR, but Sentinel is a separate Azure service that ingests logs from Defender XDR rather than being part of the XDR product itself.

158
MCQeasy

Your organization wants to provide employees with a personalized news feed and internal communications dashboard. Which Microsoft 365 service should you use?

A.Microsoft Stream
B.Microsoft Viva Topics
C.Microsoft Viva Connections
D.SharePoint Online
AnswerC

Microsoft Viva Connections is the correct choice because it provides a personalized employee dashboard that aggregates corporate news, targeted communications, and frequently used resources into a single, navigable interface. It is built on SharePoint and delivered as a Teams app, using audience targeting and Microsoft Graph to tailor content to each user's role, location, or department. Viva Connections also integrates with Viva Engage and other Viva modules, making it the dedicated entry point for internal communications and daily employee tasks.

Why this answer

Microsoft Viva Connections is the correct choice because it provides a personalized news feed and internal communications dashboard directly within Microsoft Teams. It aggregates content from SharePoint, Yammer, and other sources to create a curated employee experience, aligning with the requirement for a centralized communications hub.

Exam trap

The trap here is that candidates often confuse SharePoint Online's news web part with Viva Connections' personalized dashboard, but Viva Connections is the dedicated service for a unified, personalized employee experience within Teams.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video management and sharing service, not a news feed or communications dashboard. Option B is wrong because Microsoft Viva Topics uses AI to organize knowledge into topic pages, but it does not provide a personalized news feed or internal communications dashboard. Option D is wrong because SharePoint Online is a document management and collaboration platform that can host news posts, but it lacks the personalized, dashboard-style aggregation and integration with Teams that Viva Connections offers.

159
MCQhard

An organization uses Microsoft Bookings to manage customer appointments. Staff need to see their Bookings calendar within Outlook. What must be configured?

A.Configure calendar sharing between Bookings and Outlook.
B.Run a PowerShell script to sync calendars.
C.Add staff members to the Bookings calendar.
D.Integrate Bookings with Dynamics 365.
AnswerC

Adding staff members to the Bookings calendar is the correct action because it is the explicit step that enables the automatic Outlook integration. When staff are added, they are granted access to the underlying Exchange Online mailbox that stores Bookings appointments, and Exchange's auto-mapping feature automatically surfaces those booking items in each staff member's own Outlook calendar, requiring no manual configuration.

Why this answer

For staff to see their Bookings calendar within Outlook, they must be added as staff members in the Bookings calendar. This automatically creates a Bookings-specific calendar in their Outlook that syncs appointments. No additional sharing or scripting is required.

Exam trap

The trap here is that candidates may think additional sharing or scripting is required, but Microsoft has designed Bookings to automatically integrate with Outlook once staff membership is configured, making the other options unnecessary overhead.

How to eliminate wrong answers

Option A is wrong because calendar sharing between Bookings and Outlook is not a separate configuration step; the integration is built-in once staff are added. Option B is wrong because no PowerShell script is needed to sync calendars; the synchronization happens automatically via Exchange Web Services (EWS) when staff are members. Option D is wrong because integrating Bookings with Dynamics 365 is an advanced feature for customer relationship management, not a prerequisite for staff to see their Bookings calendar in Outlook.

160
MCQmedium

A department asks for the Microsoft 365 service best suited for interactive business dashboards. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Purview Compliance Manager
B.Power BI
C.Microsoft Defender for Endpoint
D.Microsoft Entra Privileged Identity Management
AnswerB

Power BI delivers interactive dashboards natively, with no custom operational scripts required. Its semantic models and scheduled refresh handle data preparation, satisfying the stem's constraint directly. Unlike Excel or bespoke reporting, Power BI provides governed, shareable visualisations through Microsoft Fabric and Microsoft Entra ID authentication, matching the department's stated need.

Why this answer

Power BI is the correct choice because it is Microsoft's dedicated business analytics service that enables users to create interactive dashboards and reports from various data sources. It provides drag-and-drop visualization tools, real-time data refresh, and natural language querying (Q&A) without requiring custom operational scripts, aligning perfectly with the department's requirement for no-code dashboard creation.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's compliance dashboards (which are static compliance scorecards) with interactive business dashboards, or assume that security tools like Defender for Endpoint include business analytics features, leading them to select a wrong option that sounds 'dashboard-like' but serves a completely different purpose.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that assesses and reports on an organization's compliance posture against regulations; it does not create interactive business dashboards. Option C is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response; it is not designed for business analytics or dashboarding. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged access to Azure AD and Azure resources; it has no capability for building interactive dashboards.

161
MCQmedium

An organization uses Microsoft Teams and wants to record meetings for compliance purposes. Which Microsoft 365 service provides meeting recording with automatic transcription?

A.Microsoft OneDrive
B.Microsoft Teams meeting recording
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Microsoft Teams meeting recording is the native feature that captures the meeting's audio, video, screen sharing, and chat transcript. The organizer or a presenter clicks the record button in the meeting controls, and the recording is then processed, transcribed, and stored for playback. It is the only correct method to record a Teams meeting directly.

Why this answer

Microsoft Teams meeting recording with automatic transcription is a native feature of Teams itself, not a separate service. When a meeting is recorded, Teams stores the recording in OneDrive or SharePoint, but the recording and transcription capabilities are part of the Teams meeting experience. Option B is correct because Teams meeting recording directly provides the recording and automatic transcription for compliance purposes.

Exam trap

Microsoft often tests the misconception that Microsoft Stream is the service that provides meeting recording and transcription, but in reality, Stream is only a playback and management interface, while the recording and transcription are native Teams features.

How to eliminate wrong answers

Option A is wrong because Microsoft OneDrive is a cloud storage service that stores the recorded file after the meeting, but it does not provide the meeting recording or transcription functionality itself. Option C is wrong because Microsoft Forms is a survey and quiz tool, not a meeting recording or transcription service. Option D is wrong because Microsoft Stream (classic) was previously used for storing and managing meeting recordings, but as of 2023, Teams meeting recordings are stored in OneDrive/SharePoint, and Stream (on SharePoint) is a video playback portal, not the service that performs recording or transcription.

162
MCQhard

Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that users can access their mailboxes using Outlook for Windows without re-entering credentials each time. Which Microsoft 365 service should you configure to enable single sign-on (SSO) and modern authentication?

A.Microsoft Entra ID
B.Microsoft Intune
C.Microsoft Purview
D.Microsoft Sentinel
AnswerA

Microsoft Entra ID is the cloud identity and access management service (previously Azure AD) that provides authentication, single sign-on, and conditional access for Exchange Online. When migrating from on-premises Exchange, you must synchronize and authenticate user identities to access mailboxes, using protocols like OAuth 2.0 and modern authentication. Without Entra ID, Exchange Online cannot verify user credentials or enforce MFA.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the identity and access management service that provides single sign-on (SSO) and modern authentication (OAuth 2.0, OpenID Connect) for Exchange Online. When configured, Outlook for Windows can use the Microsoft Entra ID token to authenticate silently, eliminating the need for users to re-enter credentials each time they access their mailbox.

Exam trap

The trap here is that candidates confuse Microsoft Intune (device management) with identity services, or assume that any Microsoft 365 security or management tool can enable SSO, when only the identity provider (Microsoft Entra ID) can issue authentication tokens for modern auth.

How to eliminate wrong answers

Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service; it does not handle authentication or SSO for Exchange Online. Option C is wrong because Microsoft Purview is a compliance and data governance solution (e.g., data loss prevention, eDiscovery); it has no role in enabling SSO or modern authentication. Option D is wrong because Microsoft Sentinel is a cloud-native security information and event management (SIEM) service; it is used for threat detection and response, not for identity-based authentication.

163
Multi-Selecthard

Which TWO Microsoft 365 compliance features are available in Microsoft Purview to help organizations manage and protect sensitive data?

Select 2 answers
A.Microsoft Defender for Cloud Apps
B.Data Lifecycle Management
C.Microsoft Entra ID Protection
D.Microsoft Defender XDR
E.Data Loss Prevention (DLP)
AnswersB, E

Data Lifecycle Management is a Microsoft Purview compliance solution that enables organizations to define retention and deletion policies for content across workloads such as Exchange, SharePoint, OneDrive, and Teams. It helps meet legal, regulatory, and business requirements by ensuring data is retained only as long as necessary and then systematically disposed of, reducing risk of over-retention or premature deletion.

Why this answer

Data Lifecycle Management (B) is correct because it enables organizations to govern their data through retention policies and retention labels, automatically retaining or deleting content based on regulatory requirements. Data Loss Prevention (DLP) (E) is correct because it identifies, monitors, and protects sensitive data across Microsoft 365 services (Exchange, SharePoint, OneDrive, Teams) by applying policies that prevent unauthorized sharing or leakage.

Exam trap

Microsoft often tests the distinction between security tools (Defender, Entra ID Protection) and compliance tools (Purview features), so candidates mistakenly select Defender for Cloud Apps or Defender XDR because they associate 'protect sensitive data' with security rather than data governance and loss prevention.

164
MCQhard

A multinational organization uses Microsoft 365 and wants to comply with data residency requirements. They need to ensure that data for European users stays within the European Union. Which Microsoft 365 feature should they configure?

A.Create retention policies for EU users.
B.Set conditional access policies to restrict access from outside EU.
C.Use data loss prevention policies to block data movement.
D.Configure multi-geo capabilities in SharePoint Online and OneDrive.
AnswerD

Multi-Geo capabilities in SharePoint Online and OneDrive for Business let an organization maintain a single Microsoft 365 tenant while provisioning data at rest in specific satellite geographic locations. By assigning EU users to a European Geo location, the administrator ensures their SharePoint sites and OneDrive libraries are stored in EU datacenters, meeting data residency requirements. This is the correct answer because it directly controls the physical storage location for the relevant workloads, unlike policy-based controls that only affect data lifecycle, access, or movement.

Why this answer

Multi-Geo capabilities in SharePoint Online and OneDrive allow organizations to provision and store data at rest in specific geographic locations, such as the European Union, to meet data residency requirements. This feature enables tenant administrators to define a preferred data location for users, ensuring their content remains within the EU boundary.

Exam trap

The trap here is that candidates confuse data residency (where data is stored at rest) with data protection mechanisms like retention, access control, or DLP, which address data lifecycle and security but not physical storage location.

How to eliminate wrong answers

Option A is wrong because retention policies control how long data is kept, not where it is stored geographically; they do not enforce data residency. Option B is wrong because conditional access policies control authentication and access based on location, but they do not determine where data is physically stored at rest. Option C is wrong because data loss prevention policies prevent sensitive data from being shared or exfiltrated, but they do not control the geographic location of data storage.

165
MCQeasy

A user wants to schedule a meeting with colleagues and automatically record the meeting for later viewing. Which Microsoft 365 apps should they use?

A.Microsoft SharePoint and Microsoft Viva Topics
B.Microsoft Viva Engage and Microsoft Forms
C.Microsoft OneDrive and Microsoft Stream
D.Microsoft Outlook and Microsoft Teams
AnswerD

Outlook integrates with Exchange Online to provide a shared calendar, meeting invitation workflow, and attendee availability tracking. Microsoft Teams provides the online meeting infrastructure, including audio/video conferencing, meeting recording, and live captions. Together, they automate the entire process: Outlook schedules the meeting with calendar invites, and Teams can be set to record the session for later access.

Why this answer

Microsoft Outlook is used to schedule the meeting and send invitations, while Microsoft Teams provides the platform to conduct the online meeting with the capability to automatically record the session. The recording is saved to Microsoft Stream (or OneDrive/SharePoint depending on the version), but the core apps for scheduling and recording are Outlook and Teams.

Exam trap

The trap here is that candidates may think Microsoft Stream alone is sufficient for recording, but Stream is only the storage/playback service, not the app that schedules or conducts the meeting with recording capability.

How to eliminate wrong answers

Option A is wrong because Microsoft SharePoint is a document management and collaboration platform, and Viva Topics uses AI to organize knowledge; neither provides meeting scheduling or recording. Option B is wrong because Viva Engage is an enterprise social network and Forms is for surveys and quizzes; neither supports meeting scheduling or recording. Option C is wrong because OneDrive is for file storage and sync, and Stream is a video service; while Stream can host recordings, OneDrive does not schedule meetings, and the combination lacks the scheduling and real-time meeting capabilities.

166
Multi-Selecteasy

Which TWO Microsoft 365 apps are included in the Microsoft 365 Business Basic subscription?

Select 2 answers
A.Microsoft Teams
B.Microsoft Outlook (web)
C.Microsoft Power BI Pro
D.Microsoft Word (desktop app)
E.Microsoft Purview Compliance Portal
AnswersA, B

Microsoft Teams is included in Microsoft 365 Business Basic as the primary chat, meetings, and collaboration hub. In Business Basic, Teams provides full chat, audio/video conferencing, mobile and web access, and guest collaboration through its cloud-based service, so users do not need a desktop Office installation to work together. Teams is a correct answer because it is explicitly part of the Business Basic subscription rather than an add-on or separate workload.

Why this answer

Microsoft 365 Business Basic is a cloud-only subscription that includes web and mobile versions of Office apps, not desktop installations. Microsoft Teams is included as the core collaboration hub for chat, meetings, and file sharing. Microsoft Outlook (web) is also included, providing email, calendar, and contacts via a browser interface.

