Courseiva

CCNA Secops Identity Compliance Questions

75 of 155 questions · Page 2/3 · Secops Identity Compliance topic · Answers revealed

76
MCQeasy

Your organization uses Microsoft Defender for Office 365 and wants to block malicious links in email messages in real time. Which policy should you configure?

A.Anti-phishing policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-spam policy
AnswerC

The Safe Links policy is the correct control because it directly handles malicious URLs by rewriting every link in email at the time of delivery and then performing a verdict check at the moment of click using Microsoft's threat intelligence. This time-of-click protection means that even if a URL was previously benign, it can be re-evaluated and blocked as soon as the user clicks. Safe Links extends beyond email to Teams, Office documents, and other supported workloads, making it the dedicated mechanism for URL-based threats.

Why this answer

Safe Links policy in Microsoft Defender for Office 365 provides real-time URL scanning and rewriting at the time of click, enabling the blocking of malicious links in email messages. This policy wraps URLs to route clicks through Microsoft's threat intelligence service, which checks the link against current threat data and blocks access if malicious content is detected.

Exam trap

The trap here is that candidates often confuse Safe Links with Safe Attachments, mistakenly thinking that attachment scanning covers embedded links, but Safe Attachments only handles file payloads, not URLs.

How to eliminate wrong answers

Option A is wrong because Anti-phishing policy is designed to protect against impersonation attacks and phishing attempts by analyzing sender identity and message content, not by scanning or blocking individual URLs in real time. Option B is wrong because Safe Attachments policy focuses on scanning email attachments for malware using detonation in a sandbox environment, not on inspecting links within the message body. Option D is wrong because Anti-spam policy filters messages based on bulk mail, spam, and spoofing criteria, and does not perform real-time URL blocking or rewriting.

77
MCQmedium

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to prevent users from sharing credit card numbers in email but allow sharing via encrypted email. What should they configure?

A.Assign a sensitivity label that encrypts the email automatically
B.Create a Microsoft Purview Message Encryption policy
C.Configure a DLP rule that blocks sharing unless the email is encrypted, with user override
D.Use Exchange mail flow rules to block unencrypted credit card data
AnswerC

To enforce that unencrypted emails containing credit card data are blocked, you need a Microsoft Purview DLP rule. The rule can include the condition "Content contains" the sensitive info type for credit card numbers, and an action to "Block" the message if it is not encrypted, with an option to allow users to override the block for legitimate business needs. DLP integrates with Exchange Online to inspect the message in transit and conditionally allow encrypted messages as an exception, directly addressing the stated requirement, whereas proactive encryption strategies alone cannot guarantee compliance.

Why this answer

Microsoft Purview DLP can enforce a policy that blocks sharing of credit card numbers unless the email is encrypted, with a user override option to allow legitimate encrypted sharing. This directly meets the requirement to prevent unencrypted sharing while permitting encrypted email transmission, leveraging DLP's ability to inspect email content and conditionally apply actions based on encryption status.

Exam trap

The trap here is that candidates often confuse DLP's conditional encryption check with Message Encryption policies or mail flow rules, failing to recognize that DLP provides the specific 'unless the email is encrypted' condition and user override capability needed for this requirement.

How to eliminate wrong answers

Option A is wrong because assigning a sensitivity label that encrypts the email automatically does not provide a conditional mechanism to block unencrypted sharing; it would either always encrypt or require manual labeling, failing to prevent users from sending unencrypted credit card data. Option B is wrong because Microsoft Purview Message Encryption is a service that encrypts email messages but does not include DLP rules to block unencrypted sharing; it lacks the policy-driven conditional enforcement needed to prevent non-encrypted transmission. Option D is wrong because Exchange mail flow rules (transport rules) can block or encrypt messages based on patterns, but they do not natively integrate with DLP's sensitive information types for credit card numbers and lack the user override capability that DLP provides for justified business exceptions.

78
MCQeasy

You are designing a security operations strategy for a multinational organization. The SOC team needs to correlate alerts from multiple sources including Microsoft Defender for Cloud, Microsoft Sentinel, and third-party firewalls. Which solution should you use as the primary platform for correlation?

A.Microsoft Defender for Cloud
B.Microsoft 365 Defender
C.Azure Monitor
D.Microsoft Sentinel
AnswerD

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM and SOAR platform purpose-built for security operations. It ingests logs from 100+ connectors across Azure, Microsoft 365, third-party security products, on-premises infrastructure, and open-source formats, then uses KQL-based analytics rules and built-in detections to correlate signals into incidents. Sentinel also automates response via playbooks, making it the central multi-source correlation and incident management engine that the other services are not.

Why this answer

Microsoft Sentinel (option D) is the correct choice because it is a cloud-native SIEM and SOAR platform designed to ingest, correlate, and analyze security alerts and logs from many sources, including Microsoft Defender for Cloud, Microsoft Sentinel-connected services, and third-party firewalls via data connectors and CEF/Syslog. It provides built-in analytics rules, KQL-based hunting, and incident correlation across multicloud and multiplatform telemetry, which matches the SOC's need for a central correlation platform. Microsoft Defender for Cloud (option A) is a cloud security posture management and workload protection service, not a cross-source SIEM correlation platform.

Microsoft 365 Defender (option B) correlates signals primarily across Microsoft 365 and Defender workloads, not third-party firewall telemetry as the primary platform. Azure Monitor (option C) is an infrastructure and application monitoring service, not a security incident correlation SIEM.

79
MCQhard

Your organization uses Microsoft Sentinel to aggregate logs from on-premises and cloud sources. You need to reduce the cost of data ingestion while ensuring security-critical logs are retained for at least one year. What should you do?

A.Archive all logs to Azure Storage after 90 days
B.Ingress security-critical logs to the Analytics logs tier with 365-day retention, and other logs to the Auxiliary logs tier with shorter retention
C.Use the Basic logs tier for all logs and set retention to 365 days
D.Set the default retention to 30 days and export logs to Log Analytics Workspace
AnswerB

This hybrid approach directly addresses the one-year retention requirement while optimizing cost. Security-critical logs reside in the Analytics tier, which supports full KQL, advanced hunting, detections, and 365-day retention, ensuring no loss of investigative power. The Auxiliary logs tier, introduced for verbose telemetry, offers lower ingestion cost and basic query functionality for non-critical data, letting you retain comprehensive logs without overpaying. This separation balances compliance, performance, and budget far better than a one-size-fits-all strategy.

Why this answer

Use the Analytics logs tier for security-critical logs because it provides full KQL query capabilities and supports setting 365-day retention to meet compliance. For other logs, use the Auxiliary logs tier (or Basic logs) to reduce ingestion costs while accepting shorter retention and limited query capabilities. This tiered approach balances cost and security requirements.

Exam trap

Candidates often think that using the Basic logs tier (or Auxiliary logs) for all logs is a cost-saving measure, but this fails to ensure that security-critical logs retain full query capability and long retention. The correct approach is to apply tiered retention based on log importance.

How to eliminate wrong answers

Option A is wrong because archiving all logs to Azure Storage after 90 days would remove them from Sentinel's queryable workspace, preventing real-time security monitoring and alerting on older logs, and does not guarantee one-year retention for security-critical logs. Option C is wrong because using the Basic logs tier for all logs limits query capabilities (no full KQL support) and incurs higher costs for security-critical logs that require Analytics-tier features; setting retention to 365 days on Basic logs does not address cost optimization for non-critical logs. Option D is wrong because setting default retention to 30 days and exporting logs to Log Analytics Workspace is redundant (Log Analytics Workspace is the same as Sentinel workspace) and does not reduce ingestion costs; it also fails to ensure security-critical logs are retained for one year without additional configuration.

80
MCQmedium

A company uses Microsoft Intune and wants to ensure that devices are compliant before accessing corporate resources. They create a Conditional Access policy that requires devices to be marked as compliant. However, some users report that they are blocked even though their device shows as compliant in Intune. What is the most likely cause?

A.The user's location is blocked by a location-based policy
B.The policy also requires MFA, and users haven't registered for MFA
C.The device is not registered in Microsoft Entra ID
D.The policy requires an app protection policy, which is not applied
AnswerC

For Conditional Access to require a compliant device, the device must have an identity object in Microsoft Entra ID—either through Microsoft Entra join, hybrid join, or enrollment in Intune as a registered device. Intune's compliance policy is applied to that device identity, and the resulting compliance status is stored as an attribute in Entra ID that Conditional Access can read. Without registration, the device is completely invisible to the compliance evaluation, so the policy marks it as not compliant and blocks access.

Why this answer

The correct answer is C: the device is not registered in Microsoft Entra ID. Conditional Access evaluates device compliance using the device identity and compliance state that Intune writes back to Microsoft Entra ID, so if the device object is not registered (or not properly joined/registered) in Entra ID, the 'Require device to be marked as compliant' grant control cannot be satisfied even if Intune shows the device as compliant. Options A and B describe other possible blocks (location policy or MFA registration), but they do not explain the mismatch between Intune compliance and Conditional Access blocking.

Option D is also not the most likely cause because an app protection policy requirement is a separate grant control and would not typically contradict a device already showing compliant in Intune.

81
MCQmedium

A company uses Microsoft Sentinel for security operations. The SOC team needs to automatically respond to a specific type of incident involving a known malicious IP address. They want to create an automated response that blocks the IP at the firewall and creates a Teams notification. Which feature should they use?

A.UEBA to detect anomalous behavior
B.Watchlist to correlate IP addresses
C.Automation rule with a playbook
D.Analytics rule with scheduled query
AnswerC

An automation rule in Microsoft Sentinel is the correct mechanism to automate response actions because it evaluates incident triggers or alert creation and then executes a set of configured actions, which can include running a playbook. Playbooks are built on Azure Logic Apps and can perform complex, orchestrated tasks like blocking a user, sending emails to stakeholders, opening a ticket, or gathering additional evidence—all without manual intervention. This directly fulfills the requirement to automatically respond to a security incident by turning detection results into immediate, actionable remediation steps.

Why this answer

Automation rules in Microsoft Sentinel allow you to trigger automated responses when incidents are created or updated. By associating a playbook (an Azure Logic Apps workflow) with the automation rule, you can execute actions such as blocking an IP at a firewall via a connector and posting a Teams notification. This directly meets the requirement for a two-step automated response triggered by a specific incident type.

Exam trap

The trap here is that candidates confuse the role of analytics rules (which generate incidents) with automation rules (which respond to incidents), leading them to choose option D, thinking a scheduled query can directly execute actions, whereas it only creates alerts or incidents.

How to eliminate wrong answers

Option A is wrong because UEBA (User and Entity Behavior Analytics) is used to detect anomalous behavior based on historical baselines, not to trigger automated responses to known malicious IPs. Option B is wrong because a Watchlist is a static or dynamic list of data (e.g., IP addresses) used for correlation in analytics rules or queries, but it does not itself execute automated actions like blocking or notifications. Option D is wrong because an analytics rule with a scheduled query generates alerts or incidents based on log data, but it cannot directly run multi-step automated responses; it requires an automation rule or playbook to act on the incident.

82
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that incident investigations automatically enrich alerts with relevant user and device information from Microsoft Defender XDR and Microsoft Entra ID. What should you configure?

A.Enable Fusion detection for multistage attacks.
B.Create watchlists for user and device information and reference them in analytics rules.
C.Configure automation rules to trigger a playbook on alert creation.
D.Enable User and Entity Behavior Analytics (UEBA) and configure entity behavior settings.
AnswerD

UEBA in Microsoft Sentinel profiles entities (users, devices, etc.) using historical activity to detect anomalies and enrich alerts with contextual information like risk scores, behavioral deviations, and peer comparisons. Configuring entity behavior settings enables this enrichment to be applied automatically to analytics alerts, providing security analysts with a richer view of the entity's normal vs. anomalous behavior. This directly meets the requirement to enrich alerts with user and device information, unlike static watchlists or detection-only features.

Why this answer

The correct option is D: enabling User and Entity Behavior Analytics (UEBA) and configuring entity behavior settings. In Microsoft Sentinel, UEBA ingests and correlates user and device entity data from sources such as Microsoft Defender XDR and Microsoft Entra ID, building behavior profiles and enriching incidents with entity insights (e.g., user, host, IP) that investigators see on the incident page. Option A is wrong because Fusion detection correlates multistage attack signals into incidents but does not enrich them with user/device context.

Option B is wrong because watchlists are custom reference lists used for matching in analytics rules, not automatic enrichment from Defender XDR/Entra ID. Option C is wrong because automation rules and playbooks execute response actions, not entity enrichment of incidents.

83
MCQeasy

A company wants to monitor and respond to threats across their entire digital estate, including on-premises servers, cloud workloads, and identities. Which Microsoft solution should they use as a central security information and event management (SIEM) and extended detection and response (XDR) platform?

A.Microsoft Intune
B.Microsoft Defender for Cloud
C.Microsoft Sentinel and Microsoft Defender XDR
D.Microsoft Purview
AnswerC

Microsoft Sentinel and Microsoft Defender XDR together form a complete monitoring-and-response solution. Sentinel is a cloud-native SIEM that ingests logs from every source, applies analytics rules to detect anomalies, and provides incident management, investigation, and threat hunting, while Microsoft Defender XDR correlates signals across Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps. This pairing enables automated response and a single pane of glass for security operations, satisfying the requirement to both monitor and respond to threats across the enterprise.

Why this answer

The correct answer is C: Microsoft Sentinel and Microsoft Defender XDR, because Sentinel is Microsoft's cloud-native SIEM that ingests and correlates logs from on-premises servers, cloud workloads, and identities, while Defender XDR provides the extended detection and response layer across endpoints, identities, email, and cloud apps, together forming the central security operations platform the company needs. Microsoft Intune (A) is a mobile device and endpoint management (MDM/MAM) service, not a SIEM/XDR. Microsoft Defender for Cloud (B) is a cloud security posture management (CSPM) and workload protection service, not a central SIEM/XDR.

Microsoft Purview (D) is a data governance, compliance, and information protection suite, not a threat monitoring SIEM/XDR platform.

84
MCQhard

The exhibit shows a conditional access policy in Microsoft Entra ID. What will be the effect of this policy?

A.Allow all applications except Office365
B.Block all applications including Office365
C.Allow all applications including Office365
D.Block all applications except Office365
AnswerD

The policy is configured to target 'All cloud apps', excludes Office 365, and uses the 'Block access' grant control. When a user attempts to access an included application, the policy is evaluated and blocks the sign-in. Since Office 365 is in the exclusion list, the policy is skipped for that application, leaving it unblocked. Therefore, the policy blocks all applications except Office 365.

Why this answer

The exhibit shows a Conditional Access policy that includes 'All cloud apps' in the target resources and is configured with a 'Block access' grant control. The 'Exclude' list contains 'Office365', meaning the policy applies to all applications except Office365. Therefore, the effect is to block access to all applications except Office365, making option D correct.

Exam trap

The trap here is that candidates often overlook the 'Exclude' list and assume that selecting 'All cloud apps' with 'Block access' blocks everything, but the exclusion of Office365 means it is not blocked.

How to eliminate wrong answers

Option A is wrong because the policy blocks access, not allows it; 'Allow all applications except Office365' would require an 'Allow' grant control, not 'Block'. Option B is wrong because Office365 is explicitly excluded from the policy, so it is not blocked; 'Block all applications including Office365' would require no exclusion for Office365. Option C is wrong because the policy blocks access, not allows it; 'Allow all applications including Office365' would require an 'Allow' grant control and no block action.

