Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 676–750

1279 questions total · 18pages · All types, answers revealed

Page 9

Page 10 of 18

Page 11
676
MCQmedium

Your company uses Microsoft Entra ID with P2 licenses. You want to require approval for users to activate the Global Administrator role. Which feature should you configure?

A.Privileged Identity Management (PIM)
B.Identity Protection
C.Conditional Access
D.Access reviews
AnswerA

Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. It enables approval workflows for role activation, requiring users to request elevation and obtain approval before gaining temporary administrative rights. This directly addresses the need for a controlled and auditable process for activating privileged roles.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides just-in-time privileged access, including the ability to require approval for role activation. By configuring PIM for the Global Administrator role, you can enforce that users must request activation and receive approval before gaining the role's permissions, ensuring least-privilege and auditability.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls sign-in conditions) with PIM's approval workflow, but Conditional Access cannot enforce a multi-step approval process for role activation; only PIM provides that capability.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and responding to identity risks (e.g., compromised accounts, risky sign-ins) and does not manage role activation workflows or approval requirements. Option C (Conditional Access) is wrong because it enforces access policies based on conditions like location or device state, but it does not provide approval-based role activation; it controls sign-in access, not role elevation. Option D (Access reviews) is wrong because it periodically recertifies existing role assignments, ensuring they are still needed, but it does not enforce an approval step for activating a role in real time.

677
Multi-Selecteasy

Which TWO Microsoft Entra features can be used to enforce multifactor authentication (MFA)?

Select 2 answers
A.Self-Service Password Reset
B.Security defaults
C.Identity Protection
D.Privileged Identity Management
E.Conditional Access
AnswersB, E

Security defaults are a foundational set of pre-configured identity security settings within Microsoft Entra ID designed to protect organizations from common identity-related attacks. When enabled, security defaults automatically enforce multi-factor authentication registration and usage for all users and administrators, requiring MFA for high-risk events and administrative tasks. This feature directly enforces MFA across the entire tenant, providing a strong baseline security posture.

Why this answer

Security defaults (B) is correct because it is a Microsoft Entra ID setting that, when enabled, automatically enforces MFA for all users, requiring them to register for MFA and use it at sign-in. Conditional Access (E) is correct because it lets administrators create policies that require MFA based on conditions such as user, group, application, location, or risk, making it the primary policy engine for enforcing MFA. Self-Service Password Reset (A) only allows users to reset or unlock their accounts and does not enforce MFA at sign-in.

Identity Protection (C) detects and reports risky sign-ins and users and can feed risk signals into Conditional Access, but by itself it does not enforce MFA. Privileged Identity Management (D) manages just-in-time role activation and approvals for privileged roles, not MFA enforcement for general sign-ins.

Exam trap

The trap here is that candidates often confuse Identity Protection or PIM as direct MFA enforcement features, when in reality they are risk-detection or privilege-management services that rely on Conditional Access to actually enforce MFA.

678
MCQmedium

You are a security administrator for a company that uses Microsoft 365. The company has a Microsoft Purview Data Loss Prevention (DLP) policy that blocks sharing of Social Security Numbers (SSNs) externally. Recently, a user accidentally sent an email containing SSNs to an external partner after overriding the policy by selecting a business justification. Management wants to prevent users from overriding the policy for SSNs. You need to update the DLP policy to ensure that users cannot override the block for SSNs. What should you do?

A.Modify the rule to set 'Allow override' to 'No' in the policy tip configuration.
B.Increase the rule priority to ensure it is enforced before other rules.
C.Remove the policy tip from the rule to prevent users from overriding.
D.Change the action from 'Block with override' to 'Block' and remove the policy tip.
AnswerA

Setting 'Allow override' to 'No' within the policy tip configuration directly controls the user's ability to bypass a Data Loss Prevention (DLP) policy. This specific setting removes the 'override' button or option from the policy tip presented to the user, effectively preventing them from providing a business justification to proceed with a blocked action. This ensures strict enforcement while still providing the user with crucial information about the policy violation, aligning with best practices for user education.

Why this answer

The 'Allow override' setting in the policy tip configuration directly controls whether users can bypass a DLP block action by providing a business justification. Setting this to 'No' prevents any override for the rule that blocks SSNs, ensuring that the block is enforced without exception. This is the specific mechanism in Microsoft Purview DLP to disable user overrides for a given rule.

Exam trap

The trap here is that candidates may think removing the policy tip or changing the action to 'Block' is necessary, but the correct approach is to keep the policy tip and disable the override setting, which is a subtle but distinct configuration in the DLP rule properties.

How to eliminate wrong answers

Option B is wrong because increasing rule priority only affects the order in which rules are evaluated, not the ability to override a rule; it does not change the override behavior. Option C is wrong because removing the policy tip would hide the notification from users, but the underlying 'Block with override' action would still allow override via other methods (e.g., Outlook client override prompts). Option D is wrong because changing the action to 'Block' and removing the policy tip would indeed prevent override, but this is not the intended method—the correct approach is to keep the policy tip and set 'Allow override' to 'No', which maintains user awareness while disabling the override capability.

679
MCQeasy

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that company data on personal devices is protected if the device is lost or stolen. What should you configure?

A.Compliance policy with device health requirements
B.Conditional Access policy requiring compliant devices
C.Full wipe action
D.Selective wipe action
AnswerD

A Selective wipe action, often referred to as "Retire" in Microsoft Intune, is the appropriate choice for removing only organizational data while preserving the user's personal information. This action specifically targets and deletes all managed company applications, data, email profiles, and VPN connections that were deployed or configured by Intune. It is ideal for scenarios where an employee leaves the company or a BYOD device is unenrolled, ensuring corporate data security without impacting personal privacy.

Why this answer

Selective wipe (Option D) is the correct configuration because it removes only corporate data from a personal device while preserving the user's personal apps, photos, and settings. In Microsoft Intune, a selective wipe targets managed app data and company email profiles via Exchange ActiveSync, leaving the device usable for personal purposes. This is the appropriate action for protecting company data on a lost or stolen BYOD device without overstepping into the user's private information.

Exam trap

The trap here is that candidates often confuse 'selective wipe' with 'full wipe' or assume that a Conditional Access policy alone can retroactively protect data already on a device, when in fact only a selective wipe actively removes company data from a lost or stolen personal device.

How to eliminate wrong answers

Option A is wrong because a compliance policy with device health requirements (e.g., requiring encryption or a minimum OS version) does not actively remove data; it only marks the device as noncompliant and can trigger Conditional Access blocks, but it does not wipe or protect data after loss. Option B is wrong because a Conditional Access policy requiring compliant devices blocks access from noncompliant devices but does not remove existing company data already stored on the device; it is a preventive control, not a remediation action. Option C is wrong because a full wipe resets the entire device to factory defaults, deleting all personal data, which is inappropriate for personal devices in a BYOD scenario and violates user privacy; it is intended for corporate-owned devices.

680
MCQmedium

A company has multiple Azure virtual machines running various workloads. They want a central solution that continuously assesses their security posture, identifies vulnerabilities, and provides recommendations to harden the environment. Which Azure service should they use?

A.Azure Firewall
B.Microsoft Defender for Cloud
C.Azure DDoS Protection
D.Microsoft Sentinel
AnswerB

Microsoft Defender for Cloud is the correct solution as it offers comprehensive cloud security posture management (CSPM) and cloud workload protection (CWP) capabilities. It continuously assesses the security state of Azure Virtual Machines, identifying vulnerabilities, misconfigurations, and deviations from security best practices. It then provides actionable security recommendations, a secure score, and integrates with vulnerability assessment tools to enhance the overall security posture of the VMs and their running workloads.

Why this answer

Microsoft Defender for Cloud is the correct service because it provides continuous security posture assessment, vulnerability identification, and actionable hardening recommendations across Azure, on-premises, and multi-cloud environments. It integrates with Azure Policy and uses the Secure Score to quantify security posture, making it the central solution described in the scenario.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a posture management and workload protection platform) with Microsoft Sentinel (a SIEM/SOAR for threat detection), because both are security services under the 'Defender' umbrella, but Sentinel focuses on log-based threat hunting rather than continuous vulnerability assessment and hardening recommendations.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a stateful network firewall that filters traffic based on rules (e.g., source/destination IP, port, protocol) but does not perform continuous security posture assessment or vulnerability scanning. Option C is wrong because Azure DDoS Protection is a dedicated service that mitigates Distributed Denial-of-Service attacks at the network layer (L3/L4) and does not assess vulnerabilities or provide hardening recommendations. Option D is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution that ingests logs and alerts for threat detection and incident response, not a continuous posture assessment and vulnerability management tool.

681
Multi-Selecthard

Which TWO of the following are examples of Microsoft Copilot for Security use cases?

Select 2 answers
A.Configuring firewall rules in Azure
B.Answering a natural language question about a KQL query
C.Resetting a user's password in Entra ID
D.Creating a new DLP policy in Microsoft Purview
E.Summarizing an incident investigation in natural language
AnswersB, E

Microsoft Copilot for Security is specifically engineered to understand and process natural language queries related to security operations. It can effectively translate a user's plain English question into a relevant Kusto Query Language (KQL) query, explain the syntax and purpose of an existing KQL query, or refine queries to extract specific security insights from logs within platforms like Microsoft Defender XDR or Microsoft Sentinel, significantly enhancing threat hunting capabilities.

Why this answer

Option B is correct because Microsoft Copilot for Security is designed to help security analysts understand and work with data such as KQL queries by allowing them to ask natural language questions and receive explanations or insights, which is a core embedded and standalone use case. Option E is correct because Copilot for Security can summarize incident investigations, including alerts, evidence, and analyst notes, into natural language to accelerate triage and reporting. Options A, C, and D are not Copilot for Security use cases because configuring firewall rules in Azure, resetting a user's password in Entra ID, and creating a new DLP policy in Microsoft Purview are administrative configuration or management tasks performed in their respective portals, not security analysis or investigation capabilities provided by Copilot for Security.

Exam trap

The trap here is that candidates may confuse Copilot for Security with general administrative tasks in Azure or Microsoft 365, assuming it can perform any action via natural language, when in fact it is specifically scoped to security analysis and incident response, not configuration or identity management.

682
MCQhard

A healthcare organization uses Microsoft Entra ID and needs to enforce that only users from the United States and Canada can access patient records. Access attempts from all other locations must be blocked. Which Microsoft Entra ID Conditional Access condition should be configured to meet this requirement?

A.Device state
B.Sign-in risk
C.Locations
D.Client apps
AnswerC

The Locations condition in Microsoft Entra Conditional Access is specifically designed to control access based on the network location from which a user is attempting to sign in. Administrators can define 'named locations' using specific public IPv4 ranges, representing trusted corporate networks, or by selecting entire countries/regions, allowing for granular policies to grant access only from approved geographies or block access from high-risk areas. This directly addresses the need to restrict access based on a user's physical or network geographic location.

Why this answer

The Locations condition in Microsoft Entra ID Conditional Access allows administrators to define named locations (e.g., countries or IP ranges) and then grant or block access based on those locations. By configuring a policy that blocks access from all countries except the United States and Canada, the organization can enforce geographic restrictions on patient record access.

Exam trap

The trap here is that candidates often confuse the Locations condition with Sign-in risk, mistakenly thinking that blocking by country is a risk-based control rather than a straightforward geographic restriction.

How to eliminate wrong answers

Option A is wrong because Device state controls access based on whether a device is marked as compliant or hybrid Azure AD joined, not based on geographic location. Option B is wrong because Sign-in risk is a condition that detects suspicious sign-in behavior (e.g., anonymous IP, leaked credentials) and is used for risk-based policies, not for blocking by country. Option D is wrong because Client apps condition filters access by application type (e.g., browser, mobile app, legacy auth), not by the user's physical or network location.

683
Multi-Selecteasy

Which TWO of the following are benefits of using Microsoft Entra ID for identity management? (Choose two.)

Select 2 answers
A.Storing passwords in plaintext
B.Conditional Access policies
C.Single sign-on (SSO)
D.Local authentication for all apps
E.On-premises authentication only
AnswersB, C

Conditional Access policies are a core security feature of Microsoft Entra ID, allowing organizations to enforce granular access controls based on specific, real-time conditions. These policies evaluate factors such as user location, device compliance, application sensitivity, and sign-in risk during an authentication attempt. By dynamically requiring multi-factor authentication, blocking access, or limiting session duration, Conditional Access significantly enhances security posture and compliance without impeding legitimate user productivity.

Why this answer

Option B (Conditional Access policies) is correct because Microsoft Entra ID provides a policy engine that evaluates signals such as user/group membership, device compliance, location, and risk to grant, block, or require MFA for access to cloud and integrated apps. Option C (Single sign-on, SSO) is correct because Entra ID acts as a centralized identity provider using protocols like SAML 2.0, WS-Federation, OpenID Connect, and OAuth 2.0, letting users authenticate once and access multiple applications without re-entering credentials. Option A is wrong because storing passwords in plaintext is a severe security anti-pattern and Entra ID stores credentials as salted hashes, not plaintext.

Option D is wrong because Entra ID is a cloud-based identity service, not a mechanism for local authentication of every app. Option E is wrong because Entra ID is a cloud identity provider and does not restrict authentication to on-premises only; it can integrate with on-premises AD via Entra Connect or Entra Cloud Sync.

Exam trap

SC-900 often tests the misconception that Entra ID includes on-premises-only or local authentication as benefits, when it actually provides cloud-based centralized identity with SSO and Conditional Access.

684
MCQmedium

A company uses Microsoft Entra ID (Azure AD). They have a cloud-based HR system (e.g., Workday) that contains employee records. They want to automate the process of creating user accounts in Microsoft Entra ID for new hires and deactivating accounts for terminated employees based on information from the HR system. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra Connect
B.Microsoft Entra Application Provisioning
C.Self-Service Password Reset (SSPR)
D.Microsoft Entra Access Reviews
AnswerB

Microsoft Entra Application Provisioning is a robust feature designed to automate the end-to-end lifecycle management of user identities. It directly integrates with cloud-based Human Resources (HR) systems, such as Workday or SAP SuccessFactors, to automatically create, update, and delete user accounts in Microsoft Entra ID and connected SaaS applications. This automation streamlines onboarding and offboarding processes, ensuring that user access is consistently aligned with their employment status and reducing manual administrative overhead.

Why this answer

Microsoft Entra Application Provisioning (specifically HR-driven provisioning) is the correct feature because it automates the creation, update, and deactivation of user accounts in Microsoft Entra ID based on changes in an external HR system like Workday. It uses SCIM (System for Cross-domain Identity Management) protocol to synchronize employee lifecycle events from the HR source to Entra ID, enabling fully automated user provisioning without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect (hybrid sync from on-prem AD) with HR-driven provisioning, but the question specifies a cloud-based HR system (Workday) with no on-premises AD involvement, making Application Provisioning the correct choice.

Why the other options are wrong

A

Microsoft Entra Connect is used for synchronizing on-premises Active Directory with Microsoft Entra ID, not for automating user provisioning from cloud HR systems like Workday.

C

Self-Service Password Reset (SSPR) allows users to reset their own passwords, but it does not automate the creation or deactivation of user accounts based on HR system data.

D

Access Reviews are used to review and certify existing access, not to automate the creation or deactivation of user accounts based on HR data.

When would these options actually be correct?

A

A company has an on-premises Active Directory and wants to synchronize user identities, passwords, and group memberships to Microsoft Entra ID for hybrid identity scenarios.

C

An exam question might ask: 'A company wants to allow users to reset their own passwords without help desk intervention. Which feature should they configure?' In that scenario, SSPR is the correct answer.

D

A company needs to periodically review and confirm that user access to critical applications is still appropriate, ensuring compliance and removing unnecessary permissions.

Why candidates pick the wrong answer

A

Candidates may confuse 'synchronization' with 'provisioning' and think Entra Connect can handle HR-driven automation, but it is designed for on-premises AD sync, not cloud HR integration.

C

Candidates may confuse SSPR with provisioning because both involve user account lifecycle management, but SSPR focuses only on password reset, not account creation or deactivation.

D

Candidates may confuse the concept of managing user lifecycle (provisioning) with reviewing access rights, as both involve user account governance.

685
MCQmedium

A security team wants to discover which cloud applications are being used by employees, including unsanctioned file-sharing and collaboration apps. They plan to upload network traffic logs from their firewall to analyze app usage and risk levels. Which feature of Microsoft Defender for Cloud Apps should they enable?

A.App Governance
B.Cloud Discovery
C.Conditional Access App Control
D.Information Protection
AnswerB

Cloud Discovery is a core capability of Microsoft Defender for Cloud Apps that specifically ingests and analyzes network traffic logs from firewalls, proxies, or endpoint agents. Its primary purpose is to identify all cloud applications accessed by users in an organization, including unsanctioned 'shadow IT,' and to assess their associated risk scores. This process provides crucial visibility into an organization's entire cloud app landscape by revealing usage patterns and potential vulnerabilities.

