Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 751–825

1279 questions total · 18pages · All types, answers revealed

Page 10

Page 11 of 18

Page 12
751
MCQeasy

You are viewing an application registration in Microsoft Entra ID. What can you conclude about this app?

A.The app is disabled and cannot be used
B.The app is a single-tenant application that is enabled but has no app roles defined
C.The app has custom roles for role-based access
D.The app is multi-tenant and can be used by other tenants
AnswerB

This statement is correct as it accurately describes the application's configuration. The 'signInAudience' property being set to 'AzureADMyOrg' confirms it is a single-tenant application, restricted to users within the registering tenant. Furthermore, the 'AppRoles' collection is empty, indicating that no custom application-specific roles have been defined for granular access control within the application itself, while the 'Enabled' status is 'True'.

Why this answer

The application registration shows 'App roles' with a value of 0, which means no app roles are defined. The 'Supported account types' setting indicates 'Accounts in this organizational directory only', confirming it is a single-tenant application. The 'Enabled for users to sign-in?' toggle is set to 'Yes', so the app is enabled and can be used.

Exam trap

The trap here is that candidates often confuse a disabled app (where the 'Enabled for users to sign-in?' toggle is set to 'No') with an app that has no app roles defined, leading them to incorrectly select option A when the app is actually enabled but lacks roles.

How to eliminate wrong answers

Option A is wrong because the 'Enabled for users to sign-in?' toggle is set to 'Yes', meaning the app is enabled and can be used. Option C is wrong because the 'App roles' count is 0, indicating no custom roles are defined; custom roles would require at least one app role to be listed. Option D is wrong because the 'Supported account types' is set to 'Accounts in this organizational directory only', which explicitly restricts the app to a single tenant, not multi-tenant.

752
MCQmedium

Your organization uses Microsoft Purview to manage records. For legal reasons, you need to preserve all documents related to a specific litigation case and prevent any modification or deletion. Which feature should you use?

A.Retention labels
B.eDiscovery (Premium) legal hold
C.Data Loss Prevention
D.Audit logs
AnswerB

eDiscovery (Premium) legal holds are specifically designed to preserve content across various Microsoft 365 locations, such as Exchange mailboxes, SharePoint sites, OneDrive accounts, and Microsoft Teams. When a legal hold is applied, it places an immutable preservation lock on all specified content, preventing users from modifying, deleting, or otherwise altering the data, even if a retention policy or label would normally allow it. This ensures that all relevant information is maintained in its original state for legal or investigative purposes, making it the most robust solution for preventing modification and deletion.

Why this answer

eDiscovery (Premium) legal hold is the correct feature because it preserves content in-place by placing a hold on data sources (e.g., Exchange mailboxes, SharePoint sites, OneDrive accounts) associated with a specific litigation case. This prevents any modification or deletion of documents while the hold is active, ensuring compliance with legal preservation requirements. Unlike retention labels, which manage lifecycle policies, legal hold is designed specifically for litigation scenarios to freeze data immutably.

Exam trap

The trap here is that candidates often confuse retention labels (which manage lifecycle) with legal hold (which freezes data for litigation), mistakenly thinking a retention label can prevent deletion immediately, whereas legal hold is the only feature that enforces an in-place, case-specific preservation hold.

How to eliminate wrong answers

Option A is wrong because retention labels are used to classify data and apply retention or deletion rules based on policy, but they do not prevent modification or deletion of documents already in place—they only enforce lifecycle actions at scheduled times, not an immediate, case-specific freeze. Option C is wrong because Data Loss Prevention (DLP) policies monitor and prevent unauthorized sharing or leakage of sensitive data, but they do not preserve or lock documents against modification or deletion. Option D is wrong because audit logs record user activities and changes for forensic review, but they do not prevent modification or deletion—they only provide a historical record after the fact.

753
MCQhard

A company wants to monitor employee communications in Microsoft Teams and Exchange Online for potential policy violations such as harassment or inappropriate sharing of confidential information. They need a solution that allows them to define policies, review flagged messages, and manage investigations. Which Microsoft Purview solution should they use?

A.Communication Compliance
B.Insider Risk Management
C.Information Barriers
D.Audit (Standard or Premium)
AnswerA

Communication Compliance is the dedicated Microsoft Purview solution designed for proactively monitoring and reviewing employee communications across platforms like Microsoft Teams and Exchange. It enables organizations to create policies that detect potential violations, such as harassment, inappropriate content, or regulatory non-compliance, using machine learning and keyword matching. Designated reviewers can then investigate flagged messages, apply remediation actions, and ensure adherence to internal and external standards.

Why this answer

Communication Compliance is the correct Microsoft Purview solution because it is specifically designed to monitor communications (e.g., emails in Exchange Online and messages in Microsoft Teams) for policy violations such as harassment or inappropriate sharing of confidential information. It allows administrators to define customizable policies, automatically flag messages that match sensitive information types or offensive language, and manage investigations through a built-in review workflow.

Exam trap

The trap here is confusing Communication Compliance with Insider Risk Management, as both deal with compliance and risk, but Insider Risk Management is focused on user behavior and data theft, not on monitoring communication content for policy violations like harassment or inappropriate sharing.

Why the other options are wrong

B

Insider Risk Management focuses on detecting and investigating risky user activities (e.g., data theft, malicious insiders) based on analytics, not on monitoring communications for policy violations like harassment or confidential information sharing.

C

Information Barriers are used to prevent communication and collaboration between specific groups or users (e.g., to avoid conflicts of interest), not to monitor communications for policy violations or manage investigations.

When would these options actually be correct?

B

A company wants to detect and investigate potential data theft by employees who are downloading large amounts of data to personal devices or sharing sensitive files externally. Insider Risk Management would be the correct solution.

C

A company needs to restrict communication between two departments (e.g., trading and research) to prevent insider trading. Which Microsoft Purview solution should they use to enforce these restrictions?

Why candidates pick the wrong answer

B

Candidates may confuse the two because both deal with internal policy violations and investigations, but Insider Risk Management is behavior-based, while Communication Compliance is content-based.

C

Candidates may confuse the concept of controlling communications (Information Barriers) with monitoring communications (Communication Compliance), as both involve communication policies.

754
MCQeasy

Your organization is implementing Microsoft Purview to manage data governance. You need to classify sensitive data such as social security numbers automatically. What should you create?

A.Data loss prevention policy
B.Retention label
C.Sensitive information type
D.Trainable classifier
AnswerC

This option is correct because a Sensitive Information Type (SIT) is specifically designed to identify and classify sensitive data based on predefined or custom patterns, keywords, and proximity rules. For detecting Social Security Numbers, a SIT leverages pattern matching (e.g., regular expressions) and checksums to accurately identify these specific data elements across various content sources within Microsoft Purview. This direct detection capability makes it the fundamental classification mechanism for such requirements.

Why this answer

Sensitive information type. Sensitive information types (SITs) are predefined or custom patterns that detect sensitive data like social security numbers automatically. Option A is incorrect because a data loss prevention (DLP) policy uses SITs to enforce actions, but it does not classify data on its own.

Option B is incorrect because retention labels manage data retention and disposal, not classification. Option D is incorrect because trainable classifiers require training with sample data to identify content, whereas SITs use pattern matching out of the box.

755
MCQhard

A security operations team uses Microsoft 365 Defender and wants to detect, investigate, and automatically respond to advanced identity-based attacks targeting on-premises Active Directory, such as Pass-the-Hash (PtH) and Golden Ticket attacks. They also need to integrate these alerts into Microsoft Sentinel for central incident management. Which Microsoft security solution provides these capabilities?

A.Microsoft Defender for Identity
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Office 365
AnswerA

Microsoft Defender for Identity is purpose-built to safeguard on-premises Active Directory environments from sophisticated identity-based attacks. It leverages behavioral analytics to detect suspicious activities like Pass-the-Hash, Golden Ticket attacks, and lateral movement attempts across the network. By monitoring domain controllers and AD FS servers, it provides crucial insights into compromised identities and facilitates automated investigation and response within the Microsoft 365 Defender portal.

Why this answer

Microsoft Defender for Identity (MDI) is the correct answer because it is specifically designed to detect, investigate, and automatically respond to advanced identity-based attacks targeting on-premises Active Directory, including Pass-the-Hash (PtH) and Golden Ticket attacks. It uses behavioral analytics and machine learning to identify suspicious activities such as anomalous Kerberos ticket requests and NTLM authentication anomalies. MDI also natively integrates with Microsoft Sentinel, allowing alerts to be ingested for central incident management.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Identity with Microsoft Defender for Cloud Apps, assuming both handle identity threats, but only MDI specifically targets on-premises Active Directory attacks like PtH and Golden Ticket.

Why the other options are wrong

B

Microsoft Defender for Cloud Apps focuses on cloud application security, not on-premises Active Directory attacks like Pass-the-Hash or Golden Ticket. It does not provide native detection for these identity-based attacks targeting on-prem AD.

D

Microsoft Defender for Office 365 focuses on email and collaboration threats (phishing, malware in attachments/links), not on-premises Active Directory attacks like Pass-the-Hash or Golden Ticket. It does not provide identity-based attack detection for AD or integrate with Microsoft Sentinel for those alerts.

When would these options actually be correct?

B

A question asking which Microsoft solution detects and controls risky user behavior in cloud apps, such as anomalous sign-ins or data exfiltration from SaaS applications, and integrates with Microsoft Sentinel for incident management.

D

A question asks: 'A company wants to protect against advanced phishing attacks targeting executives via email, and automatically remediate malicious messages. Which Microsoft security solution should they use?'

Why candidates pick the wrong answer

B

Candidates may confuse Defender for Cloud Apps with identity protection because it handles user behavior and app usage, but it lacks the on-prem AD attack detection required here.

D

Candidates may confuse the 'Defender' branding and assume all Defender products cover similar threats, or they might think Office 365 includes identity protection because it integrates with Azure AD.

756
MCQeasy

Your organization wants to use Microsoft Defender for Cloud to secure Azure virtual machines. Which feature should they enable to get vulnerability assessment without additional agents?

A.File integrity monitoring
B.Just-in-time VM access
C.Adaptive application controls
D.Vulnerability assessment
AnswerD

Microsoft Defender for Cloud's vulnerability assessment capability actively scans virtual machines, SQL databases, and other resources for security weaknesses, misconfigurations, and missing updates. It identifies known vulnerabilities (CVEs) in operating systems and installed applications, providing actionable recommendations to remediate these findings. This feature is crucial for maintaining a strong security posture by proactively discovering and addressing potential entry points for attackers, often leveraging integrated solutions like Qualys or Microsoft Defender for Endpoint's TVM.

Why this answer

Microsoft Defender for Cloud includes a built-in vulnerability assessment solution for Azure virtual machines that does not require any additional agents. When enabled, it uses the Qualys scanner integrated directly into the platform to continuously scan for vulnerabilities, providing findings without the need to deploy or manage separate agents on the VMs.

Exam trap

The trap here is that candidates may confuse 'vulnerability assessment' with other security controls like file integrity monitoring or adaptive application controls, not realizing that Defender for Cloud offers a dedicated, agentless vulnerability scanning capability specifically for VMs.

How to eliminate wrong answers

Option A is wrong because File integrity monitoring (FIM) tracks changes to critical files, registries, and system settings, not vulnerability scanning. Option B is wrong because Just-in-time (JIT) VM access reduces the attack surface by controlling network access to VMs, not by assessing vulnerabilities. Option C is wrong because Adaptive application controls create allowlists for running applications to prevent malware, not to scan for software vulnerabilities.

757
MCQeasy

An organization wants to allow users to reset their own passwords without help desk intervention. Which Microsoft Entra feature should they enable?

A.Conditional Access
B.Self-service password reset
C.Privileged Identity Management
D.Identity Protection
AnswerB

Self-service password reset (SSPR) is the dedicated Azure AD feature that empowers users to securely reset their own forgotten or expired passwords without requiring administrator intervention. Users must first register and verify authentication methods, such as a mobile phone or alternate email, which are then used to confirm their identity during the reset flow. This capability directly addresses the organization's need to allow users to manage their own passwords, enhancing both security and user productivity.

Why this answer

Self-service password reset (SSPR) is the Microsoft Entra feature specifically designed to allow users to reset their own passwords without requiring help desk intervention. It enforces security through authentication methods (e.g., phone, email, security questions) and can be configured to meet organizational policies. This directly addresses the scenario of reducing help desk workload for password resets.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access after authentication) with SSPR (which handles the password reset process itself), leading them to select A because they think 'self-service' implies a policy-based control.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from untrusted locations) based on signals like user, device, or location — it does not provide a mechanism for users to reset their own passwords. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation, approval workflows, and access reviews for elevated roles; it does not handle end-user password resets. Option D is wrong because Identity Protection uses risk detection (e.g., leaked credentials, anonymous IP addresses) to trigger automated responses like blocking sign-ins or requiring MFA — it does not enable users to reset their own passwords.

758
MCQhard

A compliance officer needs to evaluate their organization's security and compliance posture against multiple regulatory frameworks such as HIPAA, GDPR, and ISO 27001. The solution must provide a continuous assessment score, actionable improvement actions, and the ability to track implementation progress. Which Microsoft Purview solution should they use?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Compliance Manager
D.Microsoft Purview eDiscovery
AnswerC

Microsoft Purview Compliance Manager is the primary solution for a compliance officer to evaluate their organization's adherence to various regulatory standards and internal policies. It provides a quantifiable compliance score, pre-built assessment templates for numerous global and industry-specific regulations (e.g., GDPR, HIPAA, ISO 27001), and actionable recommendations. This service enables organizations to manage and track improvement actions, assign responsibilities, and generate reports to demonstrate compliance posture effectively.

Why this answer

Microsoft Purview Compliance Manager is the correct solution because it provides a continuous compliance assessment score against multiple regulatory frameworks (including HIPAA, GDPR, and ISO 27001), offers actionable improvement actions, and enables tracking of implementation progress through a centralized dashboard. It maps controls to specific regulations and generates a compliance score based on implemented controls, making it the only option that meets all stated requirements.

Exam trap

The trap here is that candidates often confuse Compliance Manager with Information Protection or DLP because all three are Purview solutions, but only Compliance Manager provides multi-framework compliance scoring and improvement tracking, while the others focus on data classification or leakage prevention.

Why the other options are wrong

A

Microsoft Purview Information Protection focuses on classifying and protecting sensitive data through labels and encryption, not on assessing compliance posture against regulatory frameworks like HIPAA, GDPR, or ISO 27001.

When would these options actually be correct?

A

A question asks: 'Which Microsoft Purview solution should be used to classify and protect sensitive documents and emails based on content sensitivity, and apply encryption or access restrictions?'

Why candidates pick the wrong answer

A

Candidates may confuse 'Information Protection' with 'Compliance Manager' because both involve compliance and data protection, but Information Protection is about data classification and encryption, not continuous assessment and improvement tracking.

759
MCQmedium

Your organization uses Microsoft Entra ID. You need to ensure that only users from the finance department can access a sensitive application, and they must be granted access dynamically based on their department attribute. What should you configure?

A.Create an administrative unit for the finance department.
B.Create a dynamic group with rule: user.department -eq "Finance".
C.Enable self-service group management.
D.Configure entitlement management with an access package for the finance application.
AnswerB

Creating a dynamic group with the rule user.department -eq "Finance" directly fulfills the requirement for automatic group membership. Microsoft Entra ID dynamic groups continuously evaluate user attributes against defined rules, automatically adding users whose 'department' attribute matches "Finance" and removing those who no longer meet the criteria. This ensures that the group membership remains accurate and up-to-date without manual intervention, significantly reducing administrative overhead. This feature requires a Microsoft Entra ID P1 or P2 license.

Why this answer

A dynamic group in Microsoft Entra ID automatically adds or removes members based on a rule, such as `user.department -eq "Finance"`. This ensures that only users whose department attribute equals "Finance" are granted access to the sensitive application, and membership updates dynamically as the attribute changes, without manual intervention.

Exam trap

The trap here is that candidates often confuse administrative units (which manage administrative boundaries) with dynamic groups (which manage access based on attributes), leading them to select Option A instead of the correct dynamic group solution.

