Courseiva

CCNA Design security operations, identity, and compliance capabilities Questions

75 of 155 questions · Page 1/3 · Design security operations, identity, and compliance capabilities · Answers revealed

1
MCQmedium

Your company uses Microsoft Defender for Cloud Apps and wants to prevent users from uploading sensitive files to personal cloud storage apps. What should you configure?

A.Activity policy
B.App connector
C.Session policy
D.File policy
AnswerC

Session policies, part of Conditional Access App Control, route user traffic through Defender for Cloud Apps as a reverse proxy, allowing synchronous inspection of each request and response. The proxy can evaluate conditions like device compliance, user risk, or file sensitivity and then block, allow, or restrict actions — including preventing uploads to unsanctioned apps before the request is passed through. This real-time inline enforcement is exactly what the scenario requires, making session policy the correct choice.

Why this answer

Session policy in Microsoft Defender for Cloud Apps allows real-time monitoring and control of user activities based on app and content inspection. By configuring a session policy, you can block or restrict uploads of sensitive files to personal cloud storage apps like Dropbox or Google Drive during the user's session, leveraging reverse proxy capabilities to inspect and intervene in traffic.

Exam trap

The trap here is that candidates confuse 'File policy' (which governs files at rest) with 'Session policy' (which governs files in motion), leading them to select D, even though real-time upload prevention requires session-level control via reverse proxy.

How to eliminate wrong answers

Option A is wrong because Activity policies are used for auditing and generating alerts on specific activities (e.g., multiple failed logins), not for real-time blocking of file uploads. Option B is wrong because App connectors enable API-based visibility and control for connected apps (e.g., retrieving logs), but they cannot intercept and block uploads in real time during a user session. Option D is wrong because File policies are designed for scanning and governing files already stored in cloud apps (e.g., detecting DLP violations in SharePoint), not for preventing uploads at the point of action.

2
MCQeasy

Your company uses Microsoft Purview Data Loss Prevention (DLP). You need to ensure that credit card numbers are not shared externally via email. What should you configure?

A.Create a sensitivity label that applies encryption to emails containing credit card numbers.
B.Create a DLP policy that detects credit card numbers and blocks external sharing.
C.Configure auto-labeling for credit card numbers in Microsoft 365.
D.Create a retention policy for credit card data.
AnswerB

A DLP policy is the correct control because it combines detection of a sensitive info type (credit card number uses patterns plus Luhn checksum validation) with a condition that the content is shared externally, and then enforces a blocking action. When you create a DLP policy in the Microsoft Purview compliance portal, you select the credit card number detector, scope it to Exchange/SharePoint/OneDrive, and set the rule to block access or block sending before the content leaves your tenant. This is the only option that directly prevents unauthorized external sharing while also providing user overrides and incident alerts.

Why this answer

The correct option is B: create a DLP policy that detects credit card numbers and blocks external sharing. Microsoft Purview DLP is purpose-built to identify sensitive information types such as credit card numbers and enforce protective actions like blocking email to external recipients, which directly satisfies the requirement. Option A is wrong because sensitivity labels apply encryption and classification but do not themselves block external email sharing based on content detection.

Option C is wrong because auto-labeling applies labels rather than enforcing DLP blocking actions. Option D is wrong because retention policies govern data lifecycle and deletion, not prevention of external sharing.

3
Multi-Selectmedium

Your organization is deploying Microsoft Defender for Cloud Apps. Which THREE capabilities are included in Defender for Cloud Apps? (Select three.)

Select 3 answers
A.Session controls
B.App governance
C.Cloud Discovery
D.Data Loss Prevention (DLP) policies
E.Conditional Access
AnswersA, B, C

Session controls in Microsoft Defender for Cloud Apps enforce real-time monitoring and control of user sessions via a reverse proxy. They allow organizations to apply granular access policies on cloud apps, such as preventing downloads, blocking access to sensitive files, or requiring step-up authentication. Session controls operate at the data plane level, evaluating user activity as it happens, and are often triggered by Conditional Access policies from Microsoft Entra ID.

Why this answer

Session controls (A) are a core Defender for Cloud Apps capability, delivered through Conditional Access App Control, which lets you monitor and restrict user sessions in real time (for example, blocking downloads or requiring reauthentication) for SaaS apps. App governance (B) is included in Defender for Cloud Apps and provides visibility, policy enforcement, and remediation for OAuth-enabled apps and their permissions across Microsoft 365 and other connected apps. Cloud Discovery (C) is also a foundational Defender for Cloud Apps feature that analyzes traffic logs to identify shadow IT and assess the risk of cloud apps in use.

DLP policies (D) are not a native Defender for Cloud Apps capability; data protection is handled by Microsoft Purview DLP and can be surfaced in Defender for Cloud Apps, but the policy engine itself belongs to Purview. Conditional Access (E) is a Microsoft Entra ID feature, not a Defender for Cloud Apps capability, although Defender for Cloud Apps integrates with it for app control and risk-based policies.

Exam trap

The trap here is confusing integrated features with native capabilities: candidates often select DLP policies or Conditional Access because Defender for Cloud Apps integrates with them, but the question asks for capabilities included in Defender for Cloud Apps itself, not those it leverages from other services.

4
Multi-Selecthard

Your organization uses Microsoft Sentinel and wants to improve threat hunting efficiency. Which THREE actions should you take?

Select 3 answers
A.Enable UEBA (User and Entity Behavior Analytics)
B.Integrate Microsoft Defender XDR for cross-domain hunting
C.Create custom hunting queries using KQL
D.Use watchlists to filter out known benign IPs
E.Reduce data retention period to improve query speed
AnswersA, B, C

Enabling UEBA in Microsoft Sentinel gives threat hunters behavioral baselines for users, hosts, and applications. By leveraging machine learning to detect anomalies such as unusual sign-in patterns or lateral movement, UEBA surfaces high-fidelity leads. This enriches entities in hunting queries with risk scores and behavioral insights, making detection of insider threats or compromised accounts far more effective.

Why this answer

UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel uses machine learning models to establish baseline behavioral patterns for users, hosts, and other entities. It then detects anomalous activities such as unusual logon times, impossible travel, or abnormal data exfiltration, which directly enhances threat hunting by surfacing suspicious behaviors that might otherwise go unnoticed.

Exam trap

The trap here is that candidates often confuse passive data enrichment tools (like watchlists) with active hunting techniques, or mistakenly think reducing data retention improves security operations, when in fact it hinders long-term threat detection and forensic analysis.

5
MCQhard

Your organization uses Microsoft Sentinel as a SIEM. You need to design a solution to detect advanced persistent threats (APTs) by correlating data from multiple sources, including network logs, endpoint data, and threat intelligence feeds. The solution must use machine learning to identify anomalies and reduce false positives. Which analytics rule type should you configure?

A.ML Behavior Analytics
B.Fusion
C.Anomaly detection rules
D.Scheduled query rules
AnswerB

Fusion is a built-in analytics rule in Microsoft Sentinel that leverages machine learning to correlate security alerts from multiple products—such as Microsoft Defender for Endpoint, Defender for Identity, and Defender for Office 365—into a single incident. It is specifically designed to detect advanced multi-stage attacks, including APTs, by analyzing cross-source alert relationships and timestamps. This makes Fusion the correct answer because it uniquely uses ML for multi-source correlation and APT detection.

Why this answer

Fusion analytics rules in Microsoft Sentinel are specifically designed for advanced multistage attack detection, using machine learning to correlate alerts and signals from multiple sources (network logs, endpoint data, threat intelligence) into high-fidelity incidents, which matches the APT detection and false-positive reduction requirement. ML Behavior Analytics rules focus on specific user/entity behavior anomalies rather than cross-source APT correlation. Anomaly detection rules identify unusual behavior within a single data type and do not perform the multistage fusion correlation.

Scheduled query rules run KQL queries on a schedule and lack the built-in ML-driven cross-source correlation for APTs.

6
Multi-Selecteasy

Which TWO of the following are components of Microsoft Defender XDR (Extended Detection and Response)?

Select 2 answers
A.Microsoft Sentinel
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Intune
E.Microsoft Purview
AnswersB, C

Microsoft Defender for Endpoint is a foundational component of Microsoft Defender XDR (formerly Microsoft 365 Defender). It delivers endpoint detection and response (EDR), vulnerability management, and attack surface reduction capabilities, sharing signals with the unified XDR pipeline to enable cross-domain threat correlation and automated response.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across Microsoft's first-party security workloads, and Microsoft Defender for Endpoint (B) is a core component, providing endpoint detection and response (EDR), attack surface reduction, and automated investigation and remediation for devices. Microsoft Defender for Office 365 (C) is likewise a core component, delivering protection and detection for email, collaboration tools, and phishing/URL detonation signals that feed into the XDR incident graph. By contrast, Microsoft Sentinel (A) is a standalone cloud-native SIEM/SOAR platform that, while it can integrate with Defender XDR, is not itself one of its components.

Microsoft Intune (D) is a mobile device management (MDM) and endpoint management service, and Microsoft Purview (E) is a data governance, compliance, and information-protection suite — neither is a Defender XDR component.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) as part of Defender XDR, but Sentinel is a separate Azure service that can ingest Defender XDR alerts, not a component of the XDR platform itself.

7
Multi-Selectmedium

A company uses Microsoft Purview Data Lifecycle Management. They need to retain financial records for 7 years and then delete them. Which TWO actions should they configure?

Select 2 answers
A.Create a DLP policy that blocks deletion
B.Apply a sensitivity label to the records
C.Create a retention label with a 7-year retention period
D.Use a trainable classifier to identify records
E.Configure a disposition review to approve deletion
AnswersC, E

A retention label is the Purview mechanism that directly enforces retention and deletion behavior on documents, emails, and other content. By creating a retention label with a 7-year retention period and publishing it (or auto-applying it), the organization ensures the record remains immutable and un-deletable during that period, and the label can also trigger a disposition review at expiration. This aligns with regulatory requirements for retaining records. Thus, it is the correct action to preserve the records for the mandated timeframe.

Why this answer

Option C is correct because a retention label in Microsoft Purview Data Lifecycle Management is the mechanism that defines how long content is retained (here, 7 years) and what happens at the end of that period, such as deletion. Option E is correct because a disposition review can be attached to a retention label so that when the 7-year retention period expires, designated reviewers must approve the deletion before the records are permanently removed, which is a common compliance requirement for financial records. Option A is incorrect because DLP policies are designed to prevent data loss or leakage, not to enforce retention or deletion schedules.

Option B is incorrect because sensitivity labels classify and protect content (for example, encryption and access restrictions) but do not by themselves define retention or deletion periods. Option D is incorrect because trainable classifiers identify content types for classification or auto-labeling; they do not enforce a 7-year retention-then-delete lifecycle.

Exam trap

The trap here is confusing sensitivity labels (used for classification and protection) with retention labels (used for lifecycle management), leading candidates to incorrectly select Option B instead of understanding that retention labels are the correct mechanism for timed deletion.

8
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

A.Create a Conditional Access policy that requires compliant device
B.Set up enrollment restrictions in Intune
C.Create a device configuration policy that blocks non-compliant devices
D.Configure an app protection policy for email apps
AnswerA

Conditional Access policies are the access-control layer that evaluates the device's compliance state at sign-in. When combined with an Intune compliance policy, the 'Require device to be marked as compliant' grant control forces Azure AD to check the device's compliance status and block access if the device is non-compliant. This is the correct approach because it directly enforces the access requirement for corporate resources, unlike enrollment or configuration policies that only manage settings or enrollment.

Why this answer

A Conditional Access policy in Microsoft Entra ID (formerly Azure AD) can enforce the requirement that only devices marked as compliant by Intune can access corporate email. This policy evaluates the device compliance status at authentication time and blocks or grants access based on that signal, ensuring that only managed and compliant devices can connect to services like Exchange Online.

Exam trap

The trap here is that candidates often confuse device configuration policies (which set device settings) with Conditional Access (which enforces access control based on compliance), leading them to choose option C instead of the correct policy-based access control.

How to eliminate wrong answers

Option B is wrong because enrollment restrictions in Intune control which devices can enroll into management (e.g., by platform or ownership type), but they do not enforce compliance at the point of access to corporate email. Option C is wrong because device configuration policies in Intune are used to set settings and features on devices (like password policies or restrictions), not to block non-compliant devices from accessing resources; blocking access is done via Conditional Access. Option D is wrong because an app protection policy (MAM) protects data within apps (e.g., preventing copy/paste or requiring PIN) but does not evaluate device compliance; it can be used without device enrollment but does not replace the need for a Conditional Access policy that checks device compliance.

9
MCQhard

Your organization uses Microsoft Defender for Cloud to secure multi-cloud workloads. You need to ensure that Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) resources are assessed against the same security baseline. What should you do?

A.Configure AWS Config and GCP Security Command Center to export findings to Microsoft Sentinel
B.Connect AWS and GCP accounts to Defender for Cloud and use Azure Policy to enforce the Microsoft Cloud Security Benchmark
C.Use regulatory compliance standards for each cloud separately
D.Enable the Cloud Security Posture Management (CSPM) plan and configure AWS and GCP connectors
AnswerB

Connecting AWS and GCP accounts to Defender for Cloud surfaces those resources in Azure Resource Graph, where Azure Policy can apply the Microsoft Cloud Security Benchmark (MCSB), a unified initiative built on CIS/NIST plus Microsoft controls. This gives continuous compliance assessment and enforcement, like DeployIfNotExists remediation, across all clouds. As a result, every subscription or cloud account is measured against the same baseline, regardless of native cloud tooling—this is the only option that both centralizes and enforces a single baseline.

Why this answer

Microsoft Defender for Cloud's multi-cloud CSPM capabilities allow you to connect AWS and GCP accounts directly, and then apply Azure Policy to enforce the Microsoft Cloud Security Benchmark (MCSB) across all connected clouds. This ensures a unified security baseline assessment for Azure, AWS, and GCP resources, as MCSB is the default policy initiative in Defender for Cloud.

Exam trap

The trap here is that candidates confuse enabling the CSPM plan and connectors (Option D) with the complete solution, forgetting that a specific baseline policy (MCSB) must be assigned via Azure Policy to enforce the unified assessment.

How to eliminate wrong answers

Option A is wrong because exporting findings from AWS Config and GCP Security Command Center to Microsoft Sentinel is for centralized SIEM and threat detection, not for enforcing a unified security baseline across clouds. Option C is wrong because using separate regulatory compliance standards for each cloud would not enforce a single, consistent security baseline; it would result in fragmented assessments. Option D is wrong because enabling the CSPM plan and configuring connectors is a prerequisite step, but it does not by itself enforce a specific security baseline; you must also assign the Microsoft Cloud Security Benchmark policy via Azure Policy to achieve the stated goal.