Why this answer

Cloud Discovery is the correct feature because it analyzes network traffic logs (uploaded from firewalls or proxies) to identify which cloud applications are in use, including unsanctioned file-sharing and collaboration apps. It provides a risk score for each discovered app, enabling the security team to assess usage and enforce governance policies.

Exam trap

The trap here is that candidates confuse Cloud Discovery (which analyzes uploaded logs to find unsanctioned apps) with Conditional Access App Control (which enforces policies on already-discovered apps), leading them to pick Option C instead of B.

How to eliminate wrong answers

Option A is wrong because App Governance focuses on monitoring and managing OAuth-enabled apps that have access to Microsoft 365 data, not on analyzing firewall logs to discover unsanctioned cloud apps. Option C is wrong because Conditional Access App Control enforces access policies in real-time for cloud apps (e.g., blocking downloads), but it does not perform discovery of apps from uploaded traffic logs. Option D is wrong because Information Protection deals with classifying, labeling, and protecting sensitive data (e.g., via sensitivity labels), not with discovering cloud app usage from network traffic.

686
MCQeasy

An organization adopts a Zero Trust security model. Which principle requires that every access request must be explicitly verified and granted least privilege regardless of the user's location or device?

A.Verify explicitly
B.Use least privilege access
C.Assume breach
D.Never trust, always verify
AnswerA

In a Zero Trust model, "Verify explicitly" mandates that all access requests are rigorously authenticated and authorized based on all available data points. This includes user identity, device health, location, service or workload, data classification, and any detected anomalies. Access is never implicitly granted; instead, it is always explicitly validated against policy before being permitted, ensuring a robust security posture.

Why this answer

The Zero Trust principle 'Verify explicitly' mandates that every access request—regardless of the user's location, device, or network—must be authenticated and authorized based on all available data points (e.g., user identity, device health, location, and real-time risk signals). This ensures that no implicit trust is granted, and least privilege is applied as a separate but complementary principle. In Microsoft's Zero Trust model, this is enforced through conditional access policies and continuous evaluation of session risk.

Exam trap

The trap here is that candidates confuse the popular phrase 'Never trust, always verify' with the official Microsoft Zero Trust principle 'Verify explicitly,' but the exam expects the exact terminology from the Microsoft documentation, not the generic slogan.

How to eliminate wrong answers

Option B is wrong because 'Use least privilege access' is a separate Zero Trust principle that limits user permissions to only what is needed for a task, but it does not address the requirement that every request must be explicitly verified regardless of location or device. Option C is wrong because 'Assume breach' is a principle focused on minimizing blast radius and segmenting access (e.g., using micro-segmentation and continuous monitoring), not on verifying every access request. Option D is wrong because 'Never trust, always verify' is a popular slogan summarizing Zero Trust philosophy, but it is not one of the three core principles defined by Microsoft (Verify explicitly, Use least privilege access, Assume breach); the question specifically asks for the principle that requires explicit verification and least privilege, and 'Verify explicitly' is the precise technical term.

687
MCQeasy

An attacker gains access to a company's email system and reads confidential customer emails. Which security principle has been compromised?

A.Integrity
B.Availability
C.Confidentiality
D.Non-repudiation
AnswerC

The scenario directly describes a breach of confidentiality, as an unauthorized attacker has gained access to private email communications. Confidentiality is the principle that prevents the unauthorized disclosure of information, ensuring that only authorized individuals or systems can view or access sensitive data. This compromise means the secrecy and privacy of the email content have been violated by an unapproved party.

Why this answer

Confidentiality is the security principle that ensures data is accessible only to authorized users. When an attacker reads confidential customer emails without authorization, the confidentiality of that data has been breached, as the information was exposed to an unintended party.

Exam trap

The trap here is that candidates often confuse confidentiality with integrity, mistakenly thinking that any unauthorized access to data implies data modification, but the core violation in this scenario is the unauthorized disclosure of information, not its alteration.

Why the other options are wrong

A

Integrity ensures data is not altered or tampered with, but the scenario describes unauthorized reading of emails, not modification.

D

Non-repudiation ensures that a party cannot deny having performed an action, such as sending an email. Reading emails does not involve denying an action; the breach is about unauthorized access to confidential data, which violates confidentiality.

When would these options actually be correct?

A

A question where an attacker modifies email content or deletes messages without authorization, asking which security principle is violated.

D

Non-repudiation would be correct in a scenario where an attacker sends a fraudulent email and later denies sending it, and the question asks which principle ensures the sender cannot deny the action. For example: 'An employee claims they never sent a sensitive email, but digital signatures prove otherwise. Which security principle is demonstrated?'

Why candidates pick the wrong answer

A

Candidates may confuse confidentiality with integrity, thinking that unauthorized access inherently implies data has been compromised in integrity.

D

Candidates may confuse non-repudiation with confidentiality because both involve email security. They might think that reading emails without authorization relates to non-repudiation, but non-repudiation is about accountability and proof of origin, not access control.

688
MCQmedium

A company wants to allow its employees to reset forgotten passwords or unlock their accounts without contacting the help desk. The solution must verify the user's identity using a phone call or mobile app notification before allowing the action. Which Microsoft Entra ID feature should be enabled?

A.Microsoft Entra ID Protection
B.Self-Service Password Reset (SSPR)
C.Privileged Identity Management (PIM)
D.Conditional Access
AnswerB

Self-Service Password Reset (SSPR) is a core Microsoft Entra ID capability specifically designed to empower end-users to securely reset their forgotten passwords or unlock their own accounts without requiring IT helpdesk intervention. It leverages pre-registered authentication methods, such as mobile app notifications, phone calls, or security questions, to verify the user's identity before allowing the password change or account unlock. This significantly reduces helpdesk calls and improves user productivity by enabling immediate account recovery.

Why this answer

B is correct because Self-Service Password Reset (SSPR) enables users to reset forgotten passwords or unlock accounts without help desk intervention. It supports identity verification via phone call or mobile app notification (Microsoft Authenticator), meeting the stated requirement exactly.

Exam trap

The trap here is confusing SSPR with Conditional Access or ID Protection, as both involve authentication controls, but only SSPR directly provides the self-service password reset and account unlock functionality with phone call or app notification verification.

Why the other options are wrong

A

Microsoft Entra ID Protection is designed to detect and respond to identity risks, not to enable users to reset their own passwords or unlock accounts via phone call or app notification.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not provide self-service password reset or account unlock capabilities with phone call or mobile app verification.

D

Conditional Access is a policy engine that enforces access controls based on signals like user location or device state, but it does not directly provide the self-service password reset or account unlock functionality with phone call or mobile app verification.

When would these options actually be correct?

A

A question asking which feature should be enabled to automatically block sign-ins from risky IP addresses or detect leaked credentials would make ID Protection the correct answer.

C

PIM would be correct if the question asked for a feature that enables just-in-time privileged access, manages role assignments, or provides approval workflows for elevated roles in Microsoft Entra ID.

D

A company wants to require multi-factor authentication (MFA) when users access sensitive applications from untrusted networks, using policies that evaluate conditions like location or device compliance before granting access.

Why candidates pick the wrong answer

A

Candidates may confuse identity protection features (like risk detection) with the authentication methods used in SSPR, assuming 'protection' covers password reset capabilities.

C

Candidates may confuse PIM with SSPR because both involve identity security and verification, but PIM focuses on privileged role management rather than end-user password reset.

D

Candidates may confuse Conditional Access with the authentication methods used in SSPR, as both involve verifying identity via phone or app, but Conditional Access is about controlling access, not enabling self-service password reset.

689
MCQhard

Refer to the exhibit. A compliance administrator is configuring role-based access control (RBAC) in Microsoft Purview compliance portal. Which role group would provide the permissions shown?

A.Compliance Administrator
B.Security Reader
C.Data Classification
D.Information Protection
AnswerD

The Information Protection role group is specifically designed to manage all aspects of sensitivity labels and related information protection features within the Microsoft Purview compliance portal. Members of this role group possess the necessary permissions to create, edit, publish, and delete sensitivity labels, configure label policies, and set up automatic labeling rules. This role provides the precise administrative capabilities required for comprehensive information protection management.

Why this answer

The exhibit displays permissions related to managing sensitivity labels, label policies, and data loss prevention (DLP) rules within Microsoft Purview. The Information Protection role group is specifically designed for administrators who need to configure and manage these information protection features, making it the correct choice as it directly encompasses all the displayed permissions.

Exam trap

The trap here is that candidates often confuse the 'Compliance Administrator' role group with the 'Information Protection' role group, because both involve compliance tasks, but the exhibit specifically lists permissions that map to information protection functions, not broader compliance management.

How to eliminate wrong answers

Option A is wrong because the Compliance Administrator role group provides broader permissions for compliance-related tasks (e.g., managing device compliance, eDiscovery, and audit logs) but does not include the specific 'Information Protection' and 'Data Classification' permissions shown. Option B is wrong because the Security Reader role group is read-only and cannot create or modify sensitivity labels, label policies, or DLP rules, which are required for the permissions displayed. Option C is wrong because the Data Classification role group focuses on data classification activities (e.g., viewing and managing sensitive information types) but does not include the full set of permissions for managing sensitivity labels and DLP policies that are shown in the exhibit.

690
MCQmedium

A company uses Microsoft 365 E5 and wants to implement information protection for sensitive data. They need to automatically apply sensitivity labels to documents stored in SharePoint Online based on the presence of credit card numbers. Which Microsoft Purview feature should they use?

A.Sensitivity labels with auto-labeling policies
B.Data loss prevention (DLP) policies
C.Retention labels and retention policies
D.Insider risk management policies
AnswerA

Sensitivity labels with auto-labeling policies in Microsoft Purview can automatically apply labels to documents in SharePoint Online when they match sensitive information types like credit card numbers. This feature scans content and applies the configured label, enabling persistent protection. It directly fulfills the requirement to automatically classify and label data based on content.

Why this answer

Auto-labeling policies for sensitivity labels in Microsoft Purview are designed to automatically classify and label content in SharePoint Online and other locations when it matches sensitive information types. This provides persistent protection and meets the requirement. DLP prevents sharing but does not label, retention manages lifecycle, and insider risk management detects risky behavior, so none of those automatically apply labels.

Exam trap

The trap here is confusing DLP, which blocks sharing, with auto-labeling, which applies classification labels to content at rest.

691
Multi-Selecthard

Which THREE capabilities are part of Microsoft Purview Data Lifecycle Management?

Select 3 answers
A.Retention labels
B.Data Loss Prevention policies
C.Retention policies
D.eDiscovery
E.Records management
AnswersA, C, E

Retention labels in Microsoft Purview Data Lifecycle Management enable organizations to classify content and apply specific retention settings directly to individual items, such as emails or documents. These labels can be applied manually by users, automatically based on conditions, or through event-based triggers, ensuring that data is retained or deleted according to regulatory or business requirements throughout its lifecycle. They also facilitate the declaration of records, making content immutable for compliance.

Why this answer

Retention labels (A) are a core Data Lifecycle Management capability, allowing items to be labeled manually or automatically so they are retained for a specified period and then deleted or disposed of. Retention policies (C) are also part of Data Lifecycle Management, applying retention or deletion settings at the workload, location, or user level (for example, Exchange mailboxes, SharePoint sites, OneDrive accounts, and Teams) without requiring per-item labeling. Records management (E) is the third correct capability, as it extends Data Lifecycle Management with file plan descriptors, event-based retention, and regulatory records that can be declared and locked as records.

Data Loss Prevention policies (B) belong to Microsoft Purview Data Loss Prevention, which detects and blocks sensitive data sharing rather than governing retention or deletion. eDiscovery (D) belongs to Microsoft Purview eDiscovery, which supports identifying, preserving, collecting, and reviewing content for legal or investigative cases, not lifecycle retention management.

Exam trap

SC-900 often tests the boundary between Purview solutions, tricking candidates into selecting DLP or eDiscovery because they sound like lifecycle controls when they actually belong to separate Purview pillars.

692
MCQeasy

An organization wants to automatically revoke access to cloud apps when an employee leaves the company. Which Microsoft Entra feature should they use?

A.Conditional Access
B.Automated user provisioning
C.Privileged Identity Management
D.Identity Protection
AnswerB

Automated user provisioning, often managed by services like Azure AD Connect or Azure AD provisioning to SaaS apps, synchronizes identity data between authoritative sources and target applications. When a user's account is disabled or deleted in the authoritative source (e.g., HR system or on-premises AD), the provisioning service detects this change and automatically propagates it to connected applications. This process disables the user's account and revokes their access to those applications and their associated data, directly addressing the requirement for automatic access revocation upon termination.

Why this answer

Automated user provisioning (B) is the correct answer because it can automatically disable or remove a user's access to cloud apps when the user is deleted or deactivated in the HR system or on-premises directory. This feature synchronizes identity lifecycle events (e.g., termination) to connected SaaS applications, ensuring revocation of access without manual intervention.

Exam trap

The trap here is that candidates confuse Conditional Access (which blocks new sign-ins) with full deprovisioning, not realizing that Conditional Access does not terminate existing sessions or remove the user account from the cloud app.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces access policies based on signals like location or device compliance at sign-in time, but it does not automatically revoke access when an employee leaves; it blocks new sign-ins but does not terminate existing sessions or deprovision accounts. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time privileged role activation and approval workflows, but it is not designed to deprovision standard user access to cloud apps upon termination. Option D is wrong because Identity Protection detects risks like leaked credentials or anomalous sign-ins and triggers remediation like requiring MFA, but it does not handle lifecycle-based deprovisioning when an employee leaves.

693
MCQmedium

Your organization uses Microsoft Purview Compliance Manager to track compliance with regulatory standards. You need to create a custom assessment for a new internal policy. What should you do first?

A.Define the score calculation method for the assessment
B.Create control actions and assign them to the assessment
C.Create a custom template with your internal controls
D.Use an existing Microsoft template and modify the improvement actions
AnswerC

To effectively incorporate an organization's unique internal controls and policies into Microsoft Purview Compliance Manager, creating a custom template is the essential first step. This custom template serves as the blueprint for any subsequent custom assessment, allowing administrators to define specific control families, controls, and their associated improvement actions that align precisely with internal requirements. Without a custom template, there is no structured framework to house these unique internal controls within the Compliance Manager environment.

Why this answer

In Microsoft Purview Compliance Manager, assessments are built from templates that define the controls, improvement actions, and scoring parameters. To create a custom assessment for a new internal policy, you must first create a custom template that includes your own controls, because assessments cannot be created from scratch without a template. This template serves as the foundation for the assessment, allowing you to define the specific controls and actions that map to your internal policy.

Exam trap

The trap here is that candidates often confuse the order of operations, thinking they can directly create an assessment or modify an existing template, when the correct first step is always to create a custom template that contains the internal controls.

How to eliminate wrong answers

Option A is wrong because defining the score calculation method is a configuration step that occurs after the template and assessment are created, not the first step. Option B is wrong because control actions are assigned to controls within a template, not directly to an assessment; you must first have a template with controls defined. Option D is wrong because modifying an existing Microsoft template's improvement actions would alter the built-in regulatory template, which is not intended for custom internal policies; you should instead create a new custom template from scratch.

694
MCQhard

A legal team is preparing for litigation and needs to collect relevant data from Microsoft Teams chats, email, and SharePoint documents. They need to place a hold on the data to prevent deletion, review it, and then use advanced analytics such as relevance ranking and email threading to reduce the review set. Which Microsoft Purview solution should they use to perform these tasks?

A.Microsoft Purview eDiscovery (Standard)
B.Microsoft Purview Copilot
C.Microsoft Purview eDiscovery (Premium)
D.Microsoft Purview Compliance Manager
AnswerC

Microsoft Purview eDiscovery (Premium) is the appropriate solution for legal teams preparing for litigation due to its advanced capabilities for managing large volumes of data. It provides intelligent analytics such as relevance ranking, email threading, and near-duplicate detection, which significantly reduce the data set requiring manual review. Furthermore, it supports advanced review workflows, legal holds, and communication with custodians, making it comprehensive for complex legal discovery processes.

Why this answer

Microsoft Purview eDiscovery (Premium) is the correct solution because it provides the full lifecycle of legal hold, collection, review, and advanced analytics such as relevance ranking, email threading, and predictive coding. These capabilities are specifically designed for complex litigation scenarios, whereas the Standard edition lacks the advanced analytics features needed to reduce the review set.

Exam trap

The trap here is that candidates confuse eDiscovery (Standard) with eDiscovery (Premium) because both support holds and searches, but only Premium includes the advanced analytics features explicitly mentioned in the question.

Why the other options are wrong

A

Microsoft Purview eDiscovery (Standard) lacks advanced analytics features like relevance ranking and email threading, which are required in this scenario to reduce the review set. It also does not support placing holds on data across Teams, email, and SharePoint in a unified manner.