85
MCQmedium

Your company uses Microsoft Intune to manage corporate devices. You need to design a compliance policy that requires devices to have a minimum OS version, be encrypted, and not be jailbroken or rooted. Additionally, you want to automatically block non-compliant devices from accessing corporate email. What should you configure?

A.Intune compliance policies and Conditional Access
B.Device configuration profiles and Azure AD join
C.App protection policies and Microsoft Defender for Endpoint
D.Device enrollment restrictions
AnswerA

Intune compliance policies assess a device's security posture—such as jailbreak status, OS version, encryption, and threat level from Defender for Endpoint—and generate a compliant/non-compliant state that is stored in Azure AD. Conditional Access policies then consume that state at sign-in, using a 'Require device to be marked compliant' grant control to block or allow access to email and other corporate resources. This is the definitive mechanism because it combines continuous health evaluation with identity-driven enforcement, and it works with both Android and iOS device-specific checks like the SafetyNet attestation or Apple's device compliance.

Why this answer

The correct answer is A: Intune compliance policies and Conditional Access. Compliance policies in Intune define the specific requirements you listed—minimum OS version, encryption, and jailbreak/root detection—and Conditional Access then enforces those results by blocking non-compliant devices from accessing corporate resources such as Exchange Online email. The other options do not fit: device configuration profiles and Azure AD join (B) configure settings and identity but do not evaluate compliance or block access; app protection policies and Defender for Endpoint (C) protect app data and detect threats but do not enforce device compliance for email access; and device enrollment restrictions (D) only control which devices can enroll, not ongoing compliance or access control.

86
MCQhard

Your company is deploying a new line-of-business application in Azure that must comply with PCI DSS. The application uses Azure SQL Database. You need to design a solution to encrypt sensitive data at rest and in transit, and to audit access to sensitive columns. Which combination of Microsoft security capabilities should you recommend?

A.Dynamic Data Masking and Azure SQL Firewall rules
B.Transparent Data Encryption, Always Encrypted, and Azure SQL Auditing
C.Azure Policy and Microsoft Defender for Cloud
D.Azure Storage Service Encryption and Azure Key Vault
AnswerB

Transparent Data Encryption (TDE) encrypts entire database files, backups, and transaction logs at rest using a database encryption key, protecting data at the storage layer. Always Encrypted goes further by encrypting sensitive columns with client-side keys so that database administrators and cloud operators see only ciphertext, ensuring data remains confidential even during queries. Azure SQL Auditing captures a trace of database events and queries, enabling compliance monitoring and forensic analysis of access to sensitive data. Together, these three technologies deliver encryption at rest, column-level encryption with key separation, and a clear audit trail, fully addressing typical enterprise data protection and compliance requirements.

Why this answer

Transparent Data Encryption (TDE) encrypts the SQL database at rest, Always Encrypted protects sensitive columns in transit and at rest by ensuring encryption keys are never exposed to the database engine, and Azure SQL Auditing logs all access to sensitive columns for compliance with PCI DSS requirements.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with encryption, but masking does not protect data at rest or in transit and can be bypassed by privileged users, whereas Always Encrypted and TDE provide true encryption required by PCI DSS.

How to eliminate wrong answers

Option A is wrong because Dynamic Data Masking only obfuscates data at query time for unauthorized users but does not encrypt data at rest or in transit, and Azure SQL Firewall rules control network access but do not provide encryption or auditing. Option C is wrong because Azure Policy enforces compliance rules and Microsoft Defender for Cloud provides threat detection, but neither directly encrypts data at rest or in transit nor audits column-level access. Option D is wrong because Azure Storage Service Encryption applies only to Azure Blob and File storage, not to Azure SQL Database, and Azure Key Vault is a key management service that must be paired with an encryption mechanism like TDE or Always Encrypted to actually encrypt data.

87
Multi-Selecthard

A company wants to implement hybrid identity with Microsoft Entra ID. Which TWO components are required for password hash synchronization? (Choose two.)

Select 2 answers
A.Microsoft Entra Connect
B.Microsoft Entra Domain Services
C.Password hash synchronization feature enabled in Entra Connect
D.Microsoft Entra ID Protection
E.Azure AD Application Proxy
AnswersA, C

Microsoft Entra Connect is the on-premises hybrid identity synchronization engine that installs on a server and replicates directory objects (users, groups, contacts, and devices) from your local Active Directory to Microsoft Entra ID. It is the correct answer because its primary purpose is to establish a single source of identity across on-premises and cloud directories, and it also configures the chosen authentication method (password hash sync, pass-through authentication, or AD FS federation). Without this tool, you cannot maintain synchronized identities for hybrid scenarios.

Why this answer

Microsoft Entra Connect (option A) is required because it is the on-premises synchronization tool that connects Active Directory Domain Services to Microsoft Entra ID and performs the directory synchronization and sign-in method configuration. The password hash synchronization feature enabled in Entra Connect (option C) is also required, since password hash synchronization is a sign-in option that must be explicitly selected and configured within Entra Connect for on-premises password hashes to be synchronized to Entra ID. Microsoft Entra Domain Services (option B) is a managed domain service for legacy protocols and does not perform password hash synchronization from on-premises AD.

Microsoft Entra ID Protection (option D) provides risk detection and Conditional Access signals, not directory synchronization. Azure AD Application Proxy (option E) publishes on-premises web applications remotely and is unrelated to password hash synchronization.

Exam trap

The trap here is that candidates often confuse 'Microsoft Entra Domain Services' (a managed domain service) with 'Microsoft Entra Connect' (the sync tool), or they think enabling the feature alone is sufficient without the sync engine, but both the tool and the feature toggle are required.

88
MCQhard

A multinational company uses Microsoft Purview for data governance. They need to automatically classify sensitive data in Microsoft 365 and apply retention labels. The solution must use pattern-based detection for credit card numbers and support custom keywords. What should they configure?

A.Use a trainable classifier for credit card numbers.
B.Create a custom sensitive info type with a regex pattern and keyword list.
C.Configure a DLP policy with a rule for credit card numbers.
D.Create a retention label with auto-labeling policy.
AnswerB

A custom sensitive info type is the right mechanism because it lets you define a regular expression to match the credit card number format, optionally with the Luhn checksum validation, plus a keyword list (e.g., 'VISA', 'MasterCard', 'card number') to raise confidence and reduce false positives. Purview uses these custom SITs in DLP policies, auto-labeling, and retention label conditions. This directly gives you a detectable classification without depending on built-in types.

Why this answer

The requirement specifies pattern-based detection for credit card numbers and support for custom keywords. A custom sensitive info type in Microsoft Purview allows you to define a regex pattern (e.g., for credit card numbers) and associate a custom keyword list, enabling precise auto-classification and retention label application. Trainable classifiers use machine learning, not pattern-based detection, and DLP policies or retention label auto-labeling policies do not directly create the pattern and keyword logic needed.

Exam trap

The trap here is that candidates confuse the configuration of a custom sensitive info type (which defines the detection logic) with the policy that uses it (DLP or auto-labeling), assuming DLP or auto-labeling policies can directly define regex patterns and keywords without a separate sensitive info type.

How to eliminate wrong answers

Option A is wrong because a trainable classifier uses machine learning to identify content based on examples, not pattern-based detection with regex and custom keywords. Option C is wrong because a DLP policy enforces actions (e.g., block, notify) on sensitive data but does not itself define the pattern or keyword logic for classification; it relies on existing sensitive info types. Option D is wrong because a retention label with auto-labeling policy applies labels based on existing sensitive info types or trainable classifiers, but does not create the pattern-based detection and custom keyword configuration itself.

89
MCQeasy

A company uses Microsoft Sentinel and wants to use a built-in connector to ingest logs from Amazon Web Services (AWS). Which connector should they use?

A.ServiceNow connector
B.Azure Policy for AWS
C.Office 365 connector
D.Amazon Web Services S3 connector
AnswerD

The Amazon Web Services S3 connector is the built-in Microsoft Sentinel connector for AWS, ingesting CloudTrail management events (and optionally data events) via logs stored in an S3 bucket. It uses an SQS queue to notify Sentinel of new log files, and an Azure Function runs to pull them into the Log Analytics workspace. This is the standard, supported method for continuous AWS log ingestion, making it the correct option.

Why this answer

The Amazon Web Services (AWS) S3 connector is the correct built-in connector in Microsoft Sentinel for ingesting logs from AWS. It works by configuring AWS to send logs (such as CloudTrail, VPC Flow Logs, or GuardDuty findings) to an S3 bucket, which Sentinel then polls via the S3 REST API using an IAM role for secure, cross-account access. This is the native, supported method for log ingestion from AWS into Sentinel.

Exam trap

The trap here is that candidates may confuse Azure Policy for AWS (which is a governance tool, not a log ingestion connector) with a valid data source, or assume that a generic connector like ServiceNow could be adapted for AWS log ingestion, when only the AWS S3 connector is the built-in, purpose-built option.

How to eliminate wrong answers

Option A is wrong because the ServiceNow connector is designed to ingest security incidents and IT service management data from ServiceNow, not logs from AWS. Option B is wrong because Azure Policy for AWS is a governance and compliance feature that applies Azure Policy definitions to AWS resources via Azure Arc, not a log ingestion connector for Sentinel. Option C is wrong because the Office 365 connector ingests audit logs and activity data from Microsoft 365 services, not from AWS.

90
Multi-Selecthard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to design a unified security operations platform. Which THREE capabilities should you enable?

Select 3 answers
A.Azure Policy for security controls
B.Microsoft Purview Information Protection
C.Microsoft Defender XDR incident integration with Sentinel
D.Microsoft Sentinel SIEM
E.Microsoft Sentinel UEBA (User and Entity Behavior Analytics)
AnswersC, D, E

The Microsoft Defender XDR incident integration is the correct answer because it connects Microsoft 365 Defender (covering endpoints, identities, email, and cloud apps) directly to Sentinel, pulling in pre-correlated incidents rather than raw alerts. This integration provides a single queue for security operations, enables bidirectional incident synchronization (status changes propagate both ways), and allows analysts to leverage Sentinel's SOAR actions across Defender XDR incidents. Without this integration, defenders would need to juggle multiple portals, losing the unified visibility that the question requires.

Why this answer

Option C is correct because integrating Microsoft Defender XDR incidents with Microsoft Sentinel streams correlated alerts and incidents from Defender XDR products (Defender for Endpoint, Identity, Office 365, Cloud Apps) into Sentinel, enabling a single incident queue and unified investigation across the SOC. Option D is correct because Microsoft Sentinel provides the cloud-native SIEM layer—log ingestion via data connectors, analytics rules, and KQL-based hunting—that serves as the central platform for the unified security operations design. Option E is correct because Sentinel UEBA builds behavioral baselines and entity pages (users, hosts, IPs) that surface anomalous activity and enrich incidents, which is essential for detecting threats that static rules miss in a unified SOC.

Option A is not correct here because Azure Policy governs resource compliance and configuration, not security operations incident detection or response. Option B is not correct because Microsoft Purview Information Protection focuses on data classification, labeling, and DLP, which is a data-governance capability rather than a SIEM/XDR operations capability.

Exam trap

The trap here is that candidates may confuse Azure Policy (a compliance tool) or Purview Information Protection (a data protection tool) with core security operations capabilities, when the question specifically asks for capabilities that unify detection and response across a SIEM and XDR platform.

91
MCQeasy

Your organization wants to use Microsoft Defender XDR to automatically investigate and respond to alerts. You need to ensure that the solution can autonomously remediate confirmed threats on endpoints, such as quarantining files and isolating devices. What should you enable?

A.Microsoft Defender for Identity
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Office 365
AnswerC

Microsoft Defender for Endpoint is the correct choice because it is an endpoint detection and response (EDR) solution that continuously monitors devices for malicious activity, triggers automated investigation, and executes remediation playbooks. Its automated response capabilities include quarantining infected or suspicious files, killing malicious processes, and isolating entire devices from the network—exactly the kind of 'auto' response the organization requires. As the endpoint component of Microsoft Defender XDR, it provides the necessary telemetry and action primitives for autonomous threat containment.

Why this answer

The correct option is C, Microsoft Defender for Endpoint, because it is the Microsoft Defender XDR workload that provides endpoint detection and response (EDR) capabilities, including automated investigation and response (AIR) that can autonomously quarantine files and isolate devices. Defender for Endpoint integrates with Defender XDR to trigger automated remediation actions on confirmed threats on endpoints. The other options do not provide endpoint remediation: Defender for Identity monitors identity signals, Defender for Cloud Apps governs cloud app usage, and Defender for Office 365 protects email and collaboration workloads, so none of them can isolate devices or quarantine endpoint files.

92
MCQmedium

Your organization uses Microsoft Purview Information Protection to label sensitive documents. You need to ensure that documents containing personally identifiable information (PII) are automatically labeled when saved in SharePoint Online. What should you configure?

A.Create a retention label with auto-labeling rule.
B.Publish a sensitivity label with auto-labeling for SharePoint.
C.Configure an auto-labeling policy for sensitivity labels targeting SharePoint.
D.Set up a DLP policy to detect PII and apply a label.
AnswerC

An auto-labeling policy in Microsoft Purview can be configured to automatically apply a sensitivity label to documents stored in SharePoint Online. You select the sensitivity label, choose the 'SharePoint Online' location, specify the sites, and define conditions based on sensitive info types or trainable classifiers. After testing, the policy can be set to enforce automatic labeling, which satisfies the requirement to classify the documents.

Why this answer

The correct answer is C: configure an auto-labeling policy for sensitivity labels targeting SharePoint. Auto-labeling policies in Microsoft Purview Information Protection are the specific mechanism that scans SharePoint Online (and OneDrive/Exchange) content for sensitive information types such as PII and automatically applies a sensitivity label when a match is found, which is exactly the requirement here. Option A is wrong because retention labels govern data lifecycle and retention, not sensitivity classification, and cannot apply sensitivity labels.

Option B is incorrect because publishing a sensitivity label only makes it available to users for manual application; it does not by itself auto-apply labels to content. Option D is incorrect because a DLP policy can detect PII and block or warn on sharing, but it does not automatically apply sensitivity labels to documents.

93
MCQhard

Your organization uses Microsoft Purview and needs to automatically apply a retention label to all documents containing personally identifiable information (PII) in SharePoint Online. What should you configure?

A.Auto-labeling policy
B.Data loss prevention (DLP) policy
C.Service-side sensitivity label
D.Trainable classifier
AnswerA

In Microsoft Purview, an auto-labeling policy applies retention labels automatically to SharePoint Online documents based on sensitive information types, such as PII, using content pattern detection. This satisfies the stem’s constraint of automatic application without user intervention, unlike manual or default label policies, which require user action or static inheritance.

Why this answer

An auto-labeling policy in Microsoft Purview is the correct choice because it can automatically apply a retention label to SharePoint Online content when items match specified sensitive information types such as PII, without user intervention. Auto-labeling policies are designed specifically for automatic retention label application at scale across locations like SharePoint, OneDrive, and Exchange. A DLP policy is used to detect and prevent sharing or leakage of sensitive data, not to apply retention labels.

A service-side sensitivity label applies encryption/marking for sensitivity, not retention, and a trainable classifier identifies content categories but does not by itself apply retention labels.

94
MCQmedium

The exhibit shows a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.Find alerts that were not investigated
B.Analyze entities associated with alerts
C.Identify the most frequent high-severity alerts over the past week
D.Correlate alerts by time and alert name
AnswerC

The query first filters to High-severity alerts (likely via where Severity == 'High'), then uses summarize to count occurrences per alert name, and orders the results by count descending. This produces a ranked list of high-severity alert types based on frequency, which directly identifies the most common high-severity alerts over the specified time range. The 7-day window is established by a time filter in the where clause, aligning with the question's scenario.

