Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 826–900

1279 questions total · 18pages · All types, answers revealed

Page 11

Page 12 of 18

Page 13
826
MCQmedium

Your organization uses Microsoft Entra ID. You need to grant external partners limited access to a SharePoint site for 30 days. After 30 days, access should automatically expire. Which Microsoft Entra feature should you use?

A.Microsoft Entra access reviews
B.Microsoft Entra B2B guest user accounts
C.Microsoft Entra entitlement management
D.Microsoft Entra Conditional Access
AnswerC

Microsoft Entra entitlement management is the correct solution as it allows organizations to manage identity and access lifecycle for both internal and external users at scale. It enables the creation of 'access packages' that bundle resources and define policies, including explicit expiration dates for assignments. When access is granted via an access package, it is automatically revoked upon the specified expiration, ensuring time-limited access.

Why this answer

Microsoft Entra entitlement management allows you to create access packages that grant external users time-limited access to resources like SharePoint sites. By configuring an access package with a 30-day expiration policy, access is automatically revoked when the policy expires, meeting the requirement exactly.

Exam trap

The trap here is that candidates confuse entitlement management (which handles time-bound resource access) with access reviews (which handle periodic recertification) or B2B guest accounts (which provide identity but not automatic expiration).

How to eliminate wrong answers

Option A is wrong because Microsoft Entra access reviews are used for periodic attestation of existing access, not for automatically expiring access after a fixed duration. Option B is wrong because Microsoft Entra B2B guest user accounts provide the identity for external users but do not include built-in time-limited access policies; expiration must be managed separately. Option D is wrong because Microsoft Entra Conditional Access enforces access controls based on conditions like location or device state, not for granting or expiring access to specific resources on a schedule.

827
MCQhard

Refer to the exhibit. You are reviewing an ARM template for an Azure resource. Assuming the resource is a Key Vault, what is the effect of the networkAcls configuration?

A.The Key Vault is accessible from any network.
B.The Key Vault is accessible only from the 10.0.0.0/24 subnet.
C.The Key Vault is accessible from all Azure services.
D.The Key Vault is not accessible from any network.
AnswerB

This statement is correct. The network access configuration includes an "ipRules" entry specifically allowing traffic from the "10.0.0.0/24" subnet. Since the "defaultAction" is set to "Deny," any network traffic originating from outside this explicitly permitted IP range will be blocked. This creates a precise security boundary, restricting access exclusively to the specified subnet.

Why this answer

The networkAcls configuration in the ARM template defines IP firewall rules for the Key Vault. By specifying a defaultAction of 'Deny' and a single ipRule with a value of '10.0.0.0/24', the Key Vault is configured to allow traffic only from the 10.0.0.0/24 subnet. All other traffic, including traffic from other networks and Azure services, is denied by default.

Exam trap

The trap here is that candidates may assume a single ipRule with a subnet means the Key Vault is accessible from all Azure services or from any network, but the defaultAction of 'Deny' explicitly blocks all traffic except the allowed IP range, and the absence of a bypass setting prevents Azure services from accessing the vault.

How to eliminate wrong answers

Option A is wrong because the defaultAction is set to 'Deny', which means the Key Vault is not accessible from any network by default; only explicitly allowed IP ranges can access it. Option C is wrong because allowing access from all Azure services would require setting the bypass parameter to 'AzureServices' and the defaultAction to 'Allow', or adding a specific rule for Azure services; the current configuration does not include that. Option D is wrong because the Key Vault is accessible from the 10.0.0.0/24 subnet as defined by the ipRule, so it is not completely inaccessible.

828
Multi-Selecthard

Which TWO Microsoft Purview solutions can help identify and protect sensitive data in Microsoft Teams? (Choose TWO.)

Select 2 answers
A.Communication Compliance
B.Information Protection
C.Data Lifecycle Management
D.Data Loss Prevention
E.Insider Risk Management
AnswersB, D

Microsoft Purview Information Protection (MPIP) enables organizations to discover, classify, and protect sensitive data wherever it lives or travels. By applying sensitivity labels to documents, emails, and Teams messages, MPIP can automatically or manually identify sensitive content and enforce protection actions like encryption, visual markings, and access restrictions. This directly helps identify and safeguard sensitive information across the digital estate.

Why this answer

Information Protection (B) is correct because it uses sensitivity labels and the Microsoft Purview Information Protection client/service to classify and protect content, and these labels can be applied to Teams messages and files so sensitive data is identified and protected. Data Loss Prevention (D) is correct because DLP policies in Microsoft Purview can detect sensitive information types in Teams chat and channel messages and take protective actions such as blocking or warning users. Communication Compliance (A) focuses on detecting policy violations in communications for review, not on classifying/protecting sensitive data.