B

Microsoft Purview Copilot is an AI assistant for security and compliance tasks, not a solution for legal hold, review, or advanced analytics like relevance ranking and email threading. It cannot perform eDiscovery functions such as placing holds on data or reducing review sets.

D

Microsoft Purview Compliance Manager is designed for managing compliance assessments and controls, not for collecting, holding, reviewing, or analyzing data from Teams, email, and SharePoint for litigation purposes.

When would these options actually be correct?

A

A legal team needs to perform basic eDiscovery tasks such as searching for content across Exchange Online, SharePoint Online, and OneDrive for Business, and placing holds on mailboxes and sites, but does not require advanced analytics or processing. They have a smaller case volume and do not need features like predictive coding or review sets.

B

A question asks: 'A compliance officer needs to quickly generate a summary of recent data retention policies and get recommendations for improving compliance posture. Which Microsoft Purview solution should they use?' In that scenario, Purview Copilot would be correct as it provides AI-driven insights and recommendations.

D

An organization needs to assess its compliance posture against regulatory standards (e.g., ISO 27001, NIST) and track remediation actions. The question would ask: 'Which Microsoft Purview solution helps manage compliance assessments and track improvement actions?'

Why candidates pick the wrong answer

A

Candidates may confuse 'Standard' with 'Premium' and assume that eDiscovery (Standard) includes all necessary capabilities, or they may underestimate the need for advanced analytics in litigation scenarios.

B

Candidates may confuse 'Copilot' with a tool that assists in legal review or analytics, assuming its AI capabilities extend to eDiscovery tasks like relevance ranking, when in fact it is designed for broader compliance assistance.

D

Candidates may confuse 'compliance' broadly with legal discovery tasks, or think Compliance Manager includes data collection and hold capabilities because it deals with regulatory requirements.

695
MCQmedium

A security architect explains the Zero Trust model to the board. They state that every access request must be fully authenticated and authorized based on identity, device health, location, and risk, regardless of whether the user is on the corporate network. Which Zero Trust principle does this statement represent?

A.Verify explicitly
B.Least privilege
C.Assume breach
D.Microsegmentation
AnswerA

"Verify explicitly" is a foundational principle of the Zero Trust model, mandating that all access requests, regardless of origin or resource, are rigorously authenticated and authorized. This involves evaluating every available data point, or "signal," including user identity, location, device health, service or workload, data classification, and anomalous behavior, before granting access. It moves beyond traditional perimeter-based security to ensure that trust is never assumed and is continuously re-evaluated for every transaction.

Why this answer

The statement emphasizes that every access request must be authenticated and authorized based on identity, device health, location, and risk, regardless of network location. This directly aligns with the 'Verify explicitly' principle of Zero Trust, which mandates that authentication and authorization are performed for every request using all available data points, not just once at the perimeter.

Exam trap

The trap here is that candidates often confuse 'Verify explicitly' with 'Least privilege' because both involve access control, but 'Verify explicitly' is about the continuous authentication/authorization of every request, while 'Least privilege' is about limiting permissions after access is granted.

How to eliminate wrong answers

Option B (Least privilege) is wrong because it focuses on limiting user access rights to only what is necessary to perform a task, not on the continuous verification of every request. Option C (Assume breach) is wrong because it deals with designing systems to minimize blast radius and segment access under the assumption that a breach has already occurred, not with the upfront verification of each request. Option D (Microsegmentation) is wrong because it is a network architecture technique that breaks the network into small, isolated segments to limit lateral movement, not a principle for authenticating and authorizing every access request.

696
MCQmedium

Your legal team needs to search for all emails from a specific executive that mention a project name 'ProjectX' for a litigation hold. Which Microsoft Purview tool should they use?

A.Microsoft Purview Communication Compliance
B.Microsoft Purview Data Loss Prevention
C.Microsoft Purview Audit
D.Microsoft Purview eDiscovery
AnswerD

Microsoft Purview eDiscovery provides a comprehensive set of tools specifically designed to search for, preserve, collect, analyze, and export electronic content from Microsoft 365 for legal and investigative purposes. It enables legal teams to perform targeted searches across mailboxes, SharePoint sites, and Teams messages using keywords, date ranges, and sender/recipient criteria, making it the ideal solution for retrieving specific emails relevant to litigation.

Why this answer

Microsoft Purview eDiscovery (specifically Content Search or eDiscovery (Premium)) is the correct tool because it is designed to search across Exchange Online mailboxes, SharePoint sites, and other data sources for specific content like emails containing 'ProjectX' from a specific executive. This capability directly supports litigation holds by allowing you to identify, preserve, and export relevant data. Communication Compliance focuses on policy-based detection of inappropriate communications, not ad-hoc searches for litigation.

Exam trap

The trap here is that candidates confuse Audit (which logs metadata about who did what) with eDiscovery (which searches the actual content of messages and documents), leading them to choose Audit when they need to search email body content for specific terms.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Communication Compliance is used to detect and review communications that violate organizational policies (e.g., harassment or insider trading), not to perform ad-hoc searches for specific keywords or senders for litigation holds. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental sharing of sensitive information by applying policies to data in transit or at rest, not to search for and preserve specific emails for legal discovery. Option C is wrong because Microsoft Purview Audit logs user and admin activities (e.g., who accessed a file or sent an email) but does not allow you to search the body or subject of emails for keywords like 'ProjectX' or filter by a specific sender's mailbox content.

697
MCQmedium

A compliance administrator creates the DLP policy shown in the exhibit. When a user shares a document containing a credit card number with an external partner, what is the expected outcome?

A.The document is blocked from being shared externally, and the user receives a notification.
B.The document is automatically deleted.
C.A sensitivity label is automatically applied.
D.The document is blocked from being shared both internally and externally.
AnswerA

This DLP policy is configured with an action to 'BlockAccess' specifically targeting 'BlockExternal' sharing. Consequently, any document matching the policy's conditions will be prevented from being shared outside the organization. Concurrently, the 'NotifyUser' action ensures that the individual attempting the sharing receives an immediate notification, informing them of the policy violation and the blocked action.

Why this answer

The DLP policy is configured with an action to block external sharing and notify the user when a credit card number is detected. When the user shares the document externally, the policy triggers this action, preventing the share and sending a notification to the user. This matches option A exactly.

Exam trap

The trap here is that candidates confuse DLP actions with sensitivity label auto-classification or assume DLP deletes content, but DLP only blocks or restricts sharing based on policy rules.

How to eliminate wrong answers

Option B is wrong because DLP policies do not automatically delete documents; they block sharing or apply protective actions, not deletion. Option C is wrong because sensitivity labels are applied via Microsoft Information Protection (MIP) policies, not DLP policies; DLP does not apply labels automatically. Option D is wrong because the policy specifically targets external sharing only, not internal sharing; internal sharing would not be blocked unless explicitly configured.

698
MCQeasy

A company wants to ensure that emails containing credit card numbers are blocked from being sent externally. Which Microsoft Purview solution should they use?

A.Sensitivity labels
B.Communication compliance
C.Information barriers
D.Data Loss Prevention (DLP) policy
AnswerD

Data Loss Prevention (DLP) policies are purpose-built to identify, monitor, and protect sensitive information across various locations, including email, cloud apps, and endpoints. By utilizing sensitive information types (SITs) to detect patterns like credit card numbers, DLP policies can proactively enforce actions such as blocking an email from being sent, notifying administrators, or encrypting the content. This directly prevents the unauthorized sharing or exfiltration of sensitive data.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and protect sensitive data, such as credit card numbers, by scanning email content and attachments. When a DLP policy is configured to block external sharing of this sensitive information, it can automatically prevent the email from being sent, ensuring compliance with data protection regulations.

Exam trap

The trap here is that candidates may confuse the proactive blocking capability of DLP with the reactive monitoring or classification features of communication compliance or sensitivity labels, leading them to select a wrong answer that addresses a different compliance scenario.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data through encryption and visual markings, but they do not actively block the transmission of emails containing sensitive data like credit card numbers. Option B is wrong because communication compliance is designed to detect and review inappropriate or policy-violating communications (e.g., harassment, insider trading), not to block emails based on the presence of specific sensitive data patterns. Option C is wrong because information barriers are used to prevent communication and collaboration between specific groups or users to avoid conflicts of interest, not to scan or block emails for sensitive content like credit card numbers.

699
MCQeasy

Your company, Contoso, uses Microsoft Entra ID for employee identity management. You need to ensure that when an employee leaves the company, their access to all SaaS applications is automatically revoked within 24 hours. The HR department updates the employee status in a cloud HR system (Workday). What should you do?

A.Ask HR to manually disable each user in Microsoft Entra ID after termination.
B.Configure Microsoft Entra ID provisioning from Workday to automatically disable users when their employment status changes.
C.Use Microsoft Graph API to write a custom application that polls Workday and disables users.
D.Create an Azure Automation runbook that runs daily and checks Workday for terminated employees, then disables them in Entra ID.
AnswerB

Configuring Microsoft Entra ID provisioning from Workday leverages Workday as the authoritative system of record for employee status. This automated, event-driven integration uses the SCIM protocol to automatically update user accounts in Entra ID, including disabling them, immediately upon a status change in Workday. This ensures timely and accurate deprovisioning, consistently meeting the 24-hour requirement for access revocation and enhancing overall security and compliance.

Why this answer

Microsoft Entra ID supports automated user provisioning from Workday via the built-in Workday to Entra ID provisioning connector. When an employee's status changes to 'terminated' in Workday, the provisioning service automatically disables the corresponding user account in Entra ID, typically within 40 minutes (well under the 24-hour requirement). This eliminates manual intervention and ensures timely revocation of access to all SaaS applications integrated with Entra ID.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing custom development (C or D) or manual processes (A), failing to recognize that Microsoft provides a native, automated provisioning connector specifically designed for this exact HR-driven lifecycle scenario.

How to eliminate wrong answers

Option A is wrong because manually disabling users in Entra ID is inefficient, error-prone, and does not meet the automated 24-hour revocation requirement. Option C is wrong because using Microsoft Graph API to build a custom polling application is unnecessarily complex, requires development and maintenance overhead, and is not the recommended out-of-box solution when the native Workday provisioning connector exists. Option D is wrong because an Azure Automation runbook that polls Workday daily introduces latency (up to 24 hours) and requires custom scripting, whereas the native provisioning service provides near-real-time synchronization without additional infrastructure.

700
MCQhard

Refer to the exhibit. The exhibit shows an alert from Microsoft Defender for Endpoint. The SOC team needs to decode the PowerShell command to understand the malicious intent. Which tool or method should they use?

A.Search for the SHA256 hash in threat intelligence feeds
B.Decrypt the command using the device's decryption keys
C.Use PowerShell script block logging to capture the decoded command
D.Decode the Base64 string using a built-in decoder or online tool
AnswerD

The `-EncodedCommand` parameter in PowerShell specifically utilizes Base64 encoding to obfuscate or transmit commands. To understand the actual actions the command intends to perform, the Base64 string must be decoded. This can be easily achieved using various built-in PowerShell cmdlets, programming language functions, or readily available online decoding tools, providing immediate insight into the attacker's intent.

Why this answer

The exhibit shows a PowerShell command encoded in Base64, which is a common obfuscation technique used by attackers to hide malicious intent. Decoding the Base64 string using a built-in decoder (e.g., `[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String()`) or an online tool directly reveals the plaintext command. This is the correct approach because Base64 is not encryption—it is an encoding scheme that can be reversed without any keys.

Exam trap

The trap here is that candidates confuse encoding (Base64) with encryption, leading them to incorrectly select 'decrypt' or 'decryption keys' when the solution is simply decoding without any cryptographic key.

How to eliminate wrong answers

Option A is wrong because searching for the SHA256 hash in threat intelligence feeds would identify known malware samples, but it does not decode the PowerShell command itself; the hash is a fingerprint of the file, not the encoded string. Option B is wrong because the command is encoded with Base64, not encrypted, so there are no decryption keys involved; decryption implies a cipher and key, which is a fundamental misunderstanding of encoding vs. encryption. Option C is wrong because PowerShell script block logging captures the decoded command after it has been executed, but the SOC team needs to decode the command before execution to understand intent; script block logging is a detection mechanism, not a decoding tool.

701
Multi-Selecteasy

Which TWO capabilities are part of Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Application management
B.Single sign-on (SSO)
C.Cloud security posture management
D.Mobile device management (MDM)
E.Security information and event management (SIEM)
AnswersA, B

Application management is a core Microsoft Entra ID capability, covering app registration, single sign-on configuration, provisioning and access policies for cloud and on-premises applications. It satisfies the stem's requirement by being one of the two listed capabilities genuinely delivered by the service, rather than by a separate product such as Defender or Purview.

Why this answer

Application management (A) is a core Microsoft Entra ID capability, allowing administrators to register, configure, and assign enterprise applications and manage app roles, permissions, and provisioning. Single sign-on (B) is also a native Entra ID feature, enabling users to authenticate once and access integrated SaaS and on-premises applications via protocols such as SAML, OAuth 2.0, and OpenID Connect. Cloud security posture management (C) belongs to Microsoft Defender for Cloud, not Entra ID.

Mobile device management (D) is provided by Microsoft Intune, and security information and event management (E) is delivered by Microsoft Sentinel, so neither is an Entra ID capability.

Exam trap

The trap here is that candidates confuse Microsoft Entra ID's identity and access management capabilities with broader security tools like Defender for Cloud (CSPM) or Sentinel (SIEM), or with device management tools like Intune (MDM), because all are part of Microsoft's security portfolio but serve distinct functions.

702
Multi-Selecteasy

Which TWO are capabilities of Microsoft Intune? (Choose two.)

Select 2 answers
A.Mobile application management (MAM)
B.Identity protection
C.Security posture management
D.Data loss prevention
E.Mobile device management (MDM)
AnswersA, E

Intune's Mobile Application Management (MAM) capabilities allow organizations to manage and protect corporate data within applications, even on personal devices (BYOD) not enrolled in MDM. This includes enforcing policies like requiring a PIN for app access, preventing copy/paste of corporate data to personal apps, and encrypting data at rest within the app container. MAM ensures data security and compliance without requiring full device control.

Why this answer

Microsoft Intune is a cloud-based endpoint management solution that provides both Mobile Device Management (MDM) and Mobile Application Management (MAM). MDM allows administrators to enroll, configure, and secure devices (e.g., enforce PIN policies, wipe lost devices), while MAM enables management of applications and their data on both enrolled and unenrolled devices (e.g., restrict copy/paste between managed apps). These are the two core capabilities of Intune.

Exam trap

The trap here is that candidates often confuse Intune's capabilities with those of other Microsoft security solutions, such as associating Identity Protection (Entra ID) or DLP (Purview) with Intune, because all are part of the Microsoft security ecosystem but serve distinct functions.

703
MCQeasy

You need to allow users to reset their own passwords without contacting the help desk. Which Microsoft Entra feature should you enable?

A.Microsoft Authenticator
B.Identity Governance
C.Self-service password reset
D.Conditional Access
AnswerC

Self-service password reset (SSPR) is a Microsoft Entra ID feature that allows users to reset or unlock their own passwords without requiring administrator or help desk intervention. Users are prompted to verify their identity using pre-registered authentication methods, such as a mobile app, phone call, or email, before they can set a new password. This capability significantly reduces help desk calls and improves user productivity by providing immediate password recovery.

Why this answer

Self-service password reset (SSPR) is the Microsoft Entra feature that allows users to reset their own passwords without contacting the help desk. It is designed to reduce help desk costs and improve user productivity by enabling password changes or unlocks through a verified authentication method, such as email, phone, or security questions.

Exam trap

The trap here is that candidates often confuse the authentication app (Microsoft Authenticator) with the self-service password reset feature, thinking the app itself provides password reset capabilities, when in fact it only provides a second factor for authentication.

How to eliminate wrong answers

Option A is wrong because Microsoft Authenticator is a multi-factor authentication app that provides a second factor for sign-in, not a self-service password reset mechanism. Option B is wrong because Identity Governance focuses on managing user access rights, certifications, and lifecycle, not on enabling users to reset their own passwords. Option D is wrong because Conditional Access is a policy engine that enforces access controls based on conditions like location or device state, but it does not provide a direct password reset capability.

704
MCQhard

You are investigating a potential data leak. You need to find all emails that contain the word 'confidential' sent to external recipients in the last 30 days. Which Microsoft Purview tool should you use?

A.Communication Compliance
B.Audit Log Search
C.Content Search
D.Data loss prevention (DLP) policy
AnswerC

Content Search, accessible through the Microsoft Purview compliance portal, is specifically engineered for eDiscovery and investigative purposes, enabling comprehensive searches across diverse content locations. It allows investigators to pinpoint specific keywords, phrases, sensitive information types, or other properties within mailboxes, SharePoint sites, OneDrive accounts, and Microsoft Teams chats. This capability makes it the ideal tool for locating and collecting potentially leaked data across an organization's digital repositories during an investigation.