Why this answer

The query uses `summarize` with `count()` and `top 5 by count_ desc` to rank alert names by frequency, filtered to `AlertSeverity == 'High'` and `TimeGenerated > ago(7d)`. This directly identifies the most common high-severity alerts over the past week, making option C correct.

Exam trap

The trap here is that candidates may misinterpret the `bin(TimeGenerated, 1h)` as correlating alerts by time and name (option D), but the query only aggregates counts per alert name, not correlating alerts across different time windows or names.

How to eliminate wrong answers

Option A is wrong because the query does not include any field or filter related to investigation status (e.g., `Status == 'New'` or `InvestigationState`), so it cannot find alerts that were not investigated. Option B is wrong because the query only aggregates `AlertName` and does not expand or analyze entity fields (e.g., `Entities`, `Account`, `IP`), so it cannot analyze entities associated with alerts. Option D is wrong because the query does not group or correlate by both time and alert name; it uses `bin(TimeGenerated, 1h)` only for time bucketing but does not correlate alerts across time windows or alert names—it simply counts occurrences per alert name.

95
MCQmedium

Your organization uses Microsoft Purview to protect sensitive data. You need to create a sensitivity label that automatically encrypts documents containing credit card numbers when they are shared externally. Which configuration should you use?

A.Create a trainable classifier to detect credit cards
B.Create an auto-labeling policy that applies a label with encryption for external sharing
C.Create a default label policy for SharePoint
D.Create a manual sensitivity label that users apply
AnswerB

An auto-labeling policy in Microsoft Purview can automatically detect credit card numbers using sensitive information types or classifiers and then apply a sensitivity label that is configured with encryption. By specifying that the label be applied only when content is shared externally, the policy ensures that documents containing credit card data are encrypted upon external sharing, while internal collaboration remains unaffected. This satisfies the requirement for automatic, content-aware protection without user intervention, making it the correct solution.

Why this answer

Auto-labeling in Purview can be configured to apply a sensitivity label based on sensitive info types like credit card numbers. The label should have encryption enabled for external sharing. The other options describe different scenarios: manual labeling, default labeling, or classification without encryption.

96
MCQmedium

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to design a solution that automatically remediates non-compliant devices by running a remediation script. Which Intune component should you use?

A.Remediation policy in Microsoft Intune
B.Device compliance policy
C.App protection policy
D.Device configuration profile
AnswerA

Remediation policy in Microsoft Intune is a Proactive Remediation feature that pairs detection and remediation PowerShell scripts and runs them on managed Windows devices on a set schedule. When the detection script finds a rule violation, the remediation script automatically executes to restore the device to a compliant state. It reports execution results back to Intune, allowing administrators to verify fixes without manual intervention. This is the only option here that actively performs corrective actions rather than just evaluating or defining state.

Why this answer

The correct option is A, a Remediation policy in Microsoft Intune, because this feature is specifically designed to detect and automatically fix non-compliant devices by running remediation scripts (PowerShell) on them, either on a schedule or when a compliance issue is detected. It pairs with compliance policies to evaluate device state and then executes the script to bring the device back into compliance. Device compliance policies (B) only define and evaluate compliance rules and mark devices compliant or non-compliant; they do not run scripts to remediate.

App protection policies (C) protect app data on mobile devices and do not remediate device compliance. Device configuration profiles (D) push settings to devices but do not provide detection-and-remediation script logic.

97
MCQmedium

Your organization uses Microsoft Purview to govern sensitive data. You need to design a solution that automatically detects and protects credit card numbers in emails and documents stored in Microsoft 365. The solution should also provide data loss prevention (DLP) policy tips to users when they try to share such data externally. What should you configure?

A.Sensitivity labels with auto-classification
B.Microsoft Purview Data Loss Prevention policies
C.Microsoft 365 compliance center
D.Microsoft Information Protection unified labeling
AnswerB

Microsoft Purview Data Loss Prevention (DLP) policies are the correct feature because they are purpose-built to detect sensitive data in real time and can trigger interactive policy tips in supported Microsoft 365 apps. When a user tries to share an email, document, or message that contains sensitive information, the DLP policy evaluates the content and displays a non-blocking tip or block action, educating the user and enforcing compliance. Unlike classification-only tools, DLP policies directly implement the user-notification workflow described in the question.

Why this answer

Microsoft Purview Data Loss Prevention policies (option B) are the correct choice because DLP is the service that detects sensitive information types such as credit card numbers in Exchange Online email and SharePoint/OneDrive documents, and it can enforce protection by blocking or restricting external sharing while displaying policy tips to users in supported apps like Outlook and Office. DLP policies natively support the credit card number sensitive information type and the policy tip configuration for user notifications during external sharing attempts. Sensitivity labels with auto-classification (A) apply classification and protection to content but do not provide DLP policy tips or block external sharing in real time.

The Microsoft 365 compliance center (C) is just the administrative portal, not a protection mechanism, and Microsoft Information Protection unified labeling (D) is the labeling infrastructure, not the DLP enforcement engine.

98
Multi-Selecthard

Your company is deploying Microsoft Defender XDR. You need to design a solution that uses advanced hunting to proactively search for threats. Which THREE data sources should be included in the advanced hunting schema to enable comprehensive threat hunting across endpoints, identities, and cloud apps?

Select 3 answers
A.EmailEvents
B.AzureActivity
C.CloudAppEvents
D.IdentityInfo
E.DeviceEvents
AnswersC, D, E

CloudAppEvents is the correct table for investigating SaaS application activity because it aggregates sign-in and activity transactions from Defender for Cloud Apps across thousands of cloud apps, including Office 365, AWS, and Google Workspace. Each row contains user, device, IP address, and app-specific action metadata, allowing analysts to pivot from a suspicious identity or endpoint to cloud-side anomalies. This table is one of the five default tables in Defender XDR advanced hunting and is essential for end-to-end, cloud-inclusive threat hunting.

Why this answer

CloudAppEvents (C) is correct because it is the Microsoft Defender for Cloud Apps table in the advanced hunting schema, providing audit and activity events from cloud applications (including Office 365 and other connected apps) needed to hunt for threats in the cloud-app pillar. IdentityInfo (D) is correct because it is the Microsoft Defender for Identity table that supplies identity and account metadata (such as account details, group memberships, and directory context) used to investigate and hunt identity-based attacks. DeviceEvents (E) is correct because it is the Microsoft Defender for Endpoint table containing endpoint event telemetry (such as process, file, registry, and network-related events) that enables hunting across the endpoint pillar.

EmailEvents (A) is not among the marked answers because, while it is a valid advanced hunting table for email threats, it is not one of the three sources selected to cover endpoints, identities, and cloud apps in this scenario. AzureActivity (B) is not marked correct because it is an Azure control-plane activity log table rather than a core Defender XDR endpoint, identity, or cloud-app hunting source for this design.

99
MCQhard

Your organization is implementing a zero-trust security model. You need to design a solution that continuously verifies user identity, device compliance, and access context before granting access to corporate resources. The solution should also support risk-based policies. Which Microsoft security capability should be at the core of this design?

A.Microsoft Defender for Identity
B.Microsoft Entra ID Conditional Access
C.Microsoft Sentinel
D.Microsoft Intune
AnswerB

Microsoft Entra ID Conditional Access evaluates user identity, device compliance and sign-in context at every access request, and applies risk-based policies through signals such as user risk and sign-in risk. This continuous, context-aware evaluation is the core enforcement point of a zero-trust design.

Why this answer

Microsoft Entra ID Conditional Access is the core policy engine for zero-trust, enabling continuous verification of user identity, device compliance, and access context before granting resource access. It integrates with risk signals from Microsoft Entra ID Protection to enforce risk-based policies, such as requiring multi-factor authentication when sign-in risk is high. This aligns directly with the zero-trust principle of 'never trust, always verify' by evaluating conditions in real time.

Exam trap

The trap here is that candidates often confuse Microsoft Intune's device compliance enforcement with the actual policy decision engine, not realizing that Intune provides the device compliance state but Conditional Access is the component that evaluates that state along with identity and risk to make the access decision.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Identity is a security solution that detects on-premises Active Directory attacks using behavioral analytics, not a policy engine for continuous access verification or risk-based conditional access. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR for threat detection and incident response, not a tool for enforcing access policies based on user identity, device compliance, or risk context at the point of authentication. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service that enforces device compliance policies, but it does not evaluate identity, access context, or risk signals to grant or deny access—it relies on Conditional Access to consume its compliance status.

100
MCQmedium

Your organization uses Microsoft Intune for mobile device management and Microsoft Entra ID for identity. You are designing a solution to ensure that only devices that are compliant with security policies can access corporate resources. The requirements are: 1) Devices must have a minimum OS version. 2) Devices must have encryption enabled. 3) Devices must not be jailbroken or rooted. 4) Access to corporate apps must be blocked if the device is non-compliant. 5) The solution should automatically remediate non-compliant devices when possible. You need to recommend the minimum configuration. What should you do?

A.Configure Microsoft Purview Compliance Manager to assess compliance and block access.
B.Create an app protection policy in Intune that requires minimum OS and encryption.
C.Create a device compliance policy in Intune with the required settings, and create a Conditional Access policy that requires compliant devices.
D.Create a device configuration policy in Intune for the settings, and use Azure AD Identity Protection to block access.
AnswerC

An Intune compliance policy enforces the minimum OS version, encryption and jailbreak or root detection requirements, while a Conditional Access policy requiring compliant devices blocks corporate app access for non-compliant devices and supports automatic remediation.

Why this answer

The minimum configuration is to create a device compliance policy in Intune with the required settings (minimum OS version, encryption, jailbreak/root detection) and create a Conditional Access policy that requires compliant devices. This ensures only compliant devices can access corporate resources, and Intune can automatically remediate non-compliant devices where possible.

Exam trap

SC-100 often tests the difference between configuration policies (which set settings) and compliance policies (which assess settings), and candidates may confuse the two or overlook Conditional Access as the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is for assessing compliance with regulations, not for enforcing device access. Option B is wrong because an app protection policy (MAM) protects app data but does not enforce device compliance settings like OS version or encryption; it also does not block access to all corporate apps. Option D is wrong because a device configuration policy configures settings but does not assess compliance; Azure AD Identity Protection is for identity risks, not device compliance.

101
MCQhard

Your organization is implementing a data loss prevention (DLP) strategy using Microsoft Purview. The compliance team needs to automatically classify and label sensitive data in Microsoft 365, Azure SQL Database, and Amazon S3. Which Purview feature should you use?

A.Microsoft Purview Data Map
B.Microsoft Purview Information Protection
C.Microsoft Purview Records Management
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Purview Data Map is the correct choice because it provides automated scanning and classification of sensitive data across hybrid and multi-cloud environments, including on-premises, Azure, and other clouds such as AWS S3. Its data scanners can connect to Azure SQL databases and S3 buckets, inspect schemas and content, and apply classifications that feed into DLP policies. This makes it uniquely capable of discovering and mapping sensitive data at rest in non-Microsoft 365 sources, which is the core requirement here.

Why this answer

Microsoft Purview Data Map is the correct choice because it provides unified data governance across hybrid and multi-cloud environments, including Microsoft 365, Azure SQL Database, and Amazon S3. It automatically scans, classifies, and labels sensitive data using built-in classifiers and sensitivity labels, enabling consistent DLP policies across these disparate data sources.

Exam trap

The trap here is that candidates often confuse the scanning and classification capabilities of Microsoft Purview Data Map with the labeling and protection features of Microsoft Purview Information Protection, but the Data Map is the service that actually discovers and classifies data across multiple clouds, while Information Protection applies the labels after classification.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Information Protection focuses on applying sensitivity labels and encryption to data within Microsoft 365 and Azure, but it does not natively scan or classify data in Amazon S3. Option C is wrong because Microsoft Purview Records Management is designed for managing retention, disposition, and legal hold of records, not for automatic classification and labeling of sensitive data across multi-cloud sources. Option D is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides threat protection and visibility for cloud apps, but it does not perform automatic data classification and labeling across Microsoft 365, Azure SQL, and Amazon S3 as a primary function.

102
MCQmedium

A company uses Microsoft Purview to classify data and enforce retention policies. They need to automatically apply a retention label to all documents containing credit card numbers. Which approach should they use?

A.Configure an auto-labeling policy with a sensitive info type
B.Use a trainable classifier
C.Create a manual labeling policy for users
D.Use a default label for SharePoint libraries
AnswerA

Auto-labeling policies scan content and apply retention labels when items match a sensitive info type, such as credit card numbers. This delivers automatic, condition-based labelling at scale, satisfying the requirement without relying on manual user classification.

Why this answer

Microsoft Purview auto-labeling policies can automatically apply retention labels to documents based on sensitive info types (SITs), such as credit card numbers. This approach uses pattern matching to detect the credit card number format and applies the label without user intervention, meeting the requirement for automatic enforcement.

Exam trap

The trap here is that candidates may confuse trainable classifiers with sensitive info types, thinking that 'intelligent' classification is always better, but SITs are the correct choice for specific, pattern-based data like credit card numbers.

How to eliminate wrong answers

Option B is wrong because trainable classifiers are designed to identify content based on context and patterns (e.g., contracts or resumes), not specific sensitive data like credit card numbers, which are better matched by SITs. Option C is wrong because manual labeling policies require users to apply labels themselves, contradicting the requirement for automatic application. Option D is wrong because a default label for SharePoint libraries applies a label to all documents in the library regardless of content, not selectively to those containing credit card numbers.

103
MCQmedium

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.Identify accounts that have experienced more than 10 failed login attempts from the same IP address within an hour
B.Identify IP addresses that have successfully brute-forced an account
C.Identify users who have logged in from multiple IPs in a short time
D.Identify accounts that have been disabled due to multiple failures
AnswerA

This query correctly identifies the specified brute-force pattern: it groups failed sign-in events (e.g., ResultType indicating failure) by user account, source IP address, and a 1-hour time bucket using bin(), then filters for groups where the failure count exceeds 10. That precisely matches 'accounts with more than 10 failed login attempts from the same IP within an hour.' It deliberately ignores successful logons and post-incident account states, which is exactly the described behavior.

Why this answer

The KQL query uses the `summarize` operator to count failed logon events (EventID 4625) grouped by account and IP address, then filters for counts greater than 10 within a 1-hour time window. This directly identifies accounts that have experienced more than 10 failed login attempts from the same IP address within an hour, which is a classic indicator of a brute-force attack targeting a specific account.

Exam trap

Microsoft often tests the distinction between identifying brute-force attempts (failed logins) and confirming successful brute-force attacks (failed logins followed by a successful login), so candidates may incorrectly choose Option B without checking for a successful logon event.

How to eliminate wrong answers

Option B is wrong because the query does not check for a subsequent successful login (EventID 4624) after the failures, so it cannot confirm that a brute-force attack succeeded. Option C is wrong because the query groups by both account and IP address, not by users logging in from multiple IPs; it focuses on failures from a single IP. Option D is wrong because the query does not query for account lockout events (EventID 4740) or disabled account status; it only counts failed logon attempts.

104
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Defender for Cloud automation resource. You want the automation to trigger a playbook in Microsoft Sentinel when a high-severity security assessment is found. Based on the exhibit, what is the missing configuration?