Exam trap

The trap here is that candidates often confuse 'Business Basic' with 'Business Standard' or 'Apps for Business,' assuming desktop Office apps are included, or they mistakenly think Power BI Pro is a standard component of any Microsoft 365 plan.

167
MCQhard

A company has employees who frequently work from home on personal devices. They need to ensure corporate data in Microsoft 365 is protected even if the device is lost or compromised, without managing the entire device. What should they implement?

A.Microsoft Intune App Protection Policies
B.Microsoft Defender for Endpoint
C.Microsoft Entra Conditional Access
D.Microsoft Purview Data Loss Prevention
AnswerA

Intune App Protection Policies (APP) are the correct choice because they provide mobile application management (MAM) capabilities that do not require device enrollment or full device management. APP applies policy directly to managed apps, allowing control over corporate data via features like preventing copy/paste, restricting save-as, enforcing app-level encryption, and enabling selective wipe of corporate data without removing personal data from a BYOD device. This gives protection of corporate data within apps on unmanaged personal devices, which is exactly what is needed for employees working from home on personal devices.

Why this answer

Microsoft Intune App Protection Policies (MAM) protect data at the app level without device enrollment. Conditional Access controls access. DLP prevents data loss.

MAM is the correct approach for unmanaged devices.

168
Multi-Selecteasy

Which TWO Microsoft 365 services are primarily used for enterprise social networking and communication within an organization?

Select 2 answers
A.Microsoft Teams
B.Microsoft Viva Engage
C.Microsoft SharePoint
D.Microsoft Stream
E.Exchange Online
AnswersA, B

Microsoft Teams is the correct answer because it is the primary hub for persistent, threaded chat and channel-based communication in Microsoft 365. Teams allows users to send direct messages, create group conversations, and collaborate in channels organized by project or topic, all while integrating with Office apps and meeting features. Its real-time messaging capabilities directly fulfill the 'communication' requirement for enterprise collaboration, distinct from document storage or video hosting.

Why this answer

Microsoft Teams is correct because it serves as the primary hub for persistent chat, meetings, and collaboration, integrating enterprise social networking features such as channels, @mentions, and threaded conversations. Microsoft Viva Engage (formerly Yammer) is correct because it provides a dedicated enterprise social network for broad organizational communication, communities, and knowledge sharing, distinct from Teams' more team-focused interactions.

Exam trap

Microsoft often tests the distinction between collaboration tools by making SharePoint or Exchange Online seem like social networking options, but the trap here is confusing document management or email with enterprise social networking, which requires persistent, community-driven communication features.

169
MCQmedium

A company uses Microsoft 365 E3. They want to upgrade to include advanced compliance features like communication compliance and insider risk management. Which add-on license do they need?

A.Microsoft 365 E5 Compliance
B.Microsoft 365 E5 Security
C.Microsoft Purview Compliance Manager
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft 365 E5 Compliance is a paid add-on for E3 that delivers advanced compliance workloads, including communication compliance for monitoring employee communications and insider risk management for detecting suspicious activities. These features are not available in E3 by default, making this the correct upgrade to satisfy the stated compliance requirement.

Why this answer

Microsoft 365 E5 Compliance is the correct add-on license because it includes advanced compliance features such as Communication Compliance (for monitoring and detecting inappropriate messages) and Insider Risk Management (for identifying and mitigating internal data risks). These features are not available in the base Microsoft 365 E3 subscription and require the E5 Compliance SKU to unlock.

Exam trap

The trap here is that candidates often confuse Microsoft 365 E5 Security with Microsoft 365 E5 Compliance, assuming that advanced security features automatically include compliance capabilities, but Microsoft separates these into distinct SKUs with different feature sets.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 E5 Security provides advanced security features like Microsoft Defender for Office 365 and Microsoft Defender for Identity, but it does not include Communication Compliance or Insider Risk Management, which are compliance-specific capabilities. Option C is wrong because Microsoft Purview Compliance Manager is a tool within the Microsoft Purview compliance portal for managing compliance assessments and controls, not a license add-on; it is included with E5 Compliance but cannot be purchased as a standalone license to enable the required features. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on securing cloud applications and data, not a license that provides Communication Compliance or Insider Risk Management.

170
Matchingmedium

Match each Microsoft 365 service level agreement (SLA) term to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Service is available at least 99.9% of the time monthly

Discount on bill if SLA is not met

Scheduled downtime for updates

Minimum spend or term length in contract

Why these pairings

Correct matches: Monthly Uptime Percentage is the availability percentage, Service Credit is the compensation for not meeting that percentage, Downtime is the period of unavailability, and SLA is the overarching agreement. Common confusions involve swapping the definitions of Monthly Uptime Percentage and Service Credit.

171
MCQhard

Your organization uses Microsoft 365 E5 and experiences a security incident where a user's account is compromised. You need to immediately prevent the attacker from accessing Microsoft 365 services while preserving the user's data for investigation. Which action should you take?

A.Block sign-in for the user in Microsoft Entra ID
B.Delete the user account from Microsoft Entra ID
C.Revoke the user's sessions using Microsoft Entra ID
D.Reset the user's password
AnswerA

Blocking sign-in in Microsoft Entra ID flips the user account to a disabled state (Sign-in enabled = No), which immediately rejects all new authentication requests for Entra ID and Microsoft 365 services. This prevents the attacker from obtaining any additional access tokens, and while previously issued tokens may remain technically valid until expiration, most resource access attempts will fail on the next revalidation. Crucially, this action preserves all user data such as mailbox and OneDrive contents, allowing forensic investigation without any deletion of evidence.

Why this answer

Blocking sign-in for the user in Microsoft Entra ID immediately prevents the attacker from authenticating to any Microsoft 365 service, while the user's data remains intact in Exchange Online, SharePoint, and OneDrive for forensic analysis. This action does not delete or alter any data, preserving the full investigation trail.

Exam trap

The trap here is that candidates confuse 'revoke sessions' (which only kills current sessions but allows re-authentication) with 'block sign-in' (which prevents all future authentication), leading them to choose Option C as a quick fix without realizing the attacker can simply log back in.

How to eliminate wrong answers

Option B is wrong because deleting the user account permanently removes the user object and all associated data (mailbox, OneDrive files, SharePoint access) from Microsoft 365, destroying evidence needed for investigation. Option C is wrong because revoking sessions only terminates active tokens and sessions but does not prevent the attacker from re-authenticating with the compromised credentials, leaving the account still vulnerable. Option D is wrong because resetting the password alone does not invalidate existing refresh tokens or active sessions; the attacker could still use cached tokens or non-expired sessions to access services until those tokens expire or are explicitly revoked.

172
MCQhard

A global consulting firm uses Microsoft 365 E5. Consultants frequently travel and need to access email, files, and Teams on personal iOS and Android devices without enrolling the devices in mobile device management. The security team requires that corporate data remain protected and that they can selectively wipe corporate data if a device is lost. Which Microsoft 365 feature should the firm implement?

A.Microsoft Intune device compliance policies
B.Microsoft Purview Information Barriers
C.Microsoft Intune app protection policies (MAM)
D.Microsoft Defender for Cloud Apps Conditional Access App Control
AnswerC

App protection policies in Intune protect corporate data at the app level without requiring device enrollment. They can enforce PIN, block copy-paste to personal apps, and enable selective wipe of corporate data from managed apps on iOS and Android. This directly meets the firm's need to secure email, files, and Teams on personal devices without MDM enrollment.

Why this answer

Intune app protection policies (mobile application management) secure corporate data within apps on personal devices without enrollment. They prevent data leakage between managed and unmanaged apps and allow selective wipe of corporate data. Device compliance policies, Information Barriers, and Conditional Access App Control do not provide the same app-level containerization and selective wipe for unenrolled devices.

Exam trap

The trap here is assuming that device compliance or Conditional Access App Control can protect data on unenrolled devices, when only app protection policies provide app-level containerization and selective wipe without enrollment.

173
MCQeasy

An HR manager needs to collect anonymous feedback from employees about a new benefits policy. They want the responses to be automatically summarized into charts and graphs. Which Microsoft 365 app is best suited for this task?

A.Microsoft Forms
B.Microsoft Excel
C.Microsoft Sway
D.Microsoft Power BI
AnswerA

Microsoft Forms supports anonymous responses and automatically generates charts and graphs from submitted answers, satisfying both the anonymity and summarisation constraints. It requires no additional configuration for basic visualisation, unlike Excel or Power BI, which would need manual setup. This makes it the most direct fit for collecting and summarising employee feedback.

Why this answer

Microsoft Forms is the correct choice because it is specifically designed for creating surveys and quizzes, with built-in support for anonymous responses and automatic generation of charts and graphs from collected data. The HR manager can create a feedback form, enable anonymous submissions, and view real-time summaries with visualizations directly within Forms, without needing additional tools.

Exam trap

The trap here is that candidates often confuse Microsoft Forms with Microsoft Power BI, assuming that any charting or graphing requirement must involve a dedicated analytics tool, but Forms handles simple survey summarization natively without needing Power BI's complexity.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel is a spreadsheet application for data analysis and manual chart creation, but it lacks native anonymous survey capabilities and does not automatically collect responses or generate charts without manual setup. Option C is wrong because Microsoft Sway is a presentation and storytelling app for creating interactive reports and newsletters, not for collecting feedback or generating charts from survey data. Option D is wrong because Microsoft Power BI is a business analytics service for advanced data visualization and reporting from multiple data sources, but it is overkill for simple anonymous feedback collection and does not provide built-in survey creation or anonymous response handling.

174
MCQmedium

Refer to the exhibit. An admin configures these two Conditional Access policies in Microsoft Entra ID. A user signs in from a new location with a device that is not compliant and is assigned a high risk level by identity protection. What will happen to the user's sign-in?

A.The user is granted access because the second policy requires MFA.
B.The user is prompted for MFA due to the second policy.
C.The user is blocked from signing in.
D.The user is allowed access but with session restrictions.
AnswerC

The user is blocked from signing in because the first Conditional Access policy is configured to block access when sign-in risk is high. Conditional Access aggregates all applicable policies, and a block action overrides any grant controls from other policies. Because the user's session cannot be established, no access is allowed and the sign-in attempt fails.

Why this answer

The first Conditional Access policy blocks all access for users assigned a high risk level. Since the user is assigned a high risk level by Identity Protection, this policy is triggered first, and because Conditional Access policies are evaluated in order and the first applicable policy that results in a block will prevent further evaluation, the user is blocked from signing in. The second policy requiring MFA for non-compliant devices is never evaluated because the block policy takes precedence.

Exam trap

The trap here is that candidates assume the second policy (requiring MFA) will be applied because the device is non-compliant, but they overlook that the first policy with a 'Block' grant control takes precedence and stops all further policy evaluation.

How to eliminate wrong answers

Option A is wrong because the user is blocked by the first policy before the second policy can grant access, and the second policy does not grant access unconditionally—it requires MFA. Option B is wrong because the user is blocked by the first policy, so they are never prompted for MFA by the second policy; the block overrides any subsequent grant controls. Option D is wrong because the user is blocked entirely, not allowed access with session restrictions; session restrictions would only apply if access were granted.

175
MCQmedium

A sales manager wants to create an interactive dashboard that visualizes the sales pipeline, customer interactions, and team performance. The data resides in Dynamics 365. The manager needs to build the dashboard quickly without coding and share it with the team. Which Microsoft 365 app should they use?

A.Power BI
B.Power Apps
C.Power Automate
D.Power Virtual Agents
AnswerA

Power BI is Microsoft’s business analytics and data visualization service, purpose-built for creating interactive dashboards and reports from multiple data sources, including Dynamics 365, Excel, and Azure SQL. It provides drag-and-drop visual building, cross-filtering, user-friendly sharing through the Power BI Service, and natural-language querying, which directly supports a sales manager’s need to track and analyze performance data at a glance.

Why this answer

Power BI is the correct choice because it is a business analytics service that enables users to create interactive dashboards and visualizations from data sources like Dynamics 365 without writing code. It supports quick data modeling, real-time updates, and easy sharing with team members via Power BI service or embedded reports, meeting the manager's need for speed and collaboration.

Exam trap

The trap here is that candidates may confuse Power BI with Power Apps because both are part of the Power Platform and can integrate with Dynamics 365, but Power Apps is for building custom apps, not for creating dashboards or visualizations.

How to eliminate wrong answers

Option B (Power Apps) is wrong because it is a low-code platform for building custom applications, not for creating interactive dashboards or visualizations; it focuses on app logic and forms, not data analytics. Option C (Power Automate) is wrong because it is designed for workflow automation and process orchestration, not for building dashboards or visual data exploration. Option D (Power Virtual Agents) is wrong because it is a tool for creating conversational AI chatbots, not for data visualization or reporting.

176
MCQmedium

A global sales team uses Microsoft Teams for communication. They need to automate business workflows such as sending approval requests when a new lead is created in Dynamics 365. Which Microsoft 365 service should they integrate with Teams?