Why this answer

Content Search (option C) is the correct tool because it allows you to perform targeted eDiscovery searches across Exchange Online mailboxes, including searching for specific keywords like 'confidential' and filtering by date range and recipient type (external recipients). It provides the exact capability to locate all emails containing the word 'confidential' sent to external recipients in the last 30 days, making it the appropriate choice for investigating a potential data leak.

Exam trap

The SC-900 exam often tests the distinction between proactive DLP policies (which prevent leaks) and reactive Content Search (which finds existing leaks), causing candidates to mistakenly choose DLP policy when the question asks for a tool to find already-sent emails.

How to eliminate wrong answers

Option A is wrong because Communication Compliance is designed to detect and review communications that violate organizational policies (e.g., harassment, insider trading), not to perform ad-hoc keyword searches for data leak investigations; it focuses on policy-based detection and remediation, not forensic search. Option B is wrong because Audit Log Search records user and admin activities (e.g., who accessed a file, when a policy was changed) but does not search the content of emails; it cannot find emails containing the word 'confidential' as it only logs metadata, not message body or subject text. Option D is wrong because a Data Loss Prevention (DLP) policy is a proactive, rule-based system that monitors and blocks sensitive data in transit or at rest based on predefined conditions; it is not a retrospective search tool and cannot be used to find all historical emails matching a specific keyword and recipient filter.

705
MCQmedium

A company uses Microsoft Entra ID. The security team wants to allow users to sign in only from devices that are known and managed by the organization, and to block sign-ins from personal devices. They need to enforce this for all users accessing Microsoft 365 apps. What should they configure?

A.A Conditional Access policy that requires the device to be marked as compliant or Microsoft Entra hybrid joined.
B.Multi-factor authentication (MFA) registration for all users, enforced through Security Defaults.
C.A named location in Microsoft Entra ID that includes only the corporate network IP ranges, and a Conditional Access policy that blocks all other locations.
D.A Microsoft Entra ID Protection risk policy that blocks sign-ins with a high sign-in risk.
AnswerA

Conditional Access can evaluate device state as a condition. By requiring the device to be compliant or Microsoft Entra hybrid joined, only organizational devices allowed by Intune or joined to on-premises AD are permitted. This directly enforces the requirement to block personal devices for Microsoft 365 apps.

Why this answer

Conditional Access is the policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and app to make access decisions. Requiring the device to be compliant or Microsoft Entra hybrid joined ensures that only devices managed by the organization are granted access. This directly satisfies the need to block personal devices while allowing corporate-managed devices.

Exam trap

The trap here is confusing device-based Conditional Access with risk-based ID Protection policies, which assess compromise likelihood rather than device ownership.

706
MCQhard

Refer to the exhibit. An administrator runs the Azure CLI commands shown. What is the purpose of these commands?

A.To create a new service principal.
B.To list all Azure subscriptions.
C.To log in to Azure as a user with MFA.
D.To authenticate a service principal for automated tasks.
AnswerD

The `az login --service-principal` command is precisely engineered for non-interactive authentication, making it ideal for automated processes. By providing the application ID and either a client secret or certificate, it enables scripts, CI/CD pipelines, and other unattended applications to securely access Azure resources without human intervention. This method ensures programmatic access for tasks where a human user login is impractical or undesirable.

Why this answer

The Azure CLI commands shown are used to authenticate a service principal for automated tasks. Specifically, `az login --service-principal -u <app-id> -p <password> --tenant <tenant-id>` authenticates using the service principal's credentials without interactive user login, enabling non-interactive automation or scripts.

Exam trap

The trap here is that candidates confuse the `az login` command with creating a service principal, but `az ad sp create-for-rbac` is the command for creation, while `az login --service-principal` is strictly for authentication.

How to eliminate wrong answers

Option A is wrong because the commands do not create a new service principal; they authenticate an existing one using its app ID and password. Option B is wrong because the commands do not list Azure subscriptions; they perform a login operation, and listing subscriptions would require a separate command like `az account list`. Option C is wrong because the commands use `--service-principal` with a password, which bypasses MFA; MFA is only triggered for interactive user logins, not service principal authentication.

707
MCQmedium

A security administrator receives an alert about a suspicious sign-in from an unfamiliar location. The user verified the sign-in as legitimate. Which Microsoft Entra ID feature should be used to reduce false positives for this user?

A.Passwordless authentication
B.Privileged Identity Management
C.Identity Protection confirm user safe
D.Conditional Access policies
AnswerC

The "Confirm user safe" action within Microsoft Entra Identity Protection is specifically designed to address false-positive risk detections. When a security administrator confirms a user is safe, it signals to the Identity Protection risk engine that the detected activity was legitimate and not a compromise. This action effectively dismisses the current risk event and helps refine the machine learning model, preventing similar future legitimate activities from generating new alerts for that specific user.

Why this answer

Microsoft Entra ID Identity Protection's 'Confirm user safe' feature allows administrators to manually override a risk detection when a user confirms a suspicious sign-in was legitimate. This reduces false positives by telling Identity Protection to ignore that specific risk event for that user, preventing future alerts based on the same detection.

Exam trap

The trap here is that candidates confuse Conditional Access policies (which can block or challenge sign-ins based on risk) with Identity Protection's manual risk remediation actions like 'Confirm user safe', but Conditional Access does not provide a way to retroactively dismiss a false positive alert.

How to eliminate wrong answers

Option A is wrong because passwordless authentication (e.g., Windows Hello for Business, FIDO2 security keys) eliminates passwords but does not provide a mechanism to confirm a suspicious sign-in as safe or reduce false positives from risk detections. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time access and approval workflows for privileged roles, not the ability to dismiss or confirm risk detections for sign-in anomalies. Option D is wrong because Conditional Access policies enforce access controls (e.g., require MFA, block locations) based on conditions, but they do not include a 'confirm safe' action to reduce false positives after a sign-in has been flagged.

708
Multi-Selecthard

A healthcare organization is implementing Microsoft Purview Data Lifecycle Management to retain medical records for 7 years. Which THREE components must be configured to achieve this retention requirement?

Select 3 answers
A.Create a retention label policy to publish the label.
B.Create a retention label with a retention period of 7 years.
C.Apply a sensitivity label to classify the records.
D.Configure adaptive scopes to target the relevant users or sites.
E.Implement Data Loss Prevention (DLP) policies to prevent data exfiltration.
AnswersA, B, D

After a retention label is defined, it must be published via a retention label policy to make it available for users or auto-application within Microsoft 365 services like SharePoint, OneDrive, and Exchange. This policy specifies which locations the label will be published to, ensuring the label appears as an option for manual application or is used by auto-apply policies. Without publishing through a policy, the label remains an administrative definition and cannot be actively used to manage content lifecycle.

Why this answer

A retention label policy is required to publish the retention label so that it can be automatically or manually applied to the medical records. Without publishing the label via a policy, the label itself cannot be assigned to content, and the retention period will not take effect.

Exam trap

The trap here is that candidates often confuse sensitivity labels (classification/protection) with retention labels (lifecycle management), leading them to select Option C, or they mistakenly think DLP policies are required for retention, when in fact DLP is a separate security control.

709
MCQmedium

A company runs workloads in Microsoft Azure and in Google Cloud Platform (GCP). The security team needs a single dashboard to view the security posture of both cloud environments, get recommendations for misconfigurations based on best practices, and track compliance with industry standards such as ISO 27001 and PCI DSS. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Endpoint
AnswerA

Microsoft Defender for Cloud provides multi-cloud posture management by connecting GCP projects alongside Azure subscriptions, giving one dashboard for secure score, misconfiguration recommendations, and regulatory compliance assessments against standards such as ISO 27001 and PCI DSS. This directly satisfies the stem's cross-cloud visibility and compliance-tracking requirements.

Why this answer

Microsoft Defender for Cloud is the correct solution because it provides a unified dashboard for assessing and improving the security posture of multicloud environments, including Azure and GCP. It offers continuous assessment against best practices (e.g., the Microsoft cloud security benchmark), generates actionable recommendations for misconfigurations, and tracks compliance with industry standards like ISO 27001 and PCI DSS through built-in regulatory compliance dashboards.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM for threat detection) with Defender for Cloud (a CSPM for posture management), because both appear under the 'Microsoft security solutions' umbrella and both can ingest data from multiple clouds, but Sentinel is not designed for compliance tracking or misconfiguration recommendations.

Why the other options are wrong

B

Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat detection, not a dashboard for multi-cloud security posture management, misconfiguration recommendations, or compliance tracking against standards like ISO 27001 and PCI DSS.

D

Microsoft Defender for Endpoint focuses on endpoint protection (antivirus, EDR) for devices, not on multi-cloud security posture management, compliance tracking, or misconfiguration recommendations across Azure and GCP.

When would these options actually be correct?

B

A company needs to collect and analyze security logs from multiple clouds, detect threats, and orchestrate automated responses to incidents. They require a centralized SIEM for real-time monitoring and investigation across Azure and GCP.

D

A company needs a unified endpoint security solution to protect devices (Windows, macOS, Linux) from threats, with capabilities like antivirus, attack surface reduction, and endpoint detection and response (EDR), but does not require multi-cloud posture management.

Why candidates pick the wrong answer

B

Candidates may confuse Sentinel's log aggregation and threat detection capabilities with the posture management and compliance features of Defender for Cloud, assuming a SIEM can also provide compliance dashboards and recommendations.

D

Candidates may confuse 'Defender' branding, assuming all Defender products provide similar cloud security capabilities, or they may think endpoint security includes cloud workload protection.

710
MCQeasy

A security administrator needs to ensure that only compliant and trusted devices can access Microsoft 365 resources. They want to evaluate device compliance status and apply access controls based on conditions like device state and user location. Which Microsoft Entra capability should they use?

A.Access reviews
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerD

Conditional Access in Microsoft Entra ID evaluates signals such as device compliance, user location, and application sensitivity to enforce access policies. It can require compliant devices or trusted locations before granting access to Microsoft 365 resources. This directly meets the requirement to apply access controls based on device state and location.

Why this answer

Conditional Access is the Microsoft Entra feature that enforces access policies based on conditions like device compliance and user location. It integrates with Intune to identify compliant devices and can block or grant access accordingly. PIM, Identity Protection, and access reviews serve different identity governance and risk detection purposes, so they do not provide the dynamic access control described.

Exam trap

The trap here is mixing up identity governance features like access reviews or PIM with the policy enforcement engine that is Conditional Access.

711
MCQeasy

A company stores customer data in Microsoft 365 and needs to identify which data is subject to GDPR. Which Microsoft Purview solution should be used?

A.Data Lifecycle Management
B.Data Loss Prevention
C.Audit
D.Data Classification
AnswerD

Data Classification in Microsoft Purview is the foundational process of identifying, categorizing, and labeling sensitive information, such as personal data subject to GDPR, across an organization's Microsoft 365 environment. This involves using sensitive information types, trainable classifiers, and sensitivity labels to automatically or manually tag data based on its content and context. Accurate data classification is crucial for understanding where sensitive data resides, enabling organizations to apply appropriate protection, retention, and compliance policies.

Why this answer

Microsoft Purview Data Classification uses sensitive information types (SITs) and trainable classifiers to automatically identify and label data matching regulatory patterns such as GDPR. It provides the discovery and classification layer that reveals which content is subject to GDPR obligations. Without classification, an organization cannot know where GDPR-relevant data resides across Microsoft 365 workloads.

Exam trap

SC-900 often tests the distinction between discovering/classifying data versus protecting or retaining it — candidates incorrectly pick DLP when the question asks only to identify what data is subject to a regulation.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management governs retention and deletion of content, not identification of regulated data categories. Option B is wrong because Data Loss Prevention enforces policies to block or warn on sharing of sensitive data — it depends on classification but does not itself identify what is subject to GDPR. Option C is wrong because Audit records user and admin activities for investigation and compliance reporting, not the classification of data content against regulatory frameworks.

712
MCQeasy

A company wants to deploy a single security operations portal that provides a unified view of alerts and incidents from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. Which Microsoft portal should the security team use?

A.Azure Portal
B.Microsoft 365 Defender portal
C.Microsoft 365 admin center
D.Azure Active Directory admin center
AnswerB

This portal serves as the unified Extended Detection and Response (XDR) hub, consolidating security alerts, incidents, and advanced hunting capabilities across Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender for Cloud Apps. It provides security operations teams with a single-pane-of-glass view to investigate, analyze, and respond to threats across the entire digital estate, enabling comprehensive incident management and automated remediation.

Why this answer

The Microsoft 365 Defender portal (https://security.microsoft.com) is the correct answer because it provides a unified security operations center (SOC) experience, aggregating alerts and incidents from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This portal enables security teams to triage, investigate, and respond to cross-domain threats in a single pane of glass, leveraging automated incident correlation and advanced hunting capabilities.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal with the Azure Portal or the Microsoft 365 admin center, mistakenly thinking that security alerts are managed in the same place as Azure resources or tenant administration, when in fact the security portal is a dedicated, cross-workload console.

How to eliminate wrong answers

Option A is wrong because the Azure Portal (https://portal.azure.com) is designed for managing Azure resources, subscriptions, and services like Azure Security Center or Azure Sentinel, not for providing a unified view of Microsoft 365 Defender workloads. Option C is wrong because the Microsoft 365 admin center (https://admin.microsoft.com) is used for tenant-level administrative tasks such as user management, licensing, and service configuration, not for security incident response or alert aggregation. Option D is wrong because the Azure Active Directory admin center (https://aad.portal.azure.com) focuses on identity and access management, including user accounts, groups, and conditional access policies, and does not consolidate security alerts from Defender products.

713
MCQmedium

A multinational corporation uses Microsoft Entra ID. The IT department wants to allow regional IT administrators in Europe to manage users and groups only for their own region, without granting them permissions to manage users in other regions. Which Microsoft Entra ID feature should they use?

A.A. Conditional Access
B.B. Administrative Units
C.C. Privileged Identity Management
D.D. Identity Governance
AnswerB

Administrative Units (AUs) in Microsoft Entra ID are designed to enable granular delegation of administrative responsibilities by allowing an organization to logically group a subset of users, groups, or devices. This feature is crucial for large enterprises or multinational corporations that need to assign specific administrative roles, such as User Administrator or Group Administrator, to regional IT staff. By scoping these roles to an AU, administrators can manage objects strictly confined to their assigned unit, preventing over-privileging and enhancing security.

Why this answer

Administrative Units (AUs) in Microsoft Entra ID allow you to delegate administrative permissions scoped to a subset of users, groups, or devices. By creating an AU for the Europe region and assigning regional IT administrators to it, you restrict their management scope to only those objects within that AU, preventing them from managing users in other regions.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with scope delegation, not realizing that PIM controls when a role is activated, not where it can be applied.

Why the other options are wrong

A

Conditional Access is used to enforce access controls based on conditions like location or device state, not to delegate administrative permissions over specific subsets of users or groups.

C

Privileged Identity Management (PIM) provides time-based and approval-based role activation to manage privileged access, but it does not restrict administrative scope to specific regions or organizational boundaries. It cannot limit user/group management to a subset of users based on geography.

D

Identity Governance focuses on managing user access rights, certifications, and lifecycle, not on delegating administrative permissions to manage users and groups within specific boundaries like regions.

When would these options actually be correct?

A

A question asks: 'A company wants to require multi-factor authentication for all users accessing a sensitive app from outside the corporate network. Which feature should they use?'

C

A question asks: 'The IT department wants to provide just-in-time access for administrators to manage user accounts, requiring approval for role activation and limiting the duration of elevated privileges. Which feature should they use?' In that scenario, Privileged Identity Management is the correct answer.

D

An exam question asks: 'A company needs to automate the review and certification of access rights for users in a specific department every quarter. Which Microsoft Entra ID feature should they use?'

Why candidates pick the wrong answer

A

Candidates may confuse the 'regional' restriction in the question with location-based policies, which is a common use of Conditional Access, but the requirement is about administrative delegation, not access control.

C

Candidates may confuse PIM's role-based access control with the ability to scope permissions, or they may think that activating a role via PIM can be restricted to certain regions, which is not the case.

D

Candidates may confuse Identity Governance with administrative delegation because both involve managing user permissions, but Identity Governance is about access reviews and entitlements, not scoped admin roles.

714
MCQhard

An organization uses Microsoft Purview Information Protection. They want to ensure that when a user manually applies a 'Highly Confidential' sensitivity label to a document, the label is automatically applied to any new content pasted from that document into another app. Which configuration should they enable?