Data Lifecycle Management (C) governs retention and deletion of content rather than identifying/protecting sensitive data. Insider Risk Management (E) detects risky user behavior and generates alerts/cases, but it is not the primary solution for identifying and protecting sensitive data in Teams.

Exam trap

The trap here is that candidates often confuse Communication Compliance or Insider Risk Management with data protection, but these solutions focus on behavioral monitoring and policy violations, not on identifying and protecting sensitive data through classification and blocking.

829
MCQmedium

Your company uses Microsoft Entra ID. You need to enforce that all users accessing the HR application must have a device that is compliant with company security policies. The device compliance is managed by Microsoft Intune. Which feature should you use to enforce this requirement?

A.Microsoft Intune device compliance policies
B.Microsoft Entra Conditional Access
C.Microsoft Entra Multifactor Authentication
D.Microsoft Entra device registration
AnswerB

Microsoft Entra Conditional Access is the policy engine that evaluates various signals in real-time, such as user identity, location, application, and device state, to make granular access decisions. To enforce device compliance, a Conditional Access policy is configured to require that a device be marked as compliant by an MDM solution like Intune before granting access to protected resources. This directly controls access based on the device's adherence to organizational security standards.

Why this answer

Microsoft Entra Conditional Access is the correct feature because it allows you to create policies that evaluate conditions such as device compliance before granting access to applications. By integrating with Microsoft Intune, Conditional Access can check the device compliance status reported by Intune and block or allow access to the HR application accordingly. This enforces the requirement that only compliant devices can access the app, without requiring users to authenticate differently.

Exam trap

The trap here is that candidates confuse the creation of compliance policies (Intune) with the enforcement of those policies (Conditional Access), assuming that simply defining compliance rules automatically restricts access to applications.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune device compliance policies define the compliance rules (e.g., encryption, OS version) but do not enforce access control to applications; they only mark devices as compliant or non-compliant. Option C is wrong because Microsoft Entra Multifactor Authentication adds an extra authentication factor but does not evaluate device compliance or enforce device-based access restrictions. Option D is wrong because Microsoft Entra device registration is the process of joining a device to the directory, which is a prerequisite for compliance but does not itself enforce access policies based on compliance status.

830
Multi-Selectmedium

A company uses Microsoft 365 E5 and wants to protect against advanced cyber threats. Which THREE capabilities of Microsoft Defender XDR should they implement?

Select 3 answers
A.Microsoft Intune
B.Microsoft Defender for Office 365
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
E.Microsoft Defender for Endpoint
AnswersB, D, E

This service is a core component of Microsoft 365 Defender, providing robust protection against sophisticated threats targeting email and collaboration tools. It safeguards against phishing, business email compromise (BEC), malware, and other advanced attacks across Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. Its integrated detection and response capabilities are essential for protecting user productivity and data within the Microsoft 365 ecosystem.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across endpoints, email and collaboration, identities, and cloud apps, so the three correct components here are Defender for Office 365 (B), Defender for Cloud Apps (D), and Defender for Endpoint (E). Defender for Office 365 (B) is correct because it protects Exchange Online, Teams, and SharePoint/OneDrive against phishing, business email compromise, malicious attachments/URLs, and zero-day threats via Safe Attachments, Safe Links, and automated investigation and response. Defender for Cloud Apps (D) is correct because it is the cloud access security broker (CASB) that discovers shadow IT, enforces session and conditional access policies, and detects anomalous behavior across SaaS apps, feeding those alerts into the XDR incident queue.

Defender for Endpoint (E) is correct because it delivers endpoint detection and response (EDR), attack surface reduction, next-generation antivirus, and automated investigation/remediation on Windows, macOS, Linux, iOS, and Android devices. Microsoft Intune (A) is not part of Defender XDR; it is a separate endpoint management/MDM service, and Microsoft Sentinel (C) is a standalone cloud-native SIEM/SOAR platform that can ingest Defender XDR incidents but is not itself one of the Defender XDR workloads.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with an XDR component, but Sentinel is a separate analytics service that ingests data from XDR solutions rather than being a core part of Microsoft Defender XDR's integrated threat protection suite.

831
MCQhard

A security administrator receives an alert from Microsoft Sentinel about a possible brute-force attack against a virtual machine. The administrator wants to automatically block the attacker's IP address for 24 hours using a playbook. Which automation trigger should the playbook use?

A.Incident trigger
B.Alert trigger
C.Scheduled trigger
D.Action trigger
AnswerA

An incident trigger fires the playbook automatically when Microsoft Sentinel creates the incident, letting the logic app act without manual intervention. This satisfies the requirement to block the attacker's IP for 24 hours automatically, since the playbook runs on incident creation rather than on a schedule or alert.