A.Power Apps
B.Power Automate
C.Power BI
D.Power Virtual Agents
AnswerB

Power Automate is the correct choice because it is Microsoft's dedicated workflow automation service, enabling users to create cloud flows that connect to hundreds of services, including Microsoft Teams and Dynamics 365. For a global sales team, you can design an approval flow triggered by a new lead or a Teams message, automatically routing the approval request to the appropriate manager and tracking its status in real time. It provides prebuilt templates for approval scenarios and supports both automated and manual triggers, making it the ideal solution for streamlining sales communications and approvals.

Why this answer

Power Automate (Option B) is the correct service because it is designed specifically for automating business workflows across Microsoft 365 and third-party services. When a new lead is created in Dynamics 365, a Power Automate flow can trigger an approval request in Teams, enabling seamless process automation without custom code.

Exam trap

The trap here is that candidates may confuse Power Automate with Power Apps, mistakenly thinking that building a custom app is necessary for workflow automation, whereas Power Automate is the dedicated service for no-code/low-code process automation.

How to eliminate wrong answers

Option A is wrong because Power Apps is a low-code platform for building custom applications, not for automating workflows or sending approval requests. Option C is wrong because Power BI is a business analytics tool for data visualization and reporting, not for workflow automation. Option D is wrong because Power Virtual Agents is a chatbot service for creating conversational AI agents, not for triggering automated approval workflows.

177
MCQhard

A sales team uses SharePoint Online to store contract templates. When a new contract is added to a specific library, a notification should be sent to a Microsoft Teams channel with a direct link to the document. Additionally, the contract owner must receive a custom approval request via email before the document is shared externally. Which Microsoft 365 services must be combined to achieve this?

A.Microsoft Power Automate and Microsoft Teams
B.Microsoft Teams and Microsoft Power Apps
C.Microsoft Forms and Microsoft Teams
D.Microsoft Power BI and Microsoft Teams
AnswerA

Power Automate is the correct choice because its SharePoint connector includes event-driven triggers such as "When a file is created or modified" in a document library. You can then use Teams actions to post a notification or adaptive card to a specific channel, and optionally add an email step. This provides exactly the automated contract-template workflow the sales team needs, with no custom code required.

Why this answer

Microsoft Power Automate can trigger a flow when a new contract is added to a SharePoint Online library, sending a notification with a direct link to a Microsoft Teams channel. Additionally, Power Automate can initiate a custom approval request via email to the contract owner before external sharing is allowed. This combination directly addresses both requirements without needing additional services.

Exam trap

The trap here is that candidates may assume Microsoft Teams alone can handle notifications and approvals, but Teams lacks native workflow automation for SharePoint events, requiring Power Automate as the orchestration layer.

How to eliminate wrong answers

Option B is wrong because Microsoft Power Apps is a low-code platform for building custom apps, not for automating workflows or sending notifications and approvals; it lacks the built-in triggers and actions for SharePoint events and Teams messaging. Option C is wrong because Microsoft Forms is used for creating surveys and quizzes, not for triggering notifications or approval workflows based on SharePoint document events. Option D is wrong because Microsoft Power BI is a business analytics tool for data visualization and reporting, not for workflow automation or real-time notifications.

178
MCQeasy

A marketing team needs to create a visually compelling newsletter that can be distributed via email and viewed in a browser. Which Microsoft 365 app should they use?

A.Microsoft Publisher
B.Microsoft PowerPoint
C.Microsoft Word
D.Microsoft Sway
AnswerD

Sway is a Microsoft 365 application purpose-built for creating interactive, web-based newsletters, reports, and stories. It uses a responsive design engine that automatically arranges cards containing text, images, and multimedia to look good on any device, and it provides a simple shareable link for live viewing. With no manual layout required, Sway is the correct choice for a visually compelling newsletter that must be shared online.

Why this answer

Microsoft Sway is the correct choice because it is specifically designed for creating interactive, web-based newsletters and presentations that can be easily shared via a link and viewed in any browser. Unlike traditional desktop publishing tools, Sway uses a responsive design canvas that automatically adapts to different screen sizes, making it ideal for email distribution and browser viewing without requiring recipients to download attachments.

Exam trap

The trap here is that candidates often confuse Microsoft Publisher (a desktop publishing tool) with Sway because both can create visually rich content, but Publisher lacks the web-first, responsive, and browser-based sharing capabilities that the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because Microsoft Publisher is a desktop publishing application focused on print layouts (e.g., brochures, flyers) and does not natively support web-based distribution or responsive browser viewing without manual conversion. Option B is wrong because Microsoft PowerPoint is optimized for slide-based presentations and lacks the fluid, scrollable storytelling format and built-in web publishing features that Sway offers for newsletters. Option C is wrong because Microsoft Word is a word processor designed for documents and print, and while it can be saved as HTML, it does not provide a responsive, interactive web layout or easy browser-based sharing without attachments.

179
MCQmedium

A department head asks which Microsoft 365 option should be used to allow customers to book appointments online based on staff availability. Microsoft 365 app or service is the best fit?

A.Microsoft Planner
B.Microsoft Purview Audit
C.Microsoft Bookings
D.Microsoft Forms
AnswerC

Microsoft Bookings is a native scheduling service that lets organizations publish booking pages where clients can choose from available time slots based on staff calendars. It synchronizes with Exchange Online calendars, sends confirmation and reminder notifications, and can attach Teams or Skype meeting links for virtual appointments. This directly provides the appointment-booking capability the department head requires.

Why this answer

Microsoft Bookings is the correct choice because it is a Microsoft 365 app specifically designed to allow customers to book appointments online based on staff availability. It integrates with Exchange Online to synchronize staff calendars, manage time slots, and send automated confirmations, making it the ideal solution for scheduling customer-facing appointments.

Exam trap

The trap here is that candidates may confuse Microsoft Bookings with Microsoft Forms, thinking Forms can handle scheduling, but Forms lacks calendar integration and real-time availability checks, which are core to Bookings.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing team work and projects, not for scheduling customer appointments. Option B is wrong because Microsoft Purview Audit is a compliance and auditing service that logs user and admin activities, not a booking or scheduling tool. Option D is wrong because Microsoft Forms is used to create surveys, quizzes, and polls, not for managing staff availability or customer bookings.

180
MCQmedium

A training department needs to create interactive learning modules that include content pages, quizzes, and surveys. They also need to track completion and results for each learner. Which Microsoft 365 app should they use as the primary authoring tool for the quizzes and surveys?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Sway
D.Microsoft Viva Learning
AnswerB

Microsoft Forms is the correct tool because it provides a purpose-built Form/Quiz authoring surface with automatic scoring, feedback, branching, and response analytics. It integrates natively with SharePoint, Teams, and Viva Connections, enabling interactive quizzes and surveys to be embedded directly into learning modules, with submissions captured in Excel for tracking.

Why this answer

Microsoft Forms is the correct primary authoring tool because it is specifically designed for creating quizzes, surveys, and polls with automatic grading, branching logic, and result tracking. It integrates seamlessly with Microsoft Lists and Power Automate to record completion and results per learner, making it ideal for interactive learning modules.

Exam trap

The trap here is that candidates may confuse Microsoft Forms with Microsoft Sway because both can create interactive content, but Sway lacks quiz/survey functionality and result tracking, which Forms provides natively.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing platform, not an authoring tool for quizzes or surveys; it lacks native quiz creation and result tracking capabilities. Option C is wrong because Microsoft Sway is a digital storytelling and presentation tool for creating interactive reports and newsletters, but it does not support quiz creation, grading, or survey result tracking. Option D is wrong because Microsoft Viva Learning is a learning hub that aggregates content from various sources (e.g., LinkedIn Learning, SharePoint) but is not an authoring tool; it cannot create quizzes or surveys itself.

181
Multi-Selecteasy

Which TWO Microsoft 365 apps can be used to create and edit documents collaboratively in real time? (Select exactly 2.)

Select 2 answers
A.Microsoft Teams
B.Outlook on the web
C.Access for the web
D.Word for the web
E.OneNote for the web
AnswersD, E

Word for the web is a full browser-based word processor that lets users create, format, and edit .docx documents with real-time co-authoring, comment mentions, and autosave. Multiple authors can view edits by other users within seconds, with version history accessible through the ribbon's File menu. Because it provides the core Office editing experience plus live collaboration, it is one of the two correct answers.

Why this answer

Word for the web and OneNote for the web are both part of the Microsoft 365 web apps suite that support real-time co-authoring. They leverage the Office Online Server infrastructure and the Fluid Framework to allow multiple users to edit the same document simultaneously, with changes syncing via WebSocket connections and operational transforms.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a document editing app because it allows file sharing and preview, but it does not natively provide the real-time collaborative editing capability; that is a feature of the web versions of Office apps like Word and OneNote.

182
MCQmedium

During a Microsoft 365 planning workshop, provide business-class email, calendars, contacts, and mailboxes. Microsoft 365 app or service is the best fit?

A.Exchange Online
B.Microsoft Purview Audit
C.Microsoft Forms
D.Microsoft Planner
AnswerA

Exchange Online is the correct answer because it is Microsoft 365's enterprise-grade hosted messaging service, providing business email, shared calendars, contacts, and mailbox management. During a planning workshop, Exchange Online enables users to schedule meetings, share free/busy availability, and communicate via email, which are essential for collaborative business coordination. Its architecture supports public folders, resource mailboxes, and distribution groups, making it the foundational communication tool in a Microsoft 365 tenant.

Why this answer

Exchange Online is the correct choice because it is Microsoft's cloud-hosted messaging platform that provides business-class email, shared calendars, contact management, and mailbox services. It is the core service within Microsoft 365 designed specifically for these communication and collaboration needs, supporting features like shared mailboxes, resource mailboxes, and calendar sharing via Exchange Web Services (EWS) and MAPI over HTTP.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Audit (a compliance tool) with Exchange Online's mailbox auditing or confuse Planner or Forms as capable of handling email and calendar functions, when in fact only Exchange Online provides the core messaging infrastructure.

How to eliminate wrong answers

Option B (Microsoft Purview Audit) is wrong because it is a compliance and auditing solution that logs user and admin activities across Microsoft 365 services; it does not provide email, calendar, or mailbox functionality. Option C (Microsoft Forms) is wrong because it is a survey and quiz creation tool that collects responses via web forms; it lacks any email hosting, calendar, or contact management capabilities. Option D (Microsoft Planner) is wrong because it is a task management and project planning application integrated with Microsoft Teams and SharePoint; it does not handle email, calendars, or mailboxes.

183
MCQeasy

A user receives a phishing email that bypasses the spam filter. The security team wants to report the email to Microsoft for analysis. Which Microsoft 365 Defender portal should they use?

A.Microsoft 365 Defender portal
B.Exchange admin center
C.Azure portal
D.Microsoft Purview compliance portal
AnswerA

Correct. The Microsoft 365 Defender portal is the unified security operations center for Microsoft 365, and its Email & collaboration > Submissions page is explicitly designed for admins to submit suspicious emails (including phishing that bypassed filters) to Microsoft for in-depth analysis. Submitting a sample triggers automated detonation and feeds threat intelligence back into Microsoft's filtering stack, which is the correct remediation workflow for a phish that evaded existing protections.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) is the correct destination for submitting user-reported phishing emails for analysis. It provides the Submissions page under Email & collaboration, where security teams can send suspicious messages directly to Microsoft for review, bypassing the spam filter's failure. This portal consolidates threat intelligence and automated investigation capabilities for email threats.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal with the Exchange admin center, thinking email-related tasks must be done in EAC, but Microsoft 365 Defender is the dedicated security hub for threat submission and analysis.

How to eliminate wrong answers

Option B (Exchange admin center) is wrong because it is used for managing Exchange Online mail flow, transport rules, and mailbox settings, not for submitting phishing samples to Microsoft for analysis. Option C (Azure portal) is wrong because it manages Azure infrastructure, subscriptions, and resources, not Microsoft 365 security operations like email threat submissions. Option D (Microsoft Purview compliance portal) is wrong because it focuses on data governance, compliance, eDiscovery, and retention policies, not on reporting phishing emails for security analysis.

184
MCQeasy

A company needs to ensure that sensitive documents stored in SharePoint Online are automatically encrypted and cannot be shared with external users. Which Microsoft Purview feature should they use?

A.Communication compliance
B.Data Loss Prevention (DLP) policies
C.Retention labels
D.Sensitivity labels
AnswerD

Sensitivity labels are the correct solution because they enable persistent protection by applying encryption, permissions, and visual markings to documents and emails, and these protections travel with the file even when it is shared externally. Labels can be assigned manually, automatically based on content matching, or through recommended patterns, and they integrate with Azure Information Protection and Rights Management to enforce read-only, edit, or no-access permissions. Once applied, the document is encrypted and access is restricted according to the label's policy, directly satisfying the requirement to secure sensitive documents. This classification-based approach differs from reactive controls like DLP or communication compliance.

Why this answer

Sensitivity labels are the correct choice because they enforce encryption and access restrictions directly on documents, including blocking external sharing. Unlike DLP policies, which detect and prevent sharing after the fact, sensitivity labels apply persistent protection that travels with the file, ensuring it remains encrypted even if downloaded or shared outside SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, assuming DLP can both detect and encrypt content, but DLP only monitors and blocks sharing actions—it does not apply persistent encryption to the files themselves.