A.Marking content as sensitive
B.Data Loss Prevention policies
C.Encryption with rights management
D.Auto-labeling policies
AnswerA

Marking content as sensitive involves applying a Microsoft Purview sensitivity label, which embeds persistent metadata directly within the file or email. This embedded metadata is the core mechanism that allows the sensitivity label to be tracked and recognized across various Microsoft 365 services and applications. Consequently, when content is copied, moved, or shared, the label's properties and associated protection policies (e.g., encryption, visual markings) travel with the data, ensuring consistent information protection.

Why this answer

Microsoft Purview Information Protection's 'marking content as sensitive' feature (also known as content marking) ensures that when a user manually applies a sensitivity label, the label is automatically applied to any new content pasted from that document into another app. This is achieved through automatic marking that tracks the label even when content is copied. Option B (Data Loss Prevention policies) is incorrect because DLP policies enforce rules to prevent data loss but do not automatically apply labels to copied content.

Option C (Encryption with rights management) is incorrect because encryption protects content but does not propagate labels across copy-paste. Option D (Auto-labeling policies) is incorrect because auto-labeling automatically classifies content based on conditions, not manual application.

715
MCQeasy

A company wants to automatically classify and protect sensitive documents stored in SharePoint Online. The compliance administrator needs to create a policy that detects credit card numbers and applies encryption. Which Microsoft Purview solution should the administrator use?

A.Communication Compliance
B.Sensitivity labels with auto-labeling
C.Microsoft Entra ID
D.Data Lifecycle Management
AnswerB

Sensitivity labels with auto-labeling scan SharePoint Online content for sensitive information types such as credit card numbers, then apply the label, which can enforce encryption through the label's protection settings. This satisfies both detection and encryption without manual classification; DLP alone does not apply encryption.

Why this answer

Sensitivity labels with auto-labeling (Option B) is the correct Microsoft Purview solution because it allows the compliance administrator to create a policy that automatically detects sensitive data types, such as credit card numbers, and applies encryption to documents in SharePoint Online. This feature uses trainable classifiers or sensitive information types to scan content at rest and automatically assign a label that enforces protection actions like encryption, meeting the requirement without manual user intervention.

Exam trap

On the SC-900 exam, candidates often confuse the distinction between auto-labeling (which applies labels and encryption automatically to sensitive data at rest) and Communication Compliance (which monitors communications for policy violations). This leads to incorrectly selecting Communication Compliance for data protection tasks.

How to eliminate wrong answers

Option A is wrong because Communication Compliance is designed to detect and review inappropriate communications (e.g., harassment, insider trading) in Exchange Online, Teams, or Yammer, not to classify or encrypt documents in SharePoint Online. Option C is wrong because Microsoft Entra ID is an identity and access management service that handles authentication and authorization, not content classification or encryption of documents. Option D is wrong because Data Lifecycle Management focuses on retaining or deleting content based on age or compliance requirements (e.g., retention policies), not on automatically classifying and encrypting sensitive data like credit card numbers.

716
MCQmedium

Refer to the exhibit. You are reviewing a sensitivity label configuration in Microsoft Purview. Based on the exhibit, what is the result when a user applies this label to a document?

A.The label is automatically removed after one year
B.The document is automatically deleted after 30 days
C.The document is encrypted and a header/footer is added
D.The document can be printed but not edited
AnswerC

The configuration of this sensitivity label explicitly includes both encryption and visual markings, such as headers and footers. Encryption, powered by Azure Information Protection, ensures that only authorized users can access the document and defines their specific usage rights. Concurrently, visual markings provide clear, persistent indicators within the document itself, communicating its sensitivity level to all who view it.

Why this answer

The exhibit shows a sensitivity label configured with both encryption (via Azure Information Protection) and content marking (header/footer). When a user applies this label, the document is automatically encrypted to protect sensitive data, and the specified header and footer are added to the document as visual markings. This is a common configuration in Microsoft Purview Information Protection to enforce protection and awareness simultaneously.

Exam trap

The trap here is that candidates often confuse sensitivity labels with retention labels, assuming that sensitivity labels can automatically delete or remove themselves after a time period, when in fact sensitivity labels focus on protection and marking, not lifecycle management.

How to eliminate wrong answers

Option A is wrong because sensitivity labels do not have a built-in mechanism to automatically remove themselves after a set period; removal requires manual action or a separate retention policy. Option B is wrong because sensitivity labels do not trigger automatic deletion of documents; deletion is governed by retention labels or data lifecycle management policies, not sensitivity labels. Option D is wrong because the exhibit shows encryption and content marking, not a restriction that allows printing but blocks editing; encryption can be configured with usage rights (e.g., 'View Only' or 'Edit'), but the exhibit does not specify such a granular permission, and the presence of header/footer indicates marking, not a print-only restriction.

717
MCQmedium

Your organization uses Microsoft 365 and wants to automatically quarantine suspicious emails before they reach users' inboxes. Which solution should you configure?

A.Microsoft Purview Data Loss Prevention
B.Microsoft Sentinel
C.Microsoft Intune
D.Microsoft Defender for Office 365
AnswerD

Microsoft Defender for Office 365 provides comprehensive protection against sophisticated email and collaboration threats, including phishing, business email compromise (BEC), malware, and zero-day attacks. It actively scans emails, attachments, and links in real-time before they reach user inboxes. A core capability of Defender for Office 365 is its ability to automatically detect and quarantine malicious emails, preventing users from interacting with harmful content.

Why this answer

Microsoft Defender for Office 365 includes Exchange Online Protection (EOP) and advanced threat protection features such as Safe Attachments and Safe Links. These capabilities automatically quarantine suspicious emails—including those with malicious attachments, phishing URLs, or spoofed senders—before they reach user inboxes, based on policy-defined actions like 'Quarantine message'.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (email security) with Microsoft Sentinel (SIEM) or Microsoft Purview DLP (data protection), because all three are security-related, but only Defender for Office 365 performs inline email quarantine based on threat detection.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data (e.g., credit card numbers, PII) by inspecting content at rest, in transit, or in use—it does not quarantine emails based on threat detection. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution that aggregates security logs and alerts from multiple sources for threat detection and incident response, but it does not perform inline email quarantine. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service focused on managing devices and applications, not on filtering or quarantining email messages.

718
MCQmedium

A compliance officer needs to create a policy that automatically detects and blocks the sharing of credit card numbers in emails and Teams messages. Which Microsoft Purview solution should be used?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Audit
D.Microsoft Purview Information Protection
AnswerA

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to identify, monitor, and automatically protect sensitive information across various locations and applications. DLP policies can be configured to detect specific sensitive content, such as financial data or personal health information, and then enforce preventative actions like blocking the sharing of that content, quarantining it, or notifying administrators. This directly fulfills the requirement for an automatic policy that blocks sharing based on sensitive content.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and automatically block sensitive information, such as credit card numbers, from being shared in emails and Teams messages. DLP uses built-in sensitive information types (e.g., Credit Card Number) and policies that can enforce actions like blocking the message or sending an alert, directly meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse Communication Compliance (which monitors for inappropriate behavior) with DLP (which blocks sensitive data), leading them to choose Communication Compliance because it also deals with communications, but it lacks automatic blocking capabilities for specific data types like credit card numbers.

How to eliminate wrong answers

Option B (Microsoft Purview Communication Compliance) is wrong because it focuses on monitoring and reviewing communications for policy violations (e.g., harassment, insider trading) rather than automatically detecting and blocking specific data patterns like credit card numbers. Option C (Microsoft Purview Audit) is wrong because it provides logging and investigation of past activities, not real-time detection or blocking of data sharing. Option D (Microsoft Purview Information Protection) is wrong because it applies classification and protection labels (e.g., encryption) to documents and emails, but it does not automatically detect and block sharing of specific sensitive data like credit card numbers in transit.

719
Multi-Selecthard

Which TWO Microsoft Purview features allow you to monitor and manage data across hybrid environments (on-premises and cloud)?

Select 2 answers
A.eDiscovery
B.Information Protection
C.Communication Compliance
D.Microsoft Purview Data Map
E.Microsoft Purview Data Estate Insights
AnswersD, E

The Microsoft Purview Data Map is the foundational component that automatically discovers, classifies, and catalogs data across an organization's entire data estate, including multi-cloud, SaaS, and on-premises sources. By continuously scanning and ingesting metadata, it creates a unified, holistic view of data assets, their lineage, and relationships, which is essential for understanding and monitoring the data landscape's composition and changes.

Why this answer

Microsoft Purview Data Map is correct because it provides a unified map of data assets across on-premises, multi-cloud, and SaaS sources, enabling automated scanning and classification of sensitive data. Microsoft Purview Data Estate Insights is correct because it offers monitoring and governance dashboards that track data movement, usage, and compliance posture across hybrid environments, giving administrators visibility into both on-premises and cloud data estates.

Exam trap

The trap here is that candidates confuse Information Protection (which applies labels and encryption) with the broader Purview governance suite that includes Data Map and Insights for monitoring and managing hybrid data estates.

720
Multi-Selectmedium

Which THREE of the following are key concepts of identity management in Microsoft Entra ID?

Select 3 answers
A.Encryption
B.Federation
C.Least privilege
D.Authorization
E.Authentication
AnswersB, D, E

Federation is a key concept in modern identity management that establishes a trust relationship between multiple independent identity providers and service providers. It enables users to authenticate once with their home identity provider and then gain access to various applications and services across different organizational boundaries without re-authenticating. This facilitates single sign-on (SSO) and streamlines user experience by leveraging external identity sources.

Why this answer

Authentication (E) is a core identity-management concept in Microsoft Entra ID because it verifies a user's or service principal's identity through credentials such as passwords, certificate-based authentication, Windows Hello for Business, or FIDO2 security keys, and it underpins tokens issued by the Microsoft identity platform. Authorization (D) is equally fundamental: once Entra ID authenticates an identity, it determines what that identity may access through mechanisms like role-based access control (RBAC), OAuth 2.0 scopes, app roles, and conditional access policies. Federation (B) is also a key concept because Entra ID can trust external identity providers via protocols such as SAML 2.0, WS-Federation, and OpenID Connect, enabling single sign-on and delegated authentication for partner or on-premises identities.

Encryption (A) is a security control used to protect data in transit and at rest, but it is not itself an identity-management concept. Least privilege (C) is an important security principle applied within authorization and access reviews, yet it is a guiding principle rather than one of the core identity-management concepts tested here.

Exam trap

SC-900 often tests the boundary between authentication and authorization — candidates confuse 'who you are' with 'what you can do,' and may also incorrectly include encryption or least privilege as core identity concepts.

721
MCQhard

A multinational corporation needs to enforce data residency requirements by storing data in specific geographic locations. They are using Microsoft Purview for data governance. Which capability should they leverage to meet this requirement?

A.Data loss prevention policies
B.Sensitivity labels with encryption
C.Azure Information Protection unified labeling
D.Microsoft Purview Multi-Geo
AnswerD

Microsoft Purview Multi-Geo is the specific feature designed to address data residency requirements for multinational organizations within a single Microsoft 365 tenant. It enables administrators to provision satellite geo locations and store eligible user data, such as Exchange mailboxes, SharePoint sites, and OneDrive content, at rest in specified geographical regions. This capability directly ensures compliance with local data residency regulations by controlling the physical storage location of data.

Why this answer

Microsoft Purview Multi-Geo is the correct capability because it enables organizations to store data at rest in specific geographic locations to meet data residency requirements. This feature works by provisioning data in chosen regions while maintaining a single Microsoft 365 tenant, allowing the multinational corporation to comply with local regulations without needing separate tenants.

Exam trap

The trap here is that candidates often confuse data residency with data protection, mistakenly choosing sensitivity labels or DLP policies because they think encryption or preventing data loss automatically ensures geographic storage compliance.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies are designed to detect and prevent accidental sharing of sensitive data, not to control where data is stored geographically. Option B is wrong because Sensitivity labels with encryption protect data by applying access controls and encryption, but they do not enforce data residency or storage location. Option C is wrong because Azure Information Protection unified labeling is a labeling solution for classifying and protecting data, but it does not provide the capability to store data in specific geographic locations.

722
MCQmedium

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to prevent users from sharing credit card numbers in emails to external recipients. Which DLP rule action should you configure?

A.Audit the activity only
B.Allow the message but notify the user
C.Block the message from being sent
D.Allow the message with a policy tip
AnswerC

Choosing "Block the message from being sent" is the most direct and effective action within a Microsoft Purview Data Loss Prevention (DLP) policy to prevent sensitive data from leaving the organization. When this action is triggered, the email containing the identified sensitive information is immediately quarantined or rejected, ensuring it never reaches its intended external recipient. This directly fulfills the objective of data loss prevention by physically stopping the unauthorized transmission of critical data.

Why this answer

Microsoft Purview DLP allows you to configure rule actions that enforce protective measures. When you need to prevent users from sharing credit card numbers in emails to external recipients, the 'Block the message from being sent' action stops the email from being delivered, ensuring the sensitive data is not leaked. This action can be combined with a notification or override option, but the core enforcement is blocking the message.

Exam trap

The trap here is that candidates often confuse 'Block the message' with 'Allow with policy tip' because they think a warning is sufficient, but the question explicitly requires preventing the sharing, which only a block action achieves.

How to eliminate wrong answers

Option A is wrong because 'Audit the activity only' merely logs the event for review without preventing the email from being sent, which does not meet the requirement to block sharing. Option B is wrong because 'Allow the message but notify the user' permits the email to be delivered while only sending a notification, failing to stop the data leak. Option D is wrong because 'Allow the message with a policy tip' shows a warning to the user but still allows the email to be sent, which does not enforce the block.

723
MCQeasy

Your organization wants to use Microsoft Entra ID to require multi-factor authentication (MFA) for all users when accessing a financial application. What should you configure?

A.Identity Protection policy
B.Conditional Access policy
C.Per-user MFA
D.MFA registration policy
AnswerB

Conditional Access policies are the control plane for access decisions in Microsoft Entra ID, allowing administrators to define specific conditions under which users can access resources. These policies can explicitly mandate controls like 'Require multifactor authentication' for specific users, groups, applications, or locations. This makes them the definitive tool for enforcing MFA requirements across an organization based on defined criteria and is the recommended modern approach.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA based on specific conditions, such as the application being accessed (the financial app). This is the correct, modern approach to require MFA for a specific application rather than for all sign-ins globally. It provides granular control by evaluating signals like user, device, location, and application before granting access.

Exam trap

The trap here is that candidates confuse the purpose of Identity Protection policies (risk-based) with Conditional Access policies (condition-based), or they mistakenly think Per-user MFA is the only way to enforce MFA for a specific app, when in fact it applies globally to all apps for that user.

How to eliminate wrong answers

Option A is wrong because Identity Protection policies are specifically designed to detect and respond to risky user behaviors (e.g., leaked credentials, anonymous IP addresses) and can trigger MFA automatically based on risk level, but they are not used to require MFA for all users accessing a specific application. Option C is wrong because Per-user MFA enforces MFA at the user account level for all applications, not for a specific application, and it lacks the conditional logic (e.g., location, device state) that Conditional Access provides; it is a legacy approach. Option D is wrong because the MFA registration policy (part of Entra ID Identity Protection) only enforces that users register for MFA, not that they actually use MFA during sign-in; it does not control when MFA is required for a specific application.

724
MCQhard

A company stores application secrets and encryption keys in Azure Key Vault. They want to move from the older vault access policy model to a more scalable and granular permission model that integrates with Azure's role-based access control (RBAC). They also need to audit permissions using Azure Policy. Which access configuration should they choose for Azure Key Vault?

A.Use a single vault access policy with the Contributor role
B.Enable the Azure RBAC permission model for Key Vault
C.Assign a managed identity to the Key Vault
D.Use a service principal and configure vault access policies per application
AnswerB

Enabling the Azure RBAC permission model for Key Vault is the correct approach as it allows granular control over data plane operations, such as getting, listing, or setting secrets and keys. This model integrates directly with Azure Active Directory, enabling centralized identity and access management using standard Azure RBAC roles. This integration also facilitates comprehensive auditing via Azure Policy, ensuring compliance and robust security governance for application secrets and encryption keys.

Why this answer

Enabling the Azure RBAC permission model for Key Vault replaces the older vault access policy model with Azure's native role-based access control, providing granular, scalable permissions that integrate directly with Azure Policy for auditing. This model allows you to assign roles like Key Vault Secrets User or Key Vault Crypto Officer at the management plane, enabling centralized permission management across multiple vaults and supporting Azure Policy compliance checks.

Exam trap

The trap here is that candidates confuse 'managed identity' (an authentication mechanism for resources) with the permission model itself, or assume that vault access policies are still the recommended approach for scalability, when in fact Azure RBAC is the modern, policy-auditable solution.

How to eliminate wrong answers

Option A is wrong because using a single vault access policy with the Contributor role is not a scalable or granular approach; the Contributor role grants broad management-plane access (e.g., deleting the vault) rather than fine-grained data-plane permissions for secrets and keys, and it does not leverage Azure RBAC for Key Vault. Option C is wrong because assigning a managed identity to Key Vault is not an access configuration for the vault itself; managed identities are used by Azure resources to authenticate to Key Vault, not to define the permission model for the vault. Option D is wrong because using a service principal with vault access policies per application still relies on the older vault access policy model, which is less scalable and does not integrate with Azure Policy for auditing permissions across multiple vaults.