10
MCQmedium

Your organization uses Microsoft Purview to manage data governance. You need to create a unified data catalog that automatically classifies and labels data across Azure SQL Database, Amazon S3, and on-premises SQL Server. What should you configure?

A.Microsoft Purview account with scans for all data sources.
B.Azure Data Catalog with custom classification.
C.Azure Purview (legacy) with multi-cloud scanning.
D.Microsoft Information Protection scanner on each source.
AnswerA

A Microsoft Purview account is the correct choice because it provides an automated, unified data governance solution that scans and catalogs metadata from all data sources, including on-premises, Azure, AWS, Google Cloud, and SaaS applications. This enables centralized data discovery, classification, lineage, and policy enforcement. Unlike legacy or single-purpose tools, it creates a comprehensive data map for the entire organization.

Why this answer

The correct option is A: a Microsoft Purview account with scans for all data sources. Microsoft Purview is the unified data governance service that builds a data map and catalog by registering and scanning sources such as Azure SQL Database, Amazon S3, and on-premises SQL Server, then automatically applying built-in and custom classifications and sensitivity labels during those scans. The other options do not fit: Azure Data Catalog is a retired service that lacks automated classification and labeling, Azure Purview (legacy) is the former branding of the same service and not the current configuration, and the Microsoft Information Protection scanner only discovers and labels sensitive files on file shares and on-premises repositories, not cloud databases or S3 buckets.

11
MCQmedium

Your organization uses Microsoft Purview and needs to prevent users from copying sensitive data to USB drives. Which solution should you implement?

A.Sensitivity labels with encryption
B.Insider Risk Management
C.Endpoint data loss prevention (DLP)
D.Communication Compliance
AnswerC

Endpoint data loss prevention (Endpoint DLP) is the correct choice because it installs an agent on Windows and macOS endpoints that inspects data in real time as users interact with files. It can enforce policies to block the copying of sensitive items, such as those matching sensitive info types or trainable classifiers, to removable USB devices, and optionally show a policy tip to the user. This direct, pre-action enforcement provides the precise control needed to prevent data leakage via USB.

Why this answer

Endpoint DLP is the correct solution because it extends data loss prevention policies to endpoints, enabling the detection and blocking of sensitive data being copied to removable USB drives. Unlike other controls, Endpoint DLP can monitor and restrict data exfiltration actions at the device level, such as copying files to USB media, based on the content's sensitivity classification.

Exam trap

The trap here is that candidates often confuse Insider Risk Management (a detective control) with Endpoint DLP (a preventive control), assuming that risk management can block actions, when in fact it only alerts on suspicious behavior after the fact.

How to eliminate wrong answers

Option A is wrong because sensitivity labels with encryption protect data at rest and in transit by restricting access, but they do not block the act of copying labeled data to a USB drive; encryption alone does not prevent data exfiltration via removable media. Option B is wrong because Insider Risk Management is a detection and investigation tool that identifies risky user activities (e.g., unusual file copying) but does not actively block or prevent the copy action in real time. Option D is wrong because Communication Compliance focuses on monitoring and analyzing communications (e.g., email, Teams) for policy violations, not on controlling data movement to USB drives.

12
MCQeasy

You need to audit user activities in Microsoft 365, including who accessed a specific file in SharePoint Online. Which Microsoft Purview solution should you use?

A.Microsoft Purview Information Protection
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Audit
D.Microsoft Purview Data Lifecycle Management
AnswerC

Microsoft Purview Audit is the correct solution because it provides a unified audit log that records user and admin activities across Microsoft 365 services, including file access, permission changes, and sign-ins. Organizations can search and export these audit records from the Purview compliance portal or via Office 365 Management Activity API, enabling security teams to investigate incidents and meet compliance requirements. This capability directly addresses the need to audit user activities.

Why this answer

Microsoft Purview Audit (specifically Audit (Standard) or Audit (Premium)) is the correct solution because it captures and logs user activities across Microsoft 365 services, including SharePoint Online. When a user accesses a specific file, the audit log records the event with details such as the user, file name, action (e.g., FileAccessed), and timestamp, enabling you to query this data via the Microsoft 365 Defender portal or Search-UnifiedAuditLog cmdlet.

Exam trap

The trap here is that candidates often confuse 'auditing' with 'protection' or 'compliance' solutions, mistakenly choosing Information Protection (A) because they think labeling controls access, or Communication Compliance (B) because they associate 'compliance' with monitoring user actions, when in fact Audit is the dedicated logging service for user activity tracking.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., via sensitivity labels and encryption), not on auditing user activities or file access events. Option B is wrong because Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate communications (e.g., offensive language or insider trading) in Exchange Online, Teams, or Yammer, not to audit file access in SharePoint Online. Option D is wrong because Microsoft Purview Data Lifecycle Management manages retention and deletion policies for data (e.g., automatically archiving or deleting old files), not the logging of user access events.

13
MCQeasy

A software company uses Microsoft 365 E5 and wants to ensure that when an employee is terminated, their access to all Microsoft Entra ID integrated applications is removed immediately and their manager is notified to reassign their files. The company wants to automate this without manual intervention from the IT help desk. Which Microsoft Entra ID Governance feature should you design into the solution?

A.Access reviews that require managers to certify their team's group memberships quarterly
B.Lifecycle workflows that run a leaver task on the employee's last day
C.Conditional Access policies that block sign-ins from unmanaged devices
D.Privileged Identity Management to make all application roles eligible rather than active
AnswerB

Lifecycle workflows in Microsoft Entra ID Governance automate joiner, mover, and leaver tasks based on events or schedules. A leaver workflow can disable the account, remove group and application assignments, and send notifications to the manager, which matches the requirement to revoke access immediately and notify the manager without help desk involvement.

Why this answer

The scenario calls for automated, event-driven removal of access plus manager notification at termination. Lifecycle workflows in Microsoft Entra ID Governance are built for exactly this leaver pattern, running tasks such as disabling the account, removing assignments, and sending notifications. Access reviews are periodic and manual, conditional access governs authentication conditions, and Privileged Identity Management governs privileged role activation.

Exam trap

The trap here is choosing access reviews for termination, when reviews are periodic certification cycles rather than event-driven leaver automation.

14
MCQhard

You are a security architect for a global financial services company that uses Microsoft 365 E5 and Azure. The company has 50,000 users across 10 regions. The security team needs to detect and respond to identity-based threats in real-time, automate remediation for compromised accounts, and meet regulatory requirements for audit logging. The following requirements must be met: (1) Detect risky sign-ins and user anomalies, (2) Automatically block sign-ins when risk level is high, (3) Provide a centralized dashboard for security analysts to investigate incidents, (4) Retain logs for at least one year for compliance, (5) Minimize false positives by using machine learning. You have the following services available: Microsoft Entra ID P2, Microsoft Sentinel, Microsoft Defender for Identity, Microsoft Purview, and Microsoft Intune. Which combination of services should you use to meet all requirements?

A.Microsoft Intune and Microsoft Defender for Cloud
B.Microsoft Entra ID Protection (P2) and Microsoft Sentinel
C.Microsoft Defender for Identity and Microsoft Purview
D.Microsoft Purview and Microsoft Sentinel
AnswerB

Entra ID Protection (P2) uses machine learning to continuously evaluate sign-in and user risk, assigning risk levels and enabling Conditional Access to require MFA or block high-risk attempts. Sentinel then ingests these risk detections, along with other identity logs, into a central SIEM that provides long-term retention, advanced hunting through KQL, and analyst workflow for investigation. Together they deliver both the real-time detection and the centralized visibility needed by a global financial services security team.

Why this answer

Microsoft Entra ID Protection (P2) provides the risk-based sign-in and user risk detections powered by machine learning, and its Conditional Access integration can automatically block sign-ins when risk is high, satisfying requirements 1, 2, and 5. Microsoft Sentinel supplies the centralized SIEM dashboard for analysts to investigate incidents and supports long-term log retention (including one-year retention via the data lake or workspace retention settings), covering requirements 3 and 4. Together, option B meets all five requirements.

Option A is wrong because Intune handles device management and Defender for Cloud covers cloud workload protection, not identity risk detection or SIEM. Option C is wrong because Defender for Identity monitors on-premises Active Directory signals and Purview handles data governance/compliance, not real-time sign-in risk blocking. Option D is wrong because Purview does not perform identity risk detection or automated sign-in remediation.

Exam trap

Candidates often confuse Microsoft Defender for Identity (on-premises AD) with Entra ID Protection (cloud identity). The question specifies a cloud-only environment with Microsoft 365 and Azure, so Defender for Identity is not suitable.

15
Multi-Selecthard

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to design a solution that allows corporate users to access a sensitive internal application only from managed devices that are compliant with company security policies. The solution should block access from personal devices. Which two components should you use? (Choose TWO.)

Select 2 answers
A.Microsoft Intune app protection policy
B.Microsoft Entra ID Conditional Access policy that requires hybrid Azure AD join
C.Microsoft Intune device enrollment
D.Microsoft Intune device compliance policy
E.Microsoft Entra ID Conditional Access policy that requires a compliant device
AnswersD, E

A Microsoft Intune device compliance policy defines the exact security and configuration standards that a device must meet to be considered compliant, such as requiring encryption, a minimum OS version, no jailbreak/root, or a healthy threat agent score. The policy assigns a compliance state (compliant/non-compliant) for each enrolled device, and that state is then published to Entra ID. This policy is the foundation of device-based access control because it establishes the authoritative criteria that determine whether a device should be trusted.

Why this answer

Option D (Microsoft Intune device compliance policy) is correct because it defines and evaluates the security requirements—such as BitLocker, OS version, and firewall settings—that a device must meet to be marked compliant, which is the foundation for gating access to the sensitive application. Option E (Microsoft Entra ID Conditional Access policy that requires a compliant device) is correct because Conditional Access enforces the access decision at authentication time, granting access only when Intune reports the device as compliant and blocking personal or non-compliant devices. Together, the compliance policy determines device state and the Conditional Access policy enforces it for the target app.

Option A is not correct because app protection policies (MAM) protect app data on unmanaged/personal devices rather than blocking access from them. Option B is not correct because requiring hybrid Azure AD join restricts access to domain-joined devices and does not directly enforce the company's compliance policy baseline. Option C is not correct because device enrollment alone only registers devices in Intune; without a compliance policy and Conditional Access enforcement, it does not block personal or non-compliant devices.

16
Multi-Selecthard

Your company uses Microsoft Sentinel to manage security incidents. You need to design a solution that automatically triages low-severity incidents and enriches them with threat intelligence. Which THREE capabilities would you include? (Choose three.)

Select 3 answers
A.Advanced hunting queries to investigate incidents.
B.Analytics rules to generate alerts for low-severity incidents.
C.Playbooks to perform enrichment actions like querying threat intelligence.
D.Automation rules to trigger playbooks on incident creation.
E.Watchlists to store known indicators for correlation.
AnswersC, D, E

Playbooks are Azure Logic Apps workflows that can be automatically invoked by automation rules to perform enrichment operations on an incident, such as querying Threat Intelligence platforms like MISP or Microsoft Graph Security API. By pulling threat intel about involved entities (IPs, hashes, domains) and writing those findings back to the incident, playbooks give analysts and automated rules the context needed to rapidly triage and prioritize low-severity incidents without manual querying.

Why this answer

Option C is correct because Microsoft Sentinel playbooks, built on Azure Logic Apps, are the automation mechanism that can call the Threat Intelligence connectors and other enrichment actions to add context (for example, IP/domain reputation) to an incident. Option D is correct because automation rules evaluate incident conditions (such as severity or title) at incident creation and can trigger the playbook, which is exactly how low-severity incidents get automatically triaged and enriched. Option E is correct because watchlists let you upload and correlate known indicators (IPs, domains, hashes) against incident entities, providing a lightweight threat-intelligence enrichment source within Sentinel.

Option A is not appropriate here because advanced hunting queries are manual, interactive KQL investigations rather than an automated triage/enrichment capability. Option B is not appropriate because analytics rules generate alerts and incidents; they do not perform the automated triage or threat-intelligence enrichment the scenario requires.

17
MCQeasy

Your organization needs to monitor and respond to threats across email, endpoints, and identities. Which Microsoft solution provides a unified incident response experience?

A.Microsoft Purview
B.Microsoft Intune
C.Microsoft Defender XDR
D.Microsoft Sentinel
AnswerC

Microsoft Defender XDR unifies signals across the Microsoft 365 ecosystem—Defender for Endpoint, Office 365, Identity, and Cloud Apps—into a single incident queue with automated investigation and response. It correlates kill-chain events across domains, enabling security teams to monitor and respond to threats holistically. This cross-domain correlation and built-in response automation are exactly what is required for organization-wide threat monitoring and response.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified incident response experience by correlating alerts and signals from email (Defender for Office 365), endpoints (Defender for Endpoint), and identities (Defender for Identity) into a single incident queue. This cross-domain correlation enables security teams to investigate and remediate complex multi-stage attacks from a single pane of glass, rather than switching between separate consoles.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel ingests logs and requires manual or KQL-based correlation, while Defender XDR provides automatic cross-domain incident correlation out of the box for Microsoft security signals.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a compliance and data governance solution focused on data classification, retention, and eDiscovery, not on real-time threat detection or incident response across email, endpoints, and identities. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not a security operations tool for monitoring and responding to threats. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that ingests logs from multiple sources and provides advanced analytics, but it does not natively unify incident response across Microsoft 365 security products; it requires separate data connectors and custom correlation rules to achieve similar cross-domain visibility.

18
MCQmedium

A company uses Microsoft Intune to manage devices. They need to ensure that only devices with a minimum OS version can access corporate email. Which policy type should they implement?

A.Device enrollment restrictions
B.App protection policies
C.Compliance policies combined with conditional access
D.Device configuration profiles
AnswerC

A compliance policy in Intune evaluates a device's health attributes—including whether its OS version meets the minimum required for that platform—and simply marks the device compliant or non-compliant. That compliance status is then consumed by a Conditional Access policy as a grant control, which, at the time of every authentication request, rejects access for non-compliant devices (or requires additional steps like re-enrollment or OS update). This combination is the actual enforcement chain: the compliance policy identifies the OS-version gap, and Conditional Access blocks the user's access accordingly.

Why this answer

The correct answer is C: Compliance policies combined with conditional access. Compliance policies in Intune define the required conditions a device must meet, such as a minimum OS version, and conditional access in Entra ID enforces those requirements by blocking access to corporate email (for example, Exchange Online) when the device is noncompliant. This combination is the standard way to gate email access on OS version.

Device enrollment restrictions (A) only control which devices can enroll or which platforms are allowed, not ongoing OS-version-based access to email. App protection policies (B) protect app data with PINs and encryption but do not enforce a minimum OS version for email access. Device configuration profiles (D) configure settings on devices but do not by themselves block email access based on compliance.