How to eliminate wrong answers

Option A is wrong because administrative units are used to delegate administrative scopes (e.g., managing users in a specific department), not to control access to applications dynamically based on user attributes. Option C is wrong because self-service group management allows users to create and manage their own groups, but it does not enforce dynamic membership rules based on the department attribute; it relies on manual or approval-based membership. Option D is wrong because entitlement management with access packages provides a governance framework for requesting and approving access, but it does not automatically assign membership based on a dynamic attribute like department; it typically requires manual assignment or approval workflows.

760
MCQhard

A company uses Microsoft Entra ID Privileged Identity Management (PIM) to manage elevated access to Microsoft Entra ID roles. They want to ensure that a user who activates a privileged role must provide a justification and receive approval from their manager before activation is complete. Which PIM configuration should be used?

A.Configure role settings to require multi-factor authentication on activation
B.Configure role settings to require approval on activation
C.Configure role settings to assign the user as permanently active
D.Configure role settings to require an Microsoft Entra ID compliant device
AnswerB

Configuring role settings to require approval on activation directly addresses the need for a manager to authorize privileged access. When a user attempts to activate a role, Microsoft Entra ID PIM routes the request to predefined approvers, who are typically managers or security administrators. The role remains inactive until at least one designated approver explicitly grants permission, ensuring an independent review and authorization before elevated privileges are granted.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) allows administrators to configure role settings that require approval before a role is activated. By enabling the 'Require approval to activate' setting, a designated approver (such as the user's manager) must review and approve the activation request, ensuring that the justification is validated before access is granted.

Exam trap

The trap here is that candidates often confuse 'require approval' with 'require MFA' or 'require compliant device,' not realizing that only the approval setting introduces a separate review step by another person, which is explicitly needed for manager authorization.

How to eliminate wrong answers

Option A is wrong because requiring multi-factor authentication (MFA) on activation enforces additional identity verification but does not involve a separate approval workflow or manager review. Option C is wrong because assigning the user as permanently active eliminates the need for activation entirely, bypassing both justification and approval requirements. Option D is wrong because requiring a Microsoft Entra ID compliant device enforces device health policies but does not implement an approval process for role activation.

761
MCQmedium

A company is deploying Microsoft 365 and wants to ensure that sensitive information in emails and documents is protected from unauthorized access and sharing. The compliance team requires a solution that can automatically classify and label content based on its sensitivity. Which Microsoft Purview feature should they use?

A.Data Loss Prevention (DLP) policies
B.Microsoft Defender for Cloud Apps policies
C.Retention labels
D.Sensitivity labels
AnswerD

Sensitivity labels in Microsoft Purview allow organizations to classify and protect content based on its sensitivity. Labels can be applied manually or automatically using policies that detect sensitive information types. Once labeled, the content can be encrypted, marked with visual markings, and restricted from sharing. This directly meets the requirement to automatically classify and label sensitive information in emails and documents.

Why this answer

Sensitivity labels in Microsoft Purview are designed to classify and protect content by applying encryption, visual markings, and sharing restrictions. They can be applied automatically based on sensitive information types, ensuring that sensitive data is consistently protected. Other features like DLP, retention labels, and Defender for Cloud Apps policies serve different purposes and do not provide the same classification and labeling capabilities.

Exam trap

The trap here is confusing DLP with sensitivity labels, as both deal with sensitive information, but only sensitivity labels provide persistent classification and protection.

762
Drag & Dropmedium

Sequence the steps to configure a retention policy in Microsoft Purview compliance portal.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Retention policies require signing in, navigating to retention, creating a policy, selecting locations/conditions, and setting duration.

763
Multi-Selecthard

Which THREE of the following are core principles of the Zero Trust security model? (Choose three.)

Select 3 answers
A.Verify explicitly
B.Trust but verify
C.Assume breach
D.Least privilege
E.Single factor authentication
AnswersA, C, D

This principle mandates that all access requests, regardless of origin or resource, must be authenticated and authorized rigorously. It involves continuously evaluating user identity, device health, location, and other contextual signals before granting or maintaining access. This explicit verification ensures that no entity is inherently trusted and access is always granted based on real-time policy enforcement.

Why this answer

Option A (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust based on network location. Option C (Assume breach) is correct because Zero Trust operates on the premise that threats may already exist inside the environment, so organizations must minimize blast radius, segment access, encrypt traffic, and use analytics to detect and respond to anomalies. Option D (Least privilege) is correct because Zero Trust limits user and workload access to only what is needed for the task, using just-in-time and just-enough-access policies to reduce lateral movement.

Option B (Trust but verify) is not a Zero Trust principle; it reflects a traditional perimeter-based mindset where trust is initially granted and then checked, which contradicts Zero Trust's explicit verification of every request. Option E (Single factor authentication) is not a Zero Trust principle; Zero Trust strongly favors strong authentication such as multifactor authentication and phishing-resistant methods, not single-factor authentication.

Exam trap

SC-900 often tests the exact wording of Zero Trust principles; the trap is selecting 'trust but verify' (a legacy concept) or 'single factor authentication' (insufficient) instead of the three official principles.

764
MCQeasy

A company uses a financial accounting system where the employee who creates a purchase order cannot also approve it. This policy is designed to prevent a single individual from committing fraud by both initiating and approving a transaction. Which security principle does this practice primarily implement?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Zero Trust
AnswerB

Separation of duties is a critical control in financial systems, ensuring that no single individual possesses all the necessary permissions to complete a high-risk transaction or process from start to finish. For instance, the person who approves a payment should not be the same person who initiates the payment or reconciles the bank statement. This distribution of incompatible privileges across multiple employees significantly mitigates the risk of fraud, errors, and insider threats by requiring collusion to bypass controls.

Why this answer

The practice of requiring different individuals to create and approve purchase orders directly implements the separation of duties principle. This security control ensures that no single person has complete control over a sensitive financial transaction, thereby reducing the risk of fraud or error. In the context of identity and access management, separation of duties enforces that conflicting tasks are assigned to different users to prevent abuse of privileges.

Exam trap

The trap here is that candidates confuse separation of duties with least privilege, but least privilege limits the scope of permissions while separation of duties divides critical tasks to prevent a single point of failure or fraud.

Why the other options are wrong

A

The policy prevents the same person from both creating and approving a purchase order, which is a classic example of separation of duties, not least privilege. Least privilege would limit access rights to only what is necessary for a role, but it does not address the conflict of interest between initiating and approving transactions.

C

Defense in depth is a layered security strategy using multiple controls, not a principle that separates conflicting duties to prevent fraud. The question specifically asks about preventing a single individual from both initiating and approving a transaction, which is the definition of separation of duties.

D

Zero Trust is a security model that assumes no implicit trust and continuously verifies every access request, but it does not specifically address the separation of conflicting duties like creating and approving purchase orders.

When would these options actually be correct?

A

In a scenario where a company restricts a user's access to only the specific files needed for their job, such as a customer service representative only having read access to customer records and no access to financial data, the principle of least privilege would be the correct answer.

C

An exam question might ask: 'A company implements firewalls, intrusion detection, antivirus, and employee training to protect its network. Which security principle does this illustrate?' In that context, defense in depth would be correct because it describes multiple layers of security controls.

D

A question that asks: 'A company implements a policy where all network access requests must be authenticated and authorized regardless of whether they originate from inside or outside the corporate network. Which security principle does this describe?'

Why candidates pick the wrong answer

A

Candidates may confuse least privilege with separation of duties because both involve restricting user actions, but least privilege focuses on minimal access rights, while separation of duties focuses on dividing critical tasks among multiple people to prevent fraud.

C

Candidates may confuse 'defense in depth' with any security practice that involves multiple controls, mistakenly thinking that separating duties is a form of layered defense, rather than recognizing it as a distinct principle of internal control.

D

Candidates may confuse Zero Trust with any security control that prevents fraud, not realizing that Zero Trust focuses on access verification rather than role-based task separation.

765
MCQmedium

A multinational company deploys Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers. The compliance team reports that a DLP policy blocks a legitimate payment processing workflow. What should the compliance administrator do to allow the workflow while maintaining protection?

A.Add the payment processing server to the DLP policy’s allow list.
B.Configure a DLP policy tip that allows users to override the block with a business justification.
C.Reduce the minimum confidence level in the DLP policy.
D.Disable the DLP policy for the payment processing department.
AnswerB

Configuring a DLP policy tip that allows users to override the block with a business justification is the optimal solution. This approach provides real-time notification to users when a potential policy violation occurs, offering them the flexibility to proceed if they can provide a valid business reason. This balances robust data protection with operational continuity, ensuring legitimate workflows can proceed while maintaining an auditable record of all overrides and their justifications for compliance and accountability.

Why this answer

DLP policy tips allow users to override a block by providing a business justification, which enables legitimate workflows to proceed while maintaining data protection. This approach ensures that the payment processing workflow is not permanently blocked, but the override is auditable and subject to compliance review. It balances security and operational needs without disabling or weakening the DLP policy.

Exam trap

The trap here is that candidates may think adding the server to an allow list (Option A) is the simplest fix, but this creates a security gap by exempting all data from that server, whereas the policy tip override maintains protection while allowing legitimate exceptions with accountability.

How to eliminate wrong answers

Option A is wrong because adding the payment processing server to the DLP policy's allow list would exempt all traffic from that server, potentially allowing unauthorized data exfiltration through that server and bypassing protection entirely. Option C is wrong because reducing the minimum confidence level would make the DLP policy less sensitive, increasing the risk of false negatives and potentially missing actual credit card number exposures. Option D is wrong because disabling the DLP policy for the entire payment processing department removes protection for all users in that department, leaving credit card numbers unprotected and violating compliance requirements.

766
MCQmedium

A company requires that all users accessing a financial application from outside the corporate network must complete multi-factor authentication (MFA). The IT team is configuring a Microsoft Entra ID Conditional Access policy to enforce this requirement. Which component of the policy should be configured to apply the MFA requirement?

A.Conditions
B.Assignments
C.Session controls
D.Grant controls
AnswerD

Grant controls are the specific mechanisms within a Conditional Access policy that determine how access is granted or denied, and what requirements must be satisfied before access is permitted. By configuring 'Require multi-factor authentication' under Grant controls, the policy explicitly mandates that users must successfully complete an MFA challenge before they can gain access to the protected resource. This directly enforces the MFA requirement, making it the correct choice for this scenario.

Why this answer

Grant controls are the component of a Conditional Access policy that enforce the actual access requirements, such as requiring multi-factor authentication (MFA). By configuring the 'Require multi-factor authentication' checkbox under Grant controls, the policy ensures that users must complete MFA before accessing the financial application. This is the correct setting to apply the MFA requirement.

Exam trap

The trap here is confusing Grant controls (which enforce the MFA requirement) with Conditions (which define the 'when' of the policy), leading candidates to incorrectly select Conditions because they think it controls the MFA trigger rather than the enforcement action.

Why the other options are wrong

A

Conditions define when the policy applies (e.g., location, device state), not what happens when conditions are met. The MFA requirement is enforced via Grant controls, which specify the access requirements.

B

Assignments define which users, groups, or applications the policy applies to, not what happens after access is granted. The MFA requirement is enforced via Grant controls, which specify the conditions that must be met for access.

C

Session controls manage user experience during a session (e.g., sign-in frequency, app restrictions), not enforce MFA. MFA enforcement is done via Grant controls, which require specific conditions to be met before access is granted.

When would these options actually be correct?

A

A question asks: 'Which component of a Conditional Access policy specifies that access is only allowed from trusted locations?' In that case, Conditions would be correct because it includes location conditions like IP ranges or countries.

B

In a scenario where the question asks which component specifies which users or groups are targeted by a Conditional Access policy (e.g., 'Configure a policy to require MFA for all users in the Finance group'), Assignments would be the correct answer.

C

A question asks: 'Which policy component should be configured to require users to re-authenticate every hour when accessing a sensitive app?' In that scenario, Session controls (specifically sign-in frequency) would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse 'Conditions' with the overall policy logic, thinking that specifying MFA is a condition rather than a control action. The term 'conditions' sounds like it could include requirements, but in Conditional Access, conditions are the triggers, not the enforcement.

B

Candidates may confuse 'assignments' with the action of assigning MFA requirements, not realizing that in Conditional Access, Assignments only define scope, while Grant controls enforce the actual access conditions.

C

Candidates may confuse session controls with access controls, thinking that settings like 'Require MFA reauthentication' are session controls, but in Conditional Access, MFA is a grant control, not a session control.

767
MCQeasy

You need to provide external partners with access to your organization's SharePoint site. The partners must use their own credentials. Which Microsoft Entra feature should you use?

A.Microsoft Entra B2B collaboration
B.Microsoft Entra Identity Governance
C.Privileged Identity Management
D.Microsoft Entra ID Protection
AnswerA

Microsoft Entra B2B collaboration is the correct solution for securely providing external partners with access to your organization's resources. It enables guest users to sign in using their own existing identities, such as work, school, or social accounts, without requiring them to create new credentials in your tenant. This streamlined process facilitates collaboration by inviting external users to access specific applications or documents while maintaining administrative control over their permissions.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it enables external users (partners) to access your organization's resources using their own identities (e.g., work, social, or other Azure AD accounts). It leverages the existing Azure AD tenant to issue guest user objects and supports SAML/WS-Federation or OIDC for authentication, allowing partners to authenticate with their own credentials without requiring a separate account or password in your tenant.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C (not listed), or mistakenly think Identity Governance or PIM can handle external authentication, when in fact B2B collaboration is the only feature that allows external users to bring their own credentials for resource access.

How to eliminate wrong answers

Option B (Microsoft Entra Identity Governance) is wrong because it focuses on managing the lifecycle of identities and access rights (e.g., access reviews, entitlement management) but does not itself provide the mechanism for external users to authenticate with their own credentials. Option C (Privileged Identity Management) is wrong because it is designed to manage, control, and monitor privileged roles and just-in-time access within your own directory, not to enable external authentication. Option D (Microsoft Entra ID Protection) is wrong because it is a security tool that detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not facilitate external user sign-in with their own credentials.

768
MCQhard

Fabrikam Inc., a global financial services company, uses Microsoft Purview to manage compliance. They have the following requirements: (1) Prevent users from sending emails containing credit card numbers (CCN) to external recipients; (2) automatically encrypt emails containing CCN; (3) notify users when an email is blocked; (4) allow users to override the block for business justifications; (5) generate incident reports for compliance teams. The company uses Microsoft 365 E5 licenses and has Exchange Online configured. The compliance team wants to implement a solution with minimal administrative overhead. What should the administrator configure?

A.Configure information barriers between the finance department and external recipients.
B.Create a Data Loss Prevention (DLP) policy in the Microsoft Purview compliance portal with conditions for CCN, and configure actions to block, encrypt, notify, and allow override.
C.Create a sensitivity label that automatically classifies emails with CCN and configure a label policy to encrypt them.
D.Enable Microsoft Purview Message Encryption and create a mail flow rule in Exchange to encrypt emails with CCN.
AnswerB

A Microsoft Purview DLP policy evaluates sensitive information types such as credit card numbers across Exchange Online email, then enforces block, encryption, user notification and override with business justification in one rule set. This satisfies all five requirements with minimal administrative overhead, since E5 licensing already includes the necessary Purview capabilities.

Why this answer

A DLP policy can block, encrypt, notify, and allow override, with incident reports. Option A is wrong because information barriers prevent communication between groups, not data exfiltration. Option C is wrong because sensitivity labels with auto-labeling classify but do not prevent sending.

Option D is wrong because message encryption without DLP does not block or provide override.

769
MCQmedium

A security architect is implementing a Zero Trust strategy. They state that all access requests must be verified continuously, regardless of where the request originates (corporate network or remote). They also emphasize that access is granted based on a policy that evaluates user identity, device health, location, and risk in real-time. Which Zero Trust guiding principle does this scenario primarily illustrate?

A.Verify explicitly
B.Use least privilege access
C.Assume breach
D.Enforce session controls
AnswerA

"Verify explicitly" is a foundational principle of Zero Trust, mandating that all access requests, regardless of origin, must be thoroughly authenticated and authorized before granting access. This involves evaluating multiple dynamic data points, including user identity, device health, service or workload, data classification, location, and detected anomalies, to make an informed, real-time access decision. It fundamentally shifts security from perimeter-based trust to continuous, granular validation, never implicitly trusting anything inside or outside the network.