725
MCQhard

Your organization uses Microsoft Entra ID and has deployed Microsoft Entra ID Governance for entitlement management. You need to allow external partners to request access to a specific application, but only if they have a valid email address from an approved domain. Once approved, their access should automatically expire after 30 days. You also need to ensure that the partner's access is reviewed quarterly by the application owner. What should you configure?

A.Create an access package with a connected organization for the partner's domain, add the application as a resource, configure approval, set expiration to 30 days, and add a quarterly access review.
B.Create an access package with a connected organization for the partner's domain, add the application as a resource, configure approval, and set expiration to 30 days.
C.Create a dynamic group based on partner email domain and assign the application to the group with a 30-day expiration policy.
D.Add the partner as a guest user manually and assign the application directly with an expiration date.
AnswerA

Creating an access package with a connected organization is the optimal solution as it fully leverages Microsoft Entra ID Identity Governance capabilities. This approach allows the organization to define a self-service workflow for external partners from a specific domain, ensuring that access to the application is granted only after an approval process. The access package also enforces a 30-day expiration, automatically revoking access, and mandates a quarterly access review to continuously validate the necessity of ongoing access, thereby meeting all specified security and compliance requirements comprehensively.

Why this answer

It combines all required components: a connected organization restricts access to approved partner domains, the access package includes the application as a resource, approval ensures authorization, a 30-day expiration enforces automatic access removal, and a quarterly access review satisfies ongoing compliance. Microsoft Entra ID Governance entitlement management uses access packages to bundle resources, policies, and reviews for external collaboration.

Exam trap

The trap here is that candidates often confuse access packages with simple group-based assignment or manual guest user creation, overlooking that entitlement management's connected organization and policy-driven lifecycle are required to meet domain validation, automatic expiration, and recurring review requirements simultaneously.

How to eliminate wrong answers

Option B is wrong because it omits the quarterly access review, which is explicitly required for ongoing compliance and periodic attestation by the application owner. Option C is wrong because dynamic groups do not support expiration policies or access reviews natively; they are for automatic membership based on attributes, not for time-bound external access with governance workflows. Option D is wrong because manually adding guest users and assigning applications directly bypasses entitlement management's automated approval, expiration, and review capabilities, and does not enforce domain validation or quarterly reviews.

726
MCQmedium

A security operations team uses multiple Microsoft security products, including Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Entra ID Protection. They want to aggregate alerts from these sources into a single dashboard, correlate them to create incidents, and use automated playbooks to respond to threats. The team also wants to query historical security data for threat hunting. Which Microsoft solution should they deploy?

A.Microsoft Sentinel
B.Microsoft 365 Defender portal
C.Microsoft Defender for Cloud
D.Azure Monitor
AnswerA

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It centralizes security data from various sources, including Microsoft 365 Defender, Azure AD Identity Protection, and other Microsoft security services, enabling comprehensive threat detection and incident response. Sentinel correlates alerts, creates actionable incidents, and facilitates automated remediation through playbooks, making it ideal for a security operations team managing multiple security products. Its powerful Kusto Query Language (KQL) also supports advanced threat hunting.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests alerts from multiple sources, including Microsoft Defender for Endpoint, Defender for Office 365, and Entra ID Protection, into a single dashboard. It correlates these alerts into incidents using analytics rules and supports automated playbooks via Azure Logic Apps. Additionally, Sentinel provides a Kusto Query Language (KQL)-based workspace for querying historical security data, enabling threat hunting.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal (which does unify alerts and incidents from Defender products) with a full SIEM/SOAR solution, overlooking that it lacks native automated playbook orchestration and long-term historical data querying for threat hunting, which are core to Microsoft Sentinel.

Why the other options are wrong

B

The Microsoft 365 Defender portal provides a unified view of alerts from Defender for Endpoint, Defender for Office 365, and Entra ID Protection, but it does not support custom querying of historical security data for threat hunting or advanced automation with playbooks beyond its built-in capabilities.

C

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) focused on securing cloud resources, not a SIEM/SOAR solution. It does not aggregate alerts from Defender for Endpoint, Office 365, and Entra ID Protection into a single dashboard with incident correlation and automated playbooks.

D

Azure Monitor is primarily for monitoring infrastructure performance and logs, not for aggregating security alerts from multiple Microsoft security products, correlating them into incidents, or running automated security playbooks. It lacks native SIEM and SOAR capabilities for security operations.

When would these options actually be correct?

B

A question that asks for a single portal to view and manage alerts from Microsoft 365 Defender products (Defender for Endpoint, Office 365, Identity) without requiring custom analytics, long-term data retention, or complex automated playbooks would make the Microsoft 365 Defender portal the correct answer.

C

A question asking which Microsoft solution provides unified visibility and security recommendations across multicloud environments (Azure, AWS, GCP), including vulnerability assessment, regulatory compliance, and workload protection, would make Microsoft Defender for Cloud the correct answer.

D

If the question asked for a solution to monitor Azure VM performance metrics, collect diagnostic logs, and set up alerts for CPU usage or disk space, Azure Monitor would be the correct answer. It is designed for infrastructure monitoring and observability.

Why candidates pick the wrong answer

B

Candidates may confuse the Microsoft 365 Defender portal's unified alert view and incident correlation with the more advanced SIEM and SOAR capabilities of Microsoft Sentinel, assuming it can also handle historical data queries and custom playbooks.

C

Candidates may confuse 'Defender for Cloud' with a central security dashboard because its name includes 'Defender' and 'Cloud,' suggesting it unifies security across Microsoft services, but it lacks SIEM/SOAR capabilities.

D

Candidates may confuse Azure Monitor with a security solution because it can collect logs and set up alerts, but they overlook that it does not provide the security-specific incident correlation, threat hunting, and automated response (SOAR) features that Sentinel offers.

727
MCQmedium

A user is locked out of their account after multiple failed sign-in attempts. You need to reduce false lockouts while maintaining security. What should you do?

A.Require MFA for all users
B.Disable account lockout
C.Enable Smart Lockout
D.Increase lockout threshold to 20 attempts
AnswerC

Enabling Smart Lockout is the most effective solution because it leverages cloud intelligence and machine learning to differentiate between legitimate users making typos and malicious attackers. Instead of a static threshold, Smart Lockout tracks failed sign-in attempts across various IP addresses and locations. It intelligently locks out suspicious attempts from unfamiliar sources while allowing a legitimate user to continue trying from a known location, significantly reducing false lockouts without compromising security.

Why this answer

Microsoft Entra Smart Lockout is designed to protect against brute-force attacks while reducing false lockouts for legitimate users. It uses a combination of familiar location and unfamiliar location thresholds to differentiate between malicious attempts and valid users who may have mistyped their password. Enabling Smart Lockout allows you to set a higher threshold for familiar locations and a lower threshold for unfamiliar locations, thus maintaining security without locking out legitimate users.

The other options either do not address false lockouts (MFA) or weaken security (disabling lockout, increasing threshold globally).

Exam trap

SC-900 often tests the misconception that increasing the lockout threshold or disabling lockout is a good way to reduce false lockouts, when the correct answer is to use Smart Lockout, which intelligently differentiates based on location.

How to eliminate wrong answers

Option A is wrong because requiring MFA for all users adds a security layer but does not directly reduce false lockouts from failed sign-in attempts; it may even increase lockouts if MFA prompts fail. Option B is wrong because disabling account lockout entirely removes protection against brute-force attacks, which is a security risk. Option D is wrong because increasing the lockout threshold to 20 attempts globally makes it easier for attackers to guess passwords and does not differentiate between familiar and unfamiliar locations, so it does not intelligently reduce false lockouts.

728
Multi-Selecthard

Which TWO capabilities are provided by Microsoft Defender for Cloud? (Choose two.)

Select 2 answers
A.Secure score and security recommendations
B.Endpoint detection and response (EDR)
C.Vulnerability assessment for VMs
D.Cloud Access Security Broker (CASB)
E.Security Information and Event Management (SIEM)
AnswersA, C

Secure score quantifies posture against recommended controls, and security recommendations list specific remediation actions, satisfying the stem's requirement for Defender for Cloud capabilities. Both belong to the CSPM pillar, assessing configuration rather than detecting runtime threats.

Why this answer

Microsoft Defender for Cloud provides a secure score and security recommendations (option A) as part of its Cloud Security Posture Management (CSPM) capabilities, continuously assessing resources against benchmarks like the Microsoft Cloud Security Benchmark and Azure Security Benchmark to surface prioritized remediation guidance. It also provides vulnerability assessment for VMs (option C) through integrated scanners such as Microsoft Defender for Servers' built-in vulnerability assessment powered by Qualys or the agentless scanning capability, surfacing CVEs and remediation steps in the portal. Option B (EDR) is a capability of Microsoft Defender for Endpoint, not Defender for Cloud itself, even though Defender for Servers can auto-provision the Defender for Endpoint agent.

Option D (CASB) is delivered by Microsoft Defender for Cloud Apps, a separate product in the Defender suite. Option E (SIEM) is provided by Microsoft Sentinel, not Defender for Cloud.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud with other Microsoft security products like Defender for Endpoint (EDR), Defender for Cloud Apps (CASB), or Microsoft Sentinel (SIEM), because all are part of the Microsoft Security portfolio and often work together, but each has distinct primary capabilities.

729
MCQeasy

A company's IT department deploys a multi-layered security strategy that includes a perimeter firewall, network segmentation, endpoint antivirus software, data encryption, and employee security awareness training. Which security model does this approach represent?

A.Zero Trust
B.Least Privilege
C.Defense in Depth
D.Shared Responsibility
AnswerC

Defense in Depth is a cybersecurity strategy that employs multiple, independent security controls and mechanisms across various layers of an IT environment. This approach ensures that if one security control fails or is bypassed, other controls are still in place to detect, prevent, or mitigate an attack. It involves deploying administrative, technical, and physical safeguards in a layered fashion to create a robust and resilient security posture.

Why this answer

The described approach—combining perimeter firewalls, network segmentation, endpoint antivirus, encryption, and training—is the classic definition of Defense in Depth. This model layers multiple independent security controls so that if one layer fails (e.g., a firewall rule is misconfigured), subsequent layers (e.g., segmentation, antivirus) still protect the asset. It does not assume any single control is sufficient, which is the core principle of Defense in Depth.

Exam trap

The trap here is that candidates see 'firewall' and 'encryption' and immediately think Zero Trust, but Zero Trust requires explicit identity verification and micro-segmentation, not just a layered stack of traditional controls.

How to eliminate wrong answers

Option A is wrong because Zero Trust is a model that explicitly assumes no implicit trust and requires continuous verification of every access request (e.g., using conditional access policies and micro-segmentation), whereas the question describes a layered set of static controls without the 'never trust, always verify' mandate. Option B is wrong because Least Privilege is a principle that restricts users and processes to only the permissions necessary for their tasks (e.g., via RBAC or JIT access), not a multi-layered security architecture. Option D is wrong because Shared Responsibility is a cloud model that defines which security tasks are handled by the provider vs. the customer (e.g., AWS handles physical security while the customer manages IAM), not a layered on-premises or hybrid security strategy.

730
MCQhard

A company deploys a sensitivity label as shown in the exhibit. The custom sensitive information type 'Custom_PII_Type' is configured to detect employee IDs. What happens when a user creates a new document in SharePoint Online that contains an employee ID?

A.The user is prompted to manually apply the label.
B.The document is blocked from being shared externally.
C.The document is automatically labeled 'Highly Confidential' and encrypted.
D.The document is deleted automatically.
AnswerC

Given the configuration for auto-labeling, the system will automatically identify documents meeting the specified conditions and apply the 'Highly Confidential' sensitivity label. Concurrently, the label's policy dictates that the document will be encrypted, ensuring that only authorized users with the correct permissions can access its content. This dual action of automatic classification and protection is a core function of sensitivity labels.

Why this answer

The sensitivity label is configured for auto-labeling with a condition that detects the custom sensitive information type 'Custom_PII_Type'. When a user creates a document in SharePoint Online containing an employee ID, Microsoft 365 automatically applies the 'Highly Confidential' label and enforces encryption as defined in the label policy, without requiring manual user action.

Exam trap

The trap here is that candidates confuse auto-labeling with manual labeling or assume encryption automatically blocks external sharing, but auto-labeling applies the label without user intervention, and encryption must be explicitly configured to restrict sharing.

How to eliminate wrong answers

Option A is wrong because auto-labeling is configured, so the label is applied automatically, not requiring manual prompting. Option B is wrong because the label's encryption settings control external sharing, but the question does not specify that external sharing is blocked; encryption alone does not block external sharing unless explicitly configured. Option D is wrong because sensitivity labels do not delete documents; they apply classification and protection actions like encryption, not deletion.

731
MCQhard

A company uses Microsoft Entra ID and Intune for mobile device management. They want to enforce different access requirements for their finance application: when users access from an unmanaged personal device, they must perform multi-factor authentication (MFA). When they access from a corporate-managed device that is marked as compliant (e.g., joined to Azure AD, antivirus up-to-date, encryption enabled), MFA should not be required. Device compliance is reported by Intune. Which Microsoft Entra ID feature should they use to define these rules?

A.Identity Protection risk policies
B.Conditional Access policies
C.Privileged Identity Management (PIM)
D.Intune device compliance policies
AnswerB

Conditional Access policies in Microsoft Entra ID are the enforcement engine that evaluates various signals, including device compliance status reported by Intune, user location, and sign-in risk. Based on these conditions, a policy can then enforce specific access controls, such as requiring multi-factor authentication (MFA), blocking access, or requiring a compliant device. This directly addresses the need to control access and enforce MFA based on device state.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to define granular access rules based on signals such as user, device, location, and application. In this scenario, the policy can be configured to require MFA when the device is not marked as compliant (e.g., unmanaged personal device) and to allow access without MFA when the device is reported as compliant by Intune. This is the correct feature because it directly evaluates device compliance status from Intune and enforces the specified access requirements.

Exam trap

The trap here is that candidates often confuse Intune device compliance policies (which define the rules for compliance) with Conditional Access policies (which enforce access decisions based on that compliance status), leading them to select Option D instead of the correct feature that actually enforces the MFA requirement.

Why the other options are wrong

A

Identity Protection risk policies focus on user and sign-in risk (e.g., leaked credentials, anonymous IP) to trigger MFA or block access, not on device compliance or management status. The question requires differentiating access based on device compliance (managed vs. unmanaged), which is a Conditional Access condition, not a risk policy.

C

Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not access rules based on device compliance or MFA requirements for applications.

D

Intune device compliance policies define the compliance requirements (e.g., antivirus, encryption) but do not enforce access rules like requiring MFA based on device compliance status. Conditional Access policies are needed to combine compliance status with access controls.

When would these options actually be correct?

A

A company wants to block sign-ins from users whose credentials have been leaked or require MFA when sign-in risk is medium or high. Identity Protection risk policies would be the correct feature to define these risk-based access rules.

C

A question asks: 'A company wants to require approval for activating the Global Administrator role and limit its use to a specific time window. Which feature should they use?'

D

A company wants to define the specific security requirements (e.g., require encryption, minimum OS version, antivirus) that devices must meet to be considered compliant. The exam question would ask: 'Which feature should they use to set the rules for device compliance?'

Why candidates pick the wrong answer

A

Candidates may confuse 'risk' with 'device compliance' because both can trigger MFA, but Identity Protection deals with user/sign-in risk, not device management status.

C

Candidates may confuse PIM with Conditional Access because both involve access control, but PIM specifically deals with privileged roles, not general application access policies.

D

Candidates may confuse device compliance policies (which define compliance) with Conditional Access policies (which enforce access based on compliance). They see 'device compliance' in the scenario and incorrectly assume the policy that defines compliance also enforces the access rules.

732
MCQmedium

A financial institution uses Microsoft 365 and needs to prevent employees from accidentally sharing sensitive financial data (e.g., account numbers) via email. They also need to inform the sender with a policy tip if they attempt to send such data and block the email if it's shared externally. Which Microsoft Purview solution should they use?

A.Data Loss Prevention (DLP)
B.Information Protection (Sensitivity labels)
C.Communication Compliance
D.Records Management
AnswerA

Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations like Exchange Online, SharePoint Online, and OneDrive. These policies leverage sensitive information types (SITs) to detect financial data, PII, or other critical data, providing real-time policy tips to users and blocking sharing actions that violate organizational policies. This proactive approach ensures sensitive data, such as customer financial records, is not inadvertently or maliciously exfiltrated, directly addressing the institution's need for prevention.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, warn, and block the accidental sharing of sensitive data—such as financial account numbers—via email. DLP policies can be configured with conditions that trigger a policy tip to inform the sender and automatically block the email if it is sent externally, meeting both requirements.