19
Multi-Selecteasy

Your organization uses Microsoft Purview Information Protection to label sensitive emails. You need to ensure that labels are applied automatically based on content. Which THREE methods can you use?

Select 3 answers
A.Manual labeling by users
B.File plan (for records management)
C.Sensitive information types
D.Auto-labeling policies in Microsoft Purview
E.Trainable classifiers
AnswersC, D, E

Sensitive information types detect content patterns such as credit card or national insurance numbers, so Microsoft Purview Information Protection can auto-apply labels without user input. This satisfies the requirement for automatic, content-based labelling rather than manual or default labelling.

Why this answer

Sensitive information types (C) are predefined or custom patterns that detect sensitive data such as credit card numbers or social security numbers, enabling automatic label application. Auto-labeling policies in Microsoft Purview (D) apply labels automatically to emails and files based on conditions like sensitive information types or trainable classifiers. Trainable classifiers (E) use machine learning to identify content patterns and automatically apply labels without requiring explicit pattern definitions.

Exam trap

The trap here is that candidates may confuse manual labeling or records management tools (like file plans) with automatic content-based labeling mechanisms, but only sensitive information types, auto-labeling policies, and trainable classifiers directly support automatic label application based on content analysis.

20
MCQeasy

You are designing identity security for a hybrid organization using Microsoft Entra ID. You need to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. What is the recommended approach?

A.Create a Conditional Access policy that requires MFA for the sensitive applications
B.Enable Security defaults
C.Enable per-user MFA in Entra ID
D.Use Azure AD Identity Protection user risk policy
AnswerA

A Conditional Access policy is the correct approach because it uses application-based conditions to require MFA selectively for sensitive apps while allowing other apps to use less restrictive authentication. In a hybrid environment, this integrates with on-premises applications via Azure AD Application Proxy or federated trusts, and supports session controls like sign-in frequency. This granularity aligns with the Zero Trust principle of least privilege, unlike tenant-wide or user-wide MFA enforcement.

Why this answer

Conditional Access policies in Entra ID are the recommended method to require MFA for specific applications. The other options are less granular or outdated: per-user MFA is legacy, Security defaults apply to all apps and cannot be scoped, and Azure AD Identity Protection focuses on risk-based policies.

21
Multi-Selectmedium

Which TWO actions should you take to implement a zero-trust identity strategy in Microsoft Entra ID?

Select 2 answers
A.Enable single sign-on for all applications
B.Require multi-factor authentication for all users
C.Implement passwordless authentication for all users
D.Synchronize all on-premises identities to the cloud
E.Configure Conditional Access policies based on user risk and device compliance
AnswersB, E

Requiring multi-factor authentication for all users directly enforces the zero-trust principle of verify explicitly, ensuring every sign-in is validated rather than trusted by network location. It satisfies the stem's identity-strategy constraint by adding a possession factor to credentials, blocking compromised-password attacks that single-factor authentication would otherwise permit.

Why this answer

Option B is correct because requiring multi-factor authentication (MFA) for all users is a foundational zero-trust control in Microsoft Entra ID: it enforces verification of identity beyond a password, directly supporting the 'verify explicitly' principle and reducing the risk of credential compromise. Option E is correct because Conditional Access policies that evaluate signals such as user risk (via Entra ID Protection) and device compliance (via Intune) implement adaptive, context-aware access decisions, which is the core enforcement mechanism of a zero-trust identity strategy. Options A, C, and D are not the required actions: enabling single sign-on (A) improves user experience but does not itself verify identity or enforce least-privilege access; passwordless authentication (C) is a strong phishing-resistant method but is not mandatory for zero trust and can be a subset of MFA strategy; and synchronizing on-premises identities (D) via Entra Connect extends identity reach but does not by itself enforce zero-trust verification or policy-based access.

Exam trap

SC-100 often tests the difference between identity hygiene features (SSO, passwordless, directory sync) and actual zero-trust enforcement controls (MFA and risk-based Conditional Access), and candidates who pick SSO or sync as zero-trust actions fall for the distractor.

22
MCQhard

Refer to the exhibit. You are deploying this Bicep template to enable Microsoft Defender for Cloud's VM protection. After deployment, you notice that Agentless VM scanning is not enabled for existing VMs. What is the most likely reason?

A.The pricing tier must be 'Free' to enable agentless scanning.
B.Agentless scanning is only enabled for new VMs; existing VMs require rescanning.
C.The resource name 'VirtualMachines' is incorrect; it should be 'virtualMachines'.
D.The extension 'AgentlessVmScanning' must be defined outside the pricing resource.
AnswerD

The 'AgentlessVmScanning' extension cannot be declared as a child property of the Microsoft.Security/pricings resource. In Azure Resource Manager (ARM) and Bicep, agentless scanning for virtual machines is enabled by defining a separate resource of type Microsoft.Security/vmScanners, which holds the scanner configuration such as 'scanningMode' and exclusion tags. Attempting to place it within the pricing resource's properties.extensions array will cause a validation error because that extension is not a valid member of the pricing schema. Therefore, the deployment fails unless the extension is moved to its own top-level resource definition.

Why this answer

The 'AgentlessVmScanning' extension is not a valid sub-resource of the pricing resource. In Bicep, agentless VM scanning is configured via a separate 'Microsoft.Security/vmScanners' resource, not nested inside the pricing resource. Defining it inside the pricing resource would cause a configuration error, resulting in agentless scanning not being enabled.

Option B is incorrect: agentless scanning is automatically enabled for all existing and new VMs when the plan is enabled; existing VMs do not require manual rescanning.

23
MCQeasy

Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents. Which feature should you configure?

A.Configure an automation rule to run a playbook automatically
B.Create a playbook and run it manually for each incident
C.Set up an analytics rule with automatic response
D.Use a workbook to trigger a playbook
AnswerA

Automation rules in Microsoft Sentinel are event-driven orchestration mechanisms that evaluate newly created or updated incidents against configured conditions—such as severity or name—and then execute one or more linked playbooks automatically. Playbooks are Azure Logic Apps that can perform remediation steps like isolation, data collection, or notification, ensuring consistent, immediate response without human involvement. This is the only approach listed that satisfies 'automatically' while honoring incident context, since automation rules trigger exactly when incidents are created or changed.

Why this answer

Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created or updated, including running playbooks (Azure Logic Apps workflows) automatically. This is the correct approach for automatically responding to high-severity incidents because it eliminates manual intervention and ensures consistent, immediate action based on incident properties like severity.

Exam trap

The trap here is confusing analytics rule automated responses (which run on alerts before incident creation) with automation rules (which run on incidents after creation), leading candidates to incorrectly select Option C for incident-level automation.

How to eliminate wrong answers

Option B is wrong because running a playbook manually for each incident defeats the purpose of automation and does not scale for high-severity incidents that require immediate response. Option C is wrong because analytics rules generate alerts, not incidents, and while they can have automated responses, those responses run on alerts before incidents are created; for incident-level automated response, you need automation rules. Option D is wrong because workbooks are visualization and reporting tools, not triggers for playbooks; they cannot initiate automated response actions.

24
MCQmedium

A company uses Microsoft Defender for Cloud Apps to discover and control cloud apps. They want to receive alerts when a user accesses a sanctioned app from an unusual location. Which feature should they configure?

A.Session policies
B.File policies
C.Anomaly detection policies
D.App discovery policies
AnswerC

Anomaly detection policies in Defender for Cloud Apps use behavioral analytics and machine learning to baseline normal user activities and trigger alerts for deviations, including impossible travel, unfamiliar sign-in properties, and multiple failed sign-ins. These policies are specifically tailored to identify suspicious location-based behavior, such as sign-ins from geographically distant locations in a short time span, making them the correct choice for alerting on unusual user location patterns.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify behavioral deviations, such as a user accessing a sanctioned app from an unusual geographic location. These policies leverage machine learning to establish a baseline of normal user activity and trigger alerts when access patterns deviate from that baseline, enabling detection of potential account compromise or insider threats.

Exam trap

The trap here is that candidates often confuse anomaly detection policies with session policies, assuming that location-based alerts are enforced via real-time session controls, but session policies only act on traffic after access is granted, whereas anomaly detection policies are the correct detection mechanism for unusual location access.

How to eliminate wrong answers

Option A is wrong because session policies control real-time user actions within a cloud app (e.g., blocking downloads or requiring multi-factor authentication) but do not generate alerts based on location anomalies; they are reactive controls, not detection mechanisms. Option B is wrong because file policies monitor and enforce rules on file content and metadata (e.g., detecting sensitive data or malware in files), not user access patterns or location-based anomalies. Option D is wrong because app discovery policies identify and categorize cloud apps in use (sanctioned vs. unsanctioned) but do not monitor user behavior or location anomalies for already sanctioned apps; they focus on app inventory and risk assessment.

25
Multi-Selecthard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to design a solution that investigates and responds to a ransomware incident. Which three actions should you take? (Choose THREE.)

Select 3 answers
A.Isolate affected devices using Microsoft Defender for Endpoint.
B.Review the incident timeline in Microsoft Defender XDR.
C.Create a new workbook to visualize the incident.
D.Delete all log data older than 24 hours to improve performance.
E.Run a hunting query in Microsoft Sentinel to identify affected devices.
AnswersA, B, E

Isolating affected devices with Microsoft Defender for Endpoint is the immediate containment step. Device isolation severs network connections, including inbound and outbound traffic, preventing ransomware from spreading laterally while still allowing the security team to collect forensics via the MDE sensor. The error message displayed to the user can be customized, but the action itself blocks SMB, RDP, and other communication channels.

Why this answer

Option A is correct because isolating affected devices via Microsoft Defender for Endpoint (using the live response 'isolate device' action) immediately contains the ransomware and prevents lateral spread while investigation continues. Option B is correct because the unified incident timeline in Microsoft Defender XDR correlates alerts, evidence, and entities across endpoints, identities, email, and cloud apps, giving the analyst the full attack story needed to scope and respond to the incident. Option E is correct because running a hunting query (KQL) in Microsoft Sentinel lets you search ingested logs across connected data sources to identify additional affected devices and indicators beyond those already alerted on.

Option C is not required for investigation or response; workbooks are for visualization and reporting, not incident triage. Option D is wrong because deleting log data destroys forensic evidence and violates retention requirements, and it does nothing to improve incident response.

26
Multi-Selecthard

Which TWO components are required to enable Microsoft Sentinel to ingest data from Amazon Web Services (AWS) CloudTrail?

Select 2 answers
A.An Azure Function to pull logs from AWS.
B.An AWS S3 bucket to store CloudTrail logs.
C.An AWS Lambda function to process logs.
D.An AWS Simple Queue Service (SQS) queue to trigger ingestion.
E.An Azure Event Hubs namespace to receive logs.
AnswersB, D

The AWS S3 bucket is the core storage location where AWS CloudTrail writes all of its JSON log files. The Microsoft Sentinel AWS connector is built specifically to read these log objects from the S3 bucket, parse the CloudTrail records, and send them to the Log Analytics workspace. Without this bucket there would be no source for the connector to ingest, making it an essential requirement.

Why this answer

Microsoft Sentinel's AWS CloudTrail connector uses a polling-based architecture in which CloudTrail delivers its log files to an Amazon S3 bucket, so option B (an AWS S3 bucket to store CloudTrail logs) is required as the source location that Sentinel reads from. To know when new log objects arrive, the connector relies on Amazon SQS notifications from that S3 bucket, making option D (an AWS SQS queue to trigger ingestion) the second required component, since the SQS queue signals the connector to pull newly delivered CloudTrail files. Option A is not required because the connector runs as a built-in data connector in Microsoft Sentinel rather than a customer-deployed Azure Function.

Option C is not required because no AWS Lambda function is used in the CloudTrail ingestion path. Option E is not required because Event Hubs is used for other connectors (such as CEF or syslog-based sources), not for the AWS CloudTrail S3/SQS polling connector.

Exam trap

The trap here is that candidates often assume an Azure Function or Event Hubs is needed for cross-cloud ingestion, but Sentinel's native AWS connector uses S3 and SQS directly, eliminating the need for intermediary compute or messaging services.

27
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to design a compliance policy that requires devices to have a minimum OS version and be encrypted. Which policy type should you use?

A.Create a device configuration profile in Microsoft Intune.
B.Create a Conditional Access policy in Microsoft Entra ID.
C.Create an app protection policy in Microsoft Intune.
D.Create a device compliance policy in Microsoft Intune.
AnswerD

A device compliance policy in Microsoft Intune is the correct mechanism because it defines the rules that a device must satisfy to be considered compliant, including required OS versions, encryption, password complexity, and threat-level results from Mobile Threat Defense. Once assigned, the Intune service evaluates each device against those rules, assigns a remediation status, and reports the compliance state to Microsoft Entra ID for Conditional Access to block non-compliant devices.

Why this answer

The correct option is D: Create a device compliance policy in Microsoft Intune. Compliance policies are specifically designed to define rules such as minimum OS version, encryption status, and other security settings that devices must meet, and they evaluate device state against these requirements. Device configuration profiles (A) push settings to devices but do not evaluate compliance, while Conditional Access policies (B) use compliance results to grant or block access rather than define the requirements themselves.

App protection policies (C) protect app data on mobile devices and do not enforce OS version or device encryption compliance.

28
MCQmedium

Your organization uses Microsoft Defender for Endpoint (MDE) and wants to implement automated investigation and response (AIR) for ransomware. You need to ensure that when a suspicious file is detected, the investigation is automatically started and the file is contained. What should you configure?

A.Configure the automated investigation and response capabilities in MDE.
B.Create a custom detection rule in Microsoft 365 Defender.
C.Enable attack surface reduction rules.
D.Add the file hash to the indicators of compromise list.
AnswerA

Configuring automated investigation and response (AIR) in Microsoft Defender for Endpoint enables the security solution to automatically run playbooks when alerts are triggered. These playbooks investigate the scope of the threat, contain the attack (e.g., isolating devices, blocking processes), and remediate the issue without manual intervention. AIR is the only listed option that directly addresses the requirement for automated response, because it integrates detection, investigation, and containment into one workflow.

Why this answer

Option A is correct because Microsoft Defender for Endpoint's automated investigation and response (AIR) capabilities are the built-in feature that automatically triggers investigations when alerts are raised and can take remediation actions such as containing or quarantining a suspicious file. Configuring AIR settings (including automation levels and remediation permissions) ensures that detections like ransomware lead to automatic investigation and file containment without manual intervention. Option B is incorrect because custom detection rules only generate alerts based on queries; they do not themselves perform automated investigation or containment.

Option C is incorrect because attack surface reduction rules block specific risky behaviors but do not initiate automated investigations or file containment. Option D is incorrect because adding a file hash to the indicators of compromise list only creates a block/allow indicator and does not start an automated investigation.