A.The severity filter should be 'Low' to capture all assessments
B.The action type should be 'LogicApp' instead of 'EventHub'
C.The eventSource should be 'Alerts' instead of 'Assessments'
D.The API version should be '2020-01-01'
AnswerB

To invoke a playbook in Microsoft Defender for Cloud, the automation action must be of type 'LogicApp' and contain the playbook's callback URL, not 'EventHub'. An EventHub action simply exports the event to an event hub for ingestion by external systems, whereas LogicApp directly triggers the playbook's workflow. Because the requirement is to run a playbook, the action type is the misconfigured property, and correcting it from EventHub to LogicApp is the necessary fix.

Why this answer

Microsoft Defender for Cloud automation can trigger a playbook in Microsoft Sentinel only by using a LogicApp action. The exhibit shows an EventHub action type, which is used for streaming events to an event hub, not for invoking a playbook. To trigger a Sentinel playbook from a Defender for Cloud assessment, the action type must be set to 'LogicApp' and configured with the playbook's trigger URL.

Exam trap

The trap here is that candidates may focus on the severity filter or event source, overlooking that the action type must be specifically 'LogicApp' to invoke a playbook, as 'EventHub' is a valid action but for a different purpose.

How to eliminate wrong answers

Option A is wrong because setting the severity filter to 'Low' would capture low-severity assessments, not high-severity ones; the requirement is to trigger on high-severity assessments, so the filter should be 'High'. Option C is wrong because the eventSource should remain 'Assessments' to trigger on security assessments; changing it to 'Alerts' would trigger on security alerts instead, which is a different data type. Option D is wrong because the API version '2020-01-01' is not relevant to the missing configuration; the automation resource uses the correct API version for its definition, and the issue is the action type, not the API version.

105
MCQmedium

Your organization uses Microsoft Sentinel and wants to correlate security events from multiple sources to detect multi-stage attacks. What should you create?

A.Scheduled query rule
B.NRT rule
C.Anomaly rule
D.Fusion rule
AnswerD

Fusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to correlate alerts from multiple Microsoft security products (e.g., Microsoft Defender for Identity, Defender for Office 365, Microsoft Entra ID Protection) into a single incident. The fusion engine maps alerts to MITRE ATT&CK stages, linking actions like initial access, lateral movement, and exfiltration into one coherent story. Because it automatically identifies multi-stage attack patterns without custom KQL, Fusion is the correct rule type for the organization's requirement to correlate multi-stage attacks.

Why this answer

Fusion rules in Microsoft Sentinel are specifically designed to correlate security events from multiple sources and detect multi-stage attacks by combining alerts from different detection technologies into a single incident. This matches the requirement to correlate events across sources for complex attack chains, unlike other rule types that focus on single-source or single-event detection.

Exam trap

The trap here is that candidates often confuse scheduled query rules or NRT rules as the primary tool for correlation, but those require manual KQL logic to join data across sources, whereas Fusion provides automated, built-in multi-source correlation for multi-stage attacks.

How to eliminate wrong answers

Option A is wrong because scheduled query rules run queries at regular intervals against a single data source or table, and they cannot natively correlate events from multiple disparate sources to detect multi-stage attacks. Option B is wrong because NRT (Near-Real-Time) rules provide low-latency detection but still operate on a single query against one or more tables, lacking the built-in multi-source correlation logic of Fusion. Option C is wrong because anomaly rules use machine learning to detect deviations from baseline behavior on a single data source, not to correlate events across multiple sources for multi-stage attack detection.

106
MCQmedium

Your organization, Fabrikam Inc., uses Microsoft Intune for device management and Microsoft Entra ID for identity. You need to design a solution to ensure that only compliant and healthy devices can access corporate resources. The solution must require that devices are either enrolled in Intune and compliant, or joined to Azure AD with a health attestation. Additionally, you need to block access from devices that are rooted or jailbroken. You have the following requirements: 1) Enforce conditional access policies to check device compliance and health. 2) Use Microsoft Defender for Endpoint integration for device health signals. 3) Provide a fallback option for unmanaged devices to access only web apps via browser with app protection policies. Which combination of actions should you take?

A.Configure conditional access to require MFA for all devices, and use device filters to exclude non-compliant devices.
B.Configure conditional access to require device compliance, and enable device health attestation via Intune.
C.Configure conditional access to block access from unknown locations, and require device enrollment for all users.
D.Configure conditional access policies: one requiring device compliance or Azure AD joined with health attestation, and another for unmanaged devices requiring app protection policies.
AnswerD

This option correctly applies a dual-policy conditional access strategy that covers both managed and unmanaged device scenarios. The first policy grants access only when the device is either Intune-compliant or Microsoft Entra joined and passes health attestation, ensuring that managed endpoints meet security baselines. The second policy requires app protection policies for unmanaged devices, which enforce data-loss-prevention and secure app-level controls without requiring full device enrollment, thereby protecting corporate data across every access path.

Why this answer

Option D is correct because it directly implements the stated requirements: a conditional access policy that grants access only when the device is Intune-enrolled and compliant or Azure AD joined with health attestation, plus a separate policy that allows unmanaged devices to reach only web apps when app protection policies (and thus browser-based access with Intune app protection) are applied. This layered approach also supports blocking rooted or jailbroken devices, since compliance and health attestation signals from Intune and Microsoft Defender for Endpoint integration surface device health and tamper state. Option A does not enforce compliance or health, only MFA, and excluding non-compliant devices via filters would not grant the required compliant-device access path.

Option B is incomplete because it omits the fallback policy for unmanaged devices and does not explicitly cover the Azure AD joined with health attestation alternative. Option C blocks unknown locations and forces enrollment for everyone, which contradicts the requirement to allow unmanaged devices limited browser access to web apps.

107
MCQhard

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. The query returns a list of users and IP addresses with failed sign-ins due to 'User Account Disabled' (ResultType 50057). The analyst wants to create a scheduled analytics rule that generates an incident when a user exceeds 5 such failures from the same IP in an hour. Which setting is missing from the query to meet the requirement?

A.Add a 'let' statement to define the threshold.
B.Add a 'project' to select columns.
C.Add a 'bin' or 'bin_at' to group by time windows.
D.Add a 'where' clause to filter by ResultType.
AnswerC

Without a bin or bin_at, the query computes a single count over the entire 1-hour period, and every time the scheduled rule runs it re-counts all events in that sliding window, creating duplicate incidents. Binning by a fixed interval (e.g., 5m) groups events into distinct time buckets, so each event contributes to exactly one bucket and the rule can reference the previous run's bucket to avoid reprocessing. Use bin_at with a fixed reference point to align buckets across runs when the schedule offset matters.

Why this answer

The query currently returns all failed sign-ins due to 'User Account Disabled' but does not aggregate them into time-based windows. To meet the requirement of generating an incident when a user exceeds 5 failures from the same IP in an hour, the query must group the results into 1-hour time buckets using 'bin' or 'bin_at' on the timestamp column, then count the failures per user and IP per bucket, and filter for counts greater than 5. Without this time-windowing, the query cannot enforce the 'in an hour' condition.

Exam trap

Microsoft often tests the candidate's understanding that time-based analytics rules require explicit time-windowing in the query (via bin or bin_at) rather than relying on the rule's run frequency or lookback period alone.

How to eliminate wrong answers

Option A is wrong because a 'let' statement defines a variable or threshold, but the threshold (5 failures) can be applied directly in a 'where' clause after aggregation; the missing piece is time-based grouping, not variable definition. Option B is wrong because 'project' selects or renames columns, which is useful for output but does not affect the aggregation or time-windowing required to count failures per hour. Option D is wrong because the query already filters by ResultType 50057 using a 'where' clause; adding another 'where' for ResultType would be redundant and does not address the missing time-window grouping.

108
MCQeasy

Your organization uses Microsoft Sentinel. You need to design a solution that automatically responds to a detected ransomware incident by isolating the affected device in Microsoft Defender for Endpoint. Which tool should you use to create the automated response?

A.Create a workbook in Microsoft Sentinel.
B.Create a playbook in Microsoft Sentinel using Azure Logic Apps.
C.Create an automation rule in Microsoft Sentinel.
D.Create a hunting query in Microsoft Sentinel.
AnswerB

A playbook in Microsoft Sentinel is a collection of automated procedures built on Azure Logic Apps, enabling incident response actions such as isolating a device, disabling a user, or blocking an IP address. These playbooks contain the logic and steps that execute directly against security controls, and they can be triggered by alerts or incidents. This is exactly what is needed to design an automated response workflow.

Why this answer

The correct option is B: create a playbook in Microsoft Sentinel using Azure Logic Apps. Playbooks are built on Azure Logic Apps and are the mechanism in Microsoft Sentinel for orchestrating automated response actions, including calling the Microsoft Defender for Endpoint connector to run the 'Isolate machine' action against an affected device. Automation rules (option C) can trigger playbooks and perform basic triage, but they do not themselves contain the multi-step response logic that isolates a device.

A workbook (option A) is only a visualization/reporting tool, and a hunting query (option D) is a proactive search for threats, neither of which performs automated remediation.

109
Multi-Selecteasy

Your organization needs to comply with GDPR. You need to design a data protection strategy using Microsoft Purview. Which THREE capabilities should you include?

Select 3 answers
A.Azure Policy
B.eDiscovery
C.Data classification and labeling
D.Data subject request management
E.Data Loss Prevention (DLP) policies
AnswersC, D, E

Data classification and labeling are correct because GDPR requires you to know what personal data you hold, where it is stored, and how it is processed. Azure Purview Information Protection lets you classify and label files and emails based on sensitivity (e.g., Personal, Highly Confidential), which then enables automated protections like encryption or access restrictions. This labeling is foundational for data minimization, accountability (Article 5), and the ability to efficiently respond to data subject requests, making it a key GDPR enabler.

Why this answer

Data classification and labeling (C) is essential because Microsoft Purview sensitivity labels and trainable classifiers identify and tag personal data, which is the foundation for applying GDPR-mandated protections. Data subject request management (D) directly supports GDPR data subject rights (access, erasure, portability) by using Purview's Data Subject Request case tooling to find and act on personal data across Microsoft 365. Data Loss Prevention policies (E) enforce GDPR's protection and breach-prevention requirements by detecting sensitive information types (such as EU identifiers) and blocking or auditing their improper sharing.

Azure Policy (A) governs Azure resource compliance, not the discovery, classification, or protection of personal data in Purview, and eDiscovery (B) is a legal-hold and investigation tool rather than a GDPR data protection control, so neither belongs in this strategy.

110
MCQmedium

Your organization uses Microsoft Entra ID and needs to ensure that external partners can access only specific applications for 30 days. What should you configure?

A.Entitlement management and create an access package with an expiration of 30 days
B.B2B direct connect
C.Self-service group management
D.Conditional Access policy with session control
AnswerA

Entitlement management access packages bundle specific application assignments with an expiry, directly satisfying the 30-day external partner constraint. Time-limited access packages automatically revoke access at expiration, unlike conditional access policies, which govern session conditions rather than provisioning and lifecycle.

Why this answer

Entitlement management in Microsoft Entra ID allows you to create access packages that govern external partner access to specific applications. By configuring an access package with a 30-day expiration, you enforce time-limited access, ensuring partners can only access the designated applications for the required duration. This directly meets the requirement of restricting access to specific apps with a defined expiry.

Exam trap

The trap here is that candidates often confuse Conditional Access session controls (which manage sign-in frequency or app restrictions) with the ability to grant and expire access to specific applications, overlooking that entitlement management is the correct identity governance solution for time-limited external access.

How to eliminate wrong answers

Option B (B2B direct connect) is wrong because it is designed for mutual two-way access between organizations, typically for Teams Connect shared channels, and does not provide granular control over application-specific access or automatic expiration. Option C (self-service group management) is wrong because it allows users to create and manage their own groups, but it does not enforce time-bound access to specific applications or support external partner lifecycle management. Option D (Conditional Access policy with session control) is wrong because while it can enforce session restrictions like sign-in frequency, it cannot grant or expire access to specific applications for external users; it only controls access conditions for users who already have access.

111
MCQmedium

Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Users have smartphones. Which method should you recommend as the primary authentication method?

A.FIDO2 security keys
B.Microsoft Authenticator app with passwordless sign-in
C.SMS-based authentication
D.Windows Hello for Business
AnswerB

Microsoft Authenticator app with passwordless sign-in is the correct choice because it leverages the user's smartphone as a possession factor, using a cryptographic challenge-response protocol. When the user enters their username, the Authenticator app displays a number or a number match prompt; the user's approval signs the request with a private key stored in the device's secure enclave, eliminating the password entirely. This method is phishing-resistant, supports conditional access policies, and works seamlessly on iOS and Android, making it ideal for smartphone-centric users.

Why this answer

The Microsoft Authenticator app with passwordless sign-in is the correct primary method because it leverages the user's smartphone to provide a seamless, phishing-resistant authentication experience using public/private key cryptography (FIDO2/WebAuthn). This method aligns with the organization's goal of eliminating passwords while utilizing existing smartphone hardware, and it supports a simple user experience by requiring only a biometric or PIN verification on the phone.

Exam trap

The trap here is that candidates often confuse 'passwordless' with 'MFA' and select SMS-based authentication, not realizing that SMS still relies on a shared secret (the code) and is not truly passwordless or phishing-resistant.

How to eliminate wrong answers

Option A is wrong because FIDO2 security keys are hardware tokens that require additional procurement and distribution, making them less practical as a primary method for all users who already have smartphones. Option C is wrong because SMS-based authentication is not passwordless (it still relies on a one-time code sent via text) and is vulnerable to SIM-swapping and phishing attacks, failing to meet the passwordless strategy's security goals. Option D is wrong because Windows Hello for Business is tied to Windows devices and does not leverage smartphones, so it cannot serve as the primary method for users who may not always have access to a Windows PC.

112
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. Based on the JSON snippet, what is the most likely outcome when a user with high user risk attempts to sign in?

A.The sign-in is blocked because user risk is high
B.The sign-in is blocked only if sign-in risk is also high
C.The sign-in is allowed because sign-in risk is not high
D.The user is prompted for multi-factor authentication
AnswerA

The Conditional Access policy explicitly assigns the 'High' user risk condition to the 'Block access' grant control, meaning any sign-in event where the user's risk level is assessed as High will be immediately denied. User risk is derived from identity protection signals such as leaked credentials or anomalous behavior, and once it meets the configured threshold, the policy's block action applies without regard to other conditions. In the exhibit, no sign-in risk condition is configured, so user risk alone is sufficient to trigger the block.

Why this answer

The Conditional Access policy shown in the JSON snippet includes a condition for 'userRiskLevels' set to 'high', and the grant control is 'block'. When a user with high user risk attempts to sign in, the policy evaluates the user risk level and, since it matches the condition, applies the block action, preventing the sign-in entirely.

Exam trap

The trap here is that candidates often confuse user risk with sign-in risk, assuming both must be high for a block to occur, or mistakenly think that high user risk only triggers MFA rather than a block, when the policy explicitly specifies 'block' as the control.

How to eliminate wrong answers

Option B is wrong because the policy does not require sign-in risk to be high; it only evaluates user risk, and the block is triggered solely by high user risk regardless of sign-in risk. Option C is wrong because the policy does not check sign-in risk at all; the sign-in is blocked due to high user risk, not allowed because sign-in risk is not high. Option D is wrong because the grant control is set to 'block', not 'requireMfa', so the user is not prompted for multi-factor authentication; they are blocked.

113
Multi-Selecteasy

Your organization needs to comply with regulatory requirements for data retention and deletion. Which TWO Microsoft Purview features should you use?

Select 2 answers
A.Retention policies
B.Data Loss Prevention (DLP) policies
C.Audit logs
D.Retention labels
E.eDiscovery
AnswersA, D

Retention policies in Microsoft Purview let you retain content for a defined period and then delete it automatically, directly satisfying regulatory retention and deletion obligations. They apply across Exchange, SharePoint, OneDrive and Teams without requiring manual intervention.