Exam trap

The trap here is that candidates often confuse Information Protection (sensitivity labels) with DLP, not realizing that sensitivity labels handle classification and encryption of data at rest, while DLP is the solution for monitoring and controlling data in motion (e.g., email) with real-time user notifications and blocking.

How to eliminate wrong answers

Option B (Information Protection / Sensitivity labels) is wrong because sensitivity labels are used to classify and protect data at rest (e.g., applying encryption or visual markings), but they do not natively inspect email content in transit or provide real-time policy tips and blocking actions for outgoing messages. Option C (Communication Compliance) is wrong because its primary purpose is to monitor and detect policy violations (e.g., insider trading, harassment) for review, not to proactively block emails or show policy tips to senders. Option D (Records Management) is wrong because it focuses on managing the lifecycle and retention of records for legal or regulatory compliance, not on preventing accidental data leakage via email.

733
MCQmedium

A company has a policy that prohibits employees from sharing confidential customer data with unauthorized parties. The compliance team needs to detect patterns of unusual user activity that may indicate insider data theft, such as downloading large volumes of data to a personal device or emailing sensitive files to external recipients. They also want to investigate the activity and take remediation actions like generating a case for litigation or notifying the user's manager. Which Microsoft Purview solution should they use?

A.Microsoft Purview Insider Risk Management
B.Microsoft Purview Data Loss Prevention
C.Microsoft Purview Audit
D.Microsoft Purview eDiscovery
AnswerA

Microsoft Purview Insider Risk Management is the correct solution because it proactively identifies, investigates, and acts on risky activities by users within an organization. It leverages machine learning to detect behavioral patterns indicative of data exfiltration, intellectual property theft, or confidentiality violations across various signals, providing a comprehensive workflow for managing potential insider threats and enforcing policies against sharing confidential information.

Why this answer

Microsoft Purview Insider Risk Management is designed specifically to detect, investigate, and remediate insider data theft scenarios. It uses predefined and customizable policies to identify patterns like large-volume downloads to personal devices or emailing sensitive files externally, and provides built-in remediation actions such as generating a case for litigation or notifying a user's manager.

Exam trap

The trap here is that candidates confuse Data Loss Prevention (DLP) with Insider Risk Management because both deal with data protection, but DLP is a preventive control for policy enforcement, whereas Insider Risk Management is a detective and investigative solution with remediation workflows.

Why the other options are wrong

B

Microsoft Purview Data Loss Prevention (DLP) is designed to prevent data from being shared inappropriately by enforcing policies, but it does not provide the pattern-based user activity analysis, investigation workflows, or remediation actions like case generation and manager notification that are required in this scenario.

C

Microsoft Purview Audit provides logs of user activities but does not include built-in pattern detection for insider risk or remediation actions like generating cases or notifying managers.

D

Microsoft Purview eDiscovery is used for identifying, collecting, and producing electronic content for legal cases, not for detecting patterns of unusual user activity or taking remediation actions like notifying a manager.

When would these options actually be correct?

B

A company wants to prevent users from accidentally sharing sensitive data via email or cloud apps by automatically blocking or warning about policy violations. For example, an organization needs to block emails containing credit card numbers from being sent to external recipients.

C

An exam question asks: 'The compliance team needs to review a log of all user activities related to a specific document over the past 30 days to support an investigation. Which solution should they use?'

D

A legal team needs to search for and export emails and documents related to a specific litigation case from user mailboxes and SharePoint sites, preserving them for legal review.

Why candidates pick the wrong answer

B

Candidates may confuse DLP's ability to detect and block data sharing with the broader insider risk detection and investigation capabilities needed here, as DLP is a well-known solution for protecting sensitive data.

C

Candidates may think Audit is sufficient because it records user actions, but they overlook that the question requires detection of unusual patterns and automated remediation, which Audit alone cannot provide.

D

Candidates may confuse eDiscovery with investigation and remediation because both involve reviewing user activity and content, but eDiscovery focuses on legal discovery rather than proactive risk detection.

734
MCQhard

A security manager wants to ensure that an employee who sends an email cannot later deny having sent it. Which security concept and associated technology is best suited to achieve this?

A.Confidentiality, achieved through encryption
B.Integrity, achieved through hashing
C.Non-repudiation, achieved through digital signatures
D.Access control, achieved through permissions
AnswerC

Non-repudiation, achieved through digital signatures, cryptographically links a sender to a specific message, preventing them from falsely denying authorship. By using the sender's unique private key to sign a message's hash, an undeniable proof of origin is created. The recipient can verify this signature using the sender's public key, confirming both the sender's identity and the message's integrity. This mechanism is crucial for legal and financial transactions where accountability is paramount.

Why this answer

Non-repudiation ensures that a party cannot deny an action, such as sending an email. Digital signatures, which use asymmetric cryptography (e.g., RSA or ECDSA) and a hash of the message, provide cryptographic proof of the sender's identity and message integrity, making denial impossible.

Exam trap

The trap here is that candidates confuse integrity (hashing) with non-repudiation, not realizing that a hash alone lacks sender identity binding—only a digital signature provides the cryptographic proof of origin needed to prevent denial.

Why the other options are wrong

A

Confidentiality (encryption) protects data from unauthorized access, but does not provide proof of origin or prevent the sender from denying they sent the email.

B

Integrity ensures data has not been altered, but does not prevent a sender from denying they sent a message. Non-repudiation is required to prove the origin of the email.

D

Access control and permissions manage who can access resources, but they do not provide proof of origin or prevent denial of sending an email. Non-repudiation is required to prevent a sender from denying they sent a message.

When would these options actually be correct?

A

A question asking which security concept ensures that only authorized recipients can read an email, with the technology being encryption.

B

A question asking which security concept ensures that data has not been tampered with during transmission, with the associated technology being hashing to verify integrity.

D

A question asking: 'Which security concept ensures that only authorized users can view sensitive data?' would make access control correct, typically implemented through permissions or role-based access control.

Why candidates pick the wrong answer

A

Candidates may confuse encryption with digital signatures, or think that encrypting the email also authenticates the sender.

B

Candidates may confuse integrity with non-repudiation because both involve verifying data authenticity, but integrity focuses on data unchanged, not sender identity.

D

Candidates may confuse access control with non-repudiation because both involve security policies, but access control focuses on authorization, not on irrefutable proof of action.

735
MCQmedium

A company uses Microsoft Defender for Endpoint to secure its devices, Microsoft Defender for Office 365 for email security, and Microsoft Defender for Identity for on-premises Active Directory. The security team wants a single console to view correlated incidents across these domains, where an incident might combine a suspicious email, a malicious file download, and a compromised account. Which Microsoft solution provides this unified incident view and automatic correlation?

A.Microsoft Sentinel
B.Microsoft Defender for Cloud
C.Microsoft 365 Defender (now Microsoft Defender XDR)
D.Microsoft Purview Compliance Portal
AnswerC

Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified pre- and post-breach enterprise defense suite that natively integrates and orchestrates detection, investigation, and response. It automatically correlates alerts and signals from its constituent services—Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps—into cohesive incidents. This comprehensive integration provides a holistic view of attacks and streamlines the security operations center (SOC) workflow from a single, centralized portal.

Why this answer

Microsoft 365 Defender (now Microsoft Defender XDR) is the correct answer because it provides a unified incident view across Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity. It automatically correlates alerts from these domains—such as a suspicious email, a malicious file download, and a compromised account—into a single incident, enabling security teams to investigate and respond from one console.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft 365 Defender (an XDR), mistakenly thinking Sentinel provides the same out-of-the-box cross-domain correlation, when in fact Sentinel requires manual configuration and is not the single console for native Defender product integration.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR platform that ingests logs from multiple sources, but it does not natively provide the automatic, built-in correlation across Defender for Endpoint, Office 365, and Identity; it requires custom analytics rules and data connectors to achieve similar correlation. Option B is wrong because Microsoft Defender for Cloud is focused on securing cloud workloads (IaaS, PaaS, and data services) and does not integrate email security or on-premises Active Directory signals into a unified incident view. Option D is wrong because Microsoft Purview Compliance Portal is designed for data governance, compliance, and risk management (e.g., data loss prevention, eDiscovery), not for security incident correlation across endpoint, email, and identity domains.

736
MCQmedium

Your company uses Microsoft Sentinel to manage security incidents. You need to automatically assign incidents to a specific analyst team based on the incident category (e.g., phishing incidents to the SOC team). What should you configure?

A.Create a watchlist mapping categories to teams and use it in analytics rules
B.Automation rule with a condition on incident category and an action to assign to the SOC team
C.Configure the analytics rule to set the incident owner in the rule query
D.Playbook triggered by incident creation that assigns the incident
AnswerB

Automation rules are the primary mechanism in Microsoft Sentinel for automatically managing incidents upon creation or update. By configuring an automation rule with a condition that matches the incident's category, it can directly execute an action to assign the incident to a specific owner or team, such as the SOC team, without requiring additional components or manual intervention. This provides an efficient and immediate way to route incidents.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions based on incident properties (like category) and automatically take actions such as assigning the incident to a specific team. This is the correct and most efficient method for routing incidents by category without requiring custom code or external playbooks.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing a playbook (Option D) because they think automation rules cannot handle assignment, but Sentinel automation rules natively support the 'Assign incident' action without needing Logic Apps.

How to eliminate wrong answers

Option A is wrong because watchlists are used for correlating data or enriching alerts, not for triggering automated assignment actions based on incident categories. Option C is wrong because analytics rule queries generate alerts but cannot directly set the incident owner; ownership is managed at the incident level after creation. Option D is wrong because while a playbook triggered by incident creation could assign the incident, it is an over-engineered solution compared to the simpler, built-in automation rule, and playbooks require additional configuration and logic apps.

737
MCQmedium

Your organization is using Microsoft Entra ID with P2 licenses. You need to enforce a policy that requires administrators to request approval before activating their privileged roles, and approvals must expire after 8 hours. Additionally, you need to ensure that all privileged role activations are logged for auditing. Which combination of Microsoft Entra capabilities should you use?

A.Implement Identity Protection user risk policy to block high-risk admins, and use sign-in logs.
B.Configure Privileged Identity Management (PIM) for role activation with approval and expiration, and use PIM audit logs.
C.Create a Conditional Access policy requiring multi-factor authentication for admins, and use activity logs.
D.Set up Azure AD Access Reviews to require monthly review of privileged roles, and enable diagnostic settings.
AnswerB

Configuring Privileged Identity Management (PIM) directly addresses the need for just-in-time (JIT) access to privileged roles. PIM allows administrators to activate roles only when needed, for a specified duration, and can enforce approval workflows and multi-factor authentication during activation. The comprehensive PIM audit logs provide a detailed record of all role activations, approvals, and deactivations, ensuring accountability and compliance with least privilege principles.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time role activation with configurable approval workflows and expiration durations, meeting the requirement for administrators to request approval and for approvals to expire after 8 hours. PIM audit logs capture all activation events, including who approved, when, and for which role, fulfilling the auditing requirement. This combination directly addresses the policy needs without relying on unrelated capabilities like user risk policies or access reviews.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control sign-in conditions) with PIM (which controls role activation), leading them to choose Option C because they think MFA enforcement is sufficient for privileged role security.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policy blocks users based on risk level, not role activation approval or expiration, and sign-in logs do not capture privileged role activation events. Option C is wrong because Conditional Access policies enforce authentication requirements like MFA during sign-in, not role activation approval workflows or expiration, and activity logs lack the granularity of PIM-specific activation auditing. Option D is wrong because Azure AD Access Reviews are for periodic attestation of role membership, not for controlling activation with approval and expiration, and diagnostic settings export logs but do not enforce the approval or expiration policy.

738
MCQmedium

Your company, Wingtip Toys, uses Microsoft Entra ID with a Premium P1 license. You have a third-party SaaS application that supports Security Assertion Markup Language (SAML) 2.0. You need to enable single sign-on (SSO) for users to access this application. The app requires attributes like department and employee ID in the SAML token. You also need to ensure that only users from a specific security group can access the app. What should you do?

A.Register the app using OpenID Connect and assign users to the app.
B.Add the app from the gallery using password-based SSO and configure group assignment.
C.Use Microsoft Entra Application Proxy to publish the app and configure pre-authentication.
D.Add the app from the gallery as a SAML application, configure claims mapping to include department and employee ID, and assign the app to the security group.
AnswerD

Adding the application from the Microsoft Entra gallery as a SAML application is the correct approach, as it aligns with the third-party app's supported authentication protocol. Configuring claims mapping allows for the precise inclusion of required attributes like department and employee ID within the SAML assertion sent to the service provider. Finally, assigning the app to a security group ensures efficient and scalable management of user access, meeting all specified requirements for secure and attribute-rich single sign-on.

Why this answer

With Microsoft Entra ID Premium P1, you can add the SaaS application from the gallery as a SAML application, configure custom claims to include department and employee ID in the SAML token, and assign the application to the security group. OpenID Connect is not SAML SSO. Password-based SSO cannot provide SAML attributes.

Application Proxy is used for on-premises applications, not SaaS apps.

Exam trap

Don't confuse SAML SSO with OpenID Connect, password-based SSO, or Application Proxy. Also remember that custom SAML claims mapping requires Microsoft Entra ID Premium P1 or P2.

How to eliminate wrong answers

Option A is wrong because OpenID Connect is an authentication protocol built on OAuth 2.0, not SAML 2.0, and it does not support the SAML token format or custom SAML attribute claims required by the app. Option B is wrong because password-based SSO does not use SAML tokens and cannot include custom attributes like department and employee ID in a token; it relies on form-fill or credential injection, not SAML assertions. Option C is wrong because Microsoft Entra Application Proxy is used for publishing on-premises apps, not for third-party SaaS applications, and it does not provide SAML token customization or gallery-based SAML configuration.

739
MCQmedium

A security team wants to receive a unified security posture assessment for their hybrid workloads including Azure VMs, on-premises SQL servers, and AWS EC2 instances. They need to get actionable recommendations to harden configurations and improve their overall security score. Which Microsoft security solution provides this capability?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Endpoint
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Cloud is the correct solution as it provides Cloud Security Posture Management (CSPM) capabilities across Azure, AWS, GCP, and on-premises environments. It continuously assesses the security configuration of resources, identifies misconfigurations, and offers actionable recommendations to improve security posture. This results in a unified secure score, giving security teams a consolidated view of their overall security health and compliance across their entire hybrid and multi-cloud estate.

Why this answer

Microsoft Defender for Cloud provides a unified security posture assessment across hybrid and multi-cloud workloads, including Azure VMs, on-premises SQL servers, and AWS EC2 instances. It continuously assesses configurations against security baselines (e.g., Azure Security Benchmark, CIS controls) and generates a secure score with actionable recommendations to harden resources. This aligns directly with the requirement for a single dashboard covering all listed workload types.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud (a posture management and CSPM tool) with Microsoft Sentinel (a SIEM), because both can ingest multi-cloud data, but only Defender for Cloud provides the unified secure score and actionable hardening recommendations for hybrid workloads.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices (e.g., workstations, servers) against threats like malware and ransomware, not on unified posture assessment or secure score for hybrid workloads. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR for threat detection, investigation, and response across logs and alerts, not a posture assessment tool for configuration hardening. Option D is wrong because Microsoft Defender for Cloud Apps is a CASB for shadow IT discovery, app permissions, and data protection in SaaS applications, not for assessing the security posture of VMs, SQL servers, or EC2 instances.

740
MCQeasy

Your company uses Microsoft Defender XDR. You need to integrate threat intelligence from external sources to enrich alerts and automate response actions. Which feature should you use?

A.Automation rules
B.Threat analytics
C.Advanced hunting
D.Threat intelligence integration
AnswerD

Threat intelligence integration in Microsoft Defender XDR allows organizations to import custom indicators of compromise (IOCs) and threat intelligence feeds from various external sources. This capability enables security teams to enrich their existing alerts, detections, and investigations with context from third-party or proprietary threat intelligence platforms. By integrating external TI, Defender XDR can automatically correlate incoming security events against these custom indicators, significantly enhancing detection capabilities and providing more comprehensive insights into potential threats.

Why this answer

Microsoft Defender XDR's threat intelligence integration (option D) allows you to import custom threat indicators (IOCs) from external sources—such as STIX/TAXII feeds, APIs, or manual uploads—into the Microsoft 365 Defender platform. These indicators are then used to enrich alerts, trigger automated response actions via custom detection rules, and correlate with telemetry across endpoints, email, and identities. This directly meets the requirement to integrate external threat intelligence for enrichment and automation.

Exam trap

The trap here is that candidates confuse 'threat intelligence integration' with 'threat analytics' (option B), assuming both provide external threat data, but threat analytics only surfaces Microsoft's pre-analyzed reports, not custom external feeds.