Why this answer

The scenario explicitly describes continuous verification of all access requests based on real-time signals (user identity, device health, location, risk). This directly maps to the 'Verify explicitly' Zero Trust principle, which mandates that every access attempt must be authenticated and authorized using all available data points before granting access, regardless of network location.

Exam trap

The trap here is that candidates often confuse 'Verify explicitly' with 'Assume breach' because both involve continuous monitoring, but 'Verify explicitly' is specifically about authenticating and authorizing every request, while 'Assume breach' is about containment and detection after a compromise.

How to eliminate wrong answers

Option B is wrong because 'Use least privilege access' focuses on limiting permissions to the minimum required for a task, not on continuous verification of every request. Option C is wrong because 'Assume breach' is about designing systems to minimize blast radius and detect intrusions, not about verifying each access request in real-time. Option D is wrong because 'Enforce session controls' refers to monitoring and restricting actions within an established session, not the initial or continuous verification of access requests.

770
MCQeasy

Your organization uses Microsoft Entra ID. You need to ensure that users can reset their own passwords without help desk intervention, while maintaining security by requiring multi-factor authentication (MFA) during the reset process. Which feature should you enable?

A.Microsoft Entra Identity Protection.
B.Microsoft Entra Multi-Factor Authentication.
C.Conditional Access policies.
D.Microsoft Entra self-service password reset (SSPR).
AnswerD

Microsoft Entra self-service password reset (SSPR) is a crucial feature that empowers users to reset their forgotten or locked passwords without administrator intervention. SSPR can be configured to require users to verify their identity through multiple authentication methods, including MFA, before they can successfully reset their password, thereby enhancing both convenience and security for password management within the organization.

Why this answer

Microsoft Entra self-service password reset (SSPR) is the feature specifically designed to allow users to reset their own passwords without help desk intervention. When combined with Microsoft Entra Multi-Factor Authentication (MFA) as a registration and reset requirement, SSPR enforces MFA during the reset process, meeting both the self-service and security requirements.

Exam trap

The trap here is that candidates often confuse the authentication enforcement mechanism (MFA or Conditional Access) with the actual self-service reset feature, mistakenly selecting MFA or Conditional Access instead of SSPR, which is the only option that directly provides the password reset functionality.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Identity Protection is a risk-based detection and remediation service that can trigger automated responses (e.g., requiring MFA or blocking sign-ins) but does not itself enable users to reset passwords. Option B is wrong because Microsoft Entra Multi-Factor Authentication alone provides an additional verification step during authentication but does not include the self-service password reset capability. Option C is wrong because Conditional Access policies enforce access controls (e.g., requiring MFA or blocking locations) based on conditions, but they do not directly enable users to reset their own passwords.

771
Matchingmedium

Match each security control type to its example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Warning signs or security policies

Firewall rules blocking unauthorized access

Intrusion detection system alerts

Patching a vulnerability after discovery

Requiring strong passwords via policy

Why these pairings

Security control types categorize how controls operate: preventive controls block incidents, detective controls identify them, and corrective controls fix issues. Common examples include firewall rules (preventive), IDS (detective), and backup/restore (corrective).

772
MCQmedium

A company uses Microsoft 365 and wants to deploy a security solution that can automatically detect and remediate advanced attacks on endpoints (workstations and servers), such as ransomware and fileless attacks. They also want to provide incident response teams with detailed forensic data and the ability to isolate an infected machine from the network. Which Microsoft security solution should they use?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Defender for Endpoint is a comprehensive enterprise endpoint security platform designed to protect devices from advanced threats. It offers Endpoint Detection and Response (EDR) capabilities, next-generation protection, attack surface reduction, and automated investigation and remediation. This solution actively monitors endpoints for malicious activity, isolates compromised devices, and provides a unified view of security incidents across an organization's device fleet, making it ideal for endpoint deployment.

Why this answer

Microsoft Defender for Endpoint (MDE) is the correct solution because it provides endpoint detection and response (EDR) capabilities, including automatic detection and remediation of advanced attacks like ransomware and fileless attacks. It also offers detailed forensic data for incident response and the ability to isolate an infected machine from the network, meeting all the specified requirements.

Exam trap

The trap here is that candidates confuse the endpoint-focused capabilities of Microsoft Defender for Endpoint with the email/identity/cloud-specific scopes of the other Defender products, failing to recognize that only MDE provides automated endpoint remediation and network isolation for workstations and servers.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 focuses on protecting email, SharePoint, and Teams from threats like phishing and malware, not on endpoint-level attacks or machine isolation. Option C is wrong because Microsoft Defender for Identity monitors on-premises Active Directory and cloud identities for compromised credentials and lateral movement, but does not provide endpoint detection, forensic data, or network isolation for workstations and servers. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that governs and protects cloud applications, not endpoints; it cannot detect fileless attacks on workstations or isolate machines from the network.

773
MCQeasy

Your company uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts. Which Microsoft Entra feature should you configure?

A.Microsoft Entra External ID
B.Microsoft Entra B2B collaboration
C.Conditional Access policies
D.Privileged Identity Management
AnswerA

Microsoft Entra External ID is the comprehensive solution for managing all external identities, including customers, partners, and citizens, across various applications. It specifically supports integrating social identity providers like Google, Facebook, and Microsoft accounts, as well as enterprise identity providers, allowing users to sign in to your applications using their existing credentials. This capability is crucial for consumer-facing applications that require flexible and convenient sign-up and sign-in experiences without creating new accounts.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2C) is the correct feature because it is specifically designed to enable external identities, including social identity providers like Google, Facebook, and Microsoft accounts, for customer-facing applications. It supports standards such as OAuth 2.0 and OpenID Connect to allow users to sign in with their existing social media accounts without needing a separate Microsoft Entra ID account.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration (for business partners) with Microsoft Entra External ID (for customers/consumers), mistakenly thinking B2B can also handle social identity providers, but B2B only supports organizational accounts (e.g., work/school) and not social logins.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2B collaboration is designed for business-to-business scenarios, allowing external business partners to access your organization's resources using their own corporate identities, not for consumers signing in with social media accounts. Option C is wrong because Conditional Access policies are used to enforce access controls (e.g., MFA, location) after authentication, not to configure identity providers or enable social sign-in. Option D is wrong because Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles within Microsoft Entra ID, and has no role in configuring external or social identity providers.

774
Multi-Selecthard

Which THREE Microsoft Purview solutions help protect sensitive data in Microsoft 365? (Choose three.)

Select 3 answers
A.Data Loss Prevention
B.Information Protection (sensitivity labels)
C.Insider Risk Management
D.Audit
E.eDiscovery
AnswersA, B, C

Microsoft Purview Data Loss Prevention (DLP) actively identifies, monitors, and protects sensitive information across endpoints, cloud applications, and on-premises repositories. It enforces policies to prevent the unauthorized sharing, transfer, or exfiltration of sensitive data, whether accidental or malicious, by detecting specific content and context and blocking or auditing the action. This proactive approach is fundamental to safeguarding an organization's critical information assets.

Why this answer

Data Loss Prevention (DLP) is correct because it identifies, monitors, and automatically protects sensitive data across Exchange Online, SharePoint, OneDrive, and Teams by applying policies that block or warn users when sensitive content (e.g., credit card numbers or PII) is shared inappropriately. It uses deep content analysis, including keyword matches, regex patterns, and machine learning classifiers, to enforce protection actions.

Exam trap

The trap here is that candidates confuse Audit and eDiscovery as protective solutions because they are part of the Microsoft Purview compliance portal, but they are detective and investigative tools, not preventive controls like DLP, Information Protection, or Insider Risk Management.

775
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that allows external partners to access resources using their own identity provider. Which Microsoft Entra feature should you use?

A.Microsoft Entra Permissions Management
B.Microsoft Entra Verified ID
C.Entra ID Governance
D.External ID
AnswerD

External ID is the Microsoft Entra feature designed for external identities, letting partners authenticate with their own identity provider through federation or guest accounts. It satisfies the requirement for partner access using their existing credentials, rather than creating and managing separate local accounts.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2B) allows external partners to access your organization's resources using their own identity providers, enabling secure collaboration without managing external identities. Option A is incorrect because Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) solution for multi-cloud permissions. Option B is incorrect because Microsoft Entra Verified ID is a verifiable credentials solution for decentralized identity verification.

Option C is incorrect because Entra ID Governance focuses on identity lifecycle management, access reviews, and entitlement management.

776
Multi-Selectmedium

Which TWO of the following are examples of sensitive information types in Microsoft Purview? (Select TWO.)

Select 2 answers
A.Passport number
B.Public holiday list
C.Employee name
D.Internal project code name
E.Credit card number
AnswersA, E

A passport number is considered sensitive information because it is a unique government-issued identifier directly linked to an individual's identity, nationality, and travel history. Unauthorized disclosure could lead to severe consequences such as identity theft, fraud, or impersonation. Microsoft Purview includes "Passport Number" as a predefined sensitive information type (SIT), utilizing pattern matching, keywords, and proximity to detect and protect this critical personal data across an organization's digital estate, aligning with global privacy regulations.

Why this answer

In Microsoft Purview, sensitive information types (SITs) are pattern-based classifiers that detect specific data such as personally identifiable information or financial data. Option A (Passport number) is correct because passport numbers are a built-in SIT category used to identify government-issued identity data across many countries. Option E (Credit card number) is correct because credit card numbers are a classic built-in SIT, detected via patterns like the Luhn check plus keyword corroboration (e.g., 'credit card').

Option B (Public holiday list) is not sensitive data and has no SIT pattern. Option C (Employee name) is not a standalone SIT because a name alone lacks a reliable pattern and is typically only used as supporting evidence in other SITs. Option D (Internal project code name) is business-confidential but not a predefined sensitive information type, since SITs target specific data formats rather than arbitrary internal labels.

Exam trap

The trap here is that candidates often confuse 'sensitive information' with any internal or confidential data, but Microsoft Purview only recognizes specific, pattern-based data types like passport numbers and credit card numbers, not generic labels like project code names or employee names.

777
MCQhard

A company uses Microsoft Purview to classify and protect data. They need to ensure that when a user attempts to share a file containing a credit card number externally, the file is blocked and the user is prompted with a policy tip. Which type of Microsoft Purview policy should they configure?

A.Retention policy
B.Insider Risk Management policy
C.Sensitivity label policy
D.Data Loss Prevention (DLP) policy
AnswerD

A Data Loss Prevention (DLP) policy is specifically engineered to identify, monitor, and automatically protect sensitive information across various locations and sharing scenarios. It leverages sensitive information types (SITs) to detect specific content patterns, such as credit card numbers, within documents or emails. Upon detection, a DLP policy can be configured to block external sharing in real-time, notify administrators, and provide policy tips to users, directly addressing the need to prevent sensitive data from leaving the organization.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are designed to detect sensitive information types such as credit card numbers and take action — blocking sharing, showing policy tips, or restricting access. DLP policies evaluate content in Exchange, SharePoint, OneDrive, Teams, and endpoints, and can trigger user notifications when a policy match occurs. This directly satisfies the requirement to block external sharing and prompt the user.

Exam trap

SC-900 often tests the distinction between DLP, sensitivity labels, and retention policies — candidates confuse classification (labels) with enforcement (DLP) and pick the label option when blocking and policy tips are required.

How to eliminate wrong answers

Option A is wrong because retention policies govern how long content is kept or deleted, not whether it can be shared externally. Option B is wrong because Insider Risk Management detects risky user behavior patterns but does not block file sharing or display policy tips at the point of sharing. Option C is wrong because sensitivity labels classify and protect content (e.g., encryption, watermarking) but do not by themselves block external sharing or show policy tips based on content inspection.

778
MCQhard

Refer to the exhibit. The Conditional Access policy shown is applied to all users accessing Office 365. A user with a compliant device but no MFA registered attempts to access Exchange Online. What will happen?

A.Access is blocked
B.Access is granted because the policy is only for Office 365 and the user uses Exchange Online
C.Access is granted after MFA registration prompt
D.Access is granted because the device is compliant
AnswerA

This policy explicitly requires both multi-factor authentication (MFA) and a compliant device as grant controls. For access to be permitted, all specified grant controls must be satisfied simultaneously. Since the user has not registered for MFA, this critical requirement is not met, leading to the conditional access policy blocking the access attempt.

Why this answer

The Conditional Access policy requires MFA registration for all users accessing Office 365 cloud apps. Since the user has not registered MFA, the policy's grant control (Require MFA registration) is not satisfied, and the policy blocks access. The device compliance status is irrelevant because the policy does not include device compliance as a grant control.

Exam trap

The trap here is that candidates assume a compliant device automatically satisfies Conditional Access policies, but the policy explicitly requires MFA registration, and device compliance is irrelevant unless included as a grant control.

How to eliminate wrong answers

Option B is wrong because Exchange Online is included under Office 365 in the Conditional Access policy's cloud apps assignment, so the policy applies to Exchange Online access. Option C is wrong because the policy does not grant access with an MFA registration prompt; it blocks access when the MFA registration requirement is not met. Option D is wrong because the policy does not have a 'Require compliant device' grant control, so device compliance alone does not satisfy the policy's requirements.

779
MCQhard

Your organization uses Microsoft Purview eDiscovery to manage legal holds. You need to place a hold on mailboxes and OneDrive accounts for a specific user who is involved in a litigation. Which eDiscovery solution should you use?

A.Audit
B.Communication Compliance
C.Content search
D.eDiscovery (Standard)
AnswerD

eDiscovery (Standard) supports creating holds on Exchange mailboxes and SharePoint or OneDrive sites, and the user's mailbox and OneDrive can both be placed on hold within a single case. It satisfies the litigation-hold requirement without the premium custodian and review-set features of eDiscovery (Premium).

Why this answer

eDiscovery (Standard) is the correct solution because it is designed specifically for legal hold management, allowing you to place a hold on content locations such as mailboxes and OneDrive accounts for a specific user involved in litigation. This hold preserves all content in those locations, including deleted items and versions, until the hold is released. Audit, Communication Compliance, and Content search do not provide the legal hold functionality required for this scenario.

Exam trap

The trap here is that candidates often confuse Content search with eDiscovery (Standard) because both involve searching content, but Content search lacks the legal hold capability that is explicitly required for litigation holds.

How to eliminate wrong answers

Option A is wrong because Audit in Microsoft Purview is used for logging and reviewing user and admin activities, not for placing legal holds on content. Option B is wrong because Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, sensitive info), not to place holds for litigation. Option C is wrong because Content search is used to search for content across Exchange, SharePoint, and OneDrive, but it does not have the capability to place a hold on content locations; it is a search-only tool.

780
MCQhard

A security administrator needs to block legacy authentication protocols across all applications in Microsoft Entra ID. Which conditional access policy setting should they configure?

A.Under 'Grant', select 'Block access'
B.Under 'Conditions', configure 'Locations' to block all locations
C.Set 'Sign-in frequency' to 1 hour
D.Under 'Conditions', configure 'Client apps' to block legacy authentication
AnswerD

Under 'Conditions', configuring 'Client apps' allows administrators to target specific client applications and authentication protocols. By selecting 'Other clients' (which includes clients using legacy authentication protocols like Exchange ActiveSync, POP, IMAP, and older Office clients), and then applying a 'Block' grant control, the policy effectively prevents sign-ins from these legacy methods. This precisely addresses the requirement to block legacy authentication without impacting modern authentication flows.

Why this answer

Legacy authentication protocols (such as POP3, IMAP4, SMTP, and older Office clients) do not support modern authentication methods like MFA or conditional access. By configuring the 'Client apps' condition in a Conditional Access policy to block legacy authentication, the administrator can prevent these insecure sign-in attempts across all applications in Microsoft Entra ID.

Exam trap

The trap here is that candidates may confuse 'Block access' under 'Grant' (which is a general block) with the specific condition needed to target legacy protocols, or they may think that location or sign-in frequency settings can address protocol-level restrictions.

How to eliminate wrong answers

Option A is wrong because 'Block access' under 'Grant' is a control that blocks all access after conditions are evaluated, but it does not specifically target legacy authentication protocols; it would block all users regardless of client type. Option B is wrong because configuring 'Locations' to block all locations would prevent sign-ins from any geographic location, which is unrelated to blocking legacy authentication protocols. Option C is wrong because setting 'Sign-in frequency' to 1 hour controls session lifetime and reauthentication prompts, not the type of authentication protocol used during sign-in.