29
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You need to detect and block data exfiltration from sanctioned cloud apps to personal devices. What should you configure?

A.Create an OAuth app policy to revoke permissions.
B.Create an app discovery policy to identify unsanctioned apps.
C.Create a file policy to detect sensitive data in sanctioned apps.
D.Create a session policy with app governance to block download.
AnswerD

Session policies can block data exfiltration in real time.

Why this answer

A session policy with app governance in Microsoft Defender for Cloud Apps allows you to monitor and control user activities in real time. By configuring a session policy to block downloads, you can prevent data exfiltration from sanctioned cloud apps to personal devices, as the policy inspects HTTP/HTTPS traffic and enforces access controls based on user context and device compliance.

Exam trap

The trap here is that candidates often confuse file policies (which detect sensitive data after it is stored) with session policies (which prevent exfiltration in real time), leading them to choose Option C instead of D.

How to eliminate wrong answers

Option A is wrong because an OAuth app policy revokes permissions for third-party apps that have been granted access to cloud app data, but it does not control user download actions from sanctioned apps to personal devices. Option B is wrong because an app discovery policy identifies and monitors unsanctioned cloud apps in the environment, but it does not block data exfiltration from already sanctioned apps. Option C is wrong because a file policy detects sensitive data within sanctioned apps and can trigger alerts or automated actions, but it does not block downloads in real time; it is reactive rather than preventive.

30
MCQmedium

Refer to the exhibit. You are analyzing a Microsoft Sentinel analytics rule. What does this rule detect?

A.Multiple successful logons for the same account
B.Brute-force attack against a single account
C.Multiple failed logons from the same source IP address
D.Overall number of failed logons across all accounts
AnswerB

This is the correct answer. The KQL rule filters for EventID 4625 (failed logon) and performs a summarize count() by Account over a 5-minute sliding window, alerting when an account's failure count exceeds 10. More than 10 failed logons for the same account within 5 minutes is a strong indicator of an automated brute-force attack, where an attacker tries many password variations against a single user account. The aggregation by Account ensures the alert is specific to one targeted account rather than distributed across users.

Why this answer

This rule detects a brute-force attack against a single account by triggering when the number of failed logons for a specific user exceeds a threshold within a given time window, followed by a successful logon. The condition `FailedLogons > 5` and `SuccessfulLogon > 0` for the same account indicates that the attacker has guessed the correct password after multiple failed attempts, which is a classic sign of a successful brute-force attack.

Exam trap

The trap here is that candidates often confuse a brute-force attack against a single account (detected by failed logons followed by a success for the same user) with a password spray attack (where many accounts are targeted with a few passwords), leading them to incorrectly select an option focused on source IP or overall failure counts.

How to eliminate wrong answers

Option A is wrong because the rule explicitly requires a high number of failed logons (FailedLogons > 5) before the successful logon, not just multiple successful logons for the same account. Option C is wrong because the rule aggregates failed logons by account (AccountName), not by source IP address, so it does not detect multiple failed logons from the same source IP. Option D is wrong because the rule filters on a specific account (AccountName) and requires a successful logon after failures, whereas an overall count of failed logons across all accounts would not identify a targeted brute-force attack on a single account.

31
MCQhard

Your organization uses Microsoft Intune to manage devices and wants to ensure that only compliant devices can access corporate email. Which conditional access policy setting should you configure?

A.Require device to be marked as compliant
B.Require approved client app
C.Require Multi-Factor Authentication
D.Require domain join
AnswerA

The 'Require device to be marked as compliant' grant control is correct because Intune compliance policies evaluate the device's configuration, health, and security posture. In Conditional Access, this control blocks access unless the device meets the specific compliance criteria defined in Intune, such as encryption, patch level, and threat detection. It ensures a device-level trust boundary before granting access to corporate resources, making it the appropriate device compliance control.

Why this answer

The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your Intune compliance policies (e.g., encryption, OS version, threat level) can access corporate email. This setting checks the device's compliance status reported by Intune to Azure AD during authentication, blocking non-compliant devices before they reach Exchange Online.

Exam trap

The trap here is that candidates often confuse 'Require approved client app' (which controls app-level access) with device compliance, thinking that restricting the app is sufficient to secure email, but it does not enforce device health or configuration.

How to eliminate wrong answers

Option B is wrong because 'Require approved client app' controls which client applications (e.g., Outlook mobile, Teams) can access data, not the device's compliance state; it does not enforce device health or configuration. Option C is wrong because 'Require Multi-Factor Authentication' adds an authentication factor but does not evaluate device compliance; a compromised but MFA-enabled device could still access email. Option D is wrong because 'Require domain join' is for Windows devices joined to on-premises Active Directory, not for mobile or BYOD devices managed by Intune; it does not check Intune compliance policies.

32
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with a TPM (Trusted Platform Module) version 2.0 can access corporate resources. What should you configure?

A.Create a device compliance policy that requires TPM 2.0 and use Conditional Access to block non-compliant devices
B.Use Windows Update for Business to ensure TPM firmware is updated
C.Configure device enrollment restrictions to require TPM 2.0
D.Deploy a device configuration profile that enables TPM 2.0
AnswerA

A device compliance policy in Intune can require TPM 2.0 as a compliance rule, and when paired with a Conditional Access policy that requires the device to be marked as compliant, it actively blocks access for non-compliant devices at the time of the resource request. This works as an ongoing access gate, re-evaluating compliance signals on every authentication, so devices missing TPM 2.0 are denied access immediately. That is exactly the intended mechanism for enforcing hardware security baselines on Windows 10 endpoints.

Why this answer

A device compliance policy in Microsoft Intune can check for TPM 2.0 presence and version. When combined with a Conditional Access policy that blocks non-compliant devices, only devices meeting the TPM 2.0 requirement can access corporate resources. This is the correct approach because Conditional Access enforces the compliance check at the authentication and authorization layer.

Exam trap

The trap here is that candidates confuse enrollment restrictions (which only apply at enrollment time) with ongoing compliance enforcement, or they think a configuration profile can block access, when only Conditional Access can enforce the block based on compliance.

How to eliminate wrong answers

Option B is wrong because Windows Update for Business manages firmware updates but cannot enforce a TPM version requirement for resource access; it only ensures the TPM firmware is current. Option C is wrong because device enrollment restrictions control which devices can enroll in Intune, but they do not enforce ongoing compliance for resource access after enrollment. Option D is wrong because a device configuration profile can enable or configure TPM features but cannot block access to corporate resources based on TPM version; it lacks the enforcement mechanism provided by Conditional Access.

33
Multi-Selecthard

Which THREE capabilities does Microsoft Purview provide for compliance management?

Select 3 answers
A.Identity protection and risk detection
B.Information protection with sensitivity labels
C.Data classification and labeling
D.Endpoint detection and response
E.eDiscovery and audit
AnswersB, C, E

Purview provides sensitivity labels.

Why this answer

Microsoft Purview provides compliance management capabilities including information protection with sensitivity labels, which allow organizations to classify and protect sensitive data across Microsoft 365 services, endpoints, and third-party apps. Sensitivity labels enforce encryption, visual markings, and access restrictions based on policy, directly supporting data loss prevention and governance.

Exam trap

The trap here is that candidates confuse Microsoft Purview's compliance-focused capabilities (like eDiscovery, audit, and sensitivity labels) with security operations tools (like identity protection and endpoint detection), which belong to separate Microsoft 365 security solutions.

34
MCQmedium

Your organization uses Microsoft Entra ID for identity management and wants to implement a least-privilege access model for administrators. You need to reduce standing privileges and ensure that admin roles are activated only when needed with approval workflow. Requirements: (1) Require approval for activation of Global Administrator role, (2) Set activation duration to 4 hours maximum, (3) Require Azure MFA for activation, (4) Receive notifications when roles are activated, (5) Audit all activations for compliance. Which Microsoft Entra ID capability should you use?

A.Access Reviews
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerB

Privileged Identity Management (PIM) in Microsoft Entra ID is the service that provides just-in-time (JIT) privileged role activation. PIM allows an eligible user to activate a role for a limited time, optionally requiring approval, multi-factor authentication (MFA), and justification, and it records the activation in the audit log. This directly matches the requirement to create a workflow for role activation that includes human approval, thereby making PIM the correct answer for controlling privileged access activation.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is the correct choice because it provides just-in-time role activation with configurable approval workflows, maximum activation duration, MFA enforcement, activation notifications, and audit history for privileged roles like Global Administrator. In PIM, you can set the Global Administrator role as eligible, require approval, cap activation at 4 hours, require Azure MFA, and enable notifications and auditing, which directly satisfies all five requirements. Access Reviews (A) only handles periodic attestation of group or role membership and cannot enforce activation approval, duration, or MFA.

Identity Protection (C) detects risky sign-ins and users but does not manage privileged role activation workflows. Conditional Access (D) can enforce MFA and other access controls at sign-in, but it does not provide role activation approval, time-bound activation, or activation audit trails.

35
MCQmedium

An organization uses Microsoft Intune to manage devices. They need to ensure that only devices compliant with security baselines can access corporate email via Microsoft Outlook. The solution should use existing Microsoft 365 security features. What should they implement?

A.Configure an app protection policy in Microsoft Intune.
B.Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.
C.Create a device compliance policy in Microsoft Intune.
D.Configure a device configuration profile in Microsoft Intune.
AnswerB

A Conditional Access policy in Microsoft Entra ID that includes the 'Require device to be marked as compliant' grant control is the direct integration point with Intune compliance. During authentication, Entra ID evaluates the device's compliance status and blocks sign-in if the device is non-compliant or not enrolled in Intune. This policy is the actual enforcement layer that translates the Intune compliance assessment into an access decision, making it the correct solution to block access from non-compliant devices.

Why this answer

Conditional Access policies in Microsoft Entra ID evaluate device compliance status before granting access to cloud apps like Exchange Online. By requiring a compliant device, the policy enforces that only devices meeting security baselines can access corporate email via Outlook, leveraging existing Microsoft 365 identity and access management capabilities.

Exam trap

The trap here is that candidates confuse device compliance policies (which only define rules) with Conditional Access policies (which enforce access decisions), leading them to pick Option C without realizing a separate policy is needed to block access.

How to eliminate wrong answers

Option A is wrong because app protection policies manage data within apps (e.g., preventing copy/paste) but do not enforce device-level compliance requirements like security baselines. Option C is wrong because a device compliance policy defines the compliance rules (e.g., requiring encryption) but does not itself block access; it must be paired with a Conditional Access policy to enforce the block. Option D is wrong because device configuration profiles apply settings (e.g., Wi-Fi, VPN) but do not evaluate or enforce compliance for access control.

36
MCQeasy

Your organization uses Microsoft Purview to manage data governance. The compliance team needs to be able to search for and investigate whether any sensitive data (e.g., credit card numbers) is stored in Microsoft Teams messages. They also need to place a legal hold on specific user's Teams messages for eDiscovery. You need to design the solution. What should you configure?

A.Configure a sensitivity label for credit card numbers and apply it to Teams messages.
B.Create a Data Loss Prevention policy that monitors Teams messages for credit card numbers.
C.Use Microsoft Purview eDiscovery (Premium) to create a case, search for credit card numbers in Teams messages, and place a hold on the user's mailbox and Teams data.
D.Enable Microsoft Purview Audit to search the audit log for Teams messages containing credit card numbers.
AnswerC

Microsoft Purview eDiscovery (Premium) is the correct tool because it combines robust content search with legal hold capabilities across Microsoft 365 workloads. A case can use keyword queries (including regex for credit card numbers) to locate Teams messages, and a litigation hold can then be applied to the user's Exchange mailbox—where Teams chat messages are actually stored—as well as to Teams site data. This satisfies both the need to find every instance of credit card numbers and the need to preserve that content immutably for eDiscovery.

Why this answer

Option C is correct because Microsoft Purview eDiscovery (Premium) supports creating a case, running content searches across Microsoft 365 workloads including Teams messages, and placing a legal hold on a user's mailbox and Teams data for investigative and litigation purposes. This directly satisfies both requirements: searching for sensitive data like credit card numbers in Teams messages and preserving specific users' Teams messages. Option A is wrong because sensitivity labels classify and protect content but do not provide search or legal hold capabilities.

Option B is wrong because a DLP policy detects and blocks or warns about sensitive data in Teams but does not support eDiscovery search or legal hold. Option D is wrong because Purview Audit only records and searches audit events, not message content, and cannot place holds.

37
MCQeasy

Your company needs to automatically classify and label sensitive documents in Microsoft 365 based on their content. Which Microsoft Purview solution should you implement?

A.Microsoft Purview Audit
B.Microsoft Purview Information Protection
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Insider Risk Management
AnswerB

Microsoft Purview Information Protection (IP) enables automatic classification and labeling by using sensitivity labels that can be applied based on content. Through built-in sensitive information types (e.g., credit cards, PII), trainable classifiers, or exact data match, service-side auto-labeling can scan documents and emails in Exchange Online, SharePoint Online, and OneDrive, then apply appropriate labels and optional encryption. This directly satisfies the need to automatically classify and label sensitive data, and it is the correct solution for the requirement.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) enables automatic classification and labeling of sensitive documents based on content, using trainable classifiers, exact data match (EDM), and sensitive information types. This solution applies sensitivity labels to documents in Microsoft 365 (e.g., SharePoint, Exchange, OneDrive) via client-side labeling or auto-labeling policies, meeting the requirement to classify and label by content.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection with Data Lifecycle Management, because both involve labels, but Data Lifecycle Management handles retention and deletion, not content-based classification and sensitivity labeling.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Audit focuses on logging and investigating user and admin activities, not on classifying or labeling content. Option C is wrong because Microsoft Purview Data Lifecycle Management (formerly Records Management) handles retention and deletion policies, not content-based classification and labeling. Option D is wrong because Microsoft Purview Insider Risk Management detects risky user behaviors (e.g., data exfiltration) using analytics, but does not automatically classify or label documents based on content.

38
MCQeasy

You need to design a solution to synchronize on-premises Active Directory users to Microsoft Entra ID for hybrid identity. Which tool should you use?

A.Microsoft Identity Manager (MIM)
B.Microsoft Entra Connect
C.Microsoft Entra Connect Cloud Sync
D.Active Directory Federation Services (AD FS)
AnswerB

Microsoft Entra Connect is the primary, purpose-built tool for synchronizing on-premises Active Directory identities to Microsoft Entra ID. It replicates user, group, and device objects, and supports password hash synchronization, pass-through authentication, and federation integration. As the successor to DirSync and Azure AD Sync, it's the standard first-party solution for hybrid identity, and it is the correct choice when a straightforward, sanctioned sync mechanism is required.