Why this answer

Retention policies (A) are correct because they let you apply retention and deletion settings at the workload, location, or site level (for example, all Exchange mailboxes or all SharePoint sites) so content is kept for a defined period and then deleted, which directly satisfies regulatory data-retention and deletion requirements. Retention labels (D) are also correct because they provide item-level retention and deletion control, including event-based retention and disposition review, allowing specific documents or emails to be governed precisely per regulation. Together, policies handle broad, automatic governance while labels handle granular, item-specific governance.

DLP policies (B) are not the right fit because they prevent sharing or leakage of sensitive data rather than enforcing retention or deletion periods. Audit logs (C) only record activity for investigation and compliance monitoring, and eDiscovery (E) is used to identify, hold, and export content for legal cases, not to implement retention or deletion schedules.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) policies with retention policies because both involve data governance, but DLP focuses on preventing data exfiltration, not on lifecycle management of data retention and deletion.

114
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that all incidents related to a specific critical asset are automatically assigned to the senior SOC analyst. The assignment should occur as soon as the incident is created. What should you configure?

A.Modify the analytics rule to include a custom details field for owner.
B.Create an automation rule that sets the incident owner to the senior SOC analyst.
C.Create a playbook and trigger it from an automation rule.
D.Configure a workbook to display incidents and manually assign them.
AnswerB

An automation rule is the native, direct mechanism for assigning incident ownership at creation time. You define a trigger condition (e.g., all incidents or specific severity) and add an action to set the owner to the senior SOC analyst; the rule runs automatically the moment an incident is created, ensuring immediate accountability without human intervention. This is the simplest and most scalable approach for a one-step assignment.

Why this answer

Automation rules in Microsoft Sentinel can directly set the incident owner upon creation without requiring a playbook. This is the simplest and most efficient method for immediate assignment, as automation rules run automatically when an incident is created and can modify incident properties like owner.

Exam trap

The trap here is that candidates often over-engineer the solution by selecting a playbook (Option C) for a task that can be handled natively by automation rules, failing to recognize that automation rules can directly modify incident properties without needing a playbook.

How to eliminate wrong answers

Option A is wrong because custom details fields in analytics rules are used to extract and surface specific data from raw events into the incident, not to assign ownership or trigger automated actions. Option C is wrong because while a playbook can assign an owner, it introduces unnecessary complexity and latency; automation rules can directly set the owner without invoking a playbook, making it the preferred approach for simple assignments. Option D is wrong because workbooks are visualization tools for analyzing data and cannot automate incident assignment; manual assignment contradicts the requirement for automatic assignment upon creation.

115
MCQeasy

Your organization is required to retain all Microsoft Teams chat messages for 7 years due to regulatory compliance. You need to design a solution that automatically retains and, if needed, e-discovery searches these messages. What should you configure?

A.Microsoft Purview retention policies and eDiscovery
B.Microsoft Purview Data Loss Prevention policies
C.Azure Policy
D.Sensitivity labels auto-labeling
AnswerA

Microsoft Purview retention policies can be assigned to Teams channel and chat messages to preserve data for a defined period such as seven years, protecting it from permanent deletion. eDiscovery tools in the same compliance portal provide search, legal hold, and export capabilities, enabling the organization to locate and produce retained Teams communications when required. Together they satisfy the retention mandate because retention preserves the data and eDiscovery operationalizes access to it.

Why this answer

Microsoft Purview retention policies are designed to retain data for a specified period (e.g., 7 years) and can be applied to Microsoft Teams chat messages. eDiscovery (now part of Microsoft Purview eDiscovery) allows authorized users to search, hold, and export retained content for legal or compliance purposes. Together, they meet the regulatory requirement for retention and searchability.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) policies with retention policies, thinking DLP can also retain data, but DLP only monitors and blocks data exfiltration, not retention or search.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are used to prevent sensitive information from being shared or leaked, not to enforce retention or enable eDiscovery searches. Option C is wrong because Azure Policy is used to enforce organizational standards and assess compliance at the Azure resource level (e.g., VMs, storage), not to manage Microsoft Teams chat message retention or eDiscovery. Option D is wrong because sensitivity labels auto-labeling applies classification and protection (e.g., encryption, markings) to content based on sensitive data, but does not provide retention or eDiscovery search capabilities.

116
MCQhard

Your organization is a multi-national corporation that uses Microsoft 365 E5 and Azure. You need to design a security operations center (SOC) to detect and respond to threats across identities, endpoints, and cloud apps. The SOC team will use a single pane of glass for incident management. Requirements: (1) Centralize alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps, (2) Automate incident response playbooks, (3) Use advanced hunting across all data sources, (4) Integrate with external threat intelligence feeds, (5) Provide role-based access control for SOC analysts. Which Microsoft solution should you implement?

A.Microsoft 365 Defender portal
B.Microsoft Sentinel
C.Microsoft Purview Compliance Manager
D.Microsoft Defender for Cloud
AnswerB

Microsoft Sentinel is the only option that functions as a true cloud-native SIEM/SOAR, ingesting security telemetry from across Microsoft Defender products, Azure services, and third-party sources. It provides automation playbooks for incident response, advanced hunting with Kusto Query Language (KQL), built-in threat intelligence connectors, and role-based access control for the SOC. This centralized architecture is essential for aggregating identity, endpoint, and app signals into a single detection and response workflow, meeting the requirement for a security operations center.

Why this answer

Option B is correct because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests alerts from Microsoft Defender services, third-party sources, and external threat intelligence, provides a single pane of glass for incident management, supports automation playbooks via Logic Apps, and offers advanced hunting with KQL across all connected data sources. It also supports RBAC for SOC analysts. The Microsoft 365 Defender portal (A) centralizes Defender alerts but lacks the broader SIEM/SOAR capabilities and external threat intelligence integration required.

Exam trap

SC-100 often tests the misconception that the Microsoft 365 Defender portal is a full SIEM/SOAR solution, when in fact Sentinel is required for centralized incident management, external threat intelligence, and cross-platform advanced hunting.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 Defender portal is an XDR console for Defender workloads; it does not natively ingest external threat intelligence feeds, does not provide full SIEM correlation across non-Microsoft sources, and its automation is limited compared to Sentinel's Logic Apps playbooks. Option C is wrong because Microsoft Purview Compliance Manager is a compliance assessment tool, not a SOC detection and response platform. Option D is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection tool for Azure, AWS, and GCP, not a SIEM/SOAR platform for centralized incident management.

117
MCQeasy

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). The security team receives an alert for a user who has failed authentication 10 times in 5 minutes. What should you configure to reduce false positives while ensuring legitimate brute-force attacks are still detected?

A.Customize the anomaly threshold in UEBA
B.Disable UEBA for that user
C.Modify the analytics rule that triggered the alert
D.Create a playbook to auto-acknowledge the alert
AnswerA

Customizing the anomaly threshold in UEBA is the correct approach because UEBA uses machine learning models that assign anomaly scores to user behaviors, and these models expose threshold and sensitivity settings you can tune. By adjusting the sensitivity, you directly influence the score required to trigger an alert, effectively filtering out low-confidence anomalies that cause false positives while still detecting genuinely suspicious activity. This is the intended, documented method for reducing noise from UEBA-detected behaviors without sacrificing the underlying behavioral analytics capability.

Why this answer

Customizing the anomaly threshold in UEBA allows you to adjust the sensitivity of the behavioral baseline, reducing false positives for users who legitimately fail authentication multiple times while still detecting true brute-force attacks. UEBA learns normal behavior patterns and flags deviations; by raising the threshold, you require a higher deviation from the baseline before an alert fires, preserving detection of actual attacks.

Exam trap

The trap here is that candidates assume modifying the analytics rule (Option C) is the correct tuning mechanism, but UEBA-specific thresholds are configured separately from the underlying analytics rule, and adjusting the rule itself would affect all users and all detection logic, not just the behavioral anomaly component.

How to eliminate wrong answers

Option B is wrong because disabling UEBA for that user would stop all behavioral analytics for that user, preventing detection of any future anomalous activity, including legitimate brute-force attacks. Option C is wrong because modifying the analytics rule that triggered the alert would change the detection logic for all users, potentially missing real attacks or increasing noise across the board, rather than tuning the behavioral sensitivity for this specific pattern. Option D is wrong because creating a playbook to auto-acknowledge the alert does not reduce false positives; it merely automates ignoring the alert, which could cause a real brute-force attack to be overlooked.

118
Multi-Selectmedium

Which THREE are valid sources for ingesting data into Microsoft Sentinel? (Choose three.)

Select 3 answers
A.AWS CloudTrail
B.Microsoft 365 Defender
C.Adobe Analytics
D.Azure Activity log
E.Google BigQuery
AnswersA, B, D

AWS CloudTrail is a valid source because Microsoft Sentinel provides a native data connector that ingests CloudTrail management and data plane logs. By leveraging an S3 bucket and an SQS queue, Sentinel pulls API activity from AWS, allowing security teams to detect misconfigurations, credential abuse, and unauthorized access across AWS accounts.

Why this answer

AWS CloudTrail is a valid data source for Microsoft Sentinel because Sentinel supports ingesting AWS service logs via the AWS CloudTrail data connector. This connector uses the AWS S3 bucket to collect CloudTrail logs, which are then pulled into Sentinel for analysis. This allows organizations to monitor and detect threats across their AWS environment alongside other cloud and on-premises data sources.

Exam trap

The trap here is that candidates may assume any popular cloud service (like Adobe Analytics or Google BigQuery) can be a data source for Sentinel, but Microsoft only provides built-in connectors for specific security-relevant sources, and these two are not among them.

119
MCQmedium

Your company is deploying Microsoft Intune for mobile device management. You need to ensure that corporate data on personally owned devices is protected without affecting the user's personal data. Which Intune feature should you use?

A.Device compliance policies
B.Conditional Access for app control
C.Windows Autopilot
D.App Protection Policies (MAM)
AnswerD

App Protection Policies (MAM) are specifically designed to protect corporate data within applications without requiring the device to be enrolled in device management. They enforce data-loss prevention (DLP) rules like PIN enforcement, data encryption, restrict cut/copy/paste, and prevent saving corporate data to personal stores. In a BYOD scenario, MAM policies apply to managed apps (e.g., Outlook, Word) and ensure that corporate data is contained, regardless of the device's management state, which directly matches the scenario of securing data on personal mobile devices.

Why this answer

App Protection Policies (MAM) are the correct choice because they allow you to manage and protect corporate data within applications on personally owned devices without requiring device enrollment. This ensures that corporate data is encrypted, can be selectively wiped, and is prevented from being copied to personal apps, while leaving the user's personal data untouched.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access to resources) with App Protection Policies (which protect data within apps), leading them to select Conditional Access for app control when the question specifically asks about protecting corporate data without affecting personal data.

How to eliminate wrong answers

Option A is wrong because Device Compliance Policies evaluate the security configuration of the entire device (e.g., jailbreak detection, encryption status) and require the device to be enrolled in Intune, which would give the organization visibility and control over the entire device, affecting personal data. Option B is wrong because Conditional Access for app control (e.g., using Azure AD Conditional Access with app-based policies) can restrict access based on app-level conditions but does not provide the granular data protection and selective wipe capabilities that MAM offers for corporate data within apps. Option C is wrong because Windows Autopilot is a device provisioning and deployment tool for Windows devices, not a mobile device management feature for protecting corporate data on personally owned devices.

120
MCQmedium

A retail company is designing a security operations model in Microsoft Sentinel. The security team wants to detect suspicious activity in Microsoft Entra ID, including sign-ins from unfamiliar locations and changes to privileged roles, and they want the detections to be based on Microsoft's continuously updated threat intelligence rather than custom queries. Which Microsoft Sentinel feature should you recommend?

A.A threat intelligence platform connector that ingests indicators of compromise
B.A watchlist that contains the company's list of privileged role assignments
C.Custom analytics rules written with Kusto Query Language against the SigninLogs table
D.Microsoft Sentinel solutions for Microsoft Entra ID that include analytics rule templates
AnswerD

Solutions in the Microsoft Sentinel content hub package data connectors, analytics rule templates, workbooks, and playbooks for a specific domain such as Microsoft Entra ID. The analytics rule templates cover identity scenarios like unfamiliar sign-in locations and privileged role changes, and they are maintained by Microsoft, so the team gets up-to-date detections without authoring custom queries.

Why this answer

The requirement is for Microsoft-maintained, continuously updated identity detections rather than custom logic. Solutions in the Microsoft Sentinel content hub deliver connectors, analytics rule templates, and other artifacts for domains such as Microsoft Entra ID, and the templates cover the described identity scenarios. Custom rules, threat intelligence connectors, and watchlists are supporting components, not the source of maintained detections.

Exam trap

The trap here is assuming a threat intelligence connector or a watchlist provides detection logic, when those supply enrichment data that analytics rules must consume.

121
MCQeasy

You are designing a compliance solution for your organization that must enforce retention policies for documents stored in SharePoint Online. Which Microsoft Purview solution should you use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview eDiscovery
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Insider Risk Management
AnswerA

Data Lifecycle Management is the dedicated service for enforcing retention and deletion policies across Microsoft 365 workloads. It provides retention labels and policies that let you preserve content for a specified period, then automatically dispose of it, optionally with disposition review. This directly addresses compliance needs for record keeping, regulatory retention, and data minimization. Other services lack the policy-driven automation that DLM offers for lifecycle control.

Why this answer

Microsoft Purview Data Lifecycle Management (formerly Microsoft 365 Retention) is the correct solution because it is specifically designed to enforce retention policies for documents in SharePoint Online. It allows you to apply retention labels and policies that automatically retain or delete content based on compliance requirements, without user intervention.

Exam trap

The trap here is that candidates often confuse 'retention' with 'eDiscovery holds' or 'compliance monitoring,' leading them to select eDiscovery or Communication Compliance, but Data Lifecycle Management is the only solution that directly enforces retention schedules for content in SharePoint Online.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for enforcing retention policies. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, sensitive info sharing), not to apply retention schedules. Option D is wrong because Microsoft Purview Insider Risk Management focuses on identifying and mitigating internal security risks (e.g., data theft, policy violations), not on lifecycle retention of documents.

122
Multi-Selecthard

Your organization uses Microsoft Intune for mobile device management. You need to configure a compliance policy for iOS devices that requires the device to be jailbreak-detected and have a minimum OS version. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require passcode
B.Minimum OS version
C.Device encryption
D.Jailbreak detection
AnswersB, D

The Minimum OS version setting specifies the lowest operating system version a device must run to be considered compliant, such as iOS 16.0 or Windows 10, version 22H2. This rule directly enforces that devices are on a supported and permitted OS release, but it does not detect jailbreaks or root access—a device can be jailbroken while running a fully up-to-date OS. For the scenario described, this is the correct answer because it is the only option among those listed that explicitly checks the OS version level required by the policy.

Why this answer

B is correct because the compliance policy must specify a minimum OS version to ensure iOS devices meet the required security baseline, preventing outdated devices with known vulnerabilities from accessing corporate resources. D is correct because jailbreak detection is a specific compliance setting that identifies compromised devices, which are a significant security risk as they bypass iOS security controls.

Exam trap

The trap here is that candidates may confuse 'jailbreak detection' with 'device encryption' or 'passcode requirements,' but the question explicitly asks for the two settings that directly address jailbreak detection and minimum OS version, not general security settings.

123
MCQhard

Your organization uses Microsoft Sentinel and wants to reduce alert fatigue by grouping related alerts into incidents. Which configuration should you use?