How to eliminate wrong answers

Option A is wrong because Communication compliance is designed to monitor and detect inappropriate communications (e.g., offensive language or regulatory violations) in Exchange Online, Teams, and Yammer, not to encrypt or restrict sharing of documents. Option B is wrong because Data Loss Prevention (DLP) policies can block external sharing of sensitive content, but they do not automatically encrypt the documents themselves; encryption requires a sensitivity label or Azure Information Protection. Option C is wrong because Retention labels are used to manage data lifecycle (retain or delete content) and do not provide encryption or access controls; they are unrelated to preventing external sharing.

185
Multi-Selectmedium

A company uses Microsoft 365 E5. They want to implement a solution to automatically classify and protect sensitive data in emails and documents. Which THREE Microsoft Purview features should they use?

Select 3 answers
A.Sensitivity labels
B.Auto-labeling policies
C.Retention policies
D.eDiscovery
E.Data Loss Prevention (DLP) policies
AnswersA, B, E

Sensitivity labels are the core data classification and protection mechanism in Microsoft 365. They apply persistent protection such as encryption, rights management (RMS), and visual markings (headers/footers/watermarks) to files and emails across SharePoint, OneDrive, Teams, and Windows endpoints. Labels also drive conditional access policies and can apply automatically or manually, making them the foundation for any information protection strategy.

Why this answer

Sensitivity labels are correct because they allow organizations to classify and protect sensitive data by applying encryption, markings, and access restrictions directly to emails and documents. Auto-labeling policies extend this by automatically applying sensitivity labels based on conditions like sensitive information types or patterns, ensuring consistent protection without manual user intervention. Data Loss Prevention (DLP) policies are correct because they detect and prevent accidental sharing of sensitive data by enforcing rules on email and document transmission, such as blocking or warning when sensitive content is detected.

Exam trap

The trap here is that candidates often confuse retention policies (which manage data retention and deletion) with data classification and protection features, leading them to incorrectly select retention policies as a solution for automatically classifying and protecting sensitive data.

186
MCQmedium

A department asks for the Microsoft 365 service best suited for department document libraries with version history. Which service should they use?

A.Microsoft Purview Compliance Manager
B.SharePoint Online
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

SharePoint Online provides department document libraries with built-in version history, retaining prior versions of files and enabling restore. It is the Microsoft 365 service purpose-built for team document storage and collaboration, matching the department's requirement.

Why this answer

SharePoint Online is the correct answer because it provides document libraries with built-in version history, allowing users to track, restore, and manage previous versions of documents. This feature is essential for collaboration and compliance, as it enables rollback to earlier versions and audit trails without additional configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's compliance features with document version history, but version history is a core SharePoint Online capability, not a compliance or security tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that helps assess and manage regulatory compliance risks, not a service for document storage or version history. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring privileged access to Azure AD and other Microsoft Online Services, not for document libraries. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response, not a document management service with version history capabilities.

187
MCQmedium

A company uses Microsoft 365 and wants to ensure that sensitive customer data in emails and documents is automatically classified and protected based on content. Which service should they implement?

A.Microsoft Entra ID
B.Microsoft Intune
C.Microsoft Defender for Cloud Apps
D.Microsoft Purview Information Protection
AnswerD

Microsoft Purview Information Protection is the correct service because it provides sensitivity labels that can be applied automatically based on sensitive info types, trainable classifiers, and machine-learning models. These labels classify data in SharePoint, OneDrive, Exchange, and endpoints, and then enforce protection actions like encryption or access restrictions. This directly addresses the requirement to ensure sensitive data is identified and protected, making it the appropriate choice.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides automated classification, labeling, and protection of sensitive data based on content inspection, such as credit card numbers or social security numbers, using trainable classifiers and sensitivity labels. This directly addresses the requirement to automatically classify and protect sensitive customer data in emails and documents within Microsoft 365.

Exam trap

Microsoft often tests the distinction between Microsoft Purview Information Protection (content classification and labeling) and Microsoft Defender for Cloud Apps (cloud app security and DLP), leading candidates to mistakenly choose Defender for Cloud Apps because they associate 'protection' with security monitoring rather than content-based classification.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is an identity and access management service that handles authentication and authorization, not content-based data classification or protection. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for classifying or protecting data within emails and documents. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility and control over cloud app usage, including threat detection and data loss prevention (DLP) policies, but it does not natively perform automatic content-based classification and labeling of emails and documents; that is the role of Purview Information Protection.

188
MCQmedium

Your organization is adopting Microsoft 365 Copilot and wants to ensure that Copilot responses are based only on organizational data that the user has permission to access. Which Microsoft 365 feature ensures this?

A.Microsoft Purview Compliance Manager
B.Microsoft Entra ID
C.Microsoft Intune
D.Microsoft Graph permissions
AnswerD

Microsoft Graph permissions are the correct answer because Copilot for Microsoft 365 operates by calling Microsoft Graph APIs on behalf of the signed-in user, inheriting that user's effective permissions. It can only access resources—such as emails, calendar items, documents, and chats—for which the user has at least the appropriate delegated permission scope, and it respects sensitivity labels and other restrictions. This ensures Copilot cannot surface data the user is not already allowed to see, maintaining least-privilege access.

Why this answer

Microsoft Graph permissions are the correct answer because Copilot uses Microsoft Graph to access organizational data. When a user asks a question, Copilot queries the Microsoft Graph API, which enforces the user's existing permissions (e.g., from Entra ID and SharePoint) to ensure responses are based only on data the user is authorized to see. This is the core mechanism that ties Copilot's responses to the user's access rights.

Exam trap

The trap here is that candidates often confuse identity management (Entra ID) with data-level permission enforcement (Microsoft Graph permissions), assuming that because Entra ID handles authentication, it also controls what data Copilot can access, but the actual data access control is delegated to Graph's permission model.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a tool for assessing and managing compliance posture (e.g., against regulations like GDPR), not for controlling real-time data access permissions for Copilot. Option B is wrong because Microsoft Entra ID (formerly Azure AD) is the identity and authentication service that defines user accounts and groups, but it does not directly enforce data-level permissions within Microsoft Graph queries; it provides the identity token that Graph uses, but the actual permission check is done via Graph permissions. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for controlling data access permissions within Microsoft 365 services like Copilot.

189
MCQmedium

A sales team needs to track customer interactions, manage leads, and automate follow-up emails. Which Microsoft 365 app is specifically designed for this customer relationship management (CRM) purpose?

A.Microsoft Dynamics 365 Sales
B.Microsoft Outlook
C.Microsoft SharePoint
D.Microsoft Power Automate
AnswerA

Dynamics 365 Sales provides native CRM entities — leads, opportunities and accounts — plus built-in workflow automation for follow-up emails, satisfying the sales team's requirement to track interactions and manage the pipeline without custom development.

Why this answer

Microsoft Dynamics 365 Sales is a dedicated customer relationship management (CRM) application within the Dynamics 365 suite, purpose-built for tracking customer interactions, managing leads, and automating follow-up emails. Unlike general productivity tools, it provides structured pipelines, lead scoring, and workflow automation specifically for sales processes.

Exam trap

The trap here is that candidates confuse a general productivity tool (Outlook) or a workflow engine (Power Automate) with a full CRM solution, overlooking that Dynamics 365 Sales is the only option specifically architected for end-to-end customer relationship management.

How to eliminate wrong answers

Option B is wrong because Microsoft Outlook is an email and calendar client, not a CRM system; it lacks lead management, pipeline tracking, and automated follow-up workflows. Option C is wrong because Microsoft SharePoint is a document management and collaboration platform, not designed for CRM functions like lead scoring or interaction tracking. Option D is wrong because Microsoft Power Automate is a workflow automation tool that can integrate with CRM systems but is not a CRM application itself; it has no native lead or customer interaction management capabilities.

190
MCQmedium

A sales manager needs a visual tool to track the sales pipeline with stages, deal values, and assigned team members. The team should be able to update the board in real time and see changes instantly. Which Microsoft 365 app is most suitable?

A.Microsoft Lists
B.Microsoft Dynamics 365 Sales
C.Microsoft Planner
D.Microsoft Excel
AnswerA

Microsoft Lists provides a visual, web-based tracking tool by letting you create a list with custom columns for deal stage, value, and owner, and then switch to a Board or Gallery view to display records as cards that move between stages. Because each list is backed by SharePoint, edits sync in real time and team members can see the pipeline update immediately. You retain the robustness of a data table rather than a simple task card, so monetary values, rollups, and filtering are natively supported.

Why this answer

Microsoft Lists is the most suitable app because it provides a customizable, real-time collaborative board view that can track sales pipeline stages, deal values, and assigned team members. Lists supports real-time co-authoring and instant updates via SharePoint, making it ideal for a visual, always-current sales tracking tool without requiring a full CRM system.

Exam trap

The trap here is that candidates often confuse Microsoft Planner's task board with a sales pipeline tool, but Planner lacks custom fields for deal values and real-time data updates across multiple users, making Lists the correct choice for this specific requirement.

How to eliminate wrong answers

Option B (Microsoft Dynamics 365 Sales) is wrong because it is a full-featured CRM platform designed for complex sales processes, not a simple visual board tool; it requires licensing and setup beyond the scope of a lightweight team tracking need. Option C (Microsoft Planner) is wrong because it is task-oriented with Kanban boards but lacks native fields for deal values and pipeline stages, and its real-time sync is limited to task status, not custom data like monetary amounts. Option D (Microsoft Excel) is wrong because while it can track data, it does not support real-time collaborative board views with instant updates; changes require manual refresh or sharing, and it lacks the visual pipeline stage representation needed.

191
MCQmedium

A manager wants to create a team site to collaborate with external partners on a project. They need to share documents with external users and control permissions. Which Microsoft 365 service should they use?

A.Microsoft Viva Connections
B.Microsoft Teams
C.OneDrive for Business
D.SharePoint Online
AnswerD

SharePoint Online team sites are the correct solution because they provide a dedicated, cloud-hosted collaboration site with document libraries, lists, page content, and granular permission settings. Site-level external sharing can be enabled in the SharePoint admin center to invite external users with specific roles such as site member or visitor, giving the manager the needed control. This matches the requirement of creating a team site for external collaboration better than any of the other options.

Why this answer

SharePoint Online is the correct choice because it provides team sites with granular permission controls, including the ability to share documents with external users via secure links or direct invitations. It supports external sharing at the site level, allowing the manager to collaborate with partners while maintaining control over permissions and document access.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the primary collaboration tool for external sharing, but Teams relies on SharePoint for file storage and permission management, making SharePoint the correct answer when the question emphasizes creating a team site and controlling permissions.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Connections is a personalized employee experience app within Teams and SharePoint, not designed for external collaboration or document sharing with partners. Option B is wrong because Microsoft Teams is primarily a chat-based collaboration platform that relies on SharePoint for file storage; while it can share with external users, the question specifically asks for a service to create a team site and control permissions, which is SharePoint's core function. Option C is wrong because OneDrive for Business is a personal storage service for individual users, not designed for creating team sites or managing external partner collaboration with granular permissions.

192
Drag & Dropmedium

Drag and drop the steps to assign a Microsoft 365 license to a user via the admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

License assignment involves selecting the user, managing licenses, choosing the product, and saving.

193
MCQhard

A graphic designer needs to create a professional printed brochure with custom page layouts, text wrapping around images, and precise control over typography. Which Microsoft 365 app is designed for this type of desktop publishing task?

A.Microsoft Publisher
B.Microsoft Sway
C.Microsoft Word
D.Microsoft PowerPoint
AnswerA

Microsoft Publisher is the correct choice because it is a dedicated desktop publishing (DTP) application within Microsoft 365, purpose-built for professional print production. It provides precise layout controls such as master pages, guide lines, and baseline grids, along with print-ready output features like CMYK color separation, bleed settings, and crop marks. These tools are essential for creating brochures, flyers, and newsletters that meet commercial printing standards, which generic productivity apps cannot match.

Why this answer

Microsoft Publisher is the correct choice because it is specifically designed for desktop publishing tasks such as creating professional brochures with custom page layouts, text wrapping around images, and precise typography control. Unlike general-purpose apps, Publisher offers advanced layout tools like master pages, baseline guides, and typographic controls that are essential for print-ready documents.

Exam trap

The trap here is that candidates often confuse Microsoft Word's basic text wrapping and image placement capabilities with the full desktop publishing features of Publisher, assuming Word can handle professional print layouts when it lacks the necessary precision and print-production tools.

How to eliminate wrong answers

Option B is wrong because Microsoft Sway is a web-based storytelling and presentation app focused on interactive, responsive layouts for digital consumption, not precise print desktop publishing. Option C is wrong because Microsoft Word is a word processor optimized for text-heavy documents and basic formatting, lacking the advanced layout and typography controls needed for professional brochure design. Option D is wrong because Microsoft PowerPoint is designed for slide-based presentations with sequential content, not for creating multi-page print layouts with text wrapping and precise typography.

194
MCQmedium

A project team needs a centralized workspace that includes a shared calendar, a document library for storing deliverables, a task list with assignments, and the ability to have threaded discussions about each item. They want a solution that is available out of the box in Microsoft 365 and integrates with Microsoft Teams. Which service should they use?