Why this answer

Microsoft Entra Connect is the correct tool for synchronizing on-premises Active Directory users to Microsoft Entra ID for hybrid identity because it provides a comprehensive, full-featured synchronization engine that supports password hash synchronization, pass-through authentication, and federation integration. It is the primary tool for hybrid identity scenarios where you need to synchronize a single on-premises AD forest to a single Entra ID tenant, handling attributes, password writeback, and device synchronization.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect Cloud Sync with the full Entra Connect tool, assuming the 'Cloud Sync' name implies it is the primary or newer replacement, but in reality, Entra Connect Cloud Sync is a lighter agent for specific multi-forest or limited scenarios, while Entra Connect remains the standard for full hybrid identity synchronization.

How to eliminate wrong answers

Option A is wrong because Microsoft Identity Manager (MIM) is an identity management and governance tool for managing on-premises identities and synchronization between multiple identity stores, not the primary tool for synchronizing a single on-premises AD to Entra ID for hybrid identity; it is more complex and typically used for advanced scenarios like cross-forest synchronization or identity lifecycle management. Option C is wrong because Microsoft Entra Connect Cloud Sync is a lightweight agent designed for synchronizing users from multiple on-premises AD forests to Entra ID, but it lacks full feature parity with Entra Connect (e.g., no device writeback, no pass-through authentication with seamless SSO, and limited attribute filtering) and is intended for specific scenarios like merging multiple forests or replacing older sync tools, not as the default for standard hybrid identity. Option D is wrong because Active Directory Federation Services (AD FS) is a federation service that provides single sign-on and claims-based authentication, not a synchronization tool; it does not synchronize user objects or attributes from on-premises AD to Entra ID.

39
MCQmedium

Refer to the exhibit. You are reviewing a conditional access policy JSON in Microsoft Entra ID. What does this policy accomplish?

A.Requires MFA for high-risk sign-ins.
B.Blocks external users from high-risk sign-ins.
C.Blocks all users when sign-in risk is high.
D.Blocks sign-ins from specific applications.
AnswerC

The policy's conditions combine all users with a sign-in risk level of high, and its grant control is block. Because no exclusions or other risk levels are scoped, every user is denied access whenever Microsoft Entra ID detects high sign-in risk.

Why this answer

The correct option is C: Blocks all users when sign-in risk is high. In Microsoft Entra ID conditional access, a policy that includes all users and sets the sign-in risk condition to High with a grant control of Block will deny access for any sign-in evaluated as high risk. This matches the scenario because the policy targets the broad user scope and uses sign-in risk (not user risk) as the trigger.

Option A is wrong because the policy blocks rather than requires MFA, and it does not mention an MFA grant control. Option B is wrong because the policy applies to all users, not only external or guest users. Option D is wrong because the condition is sign-in risk, not specific cloud apps or applications.

40
MCQeasy

A company uses Microsoft Defender for Identity (MDI) to monitor on-premises Active Directory. They want to integrate MDI alerts into Microsoft Sentinel. Which data connector should they use?

A.Syslog connector
B.Azure Active Directory connector
C.Microsoft Defender for Identity connector
D.Windows Security Events via AMA
AnswerC

The Microsoft Defender for Identity connector is the dedicated data connector designed to import MDI alerts into Microsoft Sentinel. It leverages the Microsoft 365 Defender data export model, pulling MDI-generated security alerts so they can be correlated with other Sentinel data. This is the only connector in the list whose native purpose is to ingest MDI alert telemetry, making it the correct choice for this scenario.

Why this answer

The Microsoft Defender for Identity connector is the correct choice because it is the purpose-built Microsoft Sentinel data connector that ingests MDI alerts and related entity data directly from the MDI service into the Sentinel workspace, enabling built-in analytics rules and incident creation. The Syslog connector is for forwarding syslog/CEF events from Linux or network devices, not for MDI's native alert stream. The Azure Active Directory connector ingests Azure AD sign-in and audit logs, not on-premises AD threat alerts from MDI.

Windows Security Events via AMA collects Windows event logs from servers, which does not include MDI's correlated identity alerts.

41
MCQeasy

Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents without human intervention. Which feature should you configure?

A.Automation rule
B.Analytics rule
C.Workbook
D.Watchlist
AnswerA

An automation rule is the correct answer because it provides the incident-level response engine within Microsoft Sentinel. It evaluates configurable conditions (such as severity, tag, or entity properties) and then executes actions automatically—including triggering a playbook, changing incident status, assigning an owner, or adding tasks—without human intervention. Because it runs on every matching incident at creation or update, it directly implements the required automated response to Sentinel incidents.

Why this answer

Automation rules in Microsoft Sentinel allow you to define automated responses to incidents based on conditions such as severity, without requiring human intervention. When a high-severity incident is created or updated, an automation rule can trigger a playbook (via Azure Logic Apps) to perform actions like blocking an IP, resetting a user password, or creating a support ticket, enabling fully automated incident response.

Exam trap

The trap here is confusing the detection phase (analytics rules) with the response phase (automation rules), leading candidates to select analytics rules because they think 'automated response' is part of the detection logic, when in fact analytics rules only generate alerts, not automated actions.

How to eliminate wrong answers

Option B is wrong because analytics rules are used to generate alerts and incidents from raw data by defining detection logic (e.g., KQL queries), not to automate responses after an incident is created. Option C is wrong because workbooks are visualization tools that provide dashboards and reports on security data, not mechanisms for automated response actions. Option D is wrong because watchlists are collections of known indicators (e.g., IP addresses, hostnames) used for correlation and enrichment in queries, not for triggering automated remediation workflows.

42
MCQhard

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the primary purpose?

A.Correlate alerts across different data sources
B.Identify new high-severity alerts in the last 7 days
C.Detect entities that have been repeatedly targeted by high-severity alerts
D.Find entities with fewer than 5 high-severity alerts
AnswerC

The query groups high-severity alerts by CompromisedEntity and then filters the resulting aggregation to retain only entities with an `AlertCount > 5`. This directly identifies entities—such as users, hosts, or accounts—that have been hit by more than five high-severity alerts, indicating a pattern of repeated targeting. The `summarize` operation plus the having clause on the aggregated count is classic for detecting brute-force or persistent attack victims.

Why this answer

The KQL query uses `make_set` to aggregate distinct high-severity alert names per entity and filters for entities with more than 5 distinct alert types. This identifies entities that have been targeted by a high variety of high-severity alerts, indicating repeated or broad attack activity.

Exam trap

Candidates may overlook that `make_set` counts distinct alert names, not total alerts, and may also confuse the filter direction (`>5` vs `<5`), leading them to pick D. In reality, C is correct because a high number of distinct alert types indicates repeated targeting.

How to eliminate wrong answers

Option A is wrong because the query does not join or correlate alerts from different data sources; it only filters alerts by severity and aggregates by entity. Option B is wrong because the query does not identify new alerts; it counts distinct alert names over the last 7 days, not the recency of individual alerts. Option D is wrong because the query uses `array_length(make_set(...)) > 5`, which finds entities with more than 5 distinct high-severity alerts, not fewer than 5.

43
MCQhard

Your company uses Microsoft Purview Compliance Manager to track compliance with regulatory standards. You need to generate a report that shows the percentage of controls that are not yet implemented for the PCI DSS standard. What should you do?

A.In Compliance Manager, open the PCI DSS assessment and view the control status.
B.Create a Data Lifecycle Management policy for PCI DSS.
C.Create a custom risk assessment in Compliance Manager for PCI DSS.
D.Configure a Communication Compliance policy to monitor PCI DSS compliance.
AnswerA

Compliance Manager ships with a pre-built PCI DSS v3.2.1 or v4.0 assessment template that maps each requirement to customer actions and Microsoft-managed controls. Opening that assessment shows per-control status (e.g., Completed, In progress, Not started), implementation and testing evidence, ownership, and corrective actions. This is the direct, supported UI for monitoring PCI DSS compliance posture, and the status reflected is exactly what an auditor would expect to see.

Why this answer

The correct option is A: in Compliance Manager, open the PCI DSS assessment and view the control status, because Compliance Manager assessments include a controls view that shows each control's implementation status and progress percentages for the specific standard, which directly provides the percentage of controls not yet implemented. This is the built-in reporting surface for tracking regulatory compliance progress against PCI DSS. Option B is incorrect because Data Lifecycle Management policies govern retention and deletion of content, not compliance control reporting.

Option C is incorrect because custom risk assessments are for assessing risks, not for reporting control implementation percentages for a regulatory standard. Option D is incorrect because Communication Compliance policies detect policy violations in communications, not PCI DSS control implementation status.

44
MCQhard

Your organization uses Microsoft Sentinel. You need to design a solution to detect and automatically respond to a potential brute-force attack against an on-premises application that is published via Azure AD Application Proxy. The solution should block the attacker's IP address in Azure AD Conditional Access for one hour after detecting more than 10 failed login attempts within 5 minutes. What should you implement?

A.Create a Microsoft Purview Data Loss Prevention policy to block the IP address based on the login pattern.
B.Create a Microsoft Sentinel analytics rule that triggers on a KQL query detecting the failed logins, then use a playbook to add the IP to a Conditional Access block list via the Azure AD API.
C.Deploy a web application firewall (WAF) in front of the application and configure rate limiting to block the IP.
D.Configure a Microsoft Entra ID Protection sign-in risk policy to automatically block the user's sign-in after detecting anomalous activity.
AnswerB

Microsoft Sentinel can ingest sign-in logs from Azure AD Application Proxy. An analytics rule with a KQL query can detect the brute-force pattern, and when triggered, a playbook can call the Azure AD API to add the IP to a Conditional Access block list for one hour, effectively blocking the attacker.

Why this answer

You can create a Microsoft Sentinel analytics rule with a KQL query that detects more than 10 failed login attempts within 5 minutes. When the rule triggers, it runs a playbook that uses the Azure AD API to add the attacker's IP to a Conditional Access block list, blocking further access for one hour. Option A is incorrect because Microsoft Purview DLP policies are for data protection, not authentication blocking.

Option C is incorrect because a WAF rate limit blocks at the network layer but does not integrate with Azure AD Conditional Access, and it cannot read authentication logs from Azure AD App Proxy. Option D is incorrect because Microsoft Entra ID Protection sign-in risk policies are user-based and cannot block specific IPs or apply custom logic like a 1-hour block.

45
MCQmedium

Your organization uses Microsoft Purview. You need to design a solution that automatically detects and classifies sensitive data such as passport numbers stored in Microsoft OneDrive. The solution should apply a 'Highly Confidential' sensitivity label without user intervention. What should you configure?

A.Create an auto-labeling policy in Microsoft Purview that targets OneDrive and includes the 'Passport Number' sensitive info type.
B.Create a Data Loss Prevention (DLP) policy that blocks sharing of files with passport numbers.
C.Enable auditing in Microsoft Purview to track where passport numbers are stored.
D.Configure a manual sensitivity label and train users to apply it.
AnswerA

An auto-labeling policy in Microsoft Purview is designed to automatically evaluate content against sensitive info types like 'Passport Number' and apply the corresponding sensitivity label without user interaction. By targeting OneDrive locations, the policy continuously scans files, and when a match is found, it assigns the label and can enforce encryption or protection. This directly fulfills the requirement because classification happens automatically based on content inspection, not on user discretion or manual workflow.

Why this answer

Option A is correct because an auto-labeling policy in Microsoft Purview is the feature designed to automatically detect sensitive information types (such as 'Passport Number') in locations like OneDrive and apply a sensitivity label like 'Highly Confidential' without user intervention. Auto-labeling policies use the sensitive info type as a condition and can apply the label directly to matching content. Option B is incorrect because a DLP policy blocks or restricts sharing; it does not apply sensitivity labels.

Option C is incorrect because auditing only records activity and does not classify or label data. Option D is incorrect because manual labeling requires user action, which contradicts the no-user-intervention requirement.

46
Multi-Selecthard

A company wants to automate incident response in Microsoft 365 Defender. Which THREE actions can be automated using automated investigation and response (AIR) capabilities? (Choose three.)

Select 3 answers
A.Block a file hash across the organization.
B.Reset a user's password.
C.Isolate a device from the network.
D.Create a new user account.
E.Delete a malicious email from all mailboxes.
AnswersA, C, E

AIR can block indicators of compromise.

Why this answer

Microsoft 365 Defender's automated investigation and response (AIR) can automatically block a file hash at the tenant level using threat intelligence and cloud-delivered protection. When a malicious file is detected, AIR can create an indicator to block the hash across all endpoints via Microsoft Defender for Endpoint, preventing further execution.

Exam trap

Candidates often mistake identity-related actions like password resets as part of AIR, but these are handled by separate Azure AD Identity Protection workflows. AIR actions are limited to endpoint, email, and collaboration containment.

47
MCQhard

Your organization uses Microsoft Entra ID with external identities. You need to design a solution that allows partners to self-service sign up using their existing Azure AD or Microsoft account credentials, while preventing them from accessing other resources. What should you use?

A.Microsoft Entra B2C
B.Microsoft Entra Identity Protection
C.Microsoft Entra B2B collaboration
D.Direct federation with partner's IdP
AnswerC

Microsoft Entra B2B collaboration is the correct choice because it allows external users to access apps with their own existing identities, and its self-service sign-up feature lets partners initiate access by providing their details without requiring a pre-configured federation trust. B2B collaboration creates guest accounts in your tenant, supports integration with various identity providers including Microsoft Entra ID and Google, and is designed specifically for business-to-business partnerships. This satisfies both the self-service and existing-credential requirements of the scenario.

Why this answer

Microsoft Entra B2B collaboration is correct because it lets you invite external partners as guest users who can redeem invitations and sign in with their existing work/school account (Azure AD) or Microsoft account, while access is scoped only to the resources you explicitly share. Guest users in B2B are represented in your tenant and governed by Conditional Access and entitlement management, so they cannot access other resources by default. Entra B2C is for customer-facing apps with local or social identities, not partner collaboration in your corporate tenant.

Identity Protection provides risk-based sign-in and user risk policies, not partner onboarding. Direct federation with a partner's IdP requires configuring a SAML/WS-Fed trust per partner and does not provide the self-service invitation and redemption model of B2B.

48
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. The policy is enabled but users who are detected as high risk are still able to sign in. What is the most likely reason?

A.No users or groups are assigned to the policy
B.The policy state is set to 'enabled' but not 'enforced'
C.The user risk level is set to 'high' but sign-in risk is 'medium'
D.The grant control is set to 'block' but should be 'require MFA'
AnswerA

Conditional Access policies only evaluate sign-ins for identities explicitly included in the assignments. With no users or groups assigned, the policy is enabled yet never applies, so high-risk users sign in unimpeded despite the configured risk condition.

Why this answer

A Conditional Access policy must have at least one user or group assigned to it to be evaluated. If no users or groups are assigned, the policy is effectively inactive, even if enabled. In this scenario, the policy is enabled but not applied to any identities, so high-risk users are not subject to its controls.