A.Configure incident creation in the analytics rule properties
B.Use a workbook to aggregate alerts
C.Use a playbook to create incidents
D.Create an automation rule to group alerts
AnswerA

The analytics rule's 'Incident settings' tab (in the rule wizard or via API) controls whether alerts generated by that rule are automatically turned into incidents, and whether related alerts are grouped into a single incident based on entity or alert properties such as account, host, or IP. This is the correct and intended mechanism because incident creation and grouping are natively executed by the rule itself at alert generation time, ensuring the grouping logic is atomic with the rule's detection and does not require separate orchestration. To reduce noise, you set the rule to create incidents and choose an entity-based grouping key (e.g., 'Group alerts by entities into a single incident') or alert property, which Microsoft Sentinel then uses to merge correlated alerts into one incident before any automation or response.

Why this answer

In Microsoft Sentinel, incident creation is configured directly within the analytics rule properties. When you create or edit a scheduled or Microsoft Security analytics rule, the 'Incident settings' tab allows you to enable incident creation and define how alerts are grouped into incidents. This is the native mechanism for reducing alert fatigue by automatically grouping related alerts into a single incident based on criteria such as entity matching or time window.

Exam trap

The trap here is that candidates often confuse automation rules with incident grouping logic, assuming that automation rules can create or group incidents, when in fact automation rules only manage incidents after they are created by analytics rules.

How to eliminate wrong answers

Option B is wrong because workbooks in Microsoft Sentinel are visualization tools that display data from queries; they do not create or group incidents. Option C is wrong because playbooks are automated workflows triggered by incidents or alerts (using Azure Logic Apps) and can perform response actions, but they are not designed to initially group alerts into incidents; incident creation is a function of the analytics rule. Option D is wrong because automation rules in Sentinel are used to automate incident management tasks (e.g., assigning, tagging, or running playbooks) after an incident is created, not to group alerts into incidents at creation time.

124
Multi-Selectmedium

Your organization uses Microsoft Purview to comply with regulatory requirements. Which TWO features should you use to manage data retention and deletion?

Select 2 answers
A.Data lifecycle management policies (retention policies).
B.Sensitivity labels.
C.Records management (retention labels and disposition).
D.Data Loss Prevention (DLP) policies.
E.Trainable classifiers.
AnswersA, C

Data lifecycle management policies in Microsoft Purview (formerly Microsoft 365 compliance retention policies) let you automatically retain and then delete content across Exchange, SharePoint, OneDrive, and Teams based on age, event, or location. These policies are organization-wide or scoped via adaptive scopes, and they run continuously without user intervention, providing a primary mechanism to meet regulatory retention requirements. They manage the entire lifecycle from retention to expiration, making them the correct choice for broad compliance mandates.

Why this answer

Data lifecycle management policies (retention policies) (A) are correct because they let you centrally define how long content is kept and when it is deleted across Exchange, SharePoint, OneDrive, Teams, and other workloads, satisfying regulatory retention and deletion requirements. Records management (retention labels and disposition) (C) is also correct because it uses retention labels with file plan descriptors, event-based retention, and disposition review to declare items as records and control their deletion with proof of disposition. Sensitivity labels (B) are for classification and protection (encryption, marking, access control), not for retention or deletion timing.

Data Loss Prevention (D) policies detect and block risky sharing of sensitive data but do not govern retention periods or deletion. Trainable classifiers (E) identify content types to support classification and labeling, but they do not themselves manage retention or deletion.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which handle classification and protection) with retention labels (which handle retention and deletion), leading them to incorrectly select sensitivity labels as a retention feature.

125
MCQhard

You are analyzing a custom detection rule in Microsoft 365 Defender. Based on the exhibit, what is a potential operational issue with this rule?

A.The threshold is too low, leading to alert fatigue.
B.The query syntax is invalid.
C.The severity should be Medium instead of High.
D.The rule does not cover PowerShell 7 (pwsh.exe).
AnswerA

A threshold of 5 events in a day, combined with a High severity rating and a rule that matches common PowerShell processes, will produce a large number of alerts from benign administrative and scripting activity. This overwhelms the SOC with low-fidelity alerts, desensitizing analysts to genuinely malicious signals and increasing the risk that a true positive is buried in the noise. The fundamental problem is the low threshold causing alert fatigue, not a technical defect in the query.

Why this answer

Option A is correct because a custom detection rule whose threshold is set too low will trigger on very few or even a single event, generating excessive alerts that overwhelm analysts with false positives and cause alert fatigue. In Microsoft 365 Defender custom detections, the threshold (aggregation) value controls how many events must occur within the query's timeframe before an alert fires, so setting it too low directly increases alert volume. Option B is incorrect because the scenario asks about an operational issue, not a syntax error, and the exhibit implies the query runs.

Option C is incorrect because severity is a triage preference, not an operational defect, and changing High to Medium would not fix alert volume. Option D is incorrect because PowerShell 7 coverage depends on the query's data source and process filters, not on the threshold, and the scenario does not indicate pwsh.exe is relevant.

126
Multi-Selecthard

Your organization is implementing Microsoft Entra ID governance. Which THREE capabilities should you include to manage the identity lifecycle and access reviews?

Select 3 answers
A.Microsoft Entra Identity Protection.
B.Microsoft Entra Access Reviews.
C.Microsoft Entra Entitlement Management.
D.Microsoft Entra Lifecycle Workflows.
E.Privileged Identity Management (PIM).
AnswersB, C, D

Access Reviews allow an administrator to create recurring review scopes covering group memberships, application assignments, and role assignments, where designated reviewers attest whether each user's access remains necessary. Once a cycle completes, the reviewer's decisions can be applied automatically to remove access that was denied, and the entire history is stored to demonstrate compliance with internal and regulatory standards. This is the purpose-built mechanism for periodic access certification.

Why this answer

Microsoft Entra Access Reviews (B) is correct because it lets reviewers periodically attest to users' group memberships, application assignments, and role assignments, which is the core mechanism for recertifying access in an identity governance program. Microsoft Entra Entitlement Management (C) is correct because access packages, catalogs, and connected organizations automate the request, approval, and assignment of resource bundles, including external user lifecycle, which is central to governing access at scale. Microsoft Entra Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks such as generating Temporary Access Passes, assigning licenses, and disabling accounts based on HR events, directly addressing identity lifecycle management.

Microsoft Entra Identity Protection (A) is not included because it detects and remediates identity-based risks like risky sign-ins and compromised credentials rather than managing lifecycle or access reviews. Privileged Identity Management (E) is not included because it focuses on just-in-time privileged role activation and approval, which is privileged access management rather than the lifecycle and review capabilities the scenario asks for.

127
Multi-Selectmedium

Your organization is implementing Microsoft Entra ID Governance. You need to design a solution that automates user access reviews for cloud applications. Which TWO capabilities should you include?

Select 2 answers
A.Identity Protection
B.Entitlement Management with access packages
C.Terms of Use
D.Access Reviews
E.Privileged Identity Management (PIM)
AnswersB, D

Entitlement Management access packages group cloud applications, groups, and SharePoint sites into catalogs with request policies, approval chains, assignment durations, and optional recurring review stages. By attaching an access review policy to an access package, the organization automates both the initial grant and the periodic recertification: when a reviewer marks a user as denied, the user's assignments are automatically removed from all resources in the package. This lifecycle-centric design directly satisfies the requirement to automate recurring user access reviews for cloud applications in Microsoft Entra ID Governance.

Why this answer

Access Reviews (D) is correct because it is the Microsoft Entra ID Governance capability specifically designed to automate periodic reviews of users' group memberships, application assignments, and role assignments, allowing reviewers to attest to continued access and automatically remove access when reviewers deny it or don't respond. Entitlement Management with access packages (B) is correct because access packages bundle resources such as cloud applications, groups, and SharePoint sites, and they support mandatory access reviews and expiration policies that automate the access lifecycle for cloud applications. Identity Protection (A) is not correct because it detects and remediates identity risk signals like risky sign-ins and compromised credentials, not access attestation workflows.

Terms of Use (C) is not correct because it presents legal disclaimers that users must accept before accessing resources, which is a consent mechanism rather than an access review. Privileged Identity Management (E) is not correct because PIM governs just-in-time activation and approval of privileged directory and Azure roles, not recurring reviews of general cloud application access.

128
Multi-Selecteasy

Your organization needs to meet compliance requirements for GDPR. You need to design a solution that uses Microsoft Purview to classify and protect personal data. Which TWO capabilities should you include?

Select 2 answers
A.Data Subject Requests (DSR) tool
B.Data Classification and labeling
C.eDiscovery (Premium)
D.Insider Risk Management
E.Communication Compliance
AnswersA, B

The DSR tool in Microsoft Purview is the correct choice because it operationalizes GDPR Article 15-21 individual rights: access, rectification, erasure, restriction, processing objection, and portability. It lets administrators search across Exchange, SharePoint, OneDrive, and Teams for a data subject's content, then generate a downloadable report for review and action, including the ability to close out the request in a auditable manner. It is specifically designed for these privacy obligations, not for general content discovery.

Why this answer

The Data Subject Requests (DSR) tool (A) is correct because GDPR grants individuals rights over their personal data (access, rectification, erasure, portability), and the Microsoft Purview DSR tool provides a workflow to discover, review, and respond to these requests across Microsoft 365 data sources. Data Classification and labeling (B) is correct because GDPR requires identifying and protecting personal data, and Purview's sensitive information types, trainable classifiers, and sensitivity labels let you automatically classify and apply protection such as encryption and access restrictions. eDiscovery (Premium) (C) is not the right fit because it is designed for legal investigations and litigation hold workflows, not for fulfilling GDPR data subject rights or building a classification/protection scheme. Insider Risk Management (D) addresses detecting and mitigating risky user behavior, which supports security but does not directly satisfy GDPR classification, protection, or DSR obligations.

Communication Compliance (E) focuses on monitoring communications for policy violations such as harassment or regulatory breaches, which is unrelated to classifying and protecting personal data for GDPR compliance.

129
Multi-Selecteasy

Which THREE are valid methods to secure privileged access in Microsoft Entra ID? (Choose three.)

Select 3 answers
A.Use privileged access groups to manage elevated access to resources.
B.Require device enrollment via Microsoft Intune.
C.Use Privileged Identity Management (PIM) for just-in-time access.
D.Configure conditional access policies to require MFA for admins.
E.Enable self-service password reset for all users.
AnswersA, C, D

Privileged access groups, such as role-assignable groups in Microsoft Entra ID, allow administrators to assign highly privileged Azure AD roles to a group rather than to individual users. This enables scalable and consistent membership management, and when integrated with Privileged Identity Management (PIM), group membership can be time-limited so users hold elevated access only during an approved activation window. Because the group itself carries the role, adding or removing members centrally controls privileged access across multiple resources.

Why this answer

Option A is correct because privileged access groups in Microsoft Entra ID (specifically Privileged Access Management for groups) let you assign users as eligible or active members of a role-assignable group, so elevated access to resources is governed and time-bound rather than permanently granted. Option C is correct because Privileged Identity Management (PIM) provides just-in-time role activation with approval workflows, MFA on activation, justification, and time-limited assignments, which directly reduces standing privileged access. Option D is correct because a Conditional Access policy that requires multifactor authentication for directory roles (admin roles) enforces strong authentication at sign-in for privileged accounts, a core control for securing privileged access.

Option B is not one of the three because Intune device enrollment/compliance is a device-management control that can be referenced in Conditional Access but is not itself a privileged-access security method. Option E is not correct because self-service password reset is an end-user credential-recovery feature and does not govern or restrict privileged access.

Exam trap

The trap here is that candidates may confuse general security best practices (like device enrollment or self-service password reset) with specific methods for securing privileged access, which require granular controls like PIM, conditional access, and privileged groups.

130
MCQhard

You are designing a security operations solution for a multinational organization using Microsoft Sentinel. The organization has multiple Azure subscriptions, each with its own Log Analytics workspace. You need to centralize incident management while minimizing data egress costs. What should you recommend?

A.Deploy a Sentinel workspace in each region and use cross-workspace views.
B.Export all logs to a third-party SIEM using Azure Event Hubs.
C.Configure Azure Monitor cross-workspace queries to correlate incidents.
D.Use a single Log Analytics workspace for all subscriptions and configure Sentinel in that workspace.
AnswerD

A single Log Analytics workspace for all subscriptions lets Microsoft Sentinel ingest every security log into one repository, so incidents are generated and managed from a unified console. This eliminates cross-region egress fees and enables seamless correlation across subscriptions, while also simplifying automation, access control, and compliance reporting. One caveat is that workspace scale limits and data sovereignty must be carefully evaluated, but for most SOC designs this is the recommended pattern.

Why this answer

Option D is correct because Microsoft Sentinel is enabled on a Log Analytics workspace, and using a single workspace for all subscriptions centralizes incident management in one place while avoiding cross-workspace query and data egress charges. All subscriptions can onboard to that workspace via Azure Lighthouse or the Sentinel data connectors, so incidents, analytics rules, and workbooks are managed centrally. Option A does not truly centralize incidents and adds cross-workspace complexity, while Option B sends data to a third-party SIEM and increases egress costs rather than minimizing them.

Option C only allows cross-workspace queries for correlation but still leaves incident management distributed across multiple workspaces.

131
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to protect users from malicious links in emails. What should you configure?

A.Anti-malware policy
B.Safe Links policy
C.Anti-phishing policy
D.Safe Attachments policy
AnswerB

Safe Links is the dedicated protection feature for URLs, automatically applying URL rewriting and time-of-click checks in Microsoft 365. When a user clicks a link, Safe Links verifies the destination against the latest threat intelligence and blocks or warns if it leads to a malicious site, even if the link initially looked benign. This is precisely the control that fulfills a requirement for malicious link protection at click time.

Why this answer

Safe Links policy is the correct answer because it specifically protects users from malicious links in emails by scanning URLs at the time of click, checking against Microsoft's threat intelligence, and optionally rewriting links to route clicks through the Safe Links service. This is the dedicated Defender for Office 365 feature designed to mitigate link-based attacks in email messages.

Exam trap

The trap here is that candidates often confuse Safe Links with Safe Attachments, but Safe Attachments handles file payloads (attachments) while Safe Links handles URL payloads (links) — a common misconception that leads to selecting the wrong policy for link protection.

How to eliminate wrong answers

Option A is wrong because Anti-malware policy focuses on scanning email attachments and messages for malware signatures, not on protecting against malicious links. Option C is wrong because Anti-phishing policy primarily protects against impersonation attacks (e.g., spoofed domains, user impersonation) and does not directly scan or rewrite URLs in emails. Option D is wrong because Safe Attachments policy is designed to detonate and analyze email attachments in a sandbox environment, not to handle hyperlinks within the message body.

132
MCQmedium

Refer to the exhibit. You are troubleshooting a KQL query in Microsoft Sentinel that is supposed to return alerts for ransomware detections in the last day. The query returns no results, but you know there were ransomware alerts. What is the most likely cause?

A.The ThreatFamily field is an integer, not a string.
B.The AlertName filter is too specific and does not match the actual alert name.
C.The TimeGenerated filter uses the wrong time range.
D.The parse_json function is failing due to malformed JSON.
AnswerB

The AlertName filter is too specific and does not match the actual alert name. In Microsoft Sentinel, analytics rule names often include suffixes, version numbers, or localized display names, and the exact string comparison in KQL is case-sensitive. For example, an alert named 'Suspicious PowerShell Activity' might be stored as 'Suspicious PowerShell Activity (Preview)' or with a different casing. Because the query filters for an exact match, it silently returns zero rows even though alerts exist. To resolve this, use the `has` or `contains` operator to match a substring instead of exact equality.