How to eliminate wrong answers

Option A is wrong because automation rules in Microsoft Defender XDR are used to define automated actions (e.g., isolate a device, block a file) based on alert triggers, but they do not import or integrate external threat intelligence sources. Option B is wrong because threat analytics is a built-in feature that provides curated threat intelligence reports and insights from Microsoft's own research, not a mechanism to integrate custom external threat feeds. Option C is wrong because advanced hunting is a query-based tool for proactively searching raw telemetry data using Kusto Query Language (KQL), not a feature for importing external threat intelligence or automating responses based on it.

741
MCQmedium

A company uses a cloud-based SaaS (Software as a Service) application for customer relationship management. According to the shared responsibility model, which security responsibility is primarily handled by the customer?

A.Physical security of the data center hosting the application
B.Security of the underlying networking infrastructure
C.Managing user access and permissions for the application
D.Applying security patches to the application's code
AnswerC

Even when consuming a SaaS application, the customer retains primary responsibility for defining and managing user identities, roles, and permissions within that specific application. This includes provisioning and de-provisioning user accounts, assigning appropriate access levels based on job functions, and enforcing least privilege principles. The customer dictates who can access what features and data within the software.

Why this answer

In a SaaS model like a cloud-based CRM application, the customer is responsible for managing user access and permissions, including identity and access management (IAM), multi-factor authentication (MFA), and role-based access control (RBAC). The cloud provider handles the underlying infrastructure, platform, and application security, but the customer must control who can access the application and what they can do within it.

Exam trap

The trap here is that candidates often assume the customer is responsible for patching the application code in SaaS, but in reality, the provider handles all code-level patches, while the customer only manages user access and permissions.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is the cloud provider's responsibility under the shared responsibility model for SaaS, as the customer has no physical access to the infrastructure. Option B is wrong because security of the underlying networking infrastructure, such as firewalls and network segmentation, is managed by the cloud provider in a SaaS deployment. Option D is wrong because applying security patches to the application's code is the cloud provider's responsibility in SaaS; the customer only manages configuration and user-level settings.

742
MCQhard

An organization uses Microsoft Intune to manage devices. They need to ensure that only devices with a compliant antivirus solution can access corporate email. Which policy type should be configured?

A.App protection policy in Microsoft 365
B.Conditional Access policy in Microsoft Entra ID
C.Device compliance policy in Intune
D.Security baseline in Microsoft Defender for Cloud
AnswerB

Conditional Access policies in Microsoft Entra ID serve as the enforcement mechanism, evaluating conditions before granting access to cloud applications and resources. These policies can be configured to mandate that a device be marked as "compliant" by Microsoft Intune. This compliance status, in turn, is determined by Intune device compliance policies, which can include specific requirements for antivirus software being enabled and up-to-date. Consequently, Conditional Access acts as the critical gatekeeper, blocking access if the device's antivirus status, as reported by Intune, fails to meet the defined organizational compliance standards.

Why this answer

Conditional Access policies in Microsoft Entra ID evaluate signals such as device compliance status before granting access to cloud apps like corporate email. By integrating with Intune device compliance policies, they can block access from devices that lack a compliant antivirus solution. This is the correct mechanism because Conditional Access enforces the access decision at the authentication layer, not just at the device management layer.

Exam trap

The trap here is that candidates often confuse the role of Intune Device compliance policies (which only mark a device as compliant or non-compliant) with the enforcement mechanism of Conditional Access, assuming the compliance policy alone can block access to corporate resources.

How to eliminate wrong answers

Option A is wrong because App protection policies in Microsoft 365 manage how data is handled within apps (e.g., copy/paste restrictions) and do not evaluate device-level antivirus compliance. Option C is wrong because Device compliance policies in Intune define the compliance criteria (e.g., antivirus status) but do not enforce access to corporate email on their own; they require a Conditional Access policy to block access. Option D is wrong because Security baselines in Microsoft Defender for Cloud provide configuration recommendations for cloud resources, not device-level antivirus compliance enforcement for email access.

743
MCQmedium

A financial institution wants to apply the principle of least privilege to its Microsoft Entra ID environment. The IT team needs to ensure that administrators only have the permissions necessary to perform their job functions and that these permissions are activated only when needed. Which feature should they implement?

A.Microsoft Entra Privileged Identity Management (PIM)
B.Microsoft Entra Conditional Access
C.Microsoft Entra Access Reviews
D.Microsoft Entra ID Protection
AnswerA

Microsoft Entra Privileged Identity Management (PIM) enables just-in-time role activation, ensuring that administrators only have privileged access when needed. It enforces least privilege by requiring approval, multi-factor authentication, and justification for role activation. PIM also provides auditing and alerts for privileged actions, helping the organization maintain tight control over administrative access and reduce the attack surface.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is designed to implement least privilege by providing just-in-time privileged access, approval workflows, and time-bound role activations. Conditional Access, ID Protection, and Access Reviews address other aspects of identity security but do not offer the same just-in-time privileged access management capabilities.

Exam trap

The trap here is selecting Conditional Access because it is commonly used for access control, but it does not provide just-in-time privileged role activation.

744
MCQeasy

A company's security team implements a system where every access attempt to sensitive data is recorded, including who accessed the data and when. The logs are regularly reviewed to detect unauthorized access and to hold users accountable for their actions. Which security goal is primarily being addressed by this logging practice?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerD

Non-repudiation provides irrefutable proof that a specific action or event occurred and identifies the entity responsible, preventing them from falsely denying their involvement. By implementing a system that logs every access, an immutable audit trail is created, documenting who accessed what, when, and from where. This comprehensive record serves as forensic evidence, holding users accountable for their actions and making it impossible for them to credibly deny having performed a particular operation.

Why this answer

Non-repudiation ensures that a user cannot deny having performed an action. By recording who accessed sensitive data and when, the logging practice creates an audit trail that can prove a specific user accessed the data at a specific time, thereby preventing the user from denying that access. This directly addresses the security goal of non-repudiation.

Exam trap

The trap here is that candidates confuse logging with confidentiality or integrity, thinking that recording access prevents unauthorized viewing or data modification, when in fact logging is about accountability and non-repudiation.

How to eliminate wrong answers

Option A is wrong because confidentiality focuses on preventing unauthorized access to data (e.g., through encryption or access controls), not on logging who accessed it. Option B is wrong because integrity ensures data has not been tampered with (e.g., through hashing or checksums), not on recording access events. Option C is wrong because availability ensures systems and data are accessible when needed (e.g., through redundancy or failover), not on tracking user actions.

745
MCQmedium

A healthcare organization uses Microsoft 365 and wants to prevent users from sending emails that contain patient health information (PHI) to external recipients. Which Microsoft Purview solution should they implement?

A.Data Lifecycle Management
B.Data Loss Prevention (DLP)
C.Insider Risk Management
D.eDiscovery
AnswerB

Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across various locations, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. These policies leverage sensitive information types, labels, or keywords to detect data such as patient records or financial details. Upon detection, DLP can automatically block sharing, warn users with policy tips, or encrypt content, thereby preventing accidental or malicious data exfiltration in real-time.

Why this answer

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and prevent the unauthorized sharing of sensitive data, such as patient health information (PHI), via email and other channels. DLP policies can be configured with sensitive information types (e.g., HIPAA-defined PHI patterns) to automatically block or warn users when they attempt to send such data to external recipients.

Exam trap

The trap here is that candidates may confuse Insider Risk Management (which investigates suspicious behavior) with DLP (which proactively prevents data loss), leading them to choose Option C because they think 'insider' implies an employee sending PHI externally.

Why the other options are wrong

A

Data Lifecycle Management focuses on retaining and deleting data based on policies, not on preventing data from being sent externally. It does not inspect or block emails containing sensitive information like PHI.

C

Insider Risk Management focuses on identifying, investigating, and acting on risky user activities (e.g., data theft or policy violations), not on preventing the sending of emails containing PHI to external recipients. The specific requirement to block outbound emails with sensitive data is a Data Loss Prevention (DLP) function.

When would these options actually be correct?

A

Data Lifecycle Management would be correct if the question asked about automatically archiving or deleting emails containing PHI after a specified retention period, or about managing the lifecycle of sensitive data to meet regulatory requirements.

C

A question might ask: 'An organization wants to detect and investigate potential data exfiltration by employees who may be copying sensitive files to personal cloud storage. Which solution should they use?' In that scenario, Insider Risk Management would be correct.

Why candidates pick the wrong answer

A

Candidates may confuse lifecycle management with data protection, thinking that managing data retention also prevents data leaks, or they may assume that any solution with 'management' in the name handles data security broadly.

C

Candidates may confuse Insider Risk Management with DLP because both deal with data protection and insider threats, but they serve different purposes: DLP prevents data loss, while Insider Risk Management detects risky behavior after the fact.

746
MCQeasy

A company implements multiple layers of security controls, including firewalls, antivirus software, access controls, and security awareness training. Which security concept does this approach best represent?

A.Zero Trust
B.Defense in depth
C.Shared responsibility
D.Least privilege
AnswerB

Defense in depth is a cybersecurity strategy that employs multiple, overlapping layers of security controls to protect information and systems. This approach ensures that if one security control fails or is bypassed, another control is in place to prevent or detect an intrusion, thereby increasing the overall resilience of the system. Examples include physical security, network firewalls, endpoint protection, identity and access management, data encryption, and security awareness training, all working in concert to create a robust security posture.

Why this answer

Defense in depth is the correct concept because it involves layering multiple independent security controls—such as firewalls, antivirus, access controls, and training—so that if one layer fails, others continue to protect the asset. This approach reduces the likelihood of a single point of failure and is a foundational strategy in cybersecurity architecture.

Exam trap

The trap here is that candidates confuse the layered approach of defense in depth with the Zero Trust model, but Zero Trust is specifically about eliminating implicit trust and enforcing per-request verification, not just adding multiple security layers.

How to eliminate wrong answers

Option A is wrong because Zero Trust is a security model based on 'never trust, always verify' that requires continuous authentication and authorization for every access request, not simply the presence of multiple security layers. Option C is wrong because Shared responsibility is a cloud computing model that delineates security obligations between the provider and customer, not a strategy for deploying layered controls on-premises. Option D is wrong because Least privilege is a principle that grants users only the minimum permissions needed to perform their tasks, which is a specific access control practice, not a comprehensive layering strategy.

747
MCQeasy

A company wants to prevent employees from accidentally sharing a document containing personally identifiable information (PII) with external users. The document is stored in OneDrive for Business. Which Microsoft Purview solution should they use?

A.Microsoft Purview Communication Compliance
B.Microsoft Purview Information Protection
C.Microsoft Purview Audit
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerD

Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and automatically protect sensitive information across various locations, including cloud services, on-premises repositories, and endpoints. DLP can detect specific sensitive information types within files, such as Personally Identifiable Information (PII), and then enforce actions like blocking external sharing, notifying users, or encrypting content. This direct enforcement capability makes DLP the ideal solution for preventing accidental data exfiltration by employees.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and prevent the accidental sharing of sensitive data, such as PII, with external users. DLP policies can be configured to scan documents in OneDrive for Business for PII patterns (e.g., Social Security numbers, credit card numbers) and automatically block sharing with external users or trigger a policy tip to warn the employee. This directly addresses the requirement to prevent accidental external sharing of PII.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling) with DLP (enforcement). Labeling alone does not block sharing; DLP is the solution that enforces the actual prevention action. In Microsoft Purview, DLP policies can automatically block external sharing of documents containing PII.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) in Exchange Online, Teams, and Yammer, not to prevent the sharing of PII in OneDrive documents. Option B is wrong because Microsoft Purview Information Protection focuses on classifying and labeling sensitive data (e.g., applying sensitivity labels) but does not inherently enforce blocking actions like preventing external sharing; it requires integration with DLP for enforcement. Option C is wrong because Microsoft Purview Audit provides logging and investigation of past activities (e.g., who shared what and when) but does not proactively prevent sharing from occurring.

748
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically block sign-ins from users whose credentials have been compromised and require them to change their password before access is granted. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra ID Protection
B.Conditional Access policies
C.Privileged Identity Management (PIM)
D.Self-Service Password Reset (SSPR)
AnswerA

Microsoft Entra ID Protection is specifically designed to detect and remediate identity-based risks, including compromised credentials. It leverages machine learning to identify suspicious activities like leaked credentials, anomalous sign-ins, and impossible travel. Upon detection, it can automatically enforce policies such as blocking sign-ins, requiring multi-factor authentication, or prompting for a password change, thereby directly protecting against credential compromise.

Why this answer

Microsoft Entra ID Protection is the correct capability because it automatically detects compromised credentials by analyzing telemetry from Microsoft's Threat Intelligence and the wider ecosystem. When a user's credentials are found in a known leak, Entra ID Protection can enforce a policy that blocks sign-in and requires the user to change their password via an integrated remediation workflow, directly addressing the scenario.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with risk-based policies, but Conditional Access alone cannot detect compromised credentials or enforce password changes—it requires Entra ID Protection as the risk signal source.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies are a decision engine that enforces access controls based on signals (like location or device state), but they do not inherently detect compromised credentials or trigger password changes; they rely on other services like Entra ID Protection for risk signals. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation, access reviews, and auditing for administrative roles, not on detecting or remediating compromised user credentials. Option D is wrong because Self-Service Password Reset (SSPR) allows users to voluntarily reset their own passwords, but it does not automatically block sign-ins or force a password change based on compromised credential detection; it requires user initiation.

749
MCQmedium

An organization uses Microsoft Entra ID and wants to require users to re-authenticate every 4 hours when accessing a critical financial application, even if the user already has an active sign-in session. Which Conditional Access control should be configured?

A.Grant control 'Require multi-factor authentication'
B.Session control 'Sign-in frequency'
C.Session control 'Persistent browser session'
D.Grant control 'Require device to be marked as compliant'
AnswerB

The 'Sign-in frequency' session control directly addresses the requirement to force re-authentication after a specific time interval. This control mandates that users must re-enter their credentials, potentially including MFA, after a defined period (e.g., 4 hours), even if their session is still active and valid. It ensures periodic re-verification of identity throughout the user's workday, enhancing security by limiting the window of compromise for a stolen session token.

Why this answer

The 'Sign-in frequency' session control in Conditional Access allows administrators to specify the time interval after which a user must re-authenticate, even if they have an active session. By setting this to 4 hours, the organization ensures that users re-authenticate before accessing the critical financial application, overriding any existing session tokens.

Exam trap

The trap here is confusing session controls (which manage token lifetime and re-authentication behavior) with grant controls (which enforce conditions at initial sign-in), leading candidates to select 'Require multi-factor authentication' thinking it will force periodic re-authentication.

How to eliminate wrong answers

Option A is wrong because 'Require multi-factor authentication' is a grant control that enforces an additional verification factor at sign-in, but it does not enforce a re-authentication interval; once MFA is satisfied, the session persists until token expiry. Option C is wrong because 'Persistent browser session' controls whether the browser keeps the user signed in after closing, not the frequency of re-authentication during an active session. Option D is wrong because 'Require device to be marked as compliant' ensures the device meets compliance policies (e.g., OS updates, antivirus), but it does not enforce a time-based re-authentication requirement.

750
MCQeasy

A company wants to automatically detect and remediate inappropriate messages in Microsoft Teams. Which Microsoft Purview solution should be configured?

A.Microsoft Purview eDiscovery
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Data Loss Prevention
D.Microsoft Purview Communication Compliance
AnswerD

Microsoft Purview Communication Compliance is specifically designed to help organizations detect, investigate, and take action on inappropriate messages across various communication channels within the organization. It leverages machine learning and predefined or custom policies to identify content related to harassment, threats, adult content, and regulatory compliance violations. This solution provides the necessary tools for proactive monitoring, review, and remediation of problematic communications, directly addressing the requirement to automatically detect and remediate inappropriate messages.

Why this answer

Microsoft Purview Communication Compliance is the correct solution because it is specifically designed to detect and remediate inappropriate messages in Microsoft Teams, including offensive language, harassment, and sensitive information. It uses configurable policies to automatically scan messages and apply remediation actions like flagging, notifying managers, or removing content, directly addressing the requirement for automated detection and remediation.

Exam trap

The trap here is that candidates often confuse Communication Compliance with Data Loss Prevention (DLP), but DLP focuses on sensitive data protection (e.g., PII) rather than inappropriate language or behavioral content, which is the core of this question.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview eDiscovery is used for legal discovery and holds, not for real-time detection or remediation of inappropriate messages; it focuses on searching and exporting content for litigation. Option B is wrong because Microsoft Purview Insider Risk Management detects risky user activities like data theft or policy violations, not inappropriate messaging content in Teams. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) prevents accidental sharing of sensitive data (e.g., credit card numbers) but does not detect or remediate inappropriate language or harassment in messages.

Page 9

Page 10 of 18

Page 11