Exam trap

The SC-100 exam often tests the misconception that an enabled policy is automatically applied to all users, but the trap here is that the policy must have explicit assignments to take effect.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies do not have an 'enforced' state; they are either 'enabled' or 'disabled'. An enabled policy is active and enforced. Option C is wrong because the user risk level and sign-in risk are separate conditions; setting user risk to 'high' does not require sign-in risk to be set, and the policy would still block high-risk users if assigned.

Option D is wrong because the grant control 'block' is the correct setting to prevent sign-ins; changing it to 'require MFA' would allow sign-ins with MFA, not block them.

49
Multi-Selecteasy

A company wants to implement a Zero Trust security model. Which TWO principles are fundamental to Zero Trust? (Choose two.)

Select 2 answers
A.Verify explicitly.
B.Use perimeter-based security.
C.Trust internal network.
D.Trust but verify.
E.Assume breach.
AnswersA, E

Verify explicitly is the foundational Zero Trust principle that mandates every access request be authenticated, authorized, and encrypted based on all available data points, including user identity, device health, location, and data sensitivity. It eliminates any implicit trust derived from network location or previous interactions, requiring continuous validation for each transaction. This principle ensures that access is granted only after a thorough, real-time assessment, making it the correct core principle for Zero Trust.

Why this answer

Option A (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points—user identity, device health, location, and resource sensitivity—rather than granting implicit trust based on network location. Option E (Assume breach) is correct because Zero Trust operates on the principle that threats may already exist inside the environment, so organizations must minimize blast radius, segment access, encrypt traffic end-to-end, and use analytics to detect and respond to anomalies. Option B (Use perimeter-based security) is incorrect because Zero Trust explicitly rejects the castle-and-moat perimeter model in favor of identity-centric controls that follow the user and device.

Option C (Trust internal network) is incorrect because Zero Trust assumes no implicit trust for traffic originating from the corporate LAN or VPN. Option D (Trust but verify) is incorrect because it implies initial trust is granted before verification, which contradicts Zero Trust's requirement to verify every request explicitly and continuously.

Exam trap

The trap here is that candidates often confuse 'trust but verify' (Option D) with Zero Trust, but Microsoft explicitly defines Zero Trust as 'never trust, always verify,' making 'trust but verify' a legacy approach that still assumes initial trust.

50
Multi-Selectmedium

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to design a solution that allows only hybrid Azure AD joined devices to access a sensitive application. The solution must also require that the device is compliant with company policies. Which two components should you configure? (Choose TWO.)

Select 2 answers
A.Intune app protection policy
B.Conditional Access policy with 'Require multifactor authentication'
C.Conditional Access policy with 'Require hybrid Azure AD joined device'
D.Intune device enrollment
E.Intune device compliance policy
AnswersC, E

A Conditional Access policy targeting the sensitive application with the 'Require hybrid Azure AD joined device' grant control blocks every device lacking that join state, satisfying the hybrid-only constraint at authentication time. Combined with a compliance requirement, it enforces both conditions before a token is issued.

Why this answer

Option C is correct because a Conditional Access policy with the 'Require hybrid Azure AD joined device' grant control enforces that only devices registered as hybrid Azure AD joined can access the sensitive application, directly satisfying the device-trust requirement. Option E is correct because an Intune device compliance policy defines and evaluates the rules (such as OS version, encryption, and password requirements) that determine whether a device is compliant, and Conditional Access can then require a compliant device. Together, C and E let Conditional Access grant access only when the device is both hybrid Azure AD joined and compliant.

Option A is not correct because Intune app protection policies (MAM) protect app data on mobile devices and do not enforce hybrid Azure AD join or device compliance for Conditional Access. Option B is not correct because requiring multifactor authentication verifies the user, not the device's join state or compliance. Option D is not correct because device enrollment merely onboards devices into Intune; it does not itself enforce the hybrid join or compliance requirements at access time.

Exam trap

SC-100 often tests whether candidates confuse device compliance with device join state or MFA, leading them to select app protection policies or MFA-only Conditional Access when the requirement explicitly demands hybrid join and compliance.

51
Multi-Selectmedium

Your organization is designing a privileged access strategy using Microsoft Entra ID. Which TWO configurations should be part of the design to protect privileged accounts?

Select 2 answers
A.Require multi-factor authentication for all administrative roles via Conditional Access
B.Enable security defaults
C.Implement Privileged Identity Management (PIM) for just-in-time access
D.Enable self-service password reset for admins
E.Disable multi-factor authentication for emergency admin accounts
AnswersA, C

Conditional Access allows MFA policies to be scoped specifically to administrative roles (e.g., Global Administrator, Privileged Role Administrator), applying risk-based and device-compliance conditions at sign-in. This provides granular control over when and where MFA is enforced, which is essential for privileged access because stolen admin credentials become insufficient without a second factor. Unlike blanket security defaults, this can also exclude break-glass accounts while still securing all other admins.

Why this answer

Options A and C are correct. Option A: Conditional Access with MFA for admin roles reduces risk of credential theft. Option C: Privileged Identity Management (PIM) provides just-in-time access and approval workflows.

Option B is wrong because security defaults enforce MFA for all users but lack granularity for privileged roles. Option D is wrong because self-service password reset is not specific to privileged accounts and does not protect against misuse. Option E is wrong because disabling MFA would weaken security.

52
MCQeasy

You need to design a security operations strategy for a hybrid environment using Microsoft Sentinel. Your environment includes on-premises servers and Azure VMs. Which data connector should you use to collect security events from both sources?

A.Azure Activity log connector
B.Windows Security Events via AMA connector
C.Office 365 connector
D.Syslog connector
AnswerB

The Windows Security Events via AMA connector uses the Azure Monitor Agent to collect Windows operating system security events, including common Event IDs such as 4624 (successful logon) and 4625 (failed logon), from both Azure VMs and Arc-enabled on-premises servers. Because it relies on AMA, it provides a single, consistent agent for hybrid environments and supports data collection rules to filter specific security event IDs. This direct, native collection path makes it the correct choice for the scenario.

Why this answer

The Windows Security Events via AMA connector is correct because the Azure Monitor Agent (AMA) can be installed on both on-premises Windows servers (via Azure Arc) and Azure VMs, allowing Windows security events to be collected and ingested into Microsoft Sentinel from both sources. This connector uses Data Collection Rules (DCRs) to define which event sets (e.g., All Events, Common, Minimal) are streamed to the Log Analytics workspace. The Azure Activity log connector only captures Azure control-plane/subscription-level operations, not OS security events from servers.

The Office 365 connector ingests audit logs from Microsoft 365 services, and the Syslog connector targets Linux/Unix or network appliances via syslog, not Windows security events.

Exam trap

Candidates may mistakenly choose the Azure Activity log connector, thinking it covers all Azure resource logs, but it does not capture Windows Security Events from VMs.

53
MCQeasy

The exhibit shows a conditional access policy from Microsoft Entra ID Identity Protection. When will this policy require MFA?

A.When user risk is medium or high AND sign-in risk is high
B.When either user risk is medium or sign-in risk is high
C.When user risk is medium or high, regardless of sign-in risk
D.When sign-in risk is high, regardless of user risk
AnswerA

In Microsoft Entra Conditional Access, when both user risk and sign-in risk are specified as conditions, they are evaluated together using AND logic. The policy only applies when the user risk is medium or high and the sign-in risk is high simultaneously, so both conditions are required to trigger access controls. This matches the policy configuration exactly.

Why this answer

The conditional access policy shown in the exhibit uses the 'Require MFA' grant control with conditions set for user risk (medium or high) AND sign-in risk (high). In Microsoft Entra ID Identity Protection, when both risk levels are evaluated together with an AND operator, MFA is only triggered when both conditions are met simultaneously. This ensures that MFA is enforced only when the user account itself is compromised (medium/high user risk) and the current sign-in session is also risky (high sign-in risk), providing a layered security response.

Exam trap

The trap here is that candidates often confuse the AND operator with OR, assuming that either risk condition alone would trigger MFA, but the exhibit explicitly shows both conditions must be satisfied simultaneously.

How to eliminate wrong answers

Option B is wrong because it describes an OR condition (either user risk medium OR sign-in risk high), but the policy uses an AND operator, meaning both conditions must be true. Option C is wrong because it ignores the sign-in risk condition entirely, suggesting MFA is required regardless of sign-in risk, which contradicts the policy's explicit requirement for high sign-in risk. Option D is wrong because it ignores the user risk condition, stating MFA is required when sign-in risk is high regardless of user risk, but the policy requires user risk to be medium or high as well.

54
MCQeasy

Your organization uses Microsoft Sentinel for security operations. You need to ensure that all incidents are automatically assigned to the appropriate analyst team based on the type of threat. What should you configure?

A.Use a watchlist to map threat types to teams and trigger a logic app.
B.Modify the analytics rule to include a custom field for the assigned team.
C.Create a playbook that assigns ownership based on incident properties.
D.Configure an automation rule to set the incident owner based on custom conditions.
AnswerD

Automation rules are the native Sentinel feature that lets you set incident properties—including owner—based on conditions like severity, tags, or rule name, and they execute automatically when an incident is created or updated. This is a built-in action with no external dependencies, so it runs reliably, quickly, and with minimal configuration, making it the correct solution. You can specify a user or group as owner, and the rule will apply that assignment when the incident matches your custom conditions.

Why this answer

The correct option is D: configure an automation rule to set the incident owner based on custom conditions. Microsoft Sentinel automation rules are designed to run on incident creation or updates and can assign an owner (analyst or team) using conditions such as the incident's title, severity, tactics, or custom details, which directly matches the requirement to route incidents by threat type. Option A is wrong because a watchlist alone does not assign incidents and would require an unnecessary logic app; watchlists are reference data, not automation triggers.

Option B is wrong because analytics rules generate incidents and can add custom details or entity mappings, but they do not assign incident ownership to a team. Option C is wrong because playbooks are Logic Apps triggered by automation rules or analytics rules and are used for response actions, not as the primary mechanism for setting incident owner based on conditions.

Exam trap

A common mistake is to think that playbooks are needed for incident assignment, but automation rules provide a simpler and more direct way to set incident owners based on conditions.

55
MCQhard

Your organization uses Microsoft Intune to manage devices. You need to ensure that corporate data on personally owned devices is removed when a user leaves the company, but personal data remains intact. What should you use?

A.Selective wipe (retire)
B.Conditional Access policy
C.Full wipe
D.Device compliance policy
AnswerA

Intune's retire action performs a selective wipe: it deletes only the organization's managed data, such as corporate email, VPN and Wi-Fi profiles, app configs, and protected app containers, then unenrolls the device. It deliberately preserves personal photos, personal apps, and other user data, making it the correct choice for BYOD when you must remove company information without damaging the user's private content.

Why this answer

Selective wipe (retire) is the correct choice because it removes only corporate data from a personally owned device enrolled in Microsoft Intune, while preserving the user's personal data. This is achieved by targeting managed app data and corporate profiles, leaving personal apps, photos, and settings intact. It aligns with the requirement to protect corporate information upon employee departure without affecting the user's personal property.

Exam trap

The trap here is that candidates often confuse 'selective wipe' with 'full wipe' or assume that a Conditional Access policy can enforce data removal, when in fact only selective wipe provides granular corporate data removal while preserving personal data.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies control access to resources based on conditions like device compliance or location, but they do not perform data removal or wipe operations. Option C is wrong because a full wipe resets the device to factory defaults, erasing both corporate and personal data, which violates the requirement to keep personal data intact. Option D is wrong because device compliance policies enforce security settings (e.g., requiring encryption or a minimum OS version) but do not remove data; they only mark devices as compliant or non-compliant.

56
MCQeasy

Your organization is implementing a zero-trust security model and needs to ensure that all access to cloud resources is verified in real-time. You plan to use Microsoft Entra ID Conditional Access. Which policy component enforces real-time verification of user identity and device compliance before granting access?

A.Enable Microsoft Secure Score
B.Use Azure AD Application Proxy
C.Conditional Access policy with conditions and grant controls
D.Assign users and groups to the policy
AnswerC

Conditional Access policies are the core enforcement mechanism for zero trust in Azure AD. They combine conditions such as user or group membership, location, device state, and sign-in risk with grant controls like requiring MFA, a compliant device, or a hybrid Azure AD joined device. These policies enforce real-time verification for every access attempt, ensuring that access is granted only when all configured conditions and controls are satisfied, aligning with the zero trust principle of 'verify explicitly'.

Why this answer

Conditional Access policies with conditions and grant controls enforce real-time verification by evaluating signals such as user identity, device compliance (via Microsoft Intune), and location before allowing access to cloud resources. The grant controls block or require multi-factor authentication (MFA) or device compliance, ensuring zero-trust principles of explicit verification and least privilege.

Exam trap

The trap here is that candidates confuse policy assignment (users/groups) with the enforcement mechanism (conditions and grant controls), thinking that merely assigning a policy to a user group enforces real-time verification, when in fact the conditions and grant controls are the components that perform the actual evaluation and access decision.

How to eliminate wrong answers

Option A is wrong because Microsoft Secure Score is a security posture measurement tool, not a policy component that enforces real-time access verification. Option B is wrong because Azure AD Application Proxy provides secure remote access to on-premises web applications, not real-time identity and device compliance checks for cloud resources. Option D is wrong because assigning users and groups to a policy defines scope but does not enforce real-time verification; the conditions and grant controls are the components that perform the actual evaluation and enforcement.

57
MCQeasy

A company uses Microsoft Defender for Cloud Apps to discover and control Shadow IT. They want to block the use of a newly discovered unsanctioned app. What should they do?

A.Create a Conditional Access policy to block the app
B.Use Microsoft Purview Data Loss Prevention to block the app
C.Mark the app as unsanctioned in Defender for Cloud Apps
D.Block the app's domain in Microsoft Intune
AnswerC

Defender for Cloud Apps presents discovered apps in the Shadow IT dashboard, where an admin can mark an app as unsanctioned to actively block it. Unsanctioning is the native CASB control point that works with the Conditional Access App Control (reverse proxy) or app connectors to terminate sessions and prevent access to the app for all users. This is the exact feature designed to govern newly discovered unsanctioned cloud applications, and it works even for apps that are not federated with Microsoft Entra ID.

Why this answer

Marking an app as unsanctioned in Microsoft Defender for Cloud Apps is the direct mechanism to block access to a discovered Shadow IT app. When an app is marked unsanctioned, Defender for Cloud Apps automatically enforces a block by integrating with Conditional Access to prevent users from accessing the app, and it can also generate alerts and session controls. This action is specifically designed for the discovered app governance workflow within Defender for Cloud Apps.