Why this answer

The query's `AlertName` filter is likely too specific (e.g., using a hardcoded string like 'RansomwareAlert') and does not match the actual alert name generated by Microsoft Sentinel's analytics rules. Ransomware alerts often have dynamic naming conventions that include variant names or suffixes, so an exact match filter fails to return results even though alerts exist. The query otherwise appears syntactically correct, and the `TimeGenerated` filter is set to the last day, which aligns with the known presence of alerts.

Exam trap

The trap here is that candidates assume a simple string comparison will match all alerts of a given category, overlooking that Microsoft Sentinel alert names often include variant-specific suffixes or prefixes, making exact-match filters too restrictive.

How to eliminate wrong answers

Option A is wrong because the `ThreatFamily` field in Microsoft Sentinel's alert schema is a string type, not an integer, and comparing it to a string literal would work correctly; an integer mismatch would cause a type error or implicit conversion, not a silent empty result. Option C is wrong because the `TimeGenerated` filter using `ago(1d)` is a standard and correct way to query the last 24 hours, and if alerts existed within that window, this filter would not suppress them. Option D is wrong because the `parse_json` function failing due to malformed JSON would typically produce an error or null value in the output, not an empty result set, and the query would still return rows with null fields rather than zero rows.

133
MCQmedium

Your company uses Microsoft Sentinel for security operations. You need to design a solution to automatically respond to a confirmed ransomware incident by isolating affected devices and blocking malicious IPs. What should you use?

A.Azure Policy
B.Sentinel automation rules with playbooks
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerB

Sentinel automation rules are the native orchestration mechanism that listens for incident/alert triggers and invokes playbooks—workflows built on Azure Logic Apps. When an incident matches a rule condition, the automation rule runs a playground that can execute actions such as isolating a device via the Microsoft Defender for Endpoint connector, blocking an IP using a firewall connector, or opening a ticket in ITSM systems. This is the correct answer because it provides a first-party, built-in path that directly links Sentinel's alert pipeline to automated response actions via Log Apps' rich connector ecosystem, with no custom scripting required.

Why this answer

Sentinel automation rules with playbooks (option B) is correct because automation rules in Microsoft Sentinel trigger Logic App playbooks in response to analytics rule alerts, and those playbooks can call Microsoft Defender for Endpoint APIs to isolate devices and update firewall/blocklist mechanisms to block malicious IPs. This directly matches the requirement for automated incident response to a confirmed ransomware incident. Azure Policy (A) is for enforcing governance and compliance on Azure resources, not for orchestrating incident response actions.

Microsoft Defender for Cloud Apps (C) is a CASB for discovering and controlling cloud app usage, not for device isolation or IP blocking. Microsoft Intune (D) is for device management and compliance, not for automated security incident response workflows.

134
MCQhard

Your organization uses Microsoft Sentinel as its SIEM. You receive a large number of low-severity alerts from various sources, overwhelming the security operations team. You need to design a solution to reduce alert fatigue while ensuring that critical incidents are not missed. The solution should also automatically collect feedback from analysts when they close an incident. What should you implement?

A.Tune analytics rules to generate incidents only for high-fidelity alerts and use automation rules to collect feedback on incident closure
B.Create a separate analytics rule for each severity level
C.Implement a playbook that automatically closes low-severity alerts and collects feedback
D.Increase the severity threshold for all analytics rules
AnswerA

Tuning analytics rules is the correct approach because it targets the root cause of alert fatigue: noisy or overly broad detection logic. By refining query thresholds, alert grouping, and incident creation settings, you ensure that only high-fidelity findings become incidents, while automation rules can trigger a playbook (e.g., an HTTP request or Teams message) to gather analyst feedback at incident closure. This feedback loop lets security operations continuously improve rule tuning without adding manual burden.

Why this answer

Tuning analytics rules to generate incidents only for high-fidelity alerts directly reduces alert volume without compromising detection of critical threats. Automation rules in Microsoft Sentinel can trigger a playbook or run a logic app on incident closure, enabling automatic collection of analyst feedback via custom fields or external systems.

Exam trap

The trap here is that candidates confuse 'automatically closing low-severity alerts' (Option C) with a valid noise-reduction technique, failing to recognize that automatic closure without analyst review can suppress true positives and violates the requirement to not miss critical incidents.

How to eliminate wrong answers

Option B is wrong because creating a separate analytics rule for each severity level does not reduce alert volume—it merely organizes alerts by severity, still overwhelming the SOC. Option C is wrong because automatically closing low-severity alerts via a playbook bypasses analyst review and risks missing critical incidents that may initially appear low-severity; feedback collection should be tied to incident closure, not automatic closure. Option D is wrong because increasing the severity threshold for all analytics rules is a blunt approach that can cause high-fidelity, critical alerts to be downgraded or missed entirely, violating the requirement to not miss critical incidents.

135
MCQhard

Your organization has Microsoft Sentinel. You need to create an analytics rule that detects when a user account is created outside of business hours (9 AM to 5 PM, Monday-Friday). Which KQL query should you use as the rule query?

A.... | where dayofweek(TimeGenerated) between (1 .. 5) and datetime_part("hour", TimeGenerated) !between (9 .. 17)
B.... | where dayofweek(TimeGenerated) between (2 .. 6) and datetime_part("hour", TimeGenerated) !between (9 .. 17)
C.... | where dayofweek(TimeGenerated) between (2 .. 6) and datetime_part("hour", TimeGenerated) between (9 .. 17)
D.... | where dayofweek(TimeGenerated) !between (2 .. 6) or datetime_part("hour", TimeGenerated) between (9 .. 17)
AnswerB

This query is correct because KQL's dayofweek() returns an integer where Sunday=1, Monday=2, ..., Saturday=7. The range 2..6 therefore includes Monday, Tuesday, Wednesday, Thursday, and Friday exactly, and the !between (9..17) operator excludes hours that are greater than or equal to 9 and less than or equal to 17, so only hours before 9 AM or after 5 PM remain. Combining these conditions with AND yields all events that occurred on weekdays and outside standard business hours, which is precisely the requirement.

Why this answer

`dayofweek()` returns 1 for Sunday, 2 for Monday, ..., 7 for Saturday. To represent Monday (2) through Friday (6), the range must be `between (2 .. 6)`. The `!between (9 .. 17)` correctly excludes the 9 AM to 5 PM business hours, so the rule triggers only when a user account is created outside those hours on a weekday.

Exam trap

The trap here is that `dayofweek()` uses a 1-based index starting on Sunday (1), not Monday (1), so candidates often incorrectly use `between (1 .. 5)` expecting Monday through Friday, but that actually covers Sunday through Thursday.

How to eliminate wrong answers

Option A is wrong because `dayofweek(TimeGenerated) between (1 .. 5)` includes Sunday (1) through Thursday (5), which misses Friday and incorrectly includes Sunday. Option C is wrong because it uses `between (9 .. 17)` instead of `!between (9 .. 17)`, so it would detect accounts created *during* business hours, not outside them. Option D is wrong because it uses `!between (2 .. 6)` which includes weekends (Sunday and Saturday) and `or` with `between (9 .. 17)`, so it would fire for any account created during business hours on any day, including weekends, failing to target only weekday after-hours creation.

136
MCQeasy

Your organization has a Microsoft 365 E5 subscription and wants to detect insider data exfiltration attempts. You need to design a solution that can identify users copying sensitive data to personal cloud storage services. Which Microsoft Purview capability should you use?

A.Data Loss Prevention (DLP) policies
B.eDiscovery (Premium)
C.Communication Compliance
D.Insider Risk Management
AnswerD

Insider Risk Management correlates signals such as file copies to personal cloud storage, detecting exfiltration intent rather than only content matches. This satisfies the requirement to identify users moving sensitive data to unsanctioned services, which DLP alone cannot contextualise.

Why this answer

Microsoft Purview Insider Risk Management is designed to detect, investigate, and act on risky user activities such as data exfiltration to personal cloud storage. It uses machine learning and policy templates to correlate signals like unusual downloads, uploads to personal cloud services, and other indicators of insider risk. DLP policies enforce data handling rules but do not focus on detecting insider intent or anomalous behavior.

Exam trap

SC-100 often tests the boundary between DLP (policy enforcement) and Insider Risk Management (behavioral detection), so candidates who see 'sensitive data' and pick DLP miss the insider threat detection requirement.

How to eliminate wrong answers

Option A is wrong because DLP policies prevent sharing of sensitive data based on content and context, but they are enforcement-focused and do not provide the behavioral analytics and investigation workflow for insider exfiltration. Option B is wrong because eDiscovery (Premium) is for legal hold, identification, and collection of content for litigation or investigations, not proactive detection of insider risk. Option C is wrong because Communication Compliance monitors communications for policy violations (e.g., harassment, sensitive info in chat), not data exfiltration to cloud storage.

137
MCQmedium

A company is implementing a zero-trust security model. They need to enforce conditional access policies that require device compliance from Microsoft Intune. However, some users report being blocked when using personal devices that are not enrolled. What is the best approach to allow access while maintaining security?

A.Allow all devices but monitor with Defender for Cloud Apps
B.Require app protection policies via Microsoft Intune
C.Block all non-compliant devices
D.Require device enrollment for all devices
AnswerB

App protection policies via Microsoft Intune are correct because they apply conditional access at the app layer, safeguarding corporate data within managed applications even on unenrolled, personally owned devices. These policies enforce PIN, encryption, and restricted copy-paste, and can remotely wipe corporate data selectively. This approach meets zero trust requirements for identity and data protection without the privacy invasive step of full device management.

Why this answer

Microsoft Intune app protection policies (APP) can enforce data protection and access controls on personal devices without requiring full enrollment. This allows the company to maintain a zero-trust posture by applying conditional access policies that check for app-level compliance, such as requiring a managed browser or blocking copy/paste, while still permitting access from unenrolled personal devices. This approach aligns with the zero-trust principle of 'never trust, always verify' by verifying device health at the application layer rather than the device layer.

Exam trap

The trap here is that candidates often assume device compliance (via Intune enrollment) is the only way to enforce zero-trust access, overlooking that app protection policies can achieve similar security controls on unmanaged devices without requiring full device enrollment.

How to eliminate wrong answers

Option A is wrong because merely monitoring with Defender for Cloud Apps does not enforce any access control; it only provides visibility, leaving the organization vulnerable to non-compliant devices accessing sensitive data. Option C is wrong because blocking all non-compliant devices would deny access to all personal devices, which contradicts the requirement to allow access while maintaining security. Option D is wrong because requiring device enrollment for all devices would force users to enroll personal devices, which is often impractical and violates privacy, and does not address the scenario where users need to use unenrolled personal devices.

138
Multi-Selecthard

Your organization uses Microsoft 365 and wants to implement a data loss prevention (DLP) strategy. You need to ensure that sensitive data is protected both at rest and in transit, and that incidents are automatically reported to the security team. Which THREE actions should you take?

Select 3 answers
A.Deploy Microsoft Intune to control app permissions on mobile devices
B.Implement Conditional Access policies to block external sharing of sensitive data
C.Enable Endpoint DLP for Windows 10/11 devices
D.Configure Microsoft Purview DLP policies for Exchange, SharePoint, and OneDrive
E.Configure DLP incident reports to be sent to the security team via email or Teams
AnswersC, D, E

Endpoint DLP extends Microsoft Purview DLP to devices, inspecting content in documents, emails, and clipboard operations. When a policy match occurs, it blocks the action and raises an alert that appears in the Purview DLP incident report. This directly supports the requirement to protect data in use and report incidents.

Why this answer

Option C is correct because Endpoint DLP extends Microsoft Purview DLP to Windows 10/11 devices, monitoring and restricting sensitive data actions on endpoints (copy to USB, print, upload to cloud) so data at rest on devices and in use is protected. Option D is correct because configuring Microsoft Purview DLP policies for Exchange Online, SharePoint Online, and OneDrive for Business enforces protection for data at rest and in transit across email and cloud storage workloads, detecting sensitive information types and blocking or auditing risky sharing. Option E is correct because configuring DLP incident reports to be sent to the security team via email or Teams ensures automatic alerting and reporting of policy matches, satisfying the requirement that incidents are automatically reported.

Option A is not correct because Intune app protection policies manage mobile app permissions and are not the DLP mechanism that detects and protects sensitive data at rest and in transit. Option B is not correct because Conditional Access governs sign-in and access conditions, not DLP content inspection or automatic incident reporting for sensitive data.

139
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to design a role activation policy that requires approval from a security group for global administrator roles, but allows self-activation for other roles. What is the correct configuration?

A.Create a single PIM policy for all roles with approver group
B.Configure separate PIM settings per role: Global Administrator requires approval, others self-activate
C.Enable just-in-time access in Azure AD Identity Protection
D.Use Azure AD entitlement management with access packages
AnswerB

This is correct because PIM supports granular, per-role configuration of activation settings, including whether approval is required. For Global Administrator, you can enable 'Require approval to activate' and assign a specific approver group, while leaving other roles configured for self-activation without approval. This balances security for highly sensitive roles with operational efficiency for lower-privilege roles, directly matching the requirement.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role-specific activation settings. By creating separate PIM policies per role, you can require approval for the Global Administrator role while allowing self-activation for other roles. This granular control ensures that high-privilege roles have additional oversight, while lower-privilege roles remain agile.

Exam trap

The trap here is that candidates confuse PIM role-specific policies with broader identity governance tools like entitlement management or Identity Protection, failing to recognize that PIM's granular per-role settings are the correct mechanism for mixed approval requirements.

How to eliminate wrong answers

Option A is wrong because a single PIM policy applies uniformly to all roles, making it impossible to require approval for only Global Administrators while allowing self-activation for others. Option C is wrong because Azure AD Identity Protection focuses on risk-based policies for user sign-ins and sessions, not role activation approval workflows. Option D is wrong because Azure AD entitlement management manages access packages and resource access, not the activation approval process for built-in directory roles like Global Administrator.

140
MCQeasy

Your company uses Microsoft Purview to protect sensitive data. You need to automatically apply a retention label to documents containing credit card numbers detected in SharePoint Online. What should you configure?

A.Configure a Data Loss Prevention (DLP) policy to apply the label.
B.Create a sensitivity label with auto-labeling for SharePoint.
C.Use a trainable classifier to detect credit card numbers and apply the label.
D.Create an auto-labeling policy for retention labels targeting sensitive info types.
AnswerD

An auto-labeling policy for retention labels is the correct solution because it natively supports automatic application of retention labels to content that matches sensitive info types, such as credit card numbers. These policies run across a tenant and can target SharePoint sites, OneDrive accounts, and Exchange mailboxes, evaluating content against built-in sensitive information types and applying the designated retention label. This approach directly aligns with the requirement to protect sensitive data while ensuring it is retained appropriately. Auto-labeling for retention labels is distinct from sensitivity-label auto-labeling, as it specifically governs data lifecycle rather than classification.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply retention labels to documents based on sensitive info types, such as credit card numbers. This allows you to enforce retention rules without manual intervention, directly targeting the detected sensitive data in SharePoint Online.

Exam trap

The trap here is that candidates confuse retention labels with sensitivity labels, or assume DLP policies can apply retention labels directly, when in fact DLP applies sensitivity labels and auto-labeling policies are the correct mechanism for retention labels.