A.Microsoft Teams
B.SharePoint team site
C.Microsoft Viva Engage
D.Microsoft Planner
AnswerB

A SharePoint team site is a true centralized workspace because it includes a document library for storing and co-authoring files, a built-in calendar, custom lists, and a discussion board web part out of the box. This site can be used directly in a browser or surfaced within Microsoft Teams as a tab, making it the correct answer. It is also the default content host for Teams, so the files and some lists in a team are actually stored in the associated SharePoint site.

Why this answer

A SharePoint team site provides a centralized workspace with a shared calendar, document library, task list, and threaded discussions out of the box, and it integrates natively with Microsoft Teams (each team is backed by a SharePoint site). This matches all stated requirements without custom development. Microsoft Teams is a collaboration hub but relies on SharePoint for file storage and doesn't natively provide a document library or task list as standalone features.

Exam trap

The trap is choosing Microsoft Teams because the question mentions Teams integration — but Teams is the front-end collaboration layer, while SharePoint provides the actual workspace components (document library, calendar, task list).

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat/collaboration interface that uses SharePoint behind the scenes for files; it does not itself provide a shared calendar, document library, or task list as out-of-the-box components. Option C is wrong because Microsoft Viva Engage (formerly Yammer) is an enterprise social network focused on communities and conversations, not structured project workspaces with calendars and document libraries. Option D is wrong because Microsoft Planner provides task management only — it lacks a shared calendar, document library, and threaded discussions.

195
Multi-Selecteasy

Which TWO Microsoft 365 services provide capabilities for insider risk management?

Select 2 answers
A.Microsoft Entra ID
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Communication Compliance
D.Microsoft Intune
E.Microsoft Defender XDR
AnswersB, C

Microsoft Purview Insider Risk Management is a dedicated solution designed to detect, investigate, and act on potential internal threats such as data exfiltration or sabotage. It uses machine learning and predefined risk indicators to score user activities across Microsoft 365, enabling security teams to identify subtle patterns of insider misuse. This service directly fulfills insider risk management requirements.

Why this answer

Microsoft Purview Insider Risk Management (option B) is a dedicated service that uses machine learning and behavioral analytics to detect, investigate, and respond to risky user activities such as data theft, policy violations, or unauthorized access. It correlates signals from Microsoft 365 logs, HR data, and user behavior to identify potential insider threats, making it the primary tool for insider risk management.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (external threat detection) with insider risk management, or mistakenly think Entra ID's identity protection features cover internal user behavior monitoring, when in fact only Purview Insider Risk Management and Communication Compliance directly address insider risk scenarios.

196
MCQmedium

A marketing team needs a shared workspace where they can store documents, manage a shared calendar, conduct video meetings, and collaborate on announcements. They want this workspace to be integrated with other Microsoft 365 apps. Which Microsoft 365 service is best suited for this requirement?

A.Microsoft Teams
B.Yammer
C.SharePoint
D.Microsoft Stream
AnswerA

Microsoft Teams provides a purpose-built multi-faceted workspace: each team contains channels for threaded conversations, a SharePoint-backed document library for file storage, a shared Outlook calendar (via the Calendar app), and native video/audio meetings. This integrated hub also supports third-party and Microsoft 365 app additions, such as Planner or Power BI, without leaving the client. That combination directly satisfies a marketing team's need for a shared workspace with notes, files, calendar, and meetings.

Why this answer

Microsoft Teams is best suited because it provides a shared workspace that integrates document storage (via SharePoint), a shared calendar (via Exchange), video meetings (via Teams meetings), and collaboration on announcements (via channel posts and the Announcement app), all within a single interface that natively integrates with other Microsoft 365 apps.

Exam trap

The trap here is that candidates often confuse SharePoint's document management capabilities with a complete workspace solution, overlooking that SharePoint alone cannot provide integrated video meetings or real-time chat without additional services.

How to eliminate wrong answers

Option B (Yammer) is wrong because Yammer is an enterprise social network focused on organization-wide conversations and communities, not a team workspace with integrated document storage, shared calendars, or video meetings. Option C (SharePoint) is wrong because while SharePoint provides document storage and some calendar functionality, it lacks native video meeting capabilities and real-time chat, requiring additional tools like Teams or Skype for Business for meetings. Option D (Microsoft Stream) is wrong because Stream is a video hosting and management platform for enterprise video content, not a collaborative workspace for documents, calendars, meetings, or announcements.

197
MCQmedium

A consulting firm needs a tool to allow customers to book 30-minute online consulting sessions. The tool must show real-time availability of consultants, send automatic reminders, and allow customers to reschedule. Which Microsoft 365 app should they use?

A.Microsoft Bookings
B.Microsoft Teams
C.Microsoft Forms
D.Microsoft Lists
AnswerA

Microsoft Bookings provides a shared booking page with real-time calendar availability, letting customers self-schedule 30-minute sessions. It automatically sends confirmation and reminder emails and permits customer rescheduling, directly satisfying all three stated requirements without custom development.

Why this answer

Microsoft Bookings is the correct choice because it is a Microsoft 365 app specifically designed for scheduling and managing appointments. It provides a public booking page that shows real-time consultant availability, sends automatic email and SMS reminders, and allows customers to reschedule or cancel bookings directly, meeting all the stated requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Teams' scheduling feature (which is for internal meetings) with the customer-facing appointment booking capabilities of Microsoft Bookings, leading them to incorrectly select Teams.

How to eliminate wrong answers

Option B is wrong because Microsoft Teams is a collaboration and communication platform (chat, meetings, calls) and does not include native appointment scheduling with real-time availability display, automatic reminders, or customer-facing rescheduling capabilities. Option C is wrong because Microsoft Forms is a survey and quiz creation tool for collecting data; it cannot manage real-time availability, send automatic reminders, or handle rescheduling of appointments. Option D is wrong because Microsoft Lists is a data tracking and organization app for creating lists and workflows; it lacks built-in scheduling features like real-time availability, automated reminders, and customer self-service rescheduling.

198
MCQhard

You are the Microsoft 365 administrator for Contoso Ltd., a multinational company with 5,000 employees. The company uses Microsoft 365 E5 licenses for all users. The HR department has requested a solution to onboard new employees more efficiently. Currently, when a new employee is hired, IT manually creates a user account in Microsoft Entra ID (formerly Azure AD), assigns licenses, creates a mailbox in Exchange Online, and provisions a OneDrive for Business account. This process takes approximately 2 hours per employee and is prone to errors. The HR team uses a third-party HR system (Workday) to manage employee records. When an employee is hired in Workday, HR wants the process to be automated so that within 15 minutes, the employee has a Microsoft 365 account, appropriate licenses based on their department, and access to Microsoft Teams and SharePoint Online. Additionally, the employee should be automatically added to a Microsoft 365 group for their department. The solution must minimize manual intervention and ensure that only authorized HR personnel can trigger the automation. What should you implement?

A.Deploy Microsoft Identity Manager (MIM) to synchronize Workday with on-premises AD, then sync to Entra ID.
B.Configure Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center.
C.Create a Power Automate flow that triggers when a new employee is added to a SharePoint Online list, then uses Graph API to create the user.
D.Develop a custom solution using Microsoft Graph API and Azure Functions that polls Workday for changes.
AnswerB

Configuring Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center is the correct solution because it enables native, automated lifecycle management between Workday as the HR source of truth and Entra ID. This prebuilt connector handles user creation, attribute mapping, group membership, and license assignment based on business rules, and it continuously syncs updates and terminations. It uses the latest provisioning service, which is cloud-native, eliminates the need for on-premises infrastructure, and is the Microsoft-recommended approach for this integration.

Why this answer

Workday to Microsoft Entra ID user provisioning is a built-in, cloud-native integration that automates the entire lifecycle of user accounts—creation, license assignment, group membership, and access to apps like Teams and SharePoint—directly from Workday HR events. It meets the 15-minute requirement, minimizes manual intervention, and can be scoped to allow only authorized HR personnel to trigger the automation via role-based access control in Entra ID.

Exam trap

The trap here is that candidates often confuse on-premises identity tools like MIM with cloud-native provisioning, or they overcomplicate the solution with custom development when a built-in connector exists, failing to recognize that Microsoft 365 E5 includes Entra ID P2 features that support automated HR-driven provisioning.

How to eliminate wrong answers

Option A is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution that requires a local Active Directory infrastructure and adds complexity, latency, and manual steps; it does not provide the cloud-native, near-real-time provisioning from Workday directly to Entra ID that the scenario demands. Option C is wrong because a Power Automate flow triggered by a SharePoint Online list is not a secure or reliable way to create user accounts—it bypasses proper HR source-of-truth integration, lacks lifecycle management, and introduces security risks by relying on a manually maintained list. Option D is wrong because developing a custom solution with Microsoft Graph API and Azure Functions that polls Workday is unnecessarily complex, requires ongoing maintenance, and does not leverage the pre-built, supported Workday-to-Entra ID provisioning connector that is designed for this exact use case.

199
MCQmedium

A project team needs to track action items and issues in a shared list that is accessible from within Outlook and SharePoint. They need to be able to create custom columns, set reminders, and view a history of changes. Which Microsoft 365 app is best suited for this?

A.Microsoft Lists
B.Microsoft To Do
C.Microsoft Planner
D.Microsoft Viva Engage
AnswerA

Microsoft Lists is a data-centric tracking application built on SharePoint that lets teams create customizable lists with tailored columns such as status, owner, due date, and priority for managing action items and issues. It provides full per-item version history, which preserves an audit trail of every change, and integrates seamlessly with Microsoft Teams, Power Automate, and Power Apps for notifications and automation. These capabilities make it the appropriate choice for shared, structured issue tracking.

Why this answer

Microsoft Lists is the correct choice because it provides a shared, customizable list that integrates directly with both Outlook and SharePoint. It allows users to create custom columns, set reminders via Power Automate or column formatting, and track version history for changes, meeting all specified requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Planner's task boards with the structured list and column customization capabilities of Microsoft Lists, overlooking the specific need for custom columns and change history.

How to eliminate wrong answers

Option B is wrong because Microsoft To Do is a personal task management app that lacks shared lists accessible from SharePoint and does not support custom columns or change history tracking. Option C is wrong because Microsoft Planner is designed for team task management with boards and buckets, but it does not offer custom columns or a detailed change history view like Lists does. Option D is wrong because Microsoft Viva Engage is an employee engagement and social networking platform, not a list or task tracking tool, and it cannot create custom columns or track action items with reminders.

200
MCQhard

An organization has users who frequently collaborate on documents across departments. They want to ensure that when a document is shared with external partners, the external users must authenticate using Azure AD credentials and cannot download or print the document. Which combination of Microsoft 365 features should they use?

A.Microsoft Teams guest access and Microsoft Defender for Cloud Apps session policies
B.OneDrive sharing settings with 'Anyone' links and Microsoft Purview Data Loss Prevention
C.SharePoint external sharing with 'Specific people' and Microsoft Purview Information Protection with 'View Only' permission
D.SharePoint anonymous sharing links and Microsoft Purview Sensitivity Labels
AnswerC

SharePoint external sharing configured with 'Specific people' requires each external user to authenticate with a Microsoft account or organizational account before accessing content, ensuring that access is traceable and intended recipients are verified. When combined with Microsoft Purview Information Protection's 'View Only' permission, the sensitivity label enforces restrictive permissions that prevent download, print, or modification of the document, even after it is accessed. This pairing directly satisfies the need to restrict download and print for external collaborators while maintaining controlled, authenticated access.

Why this answer

SharePoint 'Specific people' external sharing restricts access to explicitly invited users who must authenticate with Azure AD credentials, while Microsoft Purview Information Protection's 'View Only' permission prevents downloading, printing, and copying of the document. This combination meets both requirements: enforced authentication and restricted document actions.

Exam trap

The trap here is that candidates often confuse SharePoint external sharing settings (which control access) with Microsoft Purview Information Protection (which controls usage rights), and mistakenly think that simply restricting sharing to 'Specific people' alone prevents download/print, or that Sensitivity Labels alone enforce authentication.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams guest access does not inherently prevent download or print actions; it relies on additional configuration, and Microsoft Defender for Cloud Apps session policies are for monitoring and controlling app access, not for granular document-level restrictions like view-only. Option B is wrong because 'Anyone' links allow anonymous access without Azure AD authentication, and Microsoft Purview Data Loss Prevention (DLP) is designed to prevent data leaks via policies, not to enforce per-document view-only permissions. Option D is wrong because SharePoint anonymous sharing links do not require Azure AD authentication, and Microsoft Purview Sensitivity Labels can apply encryption but do not natively enforce a 'View Only' permission that blocks download and print without additional configuration.

201
MCQmedium

A user reports that Microsoft Teams meetings frequently drop audio. During troubleshooting, you discover that the user's network has high jitter and packet loss. Which Microsoft 365 service should you use to analyze the user's connection quality and identify the root cause?

A.Microsoft Defender XDR
B.Microsoft 365 Network Connectivity Center
C.Microsoft Teams admin center
D.Microsoft Intune
AnswerB

The Microsoft 365 Network Connectivity Center is the correct tool because it provides real-time network performance telemetry, including packet loss, latency, and geolocation-based connectivity data for Microsoft 365 endpoints. This tool lets administrators diagnose poor Teams meeting quality by identifying where network bottlenecks occur and provides actionable insights for recovery. It is specifically built for analyzing network health across Microsoft 365 services, unlike the other admin consoles.