781
MCQmedium

A company uses Microsoft 365 and needs to comply with a regulatory requirement to retain all customer contracts for 5 years after the contract's end date, after which they must be automatically deleted. Additionally, the legal department needs the ability to preserve all documents related to an ongoing lawsuit, overriding any deletion timelines. Which Microsoft Purview solution should the company use?

A.Information Barriers
B.Data Lifecycle Management with retention labels and eDiscovery holds
C.Communication Compliance
D.Audit (Premium)
AnswerB

Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels to define how long content should be retained or deleted across various services, ensuring compliance with organizational policies and regulations. Concurrently, eDiscovery holds (also known as litigation holds) are specifically designed to preserve content indefinitely for legal proceedings, overriding any existing retention or deletion policies applied by retention labels. This combination effectively addresses both routine data retention and specific legal preservation requirements.

Why this answer

Data Lifecycle Management (DLM) with retention labels allows the company to apply a retention label to customer contracts that retains them for 5 years after the contract end date and then automatically deletes them. eDiscovery holds can be placed on all documents related to an ongoing lawsuit, which overrides any deletion timelines, ensuring that content is preserved until the hold is released. This combination directly meets both the regulatory retention and legal preservation requirements.

Exam trap

The trap here is that candidates may confuse eDiscovery holds with retention labels, thinking that retention labels alone can handle legal preservation, but they fail to recognize that eDiscovery holds are required to override deletion timelines for litigation purposes.

How to eliminate wrong answers

Option A is wrong because Information Barriers are used to prevent communication and collaboration between specific groups or users to avoid conflicts of interest, not to manage retention or legal holds. Option C is wrong because Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) by analyzing messages, not to enforce retention schedules or preserve documents for litigation. Option D is wrong because Audit (Premium) provides detailed logging and investigation of user and admin activities, but it does not offer retention policies or the ability to override deletion with legal holds.

782
Multi-Selectmedium

Which TWO Microsoft Entra features can be used together to enforce risk-based conditional access?

Select 2 answers
A.Entra Verified ID
B.Conditional Access
C.Identity Protection
D.Self-Service Password Reset
E.Privileged Identity Management
AnswersB, C

Microsoft Entra Conditional Access is a policy engine that evaluates conditions, including user and sign-in risk levels detected by Identity Protection, to enforce specific access controls. It allows administrators to define "if-then" statements, such as "if a user is signing in from a risky location, then block access or require multi-factor authentication." This direct integration makes it crucial for implementing risk-based access policies.

Why this answer

Conditional Access (B) is correct because it is the policy engine that enforces access decisions based on signals, including risk levels. Identity Protection (C) is correct because it detects and calculates user and sign-in risk in real time using machine learning. Together, Identity Protection provides the risk assessment, and Conditional Access enforces the policy (e.g., block or require MFA) based on that risk.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with risk-based access, but PIM controls role activation, not risk evaluation, while Identity Protection is the dedicated risk detection service.

783
MCQmedium

Fabrikam Inc. is a global manufacturing company that uses Microsoft Entra ID for identity management. They have recently experienced a security incident where an attacker compromised a user account and accessed sensitive intellectual property. The security team wants to implement identity protection measures to detect and respond to such attacks in the future. They need a solution that can automatically detect suspicious sign-in behavior, such as impossible travel and anomalous token issuance, and then take action to block the sign-in or require additional verification. Additionally, they want to integrate threat intelligence feeds to improve detection. Which Microsoft security solution should they use to meet these requirements?

A.Microsoft Defender for Identity
B.Microsoft Entra ID Protection
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Entra ID Protection uses machine learning to detect risks like impossible travel and anomalous token issuance, and can automatically enforce policies such as requiring MFA or blocking sign-ins. It also integrates with threat intelligence feeds.

Why this answer

Microsoft Entra ID Protection uses machine learning to detect risks like impossible travel and anomalous token issuance, and can automatically enforce policies such as requiring MFA or blocking sign-ins. It also integrates with threat intelligence feeds. Option A is wrong because Microsoft Defender for Identity focuses on on-premises Active Directory, not cloud sign-ins.

Option C is wrong because Microsoft Sentinel is a SIEM, not an automated response tool for sign-in risks. Option D is wrong because Microsoft Defender for Cloud Apps is for cloud app discovery and control, not primarily for sign-in risk detection.

784
MCQeasy

A security analyst is explaining the core principles of information security to a new team member. Which principle ensures that data is not modified by unauthorized parties?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerB

Integrity is the fundamental security principle that ensures data remains accurate, complete, and unaltered by unauthorized parties throughout its lifecycle. It guarantees that information has not been tampered with, either accidentally or maliciously, maintaining its trustworthiness and reliability. Mechanisms such as cryptographic hashing, digital signatures, and robust access controls are employed to detect or prevent unauthorized modifications, thereby preserving the validity and consistency of the data.

Why this answer

The principle of integrity ensures that data remains accurate and unaltered during storage, processing, or transmission, except by authorized entities. In the context of information security, integrity is specifically concerned with preventing unauthorized modification, deletion, or creation of data. This is often enforced through mechanisms such as hashing (e.g., SHA-256), digital signatures, and checksums (e.g., CRC32) that detect any tampering.

Exam trap

The trap here is that candidates often confuse integrity with confidentiality, mistakenly thinking that encryption (which protects confidentiality) also prevents modification, but encryption alone does not guarantee data has not been altered—integrity requires separate controls like hashing or digital signatures.

Why the other options are wrong

A

Confidentiality ensures data is accessible only to authorized users, but it does not prevent unauthorized modification; integrity is the principle that protects data from unauthorized alteration.

C

Availability ensures that data and systems are accessible when needed, but it does not protect against unauthorized modification. The principle that prevents data from being altered by unauthorized parties is integrity.

D

Non-repudiation ensures that a party cannot deny having performed an action (e.g., signing a document), not that data remains unmodified. The question asks about preventing unauthorized modification, which is integrity.

When would these options actually be correct?

A

A question asks: 'Which principle ensures that data is not disclosed to unauthorized individuals?' In that context, confidentiality is the correct answer.

C

In a scenario where a company experiences a DDoS attack that prevents users from accessing a critical application, the principle being compromised is availability. A question asking which principle ensures that systems are up and running when required would have availability as the correct answer.

D

A question asks: 'Which principle ensures that a sender cannot deny having sent a message?' In that context, non-repudiation is correct because it provides proof of origin or delivery.

Why candidates pick the wrong answer

A

Candidates may confuse confidentiality with integrity because both involve protecting data, but confidentiality focuses on secrecy, not on preventing changes.

C

Candidates may confuse availability with integrity because both are part of the CIA triad, and they might think that ensuring data is available also means it hasn't been tampered with, but availability focuses on access, not modification.

D

Candidates may confuse non-repudiation with integrity because both involve data authenticity, but non-repudiation focuses on accountability for actions, not data modification.

785
MCQmedium

A company uses Microsoft Entra ID and Intune for device management. The security team wants to create a Conditional Access policy for a sensitive research application. They require that: 1) The user must use a device that is marked as compliant by Intune, and 2) The user must accept the company's terms of use before accessing the app. Which grant control combination should they configure in the policy?

A.Select 'Require device to be marked as compliant' and 'Require terms of use' and choose 'Require one of the selected controls'
B.Select 'Require multi-factor authentication' and 'Require terms of use' and choose 'Require all the selected controls'
C.Select 'Require device to be marked as compliant' and 'Require terms of use' and choose 'Require all the selected controls'
D.Select only 'Require terms of use' and configure device compliance as a condition
AnswerC

This is the correct configuration because Microsoft Entra Conditional Access policies use 'Grant controls' to define the specific requirements for access. Selecting both 'Require device to be marked as compliant' (which leverages Intune's compliance policies) and 'Require terms of use' as grant controls, combined with the 'Require all the selected controls' operator, ensures that users must satisfy both prerequisites simultaneously to gain access to resources. This precisely fulfills the scenario's need for both device compliance and terms of use acceptance.

Why this answer

The policy requires both conditions—device compliance and terms of use—to be enforced simultaneously. In Microsoft Entra Conditional Access, when multiple grant controls are selected and set to 'Require all the selected controls', the user must satisfy every control to gain access. This matches the security team's requirement that the device must be compliant AND the terms of use must be accepted.

Exam trap

The trap here is that candidates often confuse 'Require one of the selected controls' with 'Require all the selected controls', mistakenly thinking that 'one of' is sufficient when the question explicitly states both conditions must be met.

Why the other options are wrong

A

The policy requires both device compliance and terms of use to be enforced simultaneously, so 'Require one of the selected controls' would allow access if only one condition is met, violating the requirement.

B

The policy requires both device compliance and terms of use, so 'Require all the selected controls' is needed. Option B incorrectly includes multi-factor authentication, which is not required, and uses 'Require one of the selected controls', which would allow bypassing one requirement.

D

Option D is wrong because it omits the 'Require device to be marked as compliant' grant control, which is explicitly required by the policy. Configuring device compliance as a condition only affects when the policy applies, not the grant requirements.

When would these options actually be correct?

A

In a scenario where the security team wants to allow access if the user either has a compliant device OR has accepted terms of use (e.g., for a less sensitive app where flexibility is acceptable), selecting 'Require one of the selected controls' would be correct.

B

In a scenario where the security team requires both multi-factor authentication and acceptance of terms of use, and both must be satisfied, selecting 'Require multi-factor authentication' and 'Require terms of use' with 'Require all the selected controls' would be correct.

D

Option D would be correct if the question asked for a policy that only requires terms of use acceptance, and device compliance is used as a condition to scope the policy (e.g., only apply to non-compliant devices) rather than as a grant control.

Why candidates pick the wrong answer

A

Candidates may confuse 'Require one of the selected controls' with 'Require all the selected controls', thinking it means at least one control is required, but it actually means only one of the selected controls needs to be satisfied.

B

Candidates may confuse multi-factor authentication with device compliance, or mistakenly think that 'Require one of the selected controls' is sufficient when multiple conditions are needed, due to misunderstanding of grant control logic.

D

Candidates may confuse the 'Conditions' section with 'Grant controls', thinking that setting device compliance as a condition satisfies the requirement, without realizing that grant controls enforce the actual access restrictions.

786
MCQmedium

A company wants to securely grant external business partners access to internal SharePoint sites and Teams channels. The partners use various identity providers, including Google and Microsoft personal accounts. The company needs to manage these external identities in their Microsoft Entra ID directory and enforce access policies. Which Microsoft Entra capability should they use?

A.Microsoft Entra B2B collaboration
B.Microsoft Entra B2C (Business-to-Consumer)
C.Microsoft Entra Connect
D.Microsoft Entra Identity Protection
AnswerA

Microsoft Entra B2B collaboration is the correct solution for securely granting external business partners access to internal resources. This service enables organizations to invite external users, such as partners or vendors, to access specific applications and data within their Microsoft Entra tenant as guest users. It supports various identity providers, allowing partners to use their existing corporate or social credentials for authentication, thereby streamlining access while maintaining strong security controls over the shared resources.

Why this answer

Microsoft Entra B2B collaboration is designed to securely share applications and resources with external guest users from any identity provider, including Google and Microsoft personal accounts. It allows the company to manage these external identities in their Entra ID directory and enforce conditional access policies, meeting the requirement to grant partners access to SharePoint and Teams.

Exam trap

The trap here is confusing B2B collaboration (for business partners) with B2C (for customers), leading candidates to select B2C because it also supports external identities, but B2C is not designed for internal resource sharing like SharePoint or Teams.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2C is a customer-facing identity management service for external customers, not for business partners, and it does not integrate with internal resources like SharePoint or Teams. Option C is wrong because Microsoft Entra Connect is used to synchronize on-premises Active Directory identities to the cloud, not to manage external partner identities. Option D is wrong because Microsoft Entra Identity Protection is a risk-detection and remediation tool for user accounts, not a solution for inviting or managing external identities.

787
MCQeasy

Your company is adopting Microsoft Copilot for Microsoft 365 to improve productivity. The security team is concerned about data leakage, as Copilot can access emails, documents, and other content. You need to ensure that sensitive data, such as credit card numbers and social security numbers, is not inadvertently exposed by Copilot. The organization uses Microsoft Purview sensitivity labels and DLP. You need to configure a solution that automatically detects and prevents Copilot from accessing or generating content containing these sensitive data types. What should you do?

A.Configure Microsoft Defender for Cloud Apps to control Copilot
B.Disable Copilot for users who handle sensitive data
C.Apply sensitivity labels to all documents containing sensitive data
D.Create a DLP policy in Microsoft Purview that detects sensitive data types and blocks Copilot actions
AnswerD

A Microsoft Purview DLP policy scoped to Copilot detects sensitive information types such as credit card and social security numbers in prompts and responses, then blocks the action. This directly prevents Copilot from accessing or generating content containing those data types.

Why this answer

A Microsoft Purview DLP policy that detects sensitive information types (credit card numbers, SSNs) and is scoped to Copilot interactions will block Copilot from processing or generating content containing that data. Purview DLP natively integrates with Copilot for Microsoft 365, so policies can enforce restrictions on prompts and responses in real time. This is the purpose-built control for the stated requirement.

Exam trap

SC-900 often tests the difference between classifying data (sensitivity labels) and enforcing action (DLP) — the trap is picking 'apply sensitivity labels' when the requirement explicitly says 'automatically detect and prevent.'

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps governs SaaS app usage and session controls but does not natively inspect Copilot prompt/response content for sensitive information types the way Purview DLP does. Option B is wrong because disabling Copilot for sensitive-data users is a blunt, productivity-destroying workaround, not a data-protection control — it doesn't actually prevent leakage if those users re-enable it or use other paths. Option C is wrong because applying sensitivity labels alone classifies data but does not automatically block Copilot from accessing or generating content with those labels unless a DLP or label-based policy enforces the restriction.

788
MCQeasy

Which Microsoft Entra ID feature allows an organization to provide external partners with access to its applications while maintaining control over authentication and governance?

A.Microsoft Entra ID Governance
B.Microsoft Entra Domain Services
C.Microsoft Entra External ID
D.Microsoft Entra Permissions Management
AnswerC

Microsoft Entra External ID is the comprehensive solution specifically designed to manage identities for external users, enabling them to access your applications and resources securely. It supports Business-to-Business (B2B) collaboration for guest users and Business-to-Consumer (B2C) for customer-facing applications, offering features like self-service sign-up, custom branding, and integration with various social and enterprise identity providers.

Why this answer

Microsoft Entra External ID (including B2B collaboration) enables secure sharing of apps with external users. It allows the organization to manage identities and enforce policies like MFA for guests.

789
MCQeasy

Your organization wants to enable passwordless authentication for users. Which Microsoft Entra ID feature should you use?

A.Conditional Access
B.Privileged Identity Management
C.Identity Protection
D.Passwordless authentication methods
AnswerD

Passwordless authentication methods, including Windows Hello for Business, FIDO2 security keys, and the Microsoft Authenticator app, are the specific technologies that allow users to sign in without needing to type a password. These methods replace traditional passwords with more secure alternatives, significantly reducing the risk of phishing, credential stuffing, and brute-force attacks. Directly enabling and configuring these options within Microsoft Entra ID is the fundamental step to implement passwordless authentication for an organization's users.

Why this answer

Passwordless authentication methods is the correct feature because it is the specific Microsoft Entra ID capability that allows users to sign in without a password, using methods such as Windows Hello for Business, the Microsoft Authenticator app, FIDO2 security keys, or phone sign-in. This directly enables the organization's goal of passwordless authentication.

Exam trap

The trap here is that candidates may confuse Conditional Access (which can require passwordless methods as a grant control) with the actual feature that enables passwordless authentication, but Conditional Access only enforces policies, not the underlying authentication methods themselves.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from untrusted locations) based on signals, but it does not itself provide or enable passwordless authentication methods. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and access reviews for Azure AD roles and Azure resources, not passwordless sign-in capabilities. Option C is wrong because Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, impossible travel) using risk policies, but it does not configure or offer passwordless authentication methods.

790
MCQhard

A financial services organization needs to automatically classify and protect sensitive documents containing credit card information in SharePoint Online and OneDrive for Business. They want a purple-colored label to be applied automatically when the document is saved, and the document should be encrypted with a predefined template that restricts editing to internal users only. Which Microsoft Purview solution should they configure?