Exam trap

The trap here is that candidates often assume creating a Conditional Access policy directly is the correct action, but the SC-100 exam tests the understanding that marking the app as unsanctioned in Defender for Cloud Apps is the prerequisite step that triggers the automatic Conditional Access policy enforcement.

How to eliminate wrong answers

Option A is wrong because creating a Conditional Access policy to block the app is not the first step; the app must first be marked as unsanctioned in Defender for Cloud Apps, which then automatically creates the necessary Conditional Access policy via the app governance integration. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent data exfiltration and sensitive data sharing, not to block access to an entire unsanctioned app. Option D is wrong because blocking the app's domain in Microsoft Intune would only affect managed devices and does not address the broader Shadow IT discovery and control workflow that Defender for Cloud Apps provides.

58
MCQhard

Your organization uses Microsoft Sentinel as a SIEM. The security team wants to use Microsoft Copilot for Security to assist in incident investigation. You need to ensure that Copilot can access Sentinel data while meeting compliance requirements. Which integration should you configure?

A.Deploy a playbook to query Sentinel data
B.Enable Microsoft Copilot for Security plugin for Sentinel
C.Enable Sentinel's Threat Intelligence connectors
D.Use Microsoft Defender for Cloud
AnswerB

Enabling the Microsoft Copilot for Security plugin for Sentinel is the direct, secure integration that lets Copilot query and interact with Sentinel data using natural language. When enabled, a security analyst can ask Copilot questions like 'summarize the most recent high-severity alerts' or 'show all open incidents involving user X,' and Copilot translates that into KQL queries against Sentinel's underlying Log Analytics workspace. This plugin explicitly bridges Copilot to Sentinel, providing incident summaries, guided investigations, and context-aware responses, which is exactly what the organization needs to leverage Copilot as a SIEM interface.

Why this answer

The Microsoft Copilot for Security plugin for Sentinel is the correct integration because it enables Copilot to directly query and analyze Sentinel data through a native, compliant connection. This plugin uses Sentinel's API and role-based access control (RBAC) to ensure that Copilot only accesses data the user is authorized to see, meeting compliance requirements without additional data movement.

Exam trap

The trap here is that candidates often confuse enabling Threat Intelligence connectors (Option C) with granting data access, but those connectors only import external threat data and do not provide Copilot with read access to Sentinel's internal logs or incidents.

How to eliminate wrong answers

Option A is wrong because deploying a playbook to query Sentinel data introduces unnecessary complexity and latency; playbooks are designed for automated response workflows, not for providing real-time, compliant data access to Copilot. Option C is wrong because enabling Sentinel's Threat Intelligence connectors only ingests external threat intelligence feeds into Sentinel, it does not grant Copilot access to Sentinel's existing security data or logs. Option D is wrong because Microsoft Defender for Cloud is a separate cloud security posture management (CSPM) tool that does not natively integrate with Copilot for Security to access Sentinel data; it focuses on workload protection, not SIEM data access.

59
MCQeasy

Your organization uses Microsoft Intune for mobile device management. You need to ensure that only compliant devices can access corporate email. What should you configure?

A.Configure an app protection policy in Intune.
B.Create a device configuration policy in Intune.
C.Create a Conditional Access policy in Microsoft Entra ID that requires compliant device.
D.Create a device compliance policy in Intune.
AnswerC

Conditional Access enforces the compliance signal from Intune at authentication time, so only devices meeting your compliance policy obtain a token for Exchange Online. This directly satisfies the requirement that solely compliant devices reach corporate email, blocking unmanaged or non-compliant endpoints.

Why this answer

Conditional Access in Microsoft Entra ID can enforce device compliance for access. Option A is incorrect because app protection policies protect data within apps but do not control device-level access. Option B is incorrect because device configuration policies define settings but do not enforce compliance-based access.

Option D is incorrect because device compliance policies define compliance requirements, but Conditional Access is needed to enforce them.

60
MCQeasy

Your company uses Microsoft 365 E5 licenses and has deployed Microsoft Defender for Office 365. The security team wants to be alerted when a user reports a phishing email using the built-in report message button in Outlook. The alert should be sent to the security team's email address. You need to configure this in the Microsoft 365 Defender portal. What should you do?

A.Create an anti-phishing policy that notifies users about phishing.
B.Configure the User reported messages settings to send alerts to the security team.
C.Create a Safe Attachments policy to detect phishing attachments.
D.Create a Safe Links policy that alerts on phishing URLs.
AnswerB

The User reported messages settings in the Microsoft 365 Defender portal (under Email & collaboration > Policies & rules > Threat policies) let you specify where messages reported by users via Outlook, Outlook on the web, or the built-in Report Message button are sent. You can direct these submissions to an internal mailbox, Microsoft, or both, and configure alert notifications so the security team is immediately informed when a user submits a message. This directly satisfies the requirement to make reports visible and actionable.

Why this answer

The correct option is B: configure the User reported messages settings to send alerts to the security team. In the Microsoft 365 Defender portal, under Email & collaboration > Policies & rules > Threat policies > User reported messages, you can specify a reporting mailbox and enable notifications so that when a user reports a phishing message via the built-in Report Message/Report Phishing add-in, the security team is alerted. This directly addresses the requirement to alert the security team when a user reports a phishing email.

Options A, C, and D do not fit: anti-phishing policies control impersonation and spoofing protections and user tips, while Safe Attachments and Safe Links policies detonate attachments and rewrite/scan URLs at delivery and click time, respectively, and none of them trigger an alert based on a user's manual report.

61
MCQeasy

You are designing an incident response plan for a company using Microsoft Defender XDR. The team needs to automatically notify the SOC via email when an incident of high severity is created. What should you use?

A.Modify the analytics rule to send an email when an alert fires.
B.Create a playbook that sends an email when an incident is created.
C.Configure an automation rule with an action to send an email notification.
D.Use advanced hunting to query high severity incidents and send email.
AnswerC

Configuring an automation rule with an action to send an email notification is the correct approach in Microsoft Sentinel for alerting on incident creation. Automation rules are specifically designed to handle incident lifecycle events (created, updated, etc.) and can perform one or more actions immediately, without needing an external logic app. The 'Send Email' action directly sends an email to a specified recipient, using configured SMTP or Microsoft 365 settings, and can include incident details in the body. This method is natively supported, requires minimal setup, and ensures timely notification whenever an incident meets the condition (e.g., high severity).

Why this answer

Automation rules in Microsoft Defender XDR are specifically designed to trigger automated actions—including sending email notifications—when an incident is created or updated. Unlike playbooks, automation rules can directly send email without requiring a Logic Apps connector, and they operate natively within the Defender portal's incident lifecycle.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR automation rules with Microsoft Sentinel playbooks or analytics rules, assuming that playbooks are the only way to send email, when in fact Defender XDR has a built-in email notification action within automation rules.

How to eliminate wrong answers

Option A is wrong because analytics rules are used in Microsoft Sentinel, not Microsoft Defender XDR; Defender XDR uses detection rules, and modifying an analytics rule would not apply to Defender incidents. Option B is wrong because a playbook (Logic Apps) can send email but requires additional configuration and licensing, and is not the simplest or most direct method for email notification on incident creation. Option D is wrong because advanced hunting is a query tool for threat hunting and does not have native capabilities to automatically send email notifications; it would require custom scripting and external integration.

62
MCQmedium

Your organization uses Microsoft Entra ID. You need to design a solution that requires users to perform multifactor authentication when accessing a critical application from an untrusted network. The solution should not require additional licensing beyond Microsoft Entra ID P1. What should you use?

A.Create a Conditional Access policy in Microsoft Entra ID.
B.Configure a risk-based policy in Microsoft Entra ID Protection.
C.Enable per-user MFA in Microsoft Entra ID.
D.Deploy a device compliance policy in Microsoft Intune.
AnswerA

A Conditional Access policy is the modern, context-aware mechanism in Microsoft Entra ID for enforcing MFA. It can precisely target specified users, groups, or applications, and evaluate conditions such as geographic location (via named locations), trusted IPs, device state, and sign-in risk. Because Conditional Access is included with Entra ID P1, it directly satisfies the requirement to enforce MFA based on location without requiring any additional licensing.

Why this answer

The correct answer is A: Create a Conditional Access policy in Microsoft Entra ID. Conditional Access is included with Microsoft Entra ID P1 and lets you enforce MFA specifically when users access a chosen cloud app from an untrusted network location, using conditions such as the application and named locations plus a grant control requiring multifactor authentication. Option B is not the best fit because risk-based sign-in/user risk policies require Microsoft Entra ID P2 (Entra ID Protection), exceeding the stated P1 licensing limit.

Option C, per-user MFA, can require MFA but is an all-or-nothing setting that cannot target a specific application or network condition. Option D, an Intune device compliance policy, addresses device configuration and compliance rather than directly enforcing MFA for app access from untrusted networks.

Exam trap

The trap is that candidates might choose Microsoft Entra ID Protection (P2) because it seems more sophisticated, but the requirement is no additional licensing beyond P1, so Conditional Access with location condition is sufficient and included. Also candidates might confuse per-user MFA with Conditional Access.

63
MCQhard

Your organization uses Microsoft Defender XDR for detection and response. You need to create a custom detection rule that alerts when a user performs more than 10 failed sign-ins from different countries within 5 minutes. Which component should you use?

A.Automation rule in Microsoft Sentinel
B.Custom detection rule in Microsoft 365 Defender
C.Analytics rule in Microsoft Sentinel
D.Attack simulation training
AnswerB

Custom detection rules in Microsoft Defender XDR leverage Advanced Hunting Kusto Query Language (KQL) queries to continuously monitor event data across email, endpoints, identities, and cloud apps. When the query returns results, the rule triggers an alert and can also create an incident, enabling bespoke detection logic beyond built-in detections. This is the native detection engine for Defender XDR, distinct from SIEM-based rules.

Why this answer

Custom detection rules in Microsoft 365 Defender allow you to define advanced hunting queries that trigger alerts based on specific event patterns, such as more than 10 failed sign-ins from different countries within 5 minutes. This is the correct component because it operates directly on data within the Defender XDR ecosystem (e.g., AADSignInEventsBeta) without requiring data ingestion into Sentinel.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel analytics rules (which require data ingestion) with Microsoft 365 Defender custom detection rules (which operate natively on Defender XDR data), leading them to choose Sentinel options when the question explicitly states 'Microsoft Defender XDR' as the platform.

How to eliminate wrong answers

Option A is wrong because automation rules in Microsoft Sentinel are used to automate incident response actions (e.g., assigning ownership or running playbooks), not to define detection logic based on raw event patterns. Option C is wrong because analytics rules in Microsoft Sentinel require data to be ingested into the Sentinel workspace first, whereas the question specifies using Microsoft Defender XDR directly for detection and response. Option D is wrong because attack simulation training is a phishing simulation and security awareness tool, not a detection mechanism for sign-in anomalies.

64
MCQmedium

A financial services company uses Microsoft Sentinel as its SIEM. The security operations team wants to reduce the number of low-fidelity alerts that reach analysts by correlating related alerts into incidents and automatically closing incidents that match known benign patterns. The team also wants to preserve an audit trail of every automated closure. Which Microsoft Sentinel capability should you design into the solution?

A.Automation rules that run a playbook to close incidents matching a benign pattern
B.Workbooks that visualize incident trends across the last 30 days
C.Data connectors that ingest Microsoft Defender XDR incidents into Microsoft Sentinel
D.Analytics rules configured with entity mapping to group alerts by IP address
AnswerA

Automation rules in Microsoft Sentinel can trigger on incident creation, evaluate conditions such as analytics rule name or entity, and run a playbook or change incident status. Running a playbook that closes the incident and leaves a comment records the automated action in the incident timeline, giving the required audit trail while removing low-fidelity noise before analysts see it.

Why this answer

The requirement combines automated triage with an auditable record of the action. Automation rules are the Microsoft Sentinel feature that evaluates incident properties and can run a playbook or change status, and a playbook that closes the incident with a comment creates the audit trail. Analytics rules, workbooks, and connectors each address detection, visualization, or ingestion rather than automated incident closure.

Exam trap

The trap here is confusing analytics rules, which create and group incidents, with automation rules, which act on incidents after they are created.

65
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to design a solution that automatically creates an incident in Sentinel when a high-severity alert is generated in Defender for Cloud. What should you configure?

A.Enable the Microsoft Defender for Cloud data connector and create an analytics rule
B.Create a workbook to track alerts
C.Create a playbook in Microsoft Sentinel
D.Use a watchlist to import alerts
AnswerA

The Defender for Cloud data connector ingests security alerts from connected workloads into the Microsoft Sentinel workspace as raw events. However, incidents are not created automatically from these alerts; you must configure an analytics rule (typically a Microsoft security rule of type 'Microsoft Defender for Cloud') to transform the relevant alerts into incidents with assigned severity, status, and ownership. This two-step flow is the only way to get the expected incident-creation behavior from Defender for Cloud alerts.

Why this answer

The Microsoft Defender for Cloud data connector ingests security alerts from Defender for Cloud into Microsoft Sentinel. Once ingested, you create an analytics rule with a rule query that triggers on high-severity alerts and configures the rule to automatically create an incident. This is the standard method to convert a Defender for Cloud alert into a Sentinel incident without manual intervention.

Exam trap

The trap here is that candidates often confuse a playbook (which automates responses) with the analytics rule that actually creates the incident, or they think a workbook or watchlist can trigger incident creation, but only an analytics rule with the proper data connector can automatically generate incidents from ingested alerts.

How to eliminate wrong answers

Option B is wrong because a workbook is a visualization tool for dashboards and reports, not a mechanism to create incidents from alerts. Option C is wrong because a playbook automates response actions (e.g., sending emails or blocking IPs) after an incident is created, but it does not itself generate the incident from a Defender for Cloud alert. Option D is wrong because a watchlist is a collection of static data (e.g., IP addresses or hostnames) used for correlation or enrichment in analytics rules, not a method to import live alerts and create incidents.

66
Multi-Selectmedium

Which TWO actions should you take to implement a Zero Trust security strategy for identity and access? (Choose two.)

Select 2 answers
A.Require Multi-Factor Authentication for all users.
B.Use VPN for remote access to the corporate network.
C.Implement Conditional Access policies that evaluate user, device, and location.
D.Rely on strong passwords only.
E.Create shared accounts for temporary workers.
AnswersA, C

Multi-factor authentication (MFA) requires users to prove identity with at least two distinct factors—typically a password, a device-bound key, and biometrics—so that a stolen password alone cannot unlock access. In the Zero Trust model, MFA operationalizes 'verify explicitly' by forcing each authentication attempt through a nontrivial identity check. Although MFA alone does not comprise full Zero Trust, it is a mandatory baseline that reduces the impact of credential theft and phishing.