Why this answer

B is correct because Microsoft 365 Network Connectivity Center is specifically designed to analyze network performance metrics like jitter, packet loss, and latency in real time. It provides detailed insights into connection quality between a user's device and Microsoft 365 services, enabling you to pinpoint the root cause of audio drops in Teams meetings.

Exam trap

The trap here is that candidates often confuse the Microsoft Teams admin center's call analytics (which shows per-user call quality) with the Network Connectivity Center's broader network-level diagnostics, leading them to pick option C instead of B.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is a security solution for threat detection and response, not a network performance analysis tool. Option C is wrong because the Microsoft Teams admin center provides call analytics and quality dashboards for individual users, but it does not offer the broader network-level analysis and diagnostic tools that Network Connectivity Center provides. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, focused on device compliance and app policies, not network connectivity analysis.

202
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to manage leads, opportunities, customer accounts, and sales processes. Microsoft 365 app or service is the best fit?

A.Dynamics 365 Sales
B.Microsoft Planner
C.Microsoft Forms
D.Microsoft Purview Audit
AnswerA

Dynamics 365 Sales provides native lead, opportunity, account and sales-process management, matching the stem's requirement exactly. Microsoft 365 apps such as SharePoint or Teams lack these CRM entities, so they cannot manage the sales pipeline described.

Why this answer

Dynamics 365 Sales is purpose-built for managing leads, opportunities, customer accounts, and sales processes as part of the Microsoft 365 ecosystem. It provides a customer relationship management (CRM) platform with pipeline management, sales automation, and analytics, directly aligning with the consultant's requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task management features with CRM functionality, or assume Microsoft Forms can handle sales processes due to its data collection capabilities, but neither provides the structured pipeline and account management required for sales.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management tool for organizing work among teams, not designed for CRM functions like lead or opportunity tracking. Option C is wrong because Microsoft Forms is a survey and data collection tool, lacking sales process management capabilities. Option D is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user activities, unrelated to sales pipeline or customer account management.

203
MCQmedium

A marketing team needs to create a dashboard that shows real-time sales data from Dynamics 365 and customer feedback from social media. Which Microsoft 365 service should they use to build this dashboard?

A.Microsoft Power BI
B.Microsoft Power Automate
C.Microsoft SharePoint
D.Microsoft Power Apps
AnswerA

Microsoft Power BI is the correct choice because it is a dedicated business analytics and data visualization service that connects to dozens of data sources, including Dynamics 365, social media, and Azure, to build live dashboards. It supports streaming datasets, push datasets, and DirectQuery to render near-real-time visuals that update as underlying data changes, without requiring manual refresh. Team members can embed these dashboards in Microsoft Teams or SharePoint pages, but the visualization engine itself remains Power BI.

Why this answer

Microsoft Power BI is the correct service because it is designed to connect to multiple data sources, including Dynamics 365 for real-time sales data and social media APIs for customer feedback, and then create interactive, real-time dashboards. It provides built-in connectors, real-time streaming datasets, and the ability to publish dashboards for team-wide access, making it the ideal tool for this marketing requirement.

Exam trap

The trap here is that candidates often confuse Power Automate or Power Apps as dashboard-building tools because they are part of the Power Platform, but only Power BI provides the dedicated data visualization and real-time analytics capabilities required for this scenario.

How to eliminate wrong answers

Option B (Microsoft Power Automate) is wrong because it is a workflow automation tool that triggers actions based on events, not a dashboard or visualization service; it cannot natively render charts or graphs. Option C (Microsoft SharePoint) is wrong because it is a document management and collaboration platform that can host web parts but lacks native real-time data visualization and direct integration with Dynamics 365 and social media APIs for live dashboards. Option D (Microsoft Power Apps) is wrong because it is a low-code application development platform for building custom apps, not a business intelligence tool for creating dashboards; while it can display data, it does not provide the dedicated analytics, real-time streaming, and visualization capabilities of Power BI.

204
MCQhard

You are designing a solution for a global company that needs to store documents in a central location with granular permission control. Which service should you recommend?

A.Microsoft Teams
B.OneDrive for Business
C.Exchange Online
D.SharePoint
AnswerD

SharePoint Online is Microsoft 365's centralized document management platform, offering site collections, document libraries, version history, workflows, and granular permission inheritance. It supports co-authoring, metadata classification, content types, retention labels, and eDiscovery, making it suitable for a global company that needs structured collaboration across departments and sites. SharePoint is the correct foundation on which Teams files and OneDrive sync can be built.

Why this answer

SharePoint is the correct choice because it is designed as a centralized document management and collaboration platform that supports granular permission control at the site, library, folder, and item levels. Unlike other services, SharePoint allows administrators to define unique permissions using SharePoint groups or Azure AD security groups, enabling precise access management for a global company's document storage needs.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint, thinking OneDrive can serve as a central document repository, but OneDrive is designed for personal storage and lacks the centralized administration and granular permission inheritance that SharePoint provides for enterprise document management.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration workspace that stores files in the underlying SharePoint site for each team, but it does not provide native granular permission control beyond team-level settings; permissions are inherited from SharePoint. Option B is wrong because OneDrive for Business is a personal cloud storage service intended for individual file storage and sharing, not for centralized document storage with granular permission control across an organization; it lacks site-level administration and advanced permission inheritance features. Option C is wrong because Exchange Online is an email and calendaring service that stores mailbox data, not documents; it does not offer document storage or permission management for files.

205
MCQeasy

A department asks for the Microsoft 365 service best suited for enterprise video publishing and town hall recordings. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Purview Compliance Manager
B.Microsoft Stream on SharePoint
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Stream on SharePoint delivers enterprise video publishing and town hall recordings using the SharePoint platform already provisioned in Microsoft 365, so no custom operational scripts are needed. This satisfies the stem's constraint of avoiding bespoke automation.

Why this answer

Microsoft Stream on SharePoint is the correct service because it provides enterprise-grade video publishing and live event capabilities, including town hall recordings, directly integrated with SharePoint and Microsoft Teams. It leverages SharePoint's storage and permissions model, eliminating the need for custom operational scripts for video management.

Exam trap

The trap here is that candidates may confuse Microsoft Stream (classic) with the new Stream on SharePoint, or incorrectly associate video features with compliance or security services like Purview or Defender.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance and risk management tool for assessing regulatory compliance, not a video publishing or recording service. Option C is wrong because Microsoft Entra Privileged Identity Management manages just-in-time privileged access to Azure AD roles, not video content. Option D is wrong because Microsoft Defender for Endpoint is an endpoint security solution for threat detection and response, not a video platform.

206
Multi-Selecthard

Which TWO Microsoft 365 services are primarily used for business process automation?

Select 2 answers
A.Power BI
B.Power Automate
C.Power Virtual Agents
D.Power Apps
E.Microsoft Lists
AnswersB, D

Power Automate delivers workflow automation through triggers, connectors and approval flows across Microsoft 365 and external systems. It satisfies the business process automation requirement by orchestrating repetitive tasks without code, whereas services such as Exchange Online or SharePoint Online provide messaging and storage rather than process orchestration.

Why this answer

Power Automate (B) is correct because it is Microsoft's dedicated workflow engine for business process automation, letting you build event-driven flows that connect hundreds of connectors to automate approvals, notifications, data sync, and repetitive tasks. Power Apps (D) is correct because it provides low-code canvas and model-driven apps that digitize and automate business processes such as forms, approvals, and data entry, often triggered or extended by Power Automate flows. Power BI (A) is a business intelligence and reporting tool for visualizing data, not for automating processes.

Power Virtual Agents (C) is for building conversational chatbots, which is a narrower automation use case rather than general business process automation. Microsoft Lists (E) is an information-tracking and list-management app, not a process automation service.

Exam trap

The trap here is that candidates might think only Power Automate qualifies for business process automation, forgetting that Power Apps also enables automating business processes through custom apps and logic. Both Power Automate (workflow automation) and Power Apps (app-based automation) are correct. Avoid selecting Power Virtual Agents (chatbots) or Power BI (analytics) as they are not primarily for business process automation.

207
MCQeasy

An organization needs to securely store and manage user identities for Microsoft 365. Which Microsoft service should they use?

A.Microsoft Entra ID
B.Microsoft Purview
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerA

Microsoft Entra ID is the cloud identity provider that authenticates users and issues tokens for Microsoft 365 services, enforcing conditional access and multifactor authentication. It satisfies the requirement to securely store and manage user identities, unlike Exchange Online or SharePoint Online, which consume identities rather than host them.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the correct choice because it is Microsoft's cloud-based identity and access management service, specifically designed to store and manage user identities for Microsoft 365. It provides authentication, single sign-on (SSO), and conditional access policies, ensuring secure access to Microsoft 365 resources. Other options focus on data protection, security monitoring, or device management, not identity storage.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (data compliance) or Defender for Cloud Apps (security monitoring) with identity management, but only Microsoft Entra ID provides the core directory service for storing and authenticating user identities in Microsoft 365.

How to eliminate wrong answers

Option B (Microsoft Purview) is wrong because it is a data governance and compliance solution for managing sensitive data across environments, not for storing or managing user identities. Option C (Microsoft Defender for Cloud Apps) is wrong because it is a cloud access security broker (CASB) that monitors and controls cloud app usage, not an identity store. Option D (Microsoft Intune) is wrong because it is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for identity management.

208
MCQhard

A company uses Microsoft 365 E5 and wants to automatically classify sensitive emails containing credit card numbers and then apply encryption. Which solution should they use in combination with Microsoft Purview?

A.Microsoft 365 Copilot
B.Microsoft Intune
C.Microsoft Purview Information Protection
D.Microsoft Defender for Office 365
AnswerC

Microsoft Purview Information Protection provides sensitivity labels with auto-labeling policies that automatically classify and encrypt documents and emails based on sensitive information types or trainable classifiers. Once triggered, it applies encryption via Azure Rights Management, visual markings, and access restrictions to ensure only authorized users can view or modify the data. This directly satisfies the need for automatic, content-triggered compliance protection, making it the correct choice for the scenario.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) enables automatic classification of sensitive data, such as credit card numbers, using built-in sensitive information types and exact data match (EDM) classifiers. When combined with sensitivity labels, it can automatically apply encryption (e.g., via Azure Rights Management) to emails containing that data, meeting the requirement without additional services.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection with Microsoft Defender for Office 365, assuming threat protection includes data classification, when in fact Defender focuses on inbound/outbound threats and not on content-based sensitivity labels or encryption policies.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Copilot is an AI-powered productivity assistant that helps with content generation and summarization, not with data classification or encryption policies. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution focused on device compliance and app protection, not on email content classification or encryption. Option D is wrong because Microsoft Defender for Office 365 is a security solution that protects against threats like phishing, malware, and spam, but it does not provide native automatic classification or encryption of sensitive content based on data patterns like credit card numbers.

209
MCQmedium

A company deploys Microsoft 365 Business Premium. The IT team wants to enable employees to sign in using a mobile app without passwords. Which app should they configure?

A.Microsoft Intune
B.Microsoft Entra ID
C.Microsoft Copilot
D.Microsoft Authenticator
AnswerD

Microsoft Authenticator is the mobile app specifically designed to handle sign-in verification for Microsoft 365. It enables passwordless sign-in and multi-factor authentication via push notification, number matching, or a rotating one-time code. When deploying Microsoft 365 Business Premium, users are expected to install and register Authenticator with their work account in Entra ID, making it the correct tool for user sign-in in this scenario.

Why this answer

Microsoft Authenticator is the correct app because it enables passwordless sign-in for Microsoft 365 Business Premium users via FIDO2-based phone sign-in or number matching. It allows employees to authenticate using biometrics or a PIN, eliminating the need for a password during sign-in.

Exam trap

The trap here is that candidates may confuse Microsoft Entra ID (the identity provider that enables passwordless authentication) with the actual user-facing app (Microsoft Authenticator) that performs the sign-in, leading them to select Entra ID instead of the correct app.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, not an authentication app; it does not directly provide passwordless sign-in capabilities. Option B is wrong because Microsoft Entra ID (formerly Azure AD) is the identity and access management service that supports passwordless authentication methods, but it is not the app employees use to sign in; the app that facilitates the actual sign-in process is Microsoft Authenticator. Option C is wrong because Microsoft Copilot is an AI-powered productivity assistant integrated into Microsoft 365 apps, not an authentication app; it has no role in passwordless sign-in.

210
MCQhard

An organization needs to enforce that all external emails are automatically encrypted before delivery to recipients. Which feature should they configure in Microsoft 365?

A.S/MIME
B.Microsoft Purview Data Loss Prevention
C.Exchange Online mail flow rules
D.Microsoft Purview sensitivity labels
AnswerC

Exchange Online mail flow rules (transport rules) can be configured with a condition like 'The recipient is outside the organization' and an action to apply Microsoft Purview Message Encryption, which automatically encrypts all outbound messages without requiring end-user action. This makes it the correct native mechanism for enforcing encryption on every email sent to external recipients, as it operates at the transport layer and applies uniformly.

Why this answer

Exchange Online mail flow rules (also known as transport rules) can be configured to automatically encrypt all external emails by applying Office 365 Message Encryption (OME) based on conditions such as recipient domain or sender address. This allows the organization to enforce encryption for all outbound messages without requiring user intervention, meeting the stated requirement.