Why this answer

An incident trigger allows the playbook to run automatically when a new incident is created in Microsoft Sentinel. In this scenario, the alert about the brute-force attack generates an incident, and the playbook can then block the attacker's IP address for 24 hours. Option B (Alert trigger) runs on alert generation, but the administrator wants to respond to the incident for a coordinated response.

Option C (Scheduled trigger) runs on a timer and is not event-driven. Option D (Action trigger) is not a valid trigger type in Microsoft Sentinel.

832
MCQmedium

A company uses Microsoft Entra ID. They want to ensure that when users access the HR portal from an unmanaged personal device, they are prompted to sign a terms of use agreement and also required to perform multifactor authentication (MFA). Which Conditional Access control should they configure to enforce both requirements?

A.Session control - Use app enforced restrictions
B.Grant - Require MFA and Require terms of use
C.Grant - Require approved client app
D.Session control - Sign-in frequency
AnswerB

This option utilizes two distinct grant controls within a Conditional Access policy, directly addressing the requirements. "Require multifactor authentication" ensures users provide a second verification factor, significantly enhancing security at the point of access. Concurrently, "Require terms of use" mandates that users review and explicitly accept a specified document before they are permitted to access the protected resource, directly fulfilling both stated requirements for initial access.

Why this answer

The Grant control in Conditional Access allows you to require multiple conditions to be satisfied before granting access. By selecting both 'Require MFA' and 'Require terms of use' under Grant, the policy enforces that the user must complete both MFA and accept the terms of use when accessing the HR portal from an unmanaged device. This directly meets the requirement for both authentication and consent.

Exam trap

The trap here is that candidates often confuse Session controls (which manage behavior after access is granted) with Grant controls (which enforce requirements before access is granted), leading them to pick a session-based option like 'Sign-in frequency' instead of the correct Grant combination.

How to eliminate wrong answers

Option A is wrong because Session controls (like 'Use app enforced restrictions') only apply additional restrictions during an active session, such as blocking downloads, but they do not enforce pre-access requirements like MFA or terms of use acceptance. Option C is wrong because 'Require approved client app' restricts access to specific client applications (e.g., Microsoft apps) and does not enforce MFA or terms of use. Option D is wrong because 'Sign-in frequency' is a session control that re-prompts for authentication after a set time, but it does not enforce MFA or terms of use as a one-time requirement.

833
MCQeasy

Your organization uses Microsoft 365 and wants to classify and protect documents based on their content, such as credit card numbers. Which Microsoft Purview feature automatically classifies content based on sensitive information types?

A.Data Loss Prevention policy
B.Auto-labeling with sensitivity labels
C.Unified labeling client
D.eDiscovery
AnswerB

Auto-labeling policies for sensitivity labels are specifically engineered to automatically apply predefined labels to content, such as documents and emails, based on conditions like the presence of sensitive information types, keywords, or trainable classifiers. This automated process ensures consistent and scalable data classification across an organization without requiring manual user intervention. Once applied, these labels enable persistent protection and governance actions, regardless of where the data resides or travels.

Why this answer

Auto-labeling with sensitivity labels in Microsoft Purview can automatically classify and protect documents by detecting sensitive information types (e.g., credit card numbers) using built-in or custom data classifiers. This feature applies the appropriate sensitivity label based on content matches, enabling consistent protection across Microsoft 365 services.

Exam trap

The trap here is confusing Data Loss Prevention (DLP) policies with auto-labeling, as both use sensitive information types, but DLP focuses on preventing data loss through actions like blocking or alerting, while auto-labeling applies classification labels for ongoing protection.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy monitors and blocks risky activities (e.g., sharing credit card numbers externally) but does not automatically apply classification labels to documents. Option C is wrong because the Unified Labeling Client is a legacy tool for manual or client-side labeling, not an automatic content-based classification feature. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for automatic classification or protection of documents.

834
MCQhard

A multinational corporation needs to restrict data sharing in Microsoft Teams to comply with regional regulations. Users must not be able to share files with external domains from specific departments. What should the administrator configure?

A.Microsoft Intune device compliance policy
B.Microsoft Defender for Cloud Apps session policy
C.Data Loss Prevention (DLP) policy in Microsoft Purview
D.Sensitivity labels with container management in Microsoft Purview
AnswerD

Sensitivity labels with container management in Microsoft Purview are specifically designed to classify and protect data by applying predefined policies to content and its containers. When a sensitivity label is applied to a Microsoft Teams, SharePoint site, or Microsoft 365 Group, it can automatically enforce specific sharing and access policies, including blocking external sharing for all content within that labeled container. This ensures that data belonging to a particular department or project, once labeled, adheres to predefined organizational sharing restrictions, providing granular control at the container level.

Why this answer

Sensitivity labels with container management in Microsoft Purview allow administrators to configure external sharing restrictions for Microsoft Teams, SharePoint, and Groups