A.Sensitivity labels with auto-labeling
B.Data Loss Prevention (DLP) policies
C.Data Lifecycle Management (retention labels)
D.Audit (Unified Auditing)
AnswerA

Sensitivity labels, particularly when configured with auto-labeling policies, are specifically designed to automatically classify and apply protection to documents containing sensitive information types. These labels can enforce encryption, visual markings, and access restrictions directly on the content, ensuring data is protected both at rest and in transit, precisely meeting the requirement to automatically classify and encrypt documents.

Why this answer

Sensitivity labels with auto-labeling in Microsoft Purview can automatically apply a purple-colored label to documents containing credit card information when saved in SharePoint Online or OneDrive for Business. This label can be configured with encryption using a predefined template that restricts editing to internal users only, meeting the organization's classification and protection requirements.

Exam trap

The trap here is that candidates confuse DLP policies with sensitivity labels, but DLP policies only block or warn on sharing actions and do not apply persistent encryption or visual markings like labels.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies detect and prevent accidental sharing of sensitive data but do not apply persistent labels or encryption to documents; they enforce rules at the point of sharing or use. Option C is wrong because Data Lifecycle Management (retention labels) manage retention and deletion of content, not classification or encryption based on sensitive data patterns. Option D is wrong because Audit (Unified Auditing) logs user and admin activities for compliance and investigation but does not classify, label, or encrypt documents automatically.

791
MCQeasy

Your organization uses Microsoft Entra ID P1. You need to implement a solution that allows users to reset their own passwords without administrator intervention. The solution must also enforce a policy that requires users to verify their identity with two methods before resetting. What should you configure?

A.Configure Privileged Identity Management (PIM) to require approval for password reset.
B.Create an Identity Protection user risk policy to force password reset.
C.Configure a Conditional Access policy to require MFA for password changes.
D.Enable self-service password reset (SSPR) and configure the number of methods required to reset to 2.
AnswerD

Enabling Microsoft Entra ID Self-Service Password Reset (SSPR) directly addresses the requirement for users to reset their forgotten passwords without administrator intervention. By configuring the number of authentication methods required to 2, the organization enhances the security of the reset process, ensuring that users provide multiple proofs of identity (e.g., mobile app notification and phone call) before gaining access. This feature is precisely designed for secure, user-initiated password recovery.

Why this answer

Self-service password reset (SSPR) in Microsoft Entra ID P1 allows users to reset their own passwords without administrator intervention. By configuring SSPR and setting the number of methods required to reset to 2, you enforce the policy that users must verify their identity with two authentication methods before resetting their password.

Exam trap

The trap here is that candidates often confuse Conditional Access MFA policies with SSPR's multi-method verification, not realizing that SSPR has its own separate configuration for the number of required verification methods, while Conditional Access policies apply to authentication events, not the password reset workflow.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is used for managing, controlling, and monitoring access to privileged roles, not for enabling self-service password reset or enforcing multi-method verification for password resets. Option B is wrong because Identity Protection user risk policies trigger automatic password resets based on detected user risk, but they do not allow users to initiate their own password resets without administrator intervention, nor do they enforce a specific number of verification methods for the reset process. Option C is wrong because a Conditional Access policy requiring MFA for password changes would force users to authenticate with MFA when changing their password, but it does not enable self-service password reset; it only secures the change action, not the reset flow, and does not configure the number of methods required for reset.

792
MCQmedium

The exhibit shows a sign-in failure for John Doe. The admin wants to allow the sign-in while still enforcing MFA. What should the admin do?

A.Modify the Conditional Access policy to exclude Azure PowerShell or to support MFA for this client.
B.Disable MFA for the user.
C.Assign a Microsoft Entra ID P2 license to the user.
D.Reset the user's password.
AnswerA

This option correctly identifies that the sign-in failure for John Doe, an admin using Azure PowerShell, is likely due to a Conditional Access policy requiring Multi-Factor Authentication (MFA) that the client cannot satisfy. Azure PowerShell, especially older versions or specific cmdlets, may not fully support modern authentication flows required for MFA. Modifying the policy to either exclude this specific application from the MFA requirement or ensuring the client is updated and configured to properly handle MFA challenges would resolve the access issue while maintaining overall security for other access methods.

Why this answer

The sign-in failure is likely caused by a Conditional Access policy that blocks legacy authentication protocols like Azure PowerShell, which do not support MFA natively. Option A is correct because modifying the policy to exclude Azure PowerShell or to require MFA for that client app allows the sign-in while still enforcing MFA for other protocols. This ensures the user can authenticate using a modern authentication flow that supports MFA.

Exam trap

The trap here is that candidates may think resetting the password or disabling MFA is the quick fix, but the core issue is that the Conditional Access policy is blocking a client that cannot perform MFA, not that the user's credentials or license are invalid.

How to eliminate wrong answers

Option B is wrong because disabling MFA for the user removes the security requirement entirely, contradicting the admin's goal to still enforce MFA. Option C is wrong because assigning a Microsoft Entra ID P2 license provides advanced features like Identity Protection and Privileged Identity Management, but it does not directly resolve a sign-in failure caused by a Conditional Access policy blocking a non-MFA-capable client. Option D is wrong because resetting the user's password does not address the underlying policy that blocks the sign-in; the failure is due to the client app not supporting MFA, not due to incorrect credentials.

793
MCQeasy

A company uses a third-party SaaS project management application. The security team wants to monitor and control user sessions when employees access the application from personal, unmanaged devices. Specifically, they want to block the download of files to local drives and display a warning message to the user if they attempt to download. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Defender for Identity
AnswerA

Microsoft Defender for Cloud Apps provides session controls via Conditional Access App Control, enabling file download blocking and user warning messages for unmanaged devices accessing SaaS apps. This directly satisfies the requirement to monitor and restrict sessions on personal endpoints.

Why this answer

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) is the correct solution because it provides session-level controls via Conditional Access App Control. This allows the security team to monitor and control user sessions in real-time, including blocking file downloads to unmanaged devices and displaying custom warning messages, by proxying the SaaS application traffic through Defender for Cloud Apps.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming all SaaS app protection falls under Office 365, but Defender for Cloud Apps is the cross-SaaS session control solution.

Why the other options are wrong

B

Microsoft Defender for Endpoint focuses on endpoint protection (antivirus, EDR) and does not provide session-level control or conditional access policies for SaaS applications like blocking downloads from unmanaged devices.

C

Microsoft Defender for Office 365 focuses on protecting email and collaboration tools like Exchange, SharePoint, and Teams, not on monitoring and controlling user sessions for third-party SaaS applications accessed from personal devices.

D

Microsoft Defender for Identity focuses on detecting and investigating advanced attacks on on-premises Active Directory, not on controlling user sessions or file downloads in third-party SaaS applications.

When would these options actually be correct?

B

An exam scenario where a company needs to detect, investigate, and respond to advanced threats on endpoints (e.g., malware, ransomware) and requires endpoint detection and response (EDR) capabilities would make Defender for Endpoint the correct answer.

C

A company wants to protect against malicious links and attachments in emails and block zero-day threats in Office 365 apps. Deploying Microsoft Defender for Office 365 would be correct.

D

An exam question describing a scenario where the security team needs to monitor and protect on-premises Active Directory user accounts and detect identity-based attacks (e.g., pass-the-hash, kerberoasting) would make Defender for Identity the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse endpoint security with cloud app security, assuming that controlling user sessions on personal devices falls under endpoint protection rather than cloud access security broker (CASB) functionality.

C

Candidates may confuse SaaS application security with Office 365 security, assuming that all cloud app protection falls under Office 365, or they may think the warning message feature is part of Office 365's data loss prevention capabilities.

D

Candidates may confuse identity protection with cloud app session control, assuming that monitoring user sessions implies an identity-focused solution, but Defender for Identity does not provide conditional access or session policies for SaaS apps.

794
MCQeasy

According to the Zero Trust security model, which principle assumes that a breach has already occurred and therefore requires segmenting access and monitoring for lateral movement?

A.Verify explicitly
B.Use least privilege
C.Assume breach
D.Trust but verify
AnswerC

The 'Assume breach' principle is foundational to the Zero Trust security model, asserting that an organization's network and all its components should be treated as if they are already compromised, regardless of their location or previous security posture. This paradigm shift eliminates implicit trust and drives security strategies such as micro-segmentation, continuous monitoring, and robust incident response planning. It directly addresses the question by embodying the core idea that no user, device, or application can be inherently trusted, and therefore, defenses must be built with a breach in mind.

Why this answer

The 'Assume breach' principle of the Zero Trust security model explicitly operates under the mindset that a breach has already occurred or is inevitable. This drives the need for segmenting access (e.g., micro-segmentation using network policies or Azure Virtual Network security groups) and continuous monitoring for lateral movement (e.g., using Microsoft Defender for Identity to detect pass-the-hash or Kerberos ticket attacks).

Exam trap

Microsoft often tests the distinction between 'Assume breach' and 'Verify explicitly' by presenting a scenario where a candidate might confuse the proactive verification of every request with the reactive assumption that a breach has already occurred, leading them to incorrectly select 'Verify explicitly' when the question specifically asks about segmentation and lateral movement monitoring.

How to eliminate wrong answers

Option A is wrong because 'Verify explicitly' mandates that every access request must be authenticated and authorized based on all available data points (e.g., user identity, device health, location), but it does not inherently assume a breach has occurred or drive segmentation for lateral movement. Option B is wrong because 'Use least privilege' ensures users and services have only the minimum permissions needed to perform their tasks (e.g., via Azure RBAC or Privileged Identity Management), but it is a principle of access control, not a breach assumption that triggers segmentation and lateral movement monitoring. Option D is wrong because 'Trust but verify' is an outdated model that assumes internal network trust, which contradicts Zero Trust's core premise of never trusting any entity by default; it does not assume a breach has already happened.

795
Multi-Selecthard

Which THREE are features of Microsoft Purview Data Lifecycle Management (formerly Records Management)? (Choose three.)

Select 3 answers
A.Retention policies
B.Data loss prevention
C.Sensitivity labels
D.Retention labels
E.Disposition review
AnswersA, D, E

Microsoft Purview retention policies are a core feature of Data Lifecycle Management, enabling organizations to proactively manage content across various locations like Exchange mailboxes, SharePoint sites, OneDrive accounts, and Microsoft 365 Groups. These policies apply retention settings at a broad, container level, ensuring that all content within a specified location is either retained for a minimum period or deleted after a certain time, or both, to meet compliance and regulatory requirements. They are crucial for enforcing consistent data governance across the enterprise.

Why this answer

Retention policies are a core feature of Microsoft Purview Data Lifecycle Management because they allow administrators to apply retention settings at the container level (e.g., entire SharePoint site, Exchange mailbox, or OneDrive account) to automatically retain or delete content based on a defined schedule. This ensures that organizational data is kept for the required period and then removed, supporting compliance and governance requirements without manual intervention.

Exam trap

The trap here is that candidates often confuse the features of Microsoft Purview Data Lifecycle Management (retention policies, retention labels, disposition review) with those of Information Protection (sensitivity labels) or Data Loss Prevention, leading them to incorrectly select DLP or sensitivity labels as lifecycle management features.

796
MCQhard

Your organization is using Microsoft Entra ID and has deployed Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with Intune policies can access corporate email via Microsoft Outlook for iOS and Android. Additionally, you need to prevent users from copying corporate data to personal apps on the same device. Which two Microsoft Entra features should you combine?

A.Conditional Access policy requiring hybrid Azure AD joined device, and Windows Autopilot.
B.Conditional Access policy requiring MFA, and Windows Hello for Business.
C.Conditional Access policy requiring approved client app, and Azure AD Application Proxy.
D.Conditional Access policy requiring compliant device, and Microsoft Intune app protection policy (MAM) to prevent data copy/paste to unmanaged apps.
AnswerD

A Conditional Access policy requiring a compliant device ensures that only devices meeting specific security baselines, as defined and monitored by Microsoft Intune, can access corporate resources. This enforces device health and configuration, ensuring the device adheres to organizational security standards. Microsoft Intune App Protection Policies (MAM) provide a crucial layer of data protection within applications, preventing corporate data from being copied, pasted, or saved to unmanaged applications or personal storage locations, even on unmanaged devices. Together, these policies establish both device-level security posture and application-level data leakage prevention, directly addressing the need to protect data and enforce compliance.

Why this answer

Option D is correct because it combines the two features that directly address both requirements: a Conditional Access policy with the 'Require device to be marked as compliant' grant control ensures only Intune-compliant devices can access Exchange Online from Outlook mobile, while an Intune app protection policy (MAM) applied to Outlook enforces data-sharing restrictions such as blocking copy/paste to unmanaged personal apps. These work together via app-based Conditional Access, where the compliant-device requirement gates access and the MAM policy governs how corporate data can be used within the app. Option A is wrong because hybrid Azure AD join and Windows Autopilot target Windows device provisioning, not iOS/Android Outlook access or app-level data controls.

Option B is wrong because MFA and Windows Hello for Business address authentication strength on Windows, not device compliance or data leakage prevention. Option C is wrong because Azure AD Application Proxy publishes on-premises web apps and does not prevent copy/paste of corporate data in mobile apps.

797
MCQhard

A company has deployed Microsoft Defender for Identity and wants to detect pass-the-hash attacks in real time. Which alert type should they monitor?

A.Suspected Kerberoasting attack
B.Suspected Brute Force attack
C.Suspected Pass-the-Hash attack
D.Suspected Golden Ticket attack
AnswerC

A Suspected Pass-the-Hash (PtH) attack involves an attacker authenticating to a remote system or service by directly using a user's NTLM hash, without ever needing to know the plaintext password. Microsoft Defender for Identity excels at detecting PtH by analyzing NTLM authentication traffic for anomalies, such as a user authenticating from a new source IP address or to a resource without a corresponding Kerberos pre-authentication. This technique bypasses traditional password-based authentication mechanisms, making it a critical threat for MDI to identify.

Why this answer

Microsoft Defender for Identity specifically detects pass-the-hash attacks by monitoring anomalous NTLM authentication patterns, such as the use of hashed credentials from one machine to authenticate to another. The 'Suspected Pass-the-Hash attack' alert is triggered when Defender for Identity identifies a hash being reused across multiple devices in a way that indicates lateral movement, which is the core behavior of a pass-the-hash attack.

Exam trap

The trap here is that candidates often confuse pass-the-hash with Kerberoasting or Golden Ticket attacks, but the key differentiator is that pass-the-hash relies on NTLM hash reuse in real time, while the others involve Kerberos ticket manipulation or offline cracking.

How to eliminate wrong answers

Option A is wrong because a suspected Kerberoasting attack involves requesting Kerberos service tickets (TGS) for service accounts to crack their passwords offline, not real-time hash reuse. Option B is wrong because a suspected Brute Force attack involves repeated failed login attempts against a single account or endpoint, not the reuse of captured password hashes. Option D is wrong because a suspected Golden Ticket attack involves forging a Kerberos Ticket Granting Ticket (TGT) using the KRBTGT account hash, not the real-time reuse of NTLM hashes.

798
MCQhard

Refer to the exhibit. A security analyst runs this Microsoft Graph PowerShell command. What is the most likely purpose of this command?

A.To find users whose user principal name starts with 'j'.
B.To update the display names of users starting with 'j'.
C.To remove users whose user principal name starts with 'j'.
D.To list all users and their group memberships.
AnswerA

The Graph filter uses the startsWith operator on userPrincipalName with the value 'j', returning only accounts whose UPN begins with that letter. This is a prefix match, not a contains search, so users with 'j' elsewhere in the UPN are excluded.

Why this answer

The Microsoft Graph PowerShell command shown (likely Get-MgUser -Filter "startswith(userPrincipalName,'j')") retrieves users whose userPrincipalName begins with 'j'. The Get-MgUser cmdlet with a startswith filter returns matching user objects, so the purpose is to find users with a UPN starting with 'j'. This is a read-only query, not an update or delete operation.

Exam trap

SC-900 often tests the ability to interpret PowerShell commands—candidates may confuse Get with Update or Remove, or assume a filter lists all users, but the startswith filter clearly narrows the result to UPNs beginning with 'j'.