Exam trap

The trap here is that candidates often confuse Microsoft Purview sensitivity labels or DLP policies as the direct mechanism for automatic encryption, when in fact mail flow rules are the correct transport-level feature to enforce encryption on all external emails without relying on user action or client-side configuration.

How to eliminate wrong answers

Option A is wrong because S/MIME is a client-side encryption method that requires manual certificate management and configuration on each user's device, and it cannot be enforced automatically for all external emails at the transport level. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to detect and prevent the sharing of sensitive information, but it does not natively encrypt emails; it can trigger encryption via a mail flow rule, but the DLP policy itself does not perform encryption. Option D is wrong because Microsoft Purview sensitivity labels apply classification and protection (including encryption) to content, but they require user or automated labeling and are not designed to automatically encrypt all external emails based solely on the recipient being external; they are typically applied at the client or via auto-labeling policies, not as a blanket transport rule for all external messages.

211
MCQmedium

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What will this policy do?

A.Allows access but logs the sign-in risk
B.Requires multi-factor authentication for high-risk sign-ins
C.Blocks access to all cloud apps when sign-in risk is high
D.Blocks access to Office 365 apps when the sign-in risk is high
AnswerD

The policy correctly matches the exhibit: assigned to the 'Office 365' cloud app, condition set to 'High' sign-in risk, and grant control configured to 'Block access'. When a sign-in for any Office 365 app (like OneDrive, Exchange, etc.) is evaluated as high risk, Azure AD blocks the authentication and prevents the user from gaining access. This is an effective way to protect against compromised credentials without locking out legitimate low-risk sign-ins.

Why this answer

The exhibit shows a Conditional Access policy configured with the condition 'Sign-in risk: High' and the control 'Block access'. This combination means that when Microsoft Entra ID detects a high-risk sign-in (e.g., from an anonymous IP address or compromised credentials), access to the targeted cloud apps is denied. The policy specifically targets Office 365 apps (as indicated in the 'Cloud apps or actions' assignment), so it blocks access to those apps when the sign-in risk is high.

Exam trap

The trap here is that candidates often confuse 'Block access' with 'Require MFA' or assume the policy applies to all cloud apps, when the exhibit clearly shows the scope is limited to Office 365 apps.

How to eliminate wrong answers

Option A is wrong because the policy is set to 'Block access', not 'Grant access' with a session control to log risk; logging sign-in risk alone does not block access. Option B is wrong because the policy uses 'Block access' as the control, not 'Require multi-factor authentication'; MFA would be a grant control, not a block. Option C is wrong because the policy targets 'Office 365' apps specifically, not 'All cloud apps'; the scope is limited to the selected apps.

212
MCQmedium

A project team uses Microsoft Teams and wants to create a shared space where they can track tasks, deadlines, and assign work items without leaving Teams. Which Microsoft 365 app should be integrated into Teams for this purpose?

A.Microsoft Planner
B.Microsoft Project Online
C.Microsoft To Do
D.Microsoft Lists
AnswerA

Microsoft Planner is a collaborative task management service in Microsoft 365 that creates shared plans, assigns tasks to individuals with due dates, and tracks progress via charts and board views. It can be added directly as a tab in Microsoft Teams, letting all team members view and update the same task list without leaving the Teams interface. Because it is purpose-built for team-level task assignment and status tracking, it fully satisfies the need for a shared, collaborative task list.

Why this answer

Microsoft Planner is the correct choice because it provides a lightweight, Kanban-style task management solution that integrates directly into Microsoft Teams via the Planner tab. This allows the project team to create, assign, and track tasks with deadlines and progress indicators without leaving the Teams interface, fulfilling the requirement for a shared workspace for work items.

Exam trap

The trap here is that candidates often confuse Microsoft To Do (personal tasks) with Planner (team tasks) or assume Microsoft Lists can handle task tracking without realizing it lacks native assignment and Kanban features, leading them to choose an app that does not meet the shared task management requirement.

How to eliminate wrong answers

Option B is wrong because Microsoft Project Online is a full-scale project management tool for complex scheduling, resource management, and Gantt charts, which is overkill for simple task tracking and requires additional licensing and a separate web interface, not a native Teams tab. Option C is wrong because Microsoft To Do is a personal task management app designed for individual productivity and lacks shared team views, assignment capabilities, and deadline tracking across multiple users. Option D is wrong because Microsoft Lists is a data-tracking and information-management app for creating custom lists (e.g., issue trackers, inventories), but it does not provide built-in task assignment, Kanban boards, or deadline tracking out of the box without additional customization.

213
MCQeasy

A user reports that they cannot access their Microsoft 365 email on their mobile device. The user can access Outlook on the web. Which Microsoft 365 app should the administrator check to verify the user's mobile device is compliant?

A.Microsoft Intune
B.Microsoft Defender for Office 365
C.Microsoft Entra ID
D.Microsoft Purview
AnswerA

Microsoft Intune is the cloud-based MDM/MAM service that creates and enforces device compliance policies, such as requiring BitLocker encryption, a minimum OS build, or a passcode. In this scenario, the user’s device is likely non-compliant, so Intune’s compliance state is consumed by Conditional Access in Entra ID, which blocks the user’s session to Microsoft 365 Exchange Online. Thus Intune is the component that determines whether the device meets access requirements.

Why this answer

Microsoft Intune is the correct answer because it is the mobile device management (MDM) and mobile application management (MAM) component within Microsoft 365. When a user cannot access email on a mobile device but can via Outlook on the web, the issue is likely a device compliance policy blocking access. Intune enforces conditional access policies by checking device compliance (e.g., encryption, jailbreak status, minimum OS version) before allowing Exchange Online connectivity.

Exam trap

The trap here is that candidates confuse Microsoft Entra ID (which handles conditional access policies) with Intune (which actually performs the device compliance check and reports the status to Entra ID).

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Office 365 is a security service focused on protecting against email threats like phishing, malware, and spam, not on device compliance or mobile access policies. Option C is wrong because Microsoft Entra ID (formerly Azure AD) provides identity and access management, including conditional access policies, but it does not directly verify device compliance; it relies on Intune to report device compliance status. Option D is wrong because Microsoft Purview is a compliance and data governance solution covering data loss prevention, eDiscovery, and auditing, not device management or compliance enforcement.

214
Multi-Selecthard

Contoso Ltd. is a medium-sized company with 2,000 users. They use Microsoft 365 E5 and have recently deployed Microsoft Teams for collaboration. The IT department has received complaints that external partners (guests) can see internal team names and member lists in the Teams directory. The compliance team requires that external guests must only see teams they are directly added to, and they must not be able to search for other teams or see internal team members who are not members of the same team. Additionally, the HR team wants to use a custom app in Teams that allows employees to submit leave requests, and this app must be available to all employees without requiring them to install anything manually. The IT admin needs to configure Teams settings to meet these requirements. Which two actions should the admin take? (Choose two. Each correct answer is part of the solution.)

Select 2 answers
A.Disable 'Show all teams' in the Teams admin center to prevent guests from seeing teams they are not members of.
B.Create a Teams app setup policy that pins the leave request app for all users.
C.Block all external access in Teams admin center to prevent guests from joining.
D.Configure external sharing settings in SharePoint admin center to limit guest access.
E.Enable external access in Teams admin center to allow guests to communicate with internal users.
AnswersA, B

Disabling the 'Show all teams' tenant-wide setting in the Teams admin center controls whether users, including guests, can browse all teams in the organization and request to join them. When this setting is off, guests only see the specific teams they have been added to, which directly satisfies the security requirement. Unlike external access or SharePoint sharing, this setting specifically targets team discovery and visibility.

Why this answer

Disabling 'Show all teams' in the Teams admin center (under Teams settings) prevents guests from seeing teams they are not members of in the Teams directory. This directly addresses the compliance requirement that external guests must only see teams they are directly added to and cannot search for other teams or see internal team members outside their own team.

Exam trap

The trap here is confusing 'external access' (federation for chat/calling) with 'guest access' (B2B collaboration for team membership), leading candidates to select options that manage federation settings instead of the specific Teams directory visibility control.

215
Matchingmedium

Match each Microsoft 365 service to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Email and calendaring

Document management and intranet

Chat, meetings, and collaboration

Personal cloud storage and file sync

Why these pairings

Microsoft Teams is for chat and collaboration, SharePoint for document management and intranets, Exchange Online for email, and OneDrive for personal file storage. Common confusions include mixing Teams with SharePoint or Exchange with SharePoint.

216
MCQeasy

A team of financial analysts needs to collaboratively build a complex budget model that includes data from multiple sources. They require real-time co-authoring, advanced formulas, and the ability to create custom charts. Which Microsoft 365 app is best suited for this task?

A.Microsoft Word
B.Microsoft Excel
C.Microsoft PowerPoint
D.Microsoft OneNote
AnswerB

Microsoft Excel is the correct choice because it is a spreadsheet application built around a powerful calculation engine that supports financial formulas, functions, PivotTables, and a wide range of chart types. Excel's real-time co-authoring via OneDrive and SharePoint enables multiple analysts to edit the same workbook simultaneously, with AutoSave and version history ensuring no work is lost. Its ability to model complex budget scenarios through cells, named ranges, and data tables directly supports the analytical workflow the team needs.

Why this answer

Microsoft Excel is the correct choice because it is designed for complex numerical modeling with advanced formulas, real-time co-authoring via OneDrive or SharePoint, and custom chart creation. The team's requirements for multi-source data integration, collaborative editing, and analytical visualization align directly with Excel's core capabilities, unlike the other apps which lack these features.

Exam trap

The trap here is that candidates may confuse the collaborative editing features of Word or OneNote with the specialized data analysis and formula capabilities required for budget modeling, overlooking Excel's unique strength in handling complex numerical computations and real-time co-authoring for spreadsheets.

How to eliminate wrong answers

Option A is wrong because Microsoft Word is a word processor optimized for document creation and text formatting, not for numerical analysis, advanced formulas, or custom charting. Option C is wrong because Microsoft PowerPoint is a presentation tool for slideshows, lacking the formula engine and data manipulation features needed for budget modeling. Option D is wrong because Microsoft OneNote is a digital note-taking app with limited formula support and no native charting or real-time co-authoring for complex spreadsheets.

217
MCQeasy

An HR manager needs to collect feedback from employees about a new wellness program. The manager wants to create a simple survey with multiple-choice questions and have the responses automatically visualized in charts. Which Microsoft 365 app is best suited for this task?

A.Microsoft Excel
B.Microsoft Forms
C.Microsoft Word
D.Microsoft Teams
AnswerB

Microsoft Forms is the correct choice because it is purpose-built for creating surveys with multiple question types, branching logic, and validation rules. After distribution, it automatically compiles responses and presents them in real-time charts, and administrators can export the dataset to Excel if further statistical analysis is needed. This streamlined workflow makes Forms the ideal tool for an HR manager collecting employee feedback.

Why this answer

Microsoft Forms is specifically designed for creating surveys, quizzes, and polls with automatic response collection and built-in chart visualization. It allows the HR manager to quickly add multiple-choice questions and instantly see aggregated results as charts without any manual setup.

Exam trap

The trap here is that candidates may confuse Microsoft Teams as the correct answer because they know surveys can be created within Teams, but the question asks for the app best suited for the task, which is Microsoft Forms—the dedicated survey tool that Teams integrates with.

How to eliminate wrong answers

Option A is wrong because Microsoft Excel is a spreadsheet application for data analysis and manual chart creation, not a survey tool; it lacks native survey creation and automatic response visualization. Option C is wrong because Microsoft Word is a word processing application for document creation, not for building interactive surveys or generating charts. Option D is wrong because Microsoft Teams is a collaboration platform that can host a Forms tab or use the Forms app, but it is not the primary survey creation tool; the best-suited app for creating the survey itself is Microsoft Forms.

218
MCQmedium

A marketing department uses Microsoft 365 Copilot to generate content. The compliance officer is concerned about data leakage when users interact with Copilot. Which Microsoft Purview feature should the admin implement to prevent sensitive data from being used in Copilot prompts?

A.Microsoft Purview Data Loss Prevention (DLP) for Copilot
B.Microsoft Purview Audit (Standard)
C.Microsoft Purview Information Rights Management (IRM)
D.Microsoft Purview Sensitivity labels
AnswerA

Microsoft Purview DLP for Copilot inspects both the Copilot prompt and the generated response for sensitive content types, such as credit card numbers, personal data, or confidential keyword patterns, using the same policy engine as classic DLP. When a violation is detected, it can block the interaction, restrict sharing, and raise an incident in Microsoft Defender, which is why it is the control that actually prevents leakage. This is a preventive, in-line control rather than a retrospective or classification-only measure.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) for Copilot is the correct feature because it specifically inspects and blocks sensitive data (e.g., credit card numbers, PII) from being included in Copilot prompts or generated content. DLP policies can be applied to Copilot interactions to prevent data leakage by evaluating the content in real time against sensitive information types and enforcing actions like blocking or warning the user.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect static content) with DLP (which actively monitors and blocks data in motion), leading them to choose Option D instead of the correct preventive control.