How to eliminate wrong answers

Option A is wrong because DLP policies are designed to prevent data loss by blocking or alerting on sensitive data, not to apply retention labels; they can apply sensitivity labels but not retention labels. Option B is wrong because sensitivity labels with auto-labeling are for classification and protection (e.g., encryption), not for retention; retention labels are a separate concept in Purview. Option C is wrong because trainable classifiers are used to identify content based on patterns or machine learning, but they do not directly apply retention labels; they can be used in auto-labeling policies, but the policy itself must be configured for retention labels targeting sensitive info types.

141
MCQhard

You are designing a Microsoft Purview solution for a healthcare organization that must retain electronic protected health information for seven years and ensure that when a custodian leaves the company, their mailbox content remains discoverable. The organization also wants to prevent users from permanently deleting content that is under retention. Which Microsoft Purview feature should you use?

A.Sensitivity labels with encryption applied to all email containing patient data
B.Retention labels published to Exchange mailboxes with a retention period and a retention policy for the workload
C.Data Loss Prevention policies that block sharing of patient records externally
D.Communication compliance policies that review messages for inappropriate content
AnswerB

Retention labels and retention policies in Microsoft Purview can keep Exchange mailbox content for a defined period and preserve it when a user leaves by converting the mailbox to an inactive mailbox if the hold is applied. Retention also blocks permanent deletion of items that are still within the retention period, which satisfies the preservation requirement across the seven-year window.

Why this answer

The scenario requires three things: a seven-year retention period, preservation of a departed custodian's mailbox, and prevention of permanent deletion. Retention labels and retention policies in Microsoft Purview deliver all three, because items under retention cannot be permanently removed and a mailbox under retention becomes inactive when the user account is deleted. The other features address confidentiality, exfiltration, or message review rather than retention.

Exam trap

The trap here is treating sensitivity labels or DLP as retention controls, when only retention labels and policies keep content and preserve inactive mailboxes.

142
MCQmedium

A company plans to implement Microsoft Purview to enforce data loss prevention (DLP) policies. They need to prevent users from sharing credit card numbers via email. What should they configure?

A.Create a sensitivity label and apply it to emails
B.Enable communication compliance policies
C.Create a DLP policy that detects and blocks credit card numbers in Exchange Online
D.Configure a retention policy for email
AnswerC

A DLP policy scoped to Exchange Online inspects email traffic and applies sensitive information type matching for credit card numbers, blocking sharing at the transport layer. This directly satisfies the stem's requirement to prevent email exfiltration, since Exchange Online is the workload governing mail flow within Microsoft Purview.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can be configured to detect sensitive data types, such as credit card numbers, in Exchange Online emails. When a DLP policy is created with a rule that identifies credit card numbers and blocks the email from being sent, it directly prevents users from sharing that data via email. This is the native mechanism for enforcing DLP on email traffic in Microsoft 365.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify data) with DLP policies (which enforce actions on data in motion), leading them to select Option A instead of the correct DLP policy.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data based on sensitivity, but they do not inherently detect or block specific sensitive information like credit card numbers in transit; they require manual or automatic labeling and rely on other controls (like DLP) for enforcement. Option B is wrong because communication compliance policies are designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading), not to block the sharing of specific sensitive data patterns like credit card numbers. Option D is wrong because retention policies control how long data is kept or deleted, not how data is shared or blocked in real-time; they have no effect on preventing the transmission of credit card numbers via email.

143
Multi-Selectmedium

A company uses Microsoft Purview to classify and label sensitive data. They want to automatically apply a sensitivity label to documents containing a specific custom sensitive information type. Which TWO components are required for this?

Select 2 answers
A.Data loss prevention (DLP) policy
B.Retention label
C.Custom sensitive information type
D.Auto-labeling policy
E.Trainable classifier
AnswersC, D

A custom sensitive information type allows you to define a pattern using regular expressions, keywords, and validity checks to match specific sensitive data (e.g., employee IDs). When this type is referenced in an auto-labeling policy, Purview scans content and applies the configured sensitivity label on matches. It is the mechanism that identifies the content pattern, making it the correct choice for classification and labeling based on custom-defined data.

Why this answer

Option C (Custom sensitive information type) is required because the scenario specifically calls for detecting a custom-defined pattern of sensitive data, and a custom SIT (defined via regex, function, or keyword list) is what identifies that unique content. Option D (Auto-labeling policy) is required because it is the client-side or service-side policy that automatically applies a sensitivity label to items matching a condition, and that condition can reference the custom SIT. Together, the custom SIT supplies the detection logic and the auto-labeling policy supplies the automatic label application.

Option A (DLP policy) is incorrect because DLP enforces protective actions like blocking or warning on data in motion or use, not the automatic application of sensitivity labels. Option B (Retention label) is incorrect because retention labels govern how long content is kept or deleted, not classification or labeling for sensitivity. Option E (Trainable classifier) is incorrect because trainable classifiers are used for content that is hard to define by pattern (e.g., resumes, contracts), whereas this scenario calls for a specific custom SIT.

Exam trap

The trap here is that candidates often confuse the role of a DLP policy (which enforces actions like blocking) with an auto-labeling policy (which applies labels), or they mistakenly think a trainable classifier is needed when a custom sensitive information type already provides deterministic pattern matching.

144
Multi-Selecthard

Your organization is designing a Zero Trust architecture using Microsoft 365 security features. You need to ensure that all access requests are verified and least-privilege principles are applied. Which TWO capabilities should you implement?

Select 2 answers
A.Privileged Identity Management (PIM)
B.Microsoft Defender for Cloud Apps
C.Microsoft Entra ID
D.Microsoft Purview
E.Conditional Access
AnswersA, E

Azure AD Privileged Identity Management (PIM) is the specific capability designed to enforce just-in-time (JIT) and time-bound activation of privileged roles, directly implementing least-privilege access by requiring step-up authentication, approval workflows, and justifications before elevation. PIM additionally issues scoped, temporary role assignments and provides audit logs and access reviews, making it the targeted answer for minimizing standing administrative privileges in a zero-trust architecture.

Why this answer

Conditional Access (E) is a core Zero Trust policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and risk at access time, enforcing controls like MFA and compliant-device requirements so every access request is explicitly verified. Privileged Identity Management (A) enforces least privilege by making admin roles eligible rather than permanently active, requiring activation with justification, approval, MFA, and time-bound assignments, which directly satisfies the least-privilege requirement. Together they cover the two stated needs: verify every request (Conditional Access) and minimize standing privileges (PIM).

Microsoft Defender for Cloud Apps (B) provides CASB visibility and threat protection but is not the mechanism that verifies access requests or enforces least privilege. Microsoft Entra ID (C) is the underlying identity platform that hosts Conditional Access and PIM, but as a directory service it is not itself the specific capability being implemented. Microsoft Purview (D) addresses data governance, compliance, and information protection, not access verification or privilege minimization.

145
MCQhard

You are designing a privileged access strategy for a company that uses Microsoft Entra ID. The company requires that administrators must activate their privileged roles only after providing a justification and obtaining approval from a designated approver. The activation must be limited to a maximum of 4 hours. You need to configure the solution. What should you use?

A.Microsoft Entra ID Protection risk policies that block sign-ins for privileged users with risky sign-in behavior.
B.Microsoft Entra Privileged Identity Management (PIM) with role settings configured for approval and maximum activation duration.
C.Microsoft Entra ID Governance access reviews for privileged roles, configured to run monthly.
D.Conditional Access policies that require multi-factor authentication and compliant devices for privileged roles.
AnswerB

Microsoft Entra Privileged Identity Management (PIM) allows you to configure role settings that require approval for activation and set a maximum activation duration. You can specify approvers, require justification, and limit activation to a specific number of hours. This directly meets the requirements for just-in-time privileged access with approval workflow and time-bound activation.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is designed for just-in-time privileged access. It allows you to configure roles as eligible, requiring activation with justification and approval. You can set the maximum activation duration, such as 4 hours, and designate approvers.

This ensures that administrators only have privileged access when needed and for a limited time, reducing the attack surface. Other options do not provide the required approval and time-bound activation features.

Exam trap

The trap here is confusing Conditional Access or access reviews with PIM, but only PIM provides just-in-time activation with approval and time limits.

146
Multi-Selecteasy

Your organization uses Microsoft Purview. You need to design a solution that discovers and classifies sensitive data across Microsoft 365 services. Which two services should you include in your data map? (Choose TWO.)

Select 2 answers
A.Power BI
B.SharePoint Online
C.Azure SQL Database
D.OneDrive for Business
E.Azure Blob Storage
AnswersB, D

SharePoint Online is the primary collaborative document repository in Microsoft 365 where organizations store most sensitive files, including contracts, policies, and confidential records. Microsoft Purview natively indexes SharePoint Online sites and document libraries, allowing sensitivity labels, trainable classifiers, and data loss prevention (DLP) policies to identify and protect sensitive content. Because SharePoint is central to M365 file storage and classification, it is the correct source to include in a Purview data classification design.

Why this answer

SharePoint Online (B) is correct because it is a core Microsoft 365 workload whose sites, document libraries, and files are scanned by Microsoft Purview's data map via the sensitive information types and trainable classifiers, enabling discovery and classification of sensitive data at rest. OneDrive for Business (D) is also correct because each user's personal Microsoft 365 storage is crawled by the same Purview data map, so documents containing sensitive data are identified and labeled consistently with SharePoint. Power BI (A), Azure SQL Database (C), and Azure Blob Storage (E) are not the intended Microsoft 365 services for this scenario: Power BI is a business analytics service, while Azure SQL Database and Azure Blob Storage are Azure (non-Microsoft 365) data sources that would be covered by separate Purview connectors or Azure-native classification rather than the Microsoft 365 service data map.

147
MCQeasy

Your organization uses Microsoft Sentinel to centralize security events. You need to ensure that alerts from Microsoft Defender for Cloud are automatically ingested into Sentinel. Which data connector should you enable?

A.DNS connector
B.Office 365 connector
C.Microsoft Defender for Cloud connector
D.Azure Activity connector
AnswerC

The Microsoft Defender for Cloud connector is the native data connector that directly imports security alerts and recommendations from Defender for Cloud into Sentinel via its API. This connector populates the SecurityAlert table with structured findings, including severity, status, and associated entities, enabling correlation with other data sources and automated SOAR actions. It is the only connector from the options that is purpose-built for this integration.

Why this answer

The Microsoft Defender for Cloud connector (formerly Azure Security Center) is specifically designed to ingest alerts and recommendations from Defender for Cloud into Sentinel. The other options are unrelated: Office 365 connector ingests Office logs, Azure Activity logs track Azure resource operations, and DNS connector ingests DNS queries.

148
Multi-Selectmedium

An organization uses Microsoft Defender XDR to detect and respond to threats. Which THREE data sources does Defender XDR ingest? (Choose three.)

Select 3 answers
A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Sentinel
D.Microsoft Defender for Office 365
E.Microsoft Intune
AnswersA, B, D

Microsoft Defender for Identity is a cloud-based security solution that monitors on-premises Active Directory and cloud identities, generating signals for identity-based attacks such as pass-the-hash, Kerberoasting, and lateral movement. Its telemetry, including user behavior, logon events, and group policy modifications, is ingested by Microsoft Defender XDR to correlate and enrich incident detection with the identity context that is often central to attacks.

Why this answer

Microsoft Defender XDR is the unified extended detection and response platform that correlates signals from Microsoft's first-party security workloads. Option A, Microsoft Defender for Identity, is correct because it feeds identity-based signals (domain controller sensors, AD FS, Entra ID) into Defender XDR for detecting identity threats like lateral movement and pass-the-hash. Option B, Microsoft Defender for Endpoint, is correct because it supplies endpoint telemetry (device alerts, file/process events) that Defender XDR correlates into incidents.

Option D, Microsoft Defender for Office 365, is correct because it contributes email and collaboration signals (phishing, malicious attachments/URLs) to the unified incident queue. Option C, Microsoft Sentinel, is not a native Defender XDR data source; it is a separate SIEM/SOAR that can ingest Defender XDR incidents, not the reverse. Option E, Microsoft Intune, is a device management service and is not one of the Defender XDR native signal sources, even though it integrates with Defender for Endpoint for compliance and onboarding.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel as a data source for Defender XDR, when in reality Sentinel is a SIEM that consumes data from Defender XDR, not the reverse.

149
MCQeasy

Your organization needs to enforce multi-factor authentication (MFA) for all users accessing Microsoft Entra ID integrated applications. However, users in the finance department should be exempted from MFA when accessing a specific legacy financial app that does not support modern authentication. What should you design?

A.Enable security defaults for all users
B.Enable per-user MFA and exclude the finance department
C.Use Microsoft Entra Identity Protection to require MFA based on risk
D.Create a Conditional Access policy that requires MFA for all cloud apps except the legacy app
AnswerD

A Conditional Access policy can include all cloud apps in the 'target resources' assignment and then exclude the legacy application from the same assignment, allowing you to require MFA for every other cloud app. When the finance department is included in the users/groups, they will be prompted for MFA unless the sign-in targets the excluded legacy app, which precisely matches the stated requirement. Conditional Access policies are evaluated at sign-in time and provide the granular, app-level scoping that the other options lack.

Why this answer

Conditional Access policies allow granular control over which applications require MFA. By creating a policy that requires MFA for all cloud apps except the legacy financial app, you can enforce MFA broadly while exempting the specific app that does not support modern authentication. This approach is more flexible and secure than per-user MFA or security defaults, as it can target specific applications and conditions.

Exam trap

The trap here is that candidates may think per-user MFA (Option B) is sufficient for granular exclusions, but it lacks application-level control and would either block the legacy app or leave the entire finance department unprotected.

How to eliminate wrong answers

Option A is wrong because enabling security defaults enforces MFA for all users without any exclusion capability, which would block the finance department from accessing the legacy app that does not support modern authentication. Option B is wrong because per-user MFA is a legacy method that does not allow application-specific exclusions; it either enables MFA for a user entirely or not, and excluding the entire finance department would leave them unprotected for all other apps. Option C is wrong because Identity Protection risk-based policies require MFA based on user or sign-in risk, not application-specific exemptions; it cannot exempt a specific legacy app from MFA requirements.

150
MCQmedium

Your organization deploys Microsoft Sentinel and wants to automatically respond to phishing emails reported by users. You need to recommend a solution that creates an incident in Sentinel and blocks the email sender in Exchange Online. What should you configure?

A.Use a watchlist to store known phishing senders.
B.Create an automation rule that runs a playbook when an incident is created.
C.Enable UEBA to detect anomalous email behavior.
D.Create an analytics rule that queries user-reported phishing data.
AnswerB

An automation rule can be set to trigger when a Sentinel incident is created, and its action can call a playbook. The playbook, a Logic App, can use the Exchange Online connector to block the sender, disable the account, or quarantine the email, depending on the response logic. Because automation rules fire immediately on incident creation, this option provides the desired automated response to the phishing event. This is the designated mechanism for incident-driven orchestration in Sentinel.

Why this answer

Microsoft Sentinel automation rules trigger playbooks (Logic Apps) in response to incident creation. A playbook can call the Exchange Online connector to block the sender and can also update the Sentinel incident, providing the automated response the scenario requires. This is the standard SOAR pattern in Sentinel.

Exam trap

SC-100 often tests the confusion between detection (analytics rules, UEBA) and response (automation rules + playbooks); candidates must pick the component that actually performs the blocking action.

How to eliminate wrong answers

Option A is wrong because a watchlist is just a reference list of data; it does not execute any response action. Option C is wrong because UEBA detects anomalous behavior but does not block senders or create incidents by itself. Option D is wrong because an analytics rule generates alerts/incidents but does not perform the blocking action in Exchange Online.

← PreviousPage 2 of 3 · 155 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Secops Identity Compliance questions.