How to eliminate wrong answers

Option B is wrong because updating display names would require a cmdlet like Update-MgUser with -DisplayName, not a Get-MgUser filter. Option C is wrong because removing users would require Remove-MgUser, which is destructive and not indicated by a Get command. Option D is wrong because listing all users and group memberships would not use a startswith filter on userPrincipalName and would typically involve Get-MgUser without filter or additional membership cmdlets.

799
MCQmedium

A company wants to automatically detect emails in Exchange Online that contain credit card numbers and apply encryption to those emails before they are sent. Which Microsoft Purview solution should the administrator configure?

A.Information Protection (sensitivity labels)
B.Data Loss Prevention (DLP)
C.Data Lifecycle Management
D.eDiscovery
AnswerB

Data Loss Prevention (DLP) policies are specifically engineered to inspect content in real-time for sensitive information types (SITs), such as credit card numbers or national ID numbers, across various locations including Exchange Online. When a policy match is detected in an outgoing email, DLP can automatically enforce protective actions like blocking the email, notifying administrators, or applying encryption to prevent unauthorized disclosure of sensitive data in transit. This makes DLP the direct solution for automatically detecting and encrypting emails containing sensitive information.

Why this answer

Data Loss Prevention (DLP) in Microsoft Purview is specifically designed to detect sensitive information such as credit card numbers in emails and automatically apply protective actions like encryption. DLP policies can scan Exchange Online messages in transit and enforce rules to encrypt the email before it is sent, which directly meets the requirement.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which can also apply encryption) with DLP, but sensitivity labels require manual or automatic classification based on label policies, not real-time content scanning of specific sensitive data patterns like credit card numbers in transit.

How to eliminate wrong answers

Option A is wrong because Information Protection (sensitivity labels) is used to classify and protect documents and emails based on manual or automatic labeling, but it does not natively scan for specific sensitive data patterns like credit card numbers and automatically trigger encryption on outbound emails. Option C is wrong because Data Lifecycle Management focuses on retaining, deleting, or archiving data based on age or policy, not on detecting sensitive content in transit and applying encryption. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for real-time detection and protection of sensitive data in email flow.

800
Multi-Selecteasy

Which TWO capabilities are part of Microsoft Entra ID Governance?

Select 2 answers
A.Entitlement Management
B.Identity Protection
C.Conditional Access
D.Self-Service Password Reset
E.Access Reviews
AnswersA, E

Microsoft Entra Entitlement Management is a robust identity governance feature that automates the lifecycle of access requests and approvals for internal and external users. It allows organizations to define access packages, which bundle resources and policies, enabling self-service access requests and ensuring users have appropriate permissions based on their role or project. This capability streamlines the process of granting and revoking access, reducing manual overhead and improving security posture.

Why this answer

Entitlement Management is a core capability of Microsoft Entra ID Governance because it enables organizations to manage the lifecycle of access for internal and external users through access packages, catalogs, and policies. It automates the request, approval, and assignment of access to groups, apps, and SharePoint sites, ensuring governance over who gets what and for how long. Access Reviews is also a key governance feature because it allows administrators to periodically review and certify user access, automatically removing stale or inappropriate permissions to maintain compliance.

Exam trap

The trap here is that candidates often confuse Identity Protection or Conditional Access with governance because they involve security controls, but Microsoft Entra ID Governance specifically focuses on the lifecycle management and periodic review of access rights, not on risk detection or policy enforcement at sign-in.

801
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. A security analyst needs to receive an alert whenever a user accesses a cloud app from a new IP address that is not in the organization's trusted IP range. What should the analyst configure?

A.A file policy
B.A session policy
C.An app permission policy
D.An anomaly detection policy
AnswerD

An anomaly detection policy in Microsoft Defender for Cloud Apps leverages machine learning and behavioral analytics to identify unusual and potentially suspicious activities across your cloud applications. These policies establish a baseline of normal user behavior and then flag deviations, such as impossible travel, sign-ins from unfamiliar locations or IP addresses, and unusual activity volumes. Therefore, it is the correct policy type for detecting and alerting on sign-ins originating from new or previously unseen IP addresses.

Why this answer

An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user activities, such as access from a new IP address outside the organization's trusted IP range. This policy leverages machine learning to establish a baseline of normal behavior and triggers alerts when deviations occur, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse anomaly detection policies with session policies, mistakenly thinking session policies can alert on new IP addresses, but session policies only enforce controls during active sessions and do not generate standalone alerts for access from untrusted IPs.

How to eliminate wrong answers

Option A is wrong because a file policy is used to monitor and control file sharing and data exfiltration based on content inspection or metadata, not to detect anomalous access patterns like new IP addresses. Option B is wrong because a session policy controls real-time user sessions (e.g., blocking downloads or requiring authentication) based on app or user attributes, but it does not generate alerts for new IP address access outside trusted ranges. Option C is wrong because an app permission policy governs which third-party apps can access organizational data via OAuth permissions, not user access from specific IP addresses.

802
MCQeasy

A security analyst receives an alert about a suspicious process on a device. The security solution automatically investigates the device, gathers evidence, and determines that a known malware variant was detected. It then presents an action plan to the analyst for remediation. Which Microsoft security solution provides this automated investigation and response capability?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Office 365
AnswerB

Microsoft Defender for Endpoint (MDE) is a unified endpoint security platform that utilizes behavioral analytics, machine learning, and cloud intelligence to detect, investigate, and respond to advanced threats on devices. When a security analyst receives an alert about a suspicious process, MDE's Endpoint Detection and Response (EDR) capabilities automatically collect telemetry, analyze process trees, and can initiate automated investigation playbooks to determine the scope and severity of the threat, isolating the device if necessary. This directly addresses the need to investigate a suspicious process on an endpoint.

Why this answer

Microsoft Defender for Endpoint provides automated investigation and response (AIR) capabilities that automatically investigate alerts, gather evidence, and determine remediation actions. When a suspicious process is detected, Defender for Endpoint's AIR engine analyzes the device, identifies known malware variants, and presents an action plan to the security analyst for approval or execution.

Exam trap

Microsoft often tests the distinction between endpoint-focused security (Defender for Endpoint) and cloud/identity/email-focused solutions, so candidates mistakenly choose Defender for Cloud Apps or Defender for Identity when the scenario clearly describes on-device process investigation and automated response.

Why the other options are wrong

A

Microsoft Defender for Cloud Apps focuses on cloud application security, not endpoint device investigation and automated remediation of malware on devices.

C

Microsoft Defender for Identity focuses on detecting and investigating advanced attacks on on-premises Active Directory, not on automated investigation and response for suspicious processes on devices.

D

Microsoft Defender for Office 365 focuses on protecting email and collaboration tools like Exchange Online, SharePoint, and Teams, not on automated investigation and response for endpoint devices.

When would these options actually be correct?

A

This option would be correct for a question about detecting and investigating suspicious user behavior or anomalous activities across cloud applications, such as identifying a compromised account using multiple cloud apps.

C

A question asks: 'Which Microsoft security solution monitors on-premises Active Directory for suspicious activities like pass-the-hash or DCSync attacks and provides identity-based threat detection?'

D

A question describing automated investigation and response for suspicious emails, phishing attempts, or malicious attachments in Exchange Online or SharePoint would make Defender for Office 365 the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse cloud app security with endpoint security because both involve threat detection and investigation, but Defender for Cloud Apps is specific to cloud services, not device-level processes.

C

Candidates may confuse identity-based security solutions with endpoint detection and response, or assume that any 'Defender' product includes automated investigation capabilities for all scenarios.

D

Candidates may confuse the automated investigation and response capabilities across different Defender products, assuming all have the same endpoint-focused features.

803
MCQhard

Refer to the exhibit. You are evaluating a custom Azure Policy definition. The policy is intended to audit whether users assigned to a management role have MFA enabled. However, the policy is not triggering alerts for non-compliant users. What is the most likely cause?

A.The 'mfaEnabledPrincipals' parameter is not populated with the list of MFA-enabled users.
B.The policy mode is set to 'All' instead of 'Indexed'.
C.The policy only evaluates role assignments of type 'Microsoft.Authorization/roleAssignments' but not users.
D.The effect 'auditIfNotExists' should be 'deny' to trigger alerts.
AnswerA

The 'mfaEnabledPrincipals' parameter is crucial for this policy's logic, as the 'existenceCondition' relies on it to identify principals who have MFA enabled. If this parameter is not populated with the correct list of MFA-enabled user principal IDs, the policy's 'where' clause cannot accurately determine which principals are compliant. Consequently, the policy will fail to correctly evaluate whether non-MFA-enabled users hold owner role assignments, rendering its compliance assessment ineffective.

Why this answer

The policy definition includes a parameter named 'mfaEnabledPrincipals' that must be populated with the list of user object IDs who have MFA enabled. If this parameter is empty or not provided, the 'auditIfNotExists' effect cannot evaluate any users against the expected MFA status, resulting in no non-compliant alerts being triggered. Azure Policy relies on explicit parameter values to define the baseline for compliance evaluation.

Exam trap

The trap here is that candidates assume the policy will automatically detect MFA status from Azure AD, but Azure Policy requires explicit parameter input to define the compliant state, and failing to populate that parameter silently disables the audit.

How to eliminate wrong answers

Option B is wrong because the policy mode 'All' is appropriate for auditing Azure Active Directory resources (such as users and role assignments) and is not the cause of the failure; 'Indexed' mode is used for resource provider modes like 'Microsoft.Kubernetes.Data' and is irrelevant here. Option C is wrong because the policy does evaluate role assignments of type 'Microsoft.Authorization/roleAssignments' to identify users in management roles, but the issue is that the MFA-enabled user list is missing, not that the scope is incorrect. Option D is wrong because the 'auditIfNotExists' effect is designed to log non-compliance without blocking actions, and changing it to 'deny' would not trigger alerts; alerts are generated by Azure Policy compliance states, not by the effect type.

804
MCQhard

Your organization uses Microsoft Sentinel. You need to create a custom analytics rule that triggers an incident when a user executes a specific command on Azure VMs. Which data source should you connect to capture the command execution logs?

A.Office Activity log
B.Windows Security Events via Azure Monitor Agent
C.Azure AD audit logs
D.Azure Activity log
AnswerB

Command execution on Azure VMs is captured through Windows Security Events, which include process creation events (such as event ID 4688). Connecting this data source via the Azure Monitor Agent feeds those logs into Microsoft Sentinel, letting a custom analytics rule detect the specific command and raise an incident.

Why this answer

To capture command execution logs on Azure VMs, you need to collect Windows Security Events, specifically event ID 4688 (process creation), which includes the command line if audit policy is enabled. The Windows Security Events via Azure Monitor Agent connector in Microsoft Sentinel ingests these events from the VMs. This data source provides the necessary telemetry to detect specific command executions.

Exam trap

SC-900 often tests the difference between control-plane and data-plane logs, tricking candidates into selecting Azure Activity log when the question asks about in-guest command execution.

How to eliminate wrong answers

Option A is wrong because the Office Activity log contains audit events from Microsoft 365 services like Exchange, SharePoint, and Teams, not VM command execution. Option C is wrong because Azure AD audit logs contain sign-in and directory change events, not process execution on VMs. Option D is wrong because the Azure Activity log records control-plane operations on Azure resources (e.g., VM start/stop), not in-guest command execution.

805
MCQmedium

Your company uses Microsoft Purview Information Protection. They want to automatically apply a 'Confidential' sensitivity label to documents containing a credit card number. What should they create?

A.A sensitivity label
B.A data loss prevention (DLP) policy
C.An auto-labeling policy
D.A retention label policy
AnswerC

An auto-labeling policy is specifically designed within Microsoft Purview Information Protection to automatically scan content across various locations, such as SharePoint, OneDrive, and Exchange, for predefined conditions. When these conditions, which often include sensitive information types, keywords, or trainable classifiers, are met, the policy automatically applies a specified sensitivity label to the content. This ensures consistent and automated classification and protection without requiring manual user intervention.

Why this answer

An auto-labeling policy in Microsoft Purview Information Protection is designed to automatically apply sensitivity labels to documents and emails based on conditions such as the presence of sensitive information types (e.g., credit card numbers). This allows the 'Confidential' label to be applied without user intervention, meeting the requirement.

Exam trap

The trap here is confusing the function of a DLP policy (which blocks or alerts on sensitive data) with an auto-labeling policy (which applies a sensitivity label based on content), as both use sensitive information types but serve different purposes.

How to eliminate wrong answers

Option A is wrong because a sensitivity label defines the classification and protection settings (e.g., encryption, markings) but does not automatically apply itself; it must be assigned via a policy. Option B is wrong because a data loss prevention (DLP) policy enforces rules to prevent sharing of sensitive data (e.g., blocking email with credit card numbers), but it does not apply sensitivity labels. Option D is wrong because a retention label policy manages data retention and deletion rules, not sensitivity classification or automatic labeling based on content.

806
MCQmedium

You are the identity architect for a global organization with 100,000 users across 50 countries. The company uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. Recently, the security team identified that several compromised user accounts were used to exfiltrate data from a cloud storage app. The CISO wants to implement a solution that detects anomalous behavior (e.g., impossible travel, mass download) and automatically blocks the user session when such behavior is detected. The solution must also provide the ability to investigate and remediate after the fact. Which Microsoft Entra feature should you use in conjunction with Defender for Cloud Apps to meet these requirements?

A.Microsoft Entra Conditional Access session controls with Defender for Cloud Apps integration
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra access reviews
AnswerA

Microsoft Entra Conditional Access session controls, when integrated with Defender for Cloud Apps, provides granular, real-time control over user sessions *after* initial authentication. Conditional Access policies can route sessions through Defender for Cloud Apps (formerly MCAS) for continuous monitoring, allowing actions like blocking downloads, requiring re-authentication, or enforcing read-only access based on detected risky behavior *during* the session, not just at sign-in. This combination directly addresses the need for ongoing session control and behavioral enforcement.

Why this answer

Microsoft Entra Conditional Access session controls integrate directly with Defender for Cloud Apps to enable real-time session monitoring and blocking. When anomalous behaviors like impossible travel or mass downloads are detected by Defender for Cloud Apps, the session control can automatically block the user session, while also providing full investigation and remediation capabilities through the Defender for Cloud Apps portal. This meets the CISO's requirement for both automated blocking and post-incident analysis.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access policies (which block sign-ins at the authentication level) with the session-level controls needed for real-time monitoring and blocking within an already-established cloud app session.

How to eliminate wrong answers

Option B (Microsoft Entra Identity Protection) is wrong because it focuses on risk-based detection and automated remediation of identities (e.g., requiring password reset or blocking sign-in), but it does not provide session-level controls or integration with Defender for Cloud Apps for real-time session blocking and investigation of cloud app activities. Option C (Microsoft Entra Privileged Identity Management) is wrong because it is designed for managing, controlling, and monitoring privileged role assignments and just-in-time access, not for detecting anomalous user behavior or blocking sessions in cloud apps. Option D (Microsoft Entra access reviews) is wrong because it is a governance tool for periodically reviewing group memberships, application access, and role assignments, not a real-time detection or session control mechanism.

807
MCQeasy

A company uses Microsoft 365 and wants to automatically classify documents based on sensitive information types like Social Security numbers. Which Microsoft Purview feature should be used?

A.Microsoft Purview Communication Compliance
B.Microsoft Purview Data Classification
C.Microsoft Purview Data Loss Prevention
D.Microsoft Purview Sensitivity Labels
AnswerB

Microsoft Purview Data Classification provides the foundational capabilities for identifying, categorizing, and understanding the data within an organization's digital estate. It leverages a robust set of built-in sensitive information types (SITs), named entities, and trainable classifiers to automatically detect specific content patterns, such as credit card numbers, national ID numbers, or industry-specific data. This service is crucial for automatically tagging and labeling data based on its content, forming the basis for subsequent protection and governance actions.

Why this answer

Microsoft Purview Data Classification is the correct feature because it automatically scans and classifies documents based on sensitive information types (e.g., Social Security numbers) using built-in or custom classifiers. This enables organizations to identify and label content without manual intervention, directly addressing the requirement for automatic classification.