How to eliminate wrong answers

Option B (Microsoft Purview Audit (Standard)) is wrong because it only logs user activities for compliance review but does not actively prevent sensitive data from being used in prompts; it is a detective control, not a preventive one. Option C (Microsoft Purview Information Rights Management (IRM)) is wrong because it protects content after it is created by restricting access and usage rights (e.g., preventing forwarding or printing), but it does not inspect or block data at the point of prompt entry in Copilot. Option D (Microsoft Purview Sensitivity labels) is wrong because they classify and protect data by applying encryption or markings, but they do not provide real-time inspection or blocking of sensitive data in Copilot prompts; labels are applied to documents and emails, not to dynamic prompt content.

219
MCQeasy

A sales team needs to create a shared workspace where they can store customer documents, collaborate on a lead list, track follow-ups on a shared calendar, and hold video meetings with customers. Which Microsoft 365 service provides all these capabilities in a single, integrated experience?

A.Microsoft Viva Engage
B.Microsoft Teams
C.SharePoint Online
D.OneNote
AnswerB

Microsoft Teams is a comprehensive collaboration hub in Microsoft 365 that brings together persistent chat, channel-based discussions, shared document storage (backed by SharePoint Online), and co-authoring capabilities. It also includes a team calendar synced with Exchange Online and native integration with Microsoft Teams Meetings for video conferencing, enabling a sales team to manage files, schedules, and virtual meetings in one place. This integrated combination of chat, documents, calendar, and video meetings makes Teams the ideal shared workspace for a sales team's daily operations.

Why this answer

Microsoft Teams is the correct answer because it provides a single, integrated workspace that combines persistent chat, file storage (via SharePoint), collaborative editing on lists (via SharePoint or Planner), a shared calendar, and built-in video meetings. This eliminates the need to switch between separate apps for each task, fulfilling all the sales team's requirements in one experience.

Exam trap

The trap here is that candidates often pick SharePoint Online because they associate it with document storage and lists, forgetting that Teams integrates those features with video meetings and a shared calendar, making it the single, integrated solution the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Engage is primarily a social networking and employee engagement tool (formerly Yammer), not designed for document storage, lead list collaboration, shared calendars, or video meetings. Option C is wrong because SharePoint Online provides document storage and list collaboration, but lacks native video meeting capabilities and a shared calendar for tracking follow-ups without additional integration. Option D is wrong because OneNote is a digital note-taking app that supports collaboration on notes but does not offer document storage, lead list management, a shared calendar, or video meeting functionality.

220
MCQhard

Your organization, Contoso Ltd., uses Microsoft 365 E5 licenses and has 10,000 users. The company is planning to deploy Microsoft Copilot for Microsoft 365 to all users. The IT department has identified the following requirements: 1. Users must be able to use Copilot across Microsoft Teams, Word, Excel, PowerPoint, and Outlook. 2. Copilot must be able to access user data from Exchange Online, SharePoint Online, and Microsoft Graph. 3. The deployment must comply with the company's data residency policy, which requires that all data processed by Copilot remains within the European Union (EU). 4. The company wants to use a phased rollout, starting with a pilot group of 500 users. Which configuration should the IT administrator implement to meet these requirements?

A.Assign Microsoft Copilot for Microsoft 365 licenses to the pilot group, and in Microsoft Purview, create a data residency policy that restricts data to the EU.
B.Enable Microsoft Copilot for Microsoft 365 in the Microsoft 365 admin center for all users, then ask each user to customize their Copilot permissions in Graph.
C.Assign Microsoft Copilot for Microsoft 365 licenses to the pilot group, and in the Microsoft 365 admin center, configure the data storage location to 'EU'.
D.Create a separate Microsoft 365 tenant in the EU region, move pilot users to that tenant, and assign Copilot licenses there.
AnswerC

This is the correct approach because it combines the right licensing strategy (assign the Copilot add-on license to a pilot group for phased rollout) with the correct data-residency configuration. The tenant's data storage location is set in the Microsoft 365 admin center under Settings > Org settings > Security & privacy > Data location, and choosing 'EU' ensures that core data, including Copilot-related data, is stored at rest in Microsoft's European datacenters. Because this setting is at the tenant level, it applies to all users, which is exactly what a pilot rollout needs before broader deployment.

Why this answer

The Microsoft 365 admin center provides a tenant-level setting to configure the data storage location for Microsoft Copilot for Microsoft 365, ensuring all processed data remains within the EU. Assigning licenses to the pilot group enables the phased rollout, while the data residency setting satisfies the compliance requirement without needing a separate tenant or manual user configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Purview's compliance features with the Copilot-specific data residency setting in the Microsoft 365 admin center, or assume that a separate tenant is required for regional data residency, when in fact a single tenant can enforce EU data residency via the admin center configuration.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview does not offer a data residency policy for Copilot; data residency for Copilot is configured in the Microsoft 365 admin center, not Purview. Option B is wrong because enabling Copilot for all users violates the phased rollout requirement, and asking users to customize permissions in Graph is impractical and not how Copilot data access is controlled—access is managed via Microsoft Graph permissions at the tenant level. Option D is wrong because creating a separate tenant is unnecessary and overly complex; the data residency requirement can be met within the existing tenant by configuring the storage location in the admin center, and moving users to a new tenant disrupts operations and licensing.

221
Multi-Selecthard

Which THREE Microsoft 365 services can be used to enforce data classification and protection?

Select 3 answers
A.Microsoft Defender for Cloud Apps
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Information Protection
D.Microsoft Intune
E.Microsoft Entra ID
AnswersA, B, C

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that enforces data protection policies across SaaS apps by inspecting content in real time. It integrates with Microsoft Purview Information Protection to apply sensitivity labels and trigger DLP actions such as blocking downloads, uploads, or sharing of sensitive files via conditional access app control. This makes it a correct answer because it actively enforces data loss prevention rules in cloud environments, not merely classifying data at rest.

Why this answer

Microsoft Defender for Cloud Apps (A) is correct because it acts as a Cloud Access Security Broker (CASB) that can enforce data classification and protection by applying policies to control data in transit and at rest across cloud applications. It can automatically classify sensitive data using built-in DLP engines and enforce actions like blocking downloads or applying encryption based on content inspection.

Exam trap

The trap here is that candidates often confuse Microsoft Intune's device compliance policies with data classification and protection, or mistakenly think Entra ID's conditional access policies enforce data protection directly, when in fact they only control access based on identity and device state.

222
MCQhard

Your company is deploying Microsoft 365 Copilot and wants to ensure that sensitive data in emails and documents is not inadvertently exposed via Copilot responses. Which Microsoft 365 capability should you implement?

A.Microsoft Purview Sensitivity Labels
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview Customer Lockbox
D.Microsoft Purview Data Loss Prevention
AnswerD

Microsoft Purview Data Loss Prevention (DLP) is the correct control because it can identify sensitive data types (e.g., credit card numbers, passport IDs) in Copilot interactions and apply enforcement actions like blocking the response or restricting sharing. DLP policies attach to specific data sources, including Microsoft 365 Copilot endpoints, and can evaluate prompts and responses against sensitive info types or trainable classifiers. This gives administrators a direct way to prevent Copilot from returning confidential content to unauthorized users.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct choice because it is specifically designed to identify, monitor, and automatically protect sensitive data (e.g., credit card numbers, PII, or custom patterns) across Microsoft 365 services, including emails and documents. When integrated with Microsoft 365 Copilot, DLP policies can prevent Copilot from including sensitive information in its responses by enforcing real-time content checks and blocking or warning users before exposure occurs.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels (which apply persistent protection) with DLP (which enforces real-time actions), leading them to choose A, even though labels alone cannot block Copilot from surfacing sensitive data in responses.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Sensitivity Labels classify and protect data with encryption and visual markings, but they do not actively monitor or block data in Copilot responses—they require user or automated labeling, not real-time content inspection. Option B is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on shadow IT discovery, app permissions, and session controls for third-party cloud apps, not on preventing data leakage within Microsoft 365 Copilot responses. Option C is wrong because Microsoft Purview Customer Lockbox provides a controlled access approval process for Microsoft support engineers to access your data, but it has no role in scanning or blocking sensitive content in Copilot outputs.

223
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to maintain a personal checklist that syncs across devices and integrates with Outlook tasks. Microsoft 365 app or service is the best fit?

A.Microsoft Forms
B.Microsoft To Do
C.Microsoft Purview Audit
D.Microsoft Planner
AnswerB

Microsoft To Do provides a personal task list that synchronises across devices and surfaces in Outlook's Tasks view, letting the service owner maintain one checklist everywhere. This directly satisfies the stated need for cross-device sync plus Outlook task integration.

Why this answer

Microsoft To Do is the best fit because it provides a personal checklist that syncs across devices via Exchange Online and integrates natively with Outlook tasks. This allows the service owner to manage tasks from any device and see them directly within the Outlook task pane, fulfilling both requirements precisely.

Exam trap

The trap here is that candidates often confuse Microsoft Planner with Microsoft To Do because both involve tasks, but Planner is designed for team collaboration and lacks personal checklist sync with Outlook tasks, while To Do is the correct personal task management tool with direct Outlook integration.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz creation tool, not a task management or checklist app; it lacks sync with Outlook tasks. Option C is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user and admin activities, not a personal task or checklist tool. Option D is wrong because Microsoft Planner is a team-based project management app that organizes work into plans and buckets, but it does not provide a personal checklist that syncs with Outlook tasks; it focuses on collaborative assignments rather than individual task lists.

224
MCQhard

A hospital uses Microsoft 365 E5. They need to archive patient emails for 7 years and enable legal hold for ongoing litigation. Which two Microsoft Purview features should they use? (Select TWO.)

A.Sensitivity labels
B.Retention policies
C.Litigation hold
D.Data Lifecycle Management
E.eDiscovery
AnswerB, C

Retention policies in the Microsoft Purview compliance portal let administrators define how long content must be kept, such as retaining all Exchange mailbox items for 7 years before automatic deletion. These policies are centrally managed, can be scoped to specific users or groups, and can be configured to either keep content indefinitely, keep for a set period, or delete after the retention period expires. For the hospital's requirement to archive patient emails for 7 years, a retention policy is the precise and flexible solution.

Why this answer

Retention policies (B) are correct because they allow the organization to define rules that preserve patient emails for a specific duration, such as 7 years, to meet regulatory compliance requirements. Litigation hold (C) is correct because it preserves all mailbox content, including deleted items, in its original state for the duration of ongoing litigation, preventing any alteration or deletion.

Exam trap

The trap here is that candidates often confuse 'Litigation hold' with 'eDiscovery hold' or think that 'Data Lifecycle Management' is a standalone feature in Microsoft Purview, when in fact the correct feature for time-based retention is 'Retention policies' and for legal preservation is 'Litigation hold'.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data based on sensitivity (e.g., confidentiality), not to enforce time-based retention or legal holds. Option D is wrong because Data Lifecycle Management is a broader concept that includes retention and deletion policies, but in Microsoft 365, the specific feature for setting retention durations is 'Retention policies' (part of Microsoft Purview), not a separate feature named 'Data Lifecycle Management'. Option E is wrong because eDiscovery is used to search, hold, and export content for legal or investigative purposes, but it does not itself enforce a fixed 7-year retention period; it relies on holds and retention policies to preserve data.

225
MCQmedium

An organization uses Microsoft Viva Learning to provide training content. They want to ensure that only employees in the Sales department see sales-specific courses. Which feature should they use?

A.Set permissions on the SharePoint site hosting the courses.
B.Configure Viva Connections dashboard to show only Sales courses.
C.Create learning paths and assign them to the Sales department group in Viva Learning.
D.Use Viva Topics to tag courses and let users discover them.
AnswerC

Viva Learning administrators create learning paths that include the relevant courses and then assign those paths directly to the Sales department group, which is a Microsoft Entra ID security or distribution group. The assignment enforces enrollment for all members of the group, tracks progress and completion, and provides reporting for administrators, directly satisfying the requirement to deliver targeted training to the Sales department.

Why this answer

Viva Learning allows administrators to create learning paths and assign them to specific Microsoft 365 groups, such as the Sales department group. This ensures that only members of that group see the assigned sales-specific courses, providing targeted content delivery without affecting other users' views.

Exam trap

The trap here is that candidates often confuse SharePoint permissions (Option A) with Viva Learning's group-based targeting, not realizing that Viva Learning controls visibility through learning path assignments rather than underlying site permissions.

How to eliminate wrong answers

Option A is wrong because setting permissions on the SharePoint site hosting the courses would control access to the site itself, but Viva Learning aggregates content from multiple sources and permissions on the underlying SharePoint site do not directly control visibility within the Viva Learning interface; users could still see the courses listed but be denied access when trying to open them, which is not the same as controlling visibility. Option B is wrong because the Viva Connections dashboard is a personalized entry point to employee resources and news, but it does not have the capability to filter or restrict which courses appear in Viva Learning; it can surface links but cannot enforce course visibility by department. Option D is wrong because Viva Topics uses AI to automatically tag and surface knowledge content, but it is designed for discovery and knowledge management, not for controlling visibility or access to training courses; it cannot restrict who sees specific courses based on department membership.

← PreviousPage 3 of 4 · 300 questions totalNext →

Ready to test yourself?

Try a timed practice session using only M365 Apps Services questions.