Why this answer

Option A is correct because requiring Multi-Factor Authentication (MFA) for all users enforces the Zero Trust principle of verifying identity explicitly, ensuring that a compromised password alone cannot grant access. Option C is correct because Conditional Access policies evaluate signals such as user identity, device compliance, and location to make dynamic, context-aware access decisions, which is central to Zero Trust's 'never trust, always verify' model. Options B, D, and E do not belong: VPNs grant broad network-level access once authenticated rather than per-resource verification, strong passwords alone are a single factor vulnerable to credential theft, and shared accounts eliminate individual accountability and violate least-privilege and explicit-verification principles.

Exam trap

The trap here is that candidates often confuse VPN (a perimeter-based network access solution) with Zero Trust network access (ZTNA), mistakenly thinking VPNs are a valid Zero Trust identity action, when in fact they violate the core Zero Trust principle of not trusting any network segment implicitly.

67
MCQmedium

Refer to the exhibit. You create this conditional access policy in Microsoft Entra ID. What is the result?

A.Requires MFA for medium and high risk users for all applications
B.Blocks sign-ins from medium and high risk users for all applications
C.Blocks sign-ins from low risk users for all applications
D.Blocks sign-ins from medium and high risk users only for selected applications
AnswerB

This policy assigns the target to 'All cloud apps' and sets the user risk condition to 'Medium or High,' then applies the 'Block' grant control. As a result, any sign-in with a user risk level of medium or higher is denied across every application, while low-risk sign-ins are unaffected. The combination of a broad application scope and a risk threshold yields a global block for medium and high risk users.

Why this answer

The conditional access policy shown assigns the 'Block access' control to the 'Medium and High' risk levels for 'All cloud apps'. This means any sign-in from a user or session detected as medium or high risk will be blocked, regardless of the application. Option B correctly identifies this outcome.

Exam trap

The trap here is that candidates often confuse 'Block access' with 'Require MFA' when they see risk levels, assuming the policy will prompt for MFA instead of outright blocking the sign-in.

How to eliminate wrong answers

Option A is wrong because the policy uses 'Block access', not 'Grant access' with MFA, so it does not require MFA. Option C is wrong because the policy targets 'Medium and High' risk levels, not 'Low' risk. Option D is wrong because the policy applies to 'All cloud apps', not only selected applications.

68
MCQhard

A global enterprise uses Microsoft Entra ID with Privileged Identity Management (PIM) and Conditional Access. They need to ensure that all privileged role activations require an approval workflow, and that the approval process is documented for compliance. What configuration should they implement?

A.Create a Conditional Access policy requiring an Authentication Strength
B.In PIM, edit the role settings to require approval for activation
C.Configure an access review for the privileged roles
D.Create a role-assignable group and assign the privileged role to the group
AnswerB

Editing the role's activation settings to require approval enforces a documented authorisation step before any privileged role becomes active. This directly satisfies the stem's demand that every activation trigger an approval workflow, with the approval recorded in PIM for compliance auditing.

Why this answer

To require approval for privileged role activations in PIM, you must edit the role settings for the specific role and enable the 'Require approval to activate' option. This ensures that when a user activates the role, an approver must approve the request, and the approval is logged for compliance.

Exam trap

SC-100 often tests the difference between PIM settings and Conditional Access, and candidates may confuse approval workflows with access reviews or authentication strength, leading to wrong answers.

How to eliminate wrong answers

Option A is wrong because Conditional Access with Authentication Strength enforces stronger authentication methods but does not add an approval workflow. Option C is wrong because access reviews are for periodic attestation of role assignments, not for activation approval. Option D is wrong because role-assignable groups are for assigning roles to groups, not for configuring approval workflows.

69
MCQmedium

Refer to the exhibit. You receive an alert from Microsoft Defender for Cloud Apps. You need to investigate this alert in Microsoft Sentinel. Which Microsoft Sentinel feature should you use to visualize the relationship between the user account and the IP address?

A.Configure an automation rule to trigger a playbook.
B.Run a hunting query to search for similar alerts.
C.Use the Investigation graph to explore the entities involved.
D.Create a new workbook to display the alert details.
AnswerC

The Investigation graph in Microsoft Defender XDR is purpose-built for visually exploring the entities involved in an alert or incident. It dynamically maps nodes such as users, devices, IP addresses, and mailboxes, along with edges representing their connections, letting you investigate scope and expand the investigation. This interactive relationship mapping is exactly what the scenario requires, unlike automation or reporting tools.

Why this answer

The Investigation graph in Microsoft Sentinel is the correct feature because it is purpose-built to visualize and explore relationships among entities such as user accounts, IP addresses, hosts, and alerts, letting you pivot from the Defender for Cloud Apps alert to see how the user account connects to the IP address. It provides an interactive, entity-centric view that surfaces related incidents, alerts, and activities, which is exactly what is needed to investigate the relationship in this scenario. Automation rules (A) only trigger playbooks in response to alerts and do not visualize entity relationships, hunting queries (B) search log data for matching events but return tabular results rather than a relationship graph, and workbooks (D) are for building dashboards and reports of alert details, not for interactively exploring entity links.

70
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that an attacker cannot disable data collection by deleting the diagnostic settings on the Sentinel workspace. What should you configure?

A.Enable Sentinel's workspace deletion protection.
B.Assign the Log Analytics Contributor role only to specific users.
C.Apply a CanNotDelete resource lock on the Log Analytics workspace.
D.Create an Azure Policy to audit diagnostic settings.
AnswerC

Applying a CanNotDelete resource lock on the Log Analytics workspace is the only option that actively blocks any delete operation on the workspace and all its child resources, including diagnostic settings. This lock enforces a deny at the Azure Resource Manager level, overriding even elevated RBAC permissions unless a matching delete lock is removed first. As a result, it provides a robust, unbreakable-by-default safeguard that directly prevents the diagnostic settings from being deleted.

Why this answer

Applying a CanNotDelete resource lock on the Log Analytics workspace prevents any user or process, including an attacker, from deleting the workspace or its diagnostic settings. This lock overrides all role-based permissions, ensuring that even if an attacker gains high-privileged access, they cannot remove the diagnostic settings that stream telemetry to Microsoft Sentinel. Sentinel's data collection relies entirely on these diagnostic settings, so protecting them with a resource lock is the most direct and effective defense against deletion attacks.

Exam trap

The trap here is that candidates confuse workspace deletion protection (which only prevents workspace deletion) with diagnostic settings deletion protection, or they assume that RBAC alone (Option B) is sufficient to block a privileged attacker, when in fact a resource lock is the only control that enforces a hard deny on deletion regardless of permissions.

How to eliminate wrong answers

Option A is wrong because Sentinel's workspace deletion protection only prevents the accidental deletion of the Sentinel workspace itself, not the deletion of diagnostic settings on that workspace; an attacker could still remove the diagnostic settings and stop data ingestion without deleting the workspace. Option B is wrong because assigning the Log Analytics Contributor role only to specific users limits who can modify the workspace, but it does not prevent an attacker with compromised credentials or a privileged user from deleting diagnostic settings; role-based access control (RBAC) alone is insufficient against a determined attacker with elevated permissions. Option D is wrong because creating an Azure Policy to audit diagnostic settings only reports on compliance (e.g., whether settings exist) but does not block deletion; it provides no preventive control and cannot stop an attacker from removing the settings in real time.

71
Multi-Selectmedium

An organization uses Microsoft Purview to classify and protect sensitive data. Which THREE capabilities can be used to discover sensitive data? (Choose three.)

Select 3 answers
A.Trainable classifiers
B.Data loss prevention policies
C.Retention labels
D.Data classification rules
E.Sensitive information types
AnswersA, D, E

Trainable classifiers are machine learning models in Microsoft Purview that analyze content using contextual, semantic, and visual signals to identify data types that do not rely on fixed patterns. They can be trained on seed documents unique to your organization, allowing them to classify content that lacks standardized formats, such as intellectual property or internal forms. This makes them the correct answer for a ML-driven classification approach.

Why this answer

Trainable classifiers use machine learning to identify content based on patterns and context, not just exact matches. They can be trained on sample data to recognize custom sensitive information, such as specific contract clauses or internal project codes, enabling discovery of sensitive data that predefined sensitive information types might miss.

Exam trap

Microsoft often tests the distinction between discovery capabilities (which identify sensitive data) and enforcement or lifecycle management capabilities (which act on already-discovered data), causing candidates to mistakenly select DLP policies or retention labels as discovery tools.

72
MCQhard

Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You need to create an analytics rule that generates an incident when a user is reported as compromised by Microsoft Defender for Identity. The rule should use the most efficient method to get this data. What should you use as the data source?

A.The SecurityAlert table with a filter for Defender for Identity.
B.The DeviceEvents table from Advanced Hunting.
C.The OfficeActivity table.
D.The IdentityInfo table.
AnswerA

Defender for Identity alerts are normalized into the SecurityAlert table when Sentinel's data connectors ingest them from Microsoft 365 Defender or Azure ATP. This table uses a unified schema for all security alerts, so filtering by the provider or product name (such as 'Azure Advanced Threat Protection') isolates only Defender for Identity detections. Querying SecurityAlert is the correct approach because it is the standard Sentinel table for pre-correlated, high-fidelity security findings, not raw telemetry or audit logs.

Why this answer

The SecurityAlert table contains security alerts from various sources, including Microsoft Defender for Identity, when ingested via the Microsoft 365 Defender connector. By filtering for Defender for Identity alerts, you can create an analytics rule that triggers an incident when a user is reported as compromised. This is the most efficient method because the alerts are already available in this table.

Option B (DeviceEvents) is from Advanced Hunting and is not directly available in Sentinel tables; it requires running queries against the Microsoft 365 Defender advanced hunting schema, which is less efficient for creating analytics rules. Option C (OfficeActivity) contains Office 365 audit logs, not security alerts. Option D (IdentityInfo) contains identity information such as user details, but not alerts or compromise status.

73
MCQmedium

Your organization uses Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. You need to design a solution that centralizes security alerts and automates remediation across all clouds. Which security operations capability should you prioritize?

A.Configure Microsoft Purview Compliance Manager for regulatory assessments
B.Enable Microsoft Defender for Cloud's multi-cloud connector to aggregate alerts
C.Use Microsoft Sentinel as a single SIEM and SOAR platform with connectors for AWS and GCP
D.Deploy Microsoft Defender for Identity to monitor hybrid identities
AnswerC

Microsoft Sentinel is a cloud-native SIEM and SOAR that centralizes security telemetry from Azure, AWS, and GCP via native connectors, such as AWS CloudTrail/Security Hub and the GCP Pub/Sub-based connector, into a single Log Analytics workspace. It empowers analysts to run KQL-based hunt queries across all clouds, create custom analytics rules for multi-cloud attack detection, and use Automation rules and Logic Apps playbooks to orchestrate response. This provides true unified incident management and automated remediation across heterogeneous environments, far beyond what individual cloud security tools offer.

Why this answer

Microsoft Sentinel is the correct choice because it functions as a cloud-native SIEM and SOAR platform that can ingest security alerts from Azure, AWS, and GCP via native data connectors, then centralize them and drive automated remediation through playbooks (Logic Apps). This directly satisfies the requirement to centralize alerts and automate remediation across a multi-cloud estate. Option B is only partially relevant: Defender for Cloud's multi-cloud connector aggregates posture and alert data but does not provide the full SIEM/SOAR automation capability Sentinel delivers.

Option A (Purview Compliance Manager) is for regulatory compliance assessments, not security operations, and Option D (Defender for Identity) only monitors identity signals in hybrid Active Directory environments, not multi-cloud alert centralization or remediation.

74
Multi-Selectmedium

Which THREE capabilities are provided by Microsoft Defender for Cloud Apps (MDA) when integrated with Microsoft Defender XDR?

Select 3 answers
A.Email protection against phishing and malware.
B.Discovery of shadow IT cloud apps.
C.App permissions and OAuth app governance.
D.Endpoint detection and response (EDR) for devices.
E.Conditional access session controls for cloud apps.
AnswersB, C, E

MDA discovers apps used in the organization.

Why this answer

Microsoft Defender for Cloud Apps (MDA) integrates with Microsoft Defender XDR to provide shadow IT discovery by analyzing traffic logs from network devices and cloud app catalogs, identifying unsanctioned cloud applications used in the organization. This capability is core to MDA's Cloud Discovery feature, which uses log parsing and machine learning to detect and classify shadow IT.

Exam trap

The trap here is that candidates often confuse the capabilities of Microsoft Defender for Cloud Apps with those of other Microsoft Defender XDR components, such as Defender for Office 365 (email security) or Defender for Endpoint (EDR), leading them to select options that are valid security features but not provided by MDA.

75
MCQhard

Your organization uses Microsoft Defender XDR to correlate alerts across endpoints, email, and identities. You need to create a custom detection rule that triggers when a user receives a phishing email and then attempts to log in from a new location. Which approach should you use?

A.Use Advanced Hunting to create a custom detection rule
B.Create a custom detection rule in Microsoft Defender for Endpoint
C.Use an automation rule in Microsoft Defender XDR
D.Create an analytics rule in Microsoft Sentinel
AnswerA

Advanced Hunting is the XDR-native KQL query interface spanning the unified Defender XDR data schema, including endpoint, email, identity, and cloud app tables. By saving an advanced hunting query as a custom detection rule, Defender XDR continuously evaluates cross-domain signals and generates alerts, making it the correct mechanism for correlating evidence from multiple sources.

Why this answer

Advanced Hunting in Microsoft Defender XDR allows you to write Kusto Query Language (KQL) queries that correlate events across multiple data tables (e.g., EmailEvents, IdentityLogonEvents). You can then create a custom detection rule from that query, which will trigger an alert when a user receives a phishing email and subsequently logs in from a new location, enabling cross-domain correlation within Defender XDR.

Exam trap

The trap here is that candidates often confuse the scope of custom detection rules in Defender for Endpoint (endpoint-only) with the cross-domain capability of Advanced Hunting in Defender XDR, or they mistakenly think automation rules can create new detection logic rather than just automate responses to existing alerts.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint custom detection rules are limited to endpoint data (e.g., DeviceEvents, DeviceProcessEvents) and cannot query email or identity events, so they cannot correlate a phishing email with a login from a new location. Option C is wrong because automation rules in Microsoft Defender XDR are designed to automate responses (e.g., isolate a device, block an IP) based on existing alerts, not to create new detection logic that correlates raw events across different data sources. Option D is wrong because analytics rules in Microsoft Sentinel are used for SIEM-style detection across multiple data sources ingested into Sentinel, but the question specifies using Microsoft Defender XDR (not Sentinel) to correlate alerts, and Sentinel requires separate licensing and data ingestion pipelines.

Page 1 of 3 · 155 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design security operations, identity, and compliance capabilities questions.