Exam trap

The trap here is that candidates often confuse the feature that performs the initial classification (Data Classification) with the downstream enforcement tools (DLP) or the labeling mechanism (Sensitivity Labels), leading them to select DLP or Sensitivity Labels instead of the correct classification service.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Communication Compliance is designed to monitor and detect policy violations in communications (e.g., emails, Teams messages), not to automatically classify documents based on sensitive data patterns. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) enforces policies to prevent unauthorized sharing of sensitive data after classification, but it does not perform the initial automatic classification itself. Option D is wrong because Microsoft Purview Sensitivity Labels are applied manually or via auto-labeling policies that rely on classifiers (like Data Classification), but the labels themselves are not the feature that scans and identifies sensitive information types.

808
MCQhard

You are analyzing sign-in logs in Microsoft Sentinel. Based on the KQL query in the exhibit, what is the purpose of this query?

A.Identify users who have attempted to sign in with a disabled account more than 10 times in the last 7 days.
B.Identify all sign-in attempts from a specific IP address.
C.Identify impossible travel activity across different locations.
D.Identify locations with the highest number of failed sign-ins.
AnswerA

This query correctly identifies users targeting disabled accounts by specifically filtering for `ResultType 50057`, which signifies an account is disabled. By then grouping these events by `UserPrincipalName`, counting the occurrences, and applying a `where count_ > 10` clause within a specified 7-day timeframe, it precisely pinpoints users exceeding the defined threshold of failed attempts against disabled accounts. This is a critical indicator of potential malicious activity or persistent user error.

Why this answer

The KQL query filters sign-in logs for events where the 'ResultType' is '50057', which specifically indicates a sign-in attempt from a disabled account. It then groups by user and counts occurrences, using a 'where' clause to filter for users with more than 10 such attempts. Finally, it limits the results to the last 7 days via the time range filter in the query or the workspace time filter.

This directly identifies users who have attempted to sign in with a disabled account more than 10 times in the last 7 days.

Exam trap

The trap here is that candidates may confuse the 'ResultType' value '50057' with a generic failed sign-in code (e.g., '50053' for locked accounts or '50126' for invalid credentials), leading them to incorrectly select option D (locations with highest failed sign-ins) instead of recognizing the specific disabled-account scenario.

How to eliminate wrong answers

Option B is wrong because the query does not filter by any IP address field (e.g., 'IPAddress', 'ClientIP'), so it cannot identify sign-in attempts from a specific IP address. Option C is wrong because the query does not compare timestamps or locations to detect impossible travel; it only counts disabled-account sign-in failures per user. Option D is wrong because the query focuses on a specific result type (50057) for disabled accounts, not all failed sign-ins, and it groups by user, not by location.

809
MCQmedium

A company uses Microsoft Purview to map their data estate. They need to classify data stored in Azure SQL Database and Amazon S3. What should they use?

A.Microsoft Intune
B.Microsoft Sentinel
C.Microsoft Defender for Cloud
D.Microsoft Purview Data Map
AnswerD

The Microsoft Purview Data Map is the foundational component of Microsoft Purview, designed to automatically discover, catalog, and classify data assets across an organization's entire data estate, including on-premises, multi-cloud, and SaaS sources. It creates a unified metadata repository, providing a holistic view of data locations, types, and relationships. This capability is essential for understanding data landscapes, enabling data governance, compliance, and risk management initiatives.

Why this answer

Microsoft Purview Data Map is the correct choice because it provides automated data discovery, classification, and lineage across hybrid and multi-cloud environments, including Azure SQL Database and Amazon S3. It uses built-in scanners and classifiers to scan structured and unstructured data sources, mapping sensitive data types such as PII or financial information. This directly fulfills the requirement to classify data across both Azure and AWS platforms.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Data Map with Microsoft Defender for Cloud, mistakenly thinking that Defender for Cloud's 'data classification' feature (which only applies to Azure SQL and Azure Storage) can also scan Amazon S3, but it cannot—only Purview Data Map supports multi-cloud data sources like AWS S3.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, focused on managing endpoints and enforcing compliance policies, not on data classification or scanning data stores. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration Automation and Response) solution that ingests logs and alerts for threat detection, not for scanning and classifying data at rest in databases or object stores. Option C is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides security recommendations and threat protection for cloud resources, but it does not perform data classification or map data estates across Azure SQL and S3.

810
MCQmedium

Your organization uses Microsoft Purview to manage data classification. You need to ensure that sensitive data containing social security numbers is automatically labeled when stored in SharePoint Online. What should you configure?

A.Use the data classification dashboard in Microsoft Purview
B.Create a retention label policy
C.Configure a data loss prevention (DLP) policy
D.Create an auto-labeling policy for sensitivity labels
AnswerD

Creating an auto-labeling policy for sensitivity labels is the direct and most effective method within Microsoft Purview to automatically classify data based on its content. These policies are specifically engineered to scan content in locations like SharePoint, OneDrive, and Exchange, then apply appropriate sensitivity labels when specific conditions, such as the presence of sensitive information types or trainable classifiers, are met. This automation ensures consistent data classification and the application of associated protective actions without requiring manual user intervention.

Why this answer

D is correct because auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to files containing sensitive data, such as social security numbers, when stored in SharePoint Online. This uses pattern-based detection to classify and label content at rest without manual intervention.

Exam trap

The trap here is confusing data loss prevention (DLP) policies, which enforce protective actions like blocking or alerting, with auto-labeling policies that specifically apply sensitivity labels to content based on sensitive data detection.

How to eliminate wrong answers

Option A is wrong because the data classification dashboard is a monitoring and reporting tool that shows classified content, but it does not automatically apply labels to files. Option B is wrong because retention label policies manage data retention and deletion, not sensitivity classification or labeling of sensitive data. Option C is wrong because a DLP policy can detect and protect sensitive data by blocking or alerting, but it does not apply sensitivity labels to content.

811
MCQmedium

A company runs workloads in Azure and Amazon Web Services (AWS). The security team wants a single, unified dashboard to assess the security posture of all cloud resources, get prioritized recommendations for misconfigurations, and enable just-in-time (JIT) virtual machine access across both cloud environments. Which Microsoft security solution should they use?

A.Microsoft Sentinel
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Cloud
D.Azure Policy
AnswerC

Microsoft Defender for Cloud offers unified security management and threat protection across hybrid and multi-cloud environments, including Azure and AWS. It provides Cloud Security Posture Management (CSPM) for continuous assessment of security configurations, offering recommendations to improve posture. Additionally, its Cloud Workload Protection (CWP) features include just-in-time (JIT) VM access, which significantly reduces the attack surface by only opening management ports when needed.

Why this answer

Microsoft Defender for Cloud is the correct solution because it provides a unified dashboard for assessing security posture across multi-cloud environments, including Azure and AWS. It delivers prioritized recommendations for misconfigurations using the Microsoft cloud security benchmark and supports just-in-time (JIT) VM access to reduce attack surfaces by controlling inbound traffic on demand.

Exam trap

The trap here is confusing Microsoft Defender for Cloud (a CSPM and workload protection platform) with Microsoft Sentinel (a SIEM), leading candidates to choose Sentinel because it also aggregates logs from multiple clouds, but it lacks the specific posture assessment dashboard and JIT VM access features described in the question.

Why the other options are wrong

A

Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not a unified dashboard for assessing security posture across multi-cloud environments. It does not provide prioritized recommendations for misconfigurations or JIT VM access.

B

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on SaaS application usage and shadow IT, not a unified dashboard for assessing security posture across Azure and AWS with JIT VM access.

D

Azure Policy enforces and audits compliance rules across Azure resources but does not provide a unified dashboard for AWS, prioritized recommendations for misconfigurations, or JIT VM access across multi-cloud environments.

When would these options actually be correct?

A

A question asking for a cloud-native SIEM to collect security logs, detect threats, and orchestrate automated responses across Azure, AWS, and on-premises would make Microsoft Sentinel the correct answer.

B

A company wants to discover and control the use of third-party SaaS apps (e.g., Dropbox, Salesforce) across their cloud environments, enforce access policies, and detect anomalous user behavior in those apps.

D

An organization needs to enforce tagging standards, restrict resource types, or audit compliance with corporate policies across Azure subscriptions only, without requiring multi-cloud or security posture assessment features.

Why candidates pick the wrong answer

A

Candidates may confuse Sentinel's log aggregation and alerting capabilities with the posture management and recommendation features of Defender for Cloud, especially since both are part of the Microsoft security portfolio.

B

Candidates may confuse 'cloud apps' with 'cloud resources' and think Defender for Cloud Apps provides cross-cloud posture management, but it actually focuses on SaaS application governance, not infrastructure security.

D

Candidates may confuse Azure Policy's compliance enforcement with security posture management, or think it can be extended to AWS via Azure Arc, but it lacks the unified dashboard and JIT capabilities described.

812
MCQmedium

A company wants to provide external consultants with access to a specific application using their LinkedIn or Google accounts. Which Microsoft Entra feature allows this?

A.Microsoft Entra Conditional Access
B.Microsoft Entra External ID
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra Identity Protection
AnswerB

Microsoft Entra External ID is the comprehensive solution for managing and securing identities for external users, including partners, customers, and consultants. It enables organizations to collaborate securely by allowing these external users to sign in with their own identities, such as those from other Microsoft Entra tenants, social identity providers like Google or Facebook, or even via email one-time passcodes. This service specifically facilitates the onboarding and management of external users for resource access without creating full internal accounts.

Why this answer

Microsoft Entra External ID (formerly Azure AD External Identities) is the correct feature because it enables external users—such as consultants—to sign in using their own identity providers (IdPs) like LinkedIn or Google via federation. This allows the company to grant access to a specific application without creating separate Microsoft Entra accounts for each consultant, leveraging social identity providers through OpenID Connect or OAuth 2.0 protocols.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access after authentication) with the ability to authenticate external users, or they mistakenly think PIM or Identity Protection can directly enable social identity provider sign-in.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access is a policy engine that enforces access controls (e.g., MFA, location) after authentication, but it does not enable external identity providers like LinkedIn or Google for sign-in. Option C is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged role assignments and access reviews for internal users, not external authentication with social IdPs. Option D is wrong because Microsoft Entra Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, anomalous sign-ins) but does not provide the federation capability to allow external consultants to authenticate via LinkedIn or Google.

813
MCQmedium

A financial services company uses Microsoft 365 and must prevent employees from emailing credit card numbers in plain text. The compliance team wants to automatically detect credit card numbers in outgoing emails and block them before delivery. They also want to allow users to override the block with a business justification. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Information Protection
C.Microsoft Purview Records Management
D.Microsoft Purview Insider Risk Management
AnswerA

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across Microsoft 365 services, including Exchange Online emails. These policies use sensitive information types (SITs) to detect content like credit card numbers in real-time as emails are sent. Upon detection, DLP can block the email, notify administrators, and offer users the option to override the block with a business justification, directly preventing unauthorized data egress.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive data, such as credit card numbers, in transit (e.g., email) and enforce actions like blocking the message. DLP policies can be configured with user override options that require a business justification, meeting the compliance team's requirement for automatic detection and conditional blocking.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling) with DLP (enforcement), thinking that applying a sensitivity label automatically blocks emails, but DLP is required for the blocking and override functionality described in the scenario.

Why the other options are wrong

B

Microsoft Purview Information Protection focuses on classifying and protecting documents and emails with sensitivity labels, not on blocking outbound emails containing sensitive data like credit card numbers. It does not provide the automatic blocking and override capability for emails in transit that DLP does.

C

Records Management focuses on managing retention and disposition of records, not on detecting and blocking sensitive data like credit card numbers in emails.

D

Insider Risk Management is designed to detect and investigate risky user activities (e.g., data theft, policy violations) but does not block emails based on content patterns like credit card numbers. It cannot enforce real-time email blocking with override capabilities.

When would these options actually be correct?

B

A company wants to automatically apply a 'Confidential' label to all emails containing credit card numbers and encrypt them before sending, but does not need to block the email. In that scenario, Information Protection would be the correct solution.

C

An organization needs to automatically retain emails containing financial data for 7 years and then delete them. Records Management would be the correct solution to apply retention labels and disposition reviews based on content.

D

A scenario where the compliance team needs to detect and investigate employees who are exfiltrating sensitive data via email, such as sending credit card numbers to personal accounts, and require alerts and case management for HR action. The question would specify 'detect and investigate risky behavior' rather than 'automatically block with override'.

Why candidates pick the wrong answer

B

Candidates may confuse the ability to detect sensitive data (which both DLP and Information Protection can do) with the enforcement action of blocking emails, assuming that labeling and protection also include blocking capabilities.

C

Candidates may confuse 'Records Management' with managing sensitive information, thinking it includes data classification and protection, but it is actually about lifecycle management.

D

Candidates may confuse 'insider risk' with data loss prevention because both deal with sensitive data misuse. They might think that blocking credit card emails is a risk management function, overlooking that DLP is the specific tool for content-based enforcement.

814
Multi-Selectmedium

Which THREE components are part of Microsoft Defender XDR? (Choose three.)

Select 3 answers
A.Microsoft Purview
B.Microsoft Defender for Office 365
C.Microsoft Sentinel
D.Microsoft Defender for Identity
E.Microsoft Defender for Endpoint
AnswersB, D, E

Defender for Office 365 contributes email, collaboration and phishing protection signals into the unified incident queue, so it is one of the three XDR pillars alongside Defender for Endpoint and Defender for Identity. Its alerts feed the correlated incidents the stem requires.

Why this answer

Microsoft Defender XDR is Microsoft's extended detection and response suite that unifies several Defender workloads under a single portal. Option B, Microsoft Defender for Office 365, is correct because it is one of the core Defender XDR pillars, providing protection for email, collaboration tools, and phishing/URL detonation signals. Option D, Microsoft Defender for Identity, is correct because it monitors on-premises Active Directory and identity signals (via domain controller sensors) and feeds those detections into Defender XDR.

Option E, Microsoft Defender for Endpoint, is correct because it is the endpoint pillar of Defender XDR, delivering device-level detection, investigation, and response. Option A, Microsoft Purview, is not part of Defender XDR; it is a separate compliance and data-governance suite. Option C, Microsoft Sentinel, is also not a Defender XDR component; it is a standalone cloud-native SIEM/SOAR solution that can integrate with Defender XDR but is not one of its constituent workloads.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel (a SIEM) as part of Defender XDR, but Sentinel is an external analytics layer that can ingest Defender XDR data, not a built-in component of the XDR suite.

815
Multi-Selectmedium

A company uses Microsoft Purview to manage data compliance. They need to meet regulatory requirements that mandate retention of financial records for 7 years and deletion of personal data after 3 years. Which THREE capabilities should they configure?

Select 3 answers
A.Microsoft Purview Information Protection
B.Microsoft Purview Records Management
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Communication Compliance
E.Microsoft Purview eDiscovery
AnswersA, B, C

Microsoft Purview Information Protection enables organizations to classify and label sensitive data using sensitivity labels, whether manually or automatically. These labels are crucial as they can be configured to automatically apply specific retention and deletion policies, ensuring data is retained for the required period or disposed of appropriately based on its content and classification. This capability is fundamental for enforcing data compliance requirements by governing data based on its sensitivity.

Why this answer

Microsoft Purview Information Protection (A) is correct because it enables classification and labeling of sensitive data, such as financial records and personal data, with retention and deletion policies. This ensures that data is retained for the required 7 years and deleted after 3 years, meeting regulatory mandates. It works by applying sensitivity labels that trigger retention or deletion actions based on the label's configured settings.

Exam trap

The trap here is that candidates often confuse Communication Compliance or eDiscovery with retention management, but neither provides the automated retention and deletion scheduling required for regulatory compliance.

816
Multi-Selecthard

Which THREE of the following are features of Microsoft Purview Compliance Manager? (Select THREE.)

Select 3 answers
A.Record declaration and disposition reviews
B.Compliance score and templates for custom assessments
C.Pre-built assessments for common regulations like GDPR
D.Trainable classifiers to identify sensitive content
E.Microsoft-managed improvement actions for regulations
AnswersB, C, E

Microsoft Purview Compliance Manager provides a dynamic compliance score, a quantifiable measure of an organization's progress in meeting data protection and regulatory obligations. This score is calculated based on the completion of improvement actions within assessments. Furthermore, Compliance Manager offers customizable assessment templates, allowing organizations to tailor evaluations to specific internal policies or unique industry regulations not covered by pre-built templates, ensuring comprehensive compliance oversight.

Why this answer

Option B is correct because Compliance Manager provides a compliance score that quantifies an organization's posture and supports custom assessment templates so you can build assessments for your own controls and standards. Option C is correct because Compliance Manager ships with pre-built assessments mapped to common regulations and standards such as GDPR, ISO 27001, and NIST, letting you evaluate against them out of the box. Option E is correct because Compliance Manager includes Microsoft-managed improvement actions that guide remediation steps for regulations, and Microsoft updates these actions as regulations and Microsoft services change.

Option A is not a Compliance Manager feature; record declaration and disposition reviews are handled through records management in Microsoft Purview (e.g., retention labels and disposition review). Option D is not a Compliance Manager feature; trainable classifiers are a Microsoft Purview data classification capability used to identify sensitive content, not to assess regulatory compliance.

Exam trap

The trap here is that candidates confuse Compliance Manager's assessment and scoring features with other Purview capabilities like Records Management (record declaration) or Information Protection (trainable classifiers), leading them to select options that are valid Purview features but not specific to Compliance Manager.

817
MCQmedium

A security architect is explaining the Zero Trust model to the board. The architect emphasizes that the network perimeter can no longer be considered a safe zone. Which statement best describes the modern primary security perimeter according to Zero Trust principles?

A.The corporate network firewall and VPN
B.The identity of the user and device
C.The physical on-premises data center
D.The endpoint antivirus and anti-malware solution
AnswerB

Zero Trust treats identity, encompassing user and device, as the primary security perimeter because authentication and authorisation decisions replace network location. Being inside the corporate network grants no implicit trust, so access is evaluated per request against identity signals.

Why this answer

In the Zero Trust model, the primary security perimeter is the identity of the user and device, not the network location. This is because Zero Trust assumes breach and requires explicit verification for every access request, regardless of whether it originates from inside or outside the corporate network. By treating identity as the new control plane, organizations enforce least-privilege access and continuous authentication, making the user and device identity the critical trust boundary.

Exam trap

The trap here is that candidates often confuse the Zero Trust model with traditional defense-in-depth layers, mistakenly selecting the corporate firewall or VPN as the primary perimeter, when in fact Zero Trust shifts the trust boundary to the identity of the user and device.

How to eliminate wrong answers

Option A is wrong because the corporate network firewall and VPN represent a traditional perimeter-based security approach, which Zero Trust explicitly rejects as the primary security boundary; in Zero Trust, network location does not grant implicit trust. Option C is wrong because the physical on-premises data center is a legacy concept of a trusted internal zone, whereas Zero Trust assumes that threats can exist anywhere, including inside the data center. Option D is wrong because endpoint antivirus and anti-malware solutions are only one component of endpoint protection and do not serve as the primary security perimeter; Zero Trust focuses on identity and device health as the core trust decision point.

818
MCQeasy

A user reports that they cannot sign in to Microsoft Entra ID because they forgot their password. Which Microsoft Entra ID feature allows them to reset their password without contacting IT support?

A.Microsoft Entra ID Connect
B.Microsoft Entra ID Protection
C.Microsoft Entra ID Domain Services
D.Self-Service Password Reset (SSPR)
AnswerD

Self-Service Password Reset (SSPR) is a crucial Microsoft Entra ID feature that empowers users to reset their forgotten or locked-out passwords without requiring administrator assistance. Users authenticate their identity through pre-registered verification methods, such as a mobile app notification, phone call, or personal email, to prove they are legitimate. This capability directly addresses the scenario where a user cannot sign in because they have forgotten their password, allowing them to regain access independently.

Why this answer

Self-Service Password Reset (SSPR) is the Microsoft Entra ID feature that allows users to reset their own forgotten passwords without needing to contact IT support. It works by verifying the user's identity through pre-configured authentication methods (e.g., phone, email, security questions) before permitting the password change. This directly addresses the user's inability to sign in due to a forgotten password.

Exam trap

The trap here is that candidates may confuse Microsoft Entra ID Protection (which deals with risk detection) with SSPR, because both involve security and user authentication, but only SSPR enables the user to directly reset their own password without IT intervention.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Connect is a tool used to synchronize on-premises Active Directory identities to Microsoft Entra ID, not a password reset feature. Option B is wrong because Microsoft Entra ID Protection is a security service that detects and responds to identity risks (e.g., leaked credentials, sign-ins from anonymous IPs), but it does not provide a mechanism for users to reset their own passwords. Option C is wrong because Microsoft Entra ID Domain Services provides managed domain services (e.g., Kerberos, LDAP) for Azure VMs, not self-service password reset capabilities.

819
MCQhard

A financial services firm has a strict compliance requirement to prevent insider trading. The firm must ensure that employees in the Investment Banking division cannot communicate or share documents via Microsoft Teams and SharePoint Online with employees in the Equity Research division. The solution must automatically block all communication and collaboration between the two groups, and any attempts to share must be denied. Which Microsoft Purview solution should they implement?

A.Information Barriers
B.Communication Compliance
C.Insider Risk Management
D.Sensitivity Labels
AnswerA

Information Barriers in Microsoft 365 are specifically designed to prevent specific groups of users from communicating or collaborating with each other, fulfilling "ethical wall" requirements. Administrators define policies that segment users and restrict interactions in services like Microsoft Teams, SharePoint, and Exchange Online. This directly addresses the firm's need to proactively block communication to ensure compliance and prevent information leakage between sensitive departments.

Why this answer

Information Barriers (A) is the correct solution because it is specifically designed to prevent communication and collaboration between defined user groups within Microsoft Teams, SharePoint Online, and other Microsoft 365 services. It enforces policies that automatically block unauthorized communications and document sharing, which directly meets the firm's compliance requirement to segregate Investment Banking and Equity Research divisions to prevent insider trading.

Exam trap

The trap here is that candidates often confuse Information Barriers with Communication Compliance, mistakenly thinking that monitoring and reviewing communications (Option B) can prevent insider trading, but only Information Barriers provide the proactive, automatic blocking required by the scenario.

Why the other options are wrong

B

Communication Compliance is designed to detect and review communications for policy violations (e.g., insider trading), not to automatically block all communication and collaboration between groups. It relies on post-hoc detection and review, not real-time blocking.

C

Insider Risk Management is designed to detect, investigate, and act on potential insider threats after they occur, not to proactively block all communication and collaboration between groups as required by the compliance policy.

D

Sensitivity labels classify and protect data based on sensitivity, but they do not automatically block all communication and collaboration between specific groups. They require manual application or automated labeling policies, and cannot enforce communication restrictions between divisions.

When would these options actually be correct?

B

A company wants to monitor employee communications for potential insider trading or regulatory breaches, and requires a solution that captures, reviews, and escalates suspicious messages or documents. The goal is detection and investigation, not automatic blocking.

C

An organization wants to detect and investigate suspicious user activities that could lead to insider trading, such as unusual data access or exfiltration, and apply automated remediation actions like triggering alerts or initiating investigations.

D

A company needs to automatically apply encryption and access restrictions to documents containing financial data shared externally. Sensitivity labels with auto-labeling policies would be the correct solution to protect sensitive data based on content.

Why candidates pick the wrong answer

B

Candidates may confuse the goal of preventing insider trading with the tool that monitors for it, assuming that Communication Compliance can enforce restrictions rather than just detect violations.

C

Candidates may confuse the proactive blocking of communications (Information Barriers) with the detection and investigation of risky user behavior (Insider Risk Management), especially since both relate to insider trading scenarios.

D

Candidates may think sensitivity labels can restrict sharing between groups because labels can enforce encryption and permissions, but they lack the ability to block communications and are not designed for organizational segmentation.

820
MCQmedium

A compliance team at Litware needs to respond to a regulatory request for all documents related to a specific project. The documents are stored in SharePoint Online, OneDrive for Business, and Exchange Online. The team must preserve the content in place and be able to search and export it. Which Microsoft Purview solution should they use?

A.Content search in the Microsoft Purview compliance portal
B.eDiscovery (Standard) case with holds and searches
C.Data Loss Prevention (DLP) policies
D.Audit log search in Microsoft Purview
AnswerB

eDiscovery (Standard) allows creating a case, placing holds on Exchange, SharePoint, and OneDrive locations, and running searches to identify and export relevant content. It preserves data in place and supports the legal hold requirement. This solution directly addresses the need to preserve, search, and export documents across these workloads.

Why this answer

eDiscovery (Standard) is the appropriate solution because it supports creating a case, placing holds on Exchange Online, SharePoint Online, and OneDrive for Business to preserve content in place, and running searches to identify and export relevant items. It provides the case management and legal hold features needed for regulatory requests.

Exam trap

The trap here is confusing content search with eDiscovery; content search can find items but lacks holds and case management needed for legal preservation.

821
MCQmedium

A security analyst needs to detect and investigate compromised identities in on-premises Active Directory. They want to monitor for lateral movement, reconnaissance, and credential theft using behavioral analytics. Which Microsoft security solution is designed specifically for this purpose?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Cloud
C.Microsoft Defender for Identity
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Identity is the dedicated solution for detecting and investigating advanced threats and compromised identities within on-premises Active Directory environments. It deploys lightweight sensors directly on domain controllers to monitor network traffic and Windows events, leveraging behavioral analytics and machine learning to identify suspicious activities. This allows it to detect attack patterns such as lateral movement, credential theft, reconnaissance, and other indicators of compromise targeting on-premises user accounts and domain infrastructure.

Why this answer

Microsoft Defender for Identity (MDI) is a cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats like lateral movement, reconnaissance, and credential theft. It uses behavioral analytics and machine learning to profile user and entity behavior, alerting on suspicious activities such as Pass-the-Hash, DCSync, and Kerberoasting without requiring agents on domain controllers.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Identity with Microsoft Sentinel, assuming Sentinel's SIEM capabilities automatically cover identity-based behavioral analytics, but Sentinel lacks the native, agentless Active Directory behavioral profiling that MDI provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 focuses on email and collaboration threats (phishing, malware in attachments, and malicious links) and does not monitor on-premises Active Directory or lateral movement. Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform for Azure, AWS, and GCP resources, not for on-premises Active Directory identity threats. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR solution that can ingest logs from various sources, but it is not purpose-built for detecting compromised identities via behavioral analytics on Active Directory; it requires additional configuration and data connectors to achieve similar functionality.

822
MCQhard

An organization uses Microsoft Purview Compliance Manager. They need to track their progress against a specific regulatory standard and assign improvement actions to different teams. Which component should they use?

A.Compliance Manager assessments
B.eDiscovery
C.Data Loss Prevention
D.Audit logs
AnswerA

Assessments group improvement actions against a specific regulation or standard, letting organisations track progress and assign actions to teams. This satisfies the need to measure movement toward a named standard, whereas the other components do not organise work by regulatory framework.

Why this answer

Compliance Manager assessments are the correct component because they allow you to track progress against a specific regulatory standard (e.g., ISO 27001, SOC 2) by creating an assessment that maps controls to that standard. Improvement actions are the granular tasks within an assessment that can be assigned to different teams for remediation, directly supporting the need to track progress and assign work.

Exam trap

The trap here is that candidates may confuse Compliance Manager assessments with general compliance features like DLP or eDiscovery, but the question specifically asks for a component that tracks progress against a regulatory standard and assigns improvement actions, which is unique to assessments within Compliance Manager.

How to eliminate wrong answers

Option B is wrong because eDiscovery is used for identifying, preserving, and exporting content relevant to legal or regulatory investigations, not for tracking compliance progress or assigning improvement actions. Option C is wrong because Data Loss Prevention (DLP) policies are designed to prevent unauthorized sharing or leakage of sensitive data, not to manage compliance assessments or assign tasks. Option D is wrong because Audit logs record user and admin activity for security and compliance auditing, but they do not provide a structured framework for tracking progress against a regulatory standard or assigning improvement actions.

823
MCQmedium

Refer to the exhibit. An administrator created a retention label with the settings shown. What is the behavior of this label when applied to content?

A.It retains content for 5 years and then applies a disposition review.
B.It marks content as a regulatory record and prevents deletion.
C.It retains content for 7 years and then automatically deletes it.
D.It retains content indefinitely with no deletion.
AnswerC

This option accurately describes the retention label's behavior. The specified retention duration of 2555 days precisely equates to 7 years (2555 days / 365 days/year). Following this 7-year retention period, the 'DeleteAfterRetention' property, which is set to 'true', ensures that the content is automatically and permanently deleted without requiring any manual intervention or disposition review.

Why this answer

The retention label is configured with a retention period of 7 years and an action of 'Delete items automatically when the retention period ends.' Since no disposition review is enabled, the content will be automatically deleted after 7 years. This matches option C exactly.

Exam trap

The trap here is that candidates often confuse the retention period with the disposition review setting, assuming a disposition review is always required for deletion, or misread the 7-year period as 5 years due to the visual layout of the exhibit.

How to eliminate wrong answers

Option A is wrong because the label specifies a 7-year retention period, not 5 years, and no disposition review is configured. Option B is wrong because marking content as a regulatory record is a separate configuration that requires enabling 'Regulatory record' under 'Retention settings' and is not implied by the shown settings. Option D is wrong because the label has a finite retention period of 7 years, not indefinite retention.

824
MCQmedium

A security analyst needs to investigate a potential malware outbreak that started on an on-premises Windows server several days ago. They want to trace the attack timeline, see which files were modified, and understand how the attacker moved laterally across the network. Which Microsoft solution provides advanced endpoint detection and response (EDR) for on-premises servers?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Endpoint is the dedicated Endpoint Detection and Response (EDR) solution designed to protect, detect, investigate, and respond to advanced threats on endpoints, including on-premises servers. It provides comprehensive capabilities such as real-time monitoring, behavioral analytics, automated investigation and remediation, and advanced threat hunting tools. This platform is specifically engineered to identify and analyze malware, track its activities, and facilitate a security analyst's investigation into potential compromises directly on the affected machines.

Why this answer

Microsoft Defender for Endpoint (MDE) provides advanced endpoint detection and response (EDR) capabilities, including behavioral-based detection, automated investigation, and threat analytics. For on-premises Windows servers, MDE can be deployed via Microsoft Defender for Cloud (formerly Azure Security Center) or directly, enabling full attack timeline reconstruction, file modification tracking, and lateral movement path analysis through its rich telemetry and incident graph.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud's 'servers' workload protection with the actual EDR engine, not realizing that Defender for Cloud merely enables MDE on servers but does not replace its dedicated endpoint detection and response capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that can enable MDE on servers but does not itself provide the EDR functionality; it integrates with MDE for that purpose. Option C is wrong because Microsoft Defender for Office 365 protects email, SharePoint, OneDrive, and Teams from malicious content, not on-premises server endpoints or lateral movement analysis. Option D is wrong because Microsoft Defender for Identity is an identity-based threat detection solution that monitors Active Directory signals for attacks like pass-the-hash, not file-level or endpoint-level EDR on servers.

825
Multi-Selecteasy

Which TWO Microsoft security solutions can be used to detect and respond to threats across email, endpoints, and identities? (Choose two.)

Select 2 answers
A.Microsoft Intune
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview
D.Microsoft Sentinel
E.Microsoft Defender XDR
AnswersD, E

Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests signals from Microsoft 365, Defender services and Microsoft Entra ID, correlating them into incidents and automating response with playbooks. This cross-domain visibility satisfies the requirement to detect and respond across email, endpoints and identities.

Why this answer

Microsoft Defender XDR (E) is correct because it is the extended detection and response platform that natively correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps, providing unified detection and automated response. Microsoft Sentinel (D) is correct because it is a cloud-native SIEM/SOAR solution that ingests telemetry from email, endpoint, identity, and other sources via connectors, then uses analytics rules, fusion, and playbooks to detect and respond to threats across those domains. Microsoft Intune (A) is not correct because it is a mobile device and endpoint management (MDM/MAM) service for configuration and compliance, not a threat detection and response solution.

Microsoft Defender for Cloud Apps (B) is not correct here because, although it is part of the Defender XDR suite, on its own it is a CASB focused on cloud app discovery, session control, and SaaS threat protection rather than covering email, endpoints, and identities. Microsoft Purview (C) is not correct because it is a data governance, compliance, and information protection suite (DLP, eDiscovery, sensitivity labels), not a cross-domain threat detection and response platform.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a CASB focused on cloud app security) with a cross-domain detection and response solution, but it does not natively cover email or endpoint threat detection, making it an incorrect choice for this question.

Page 10

Page 11 of 18

Page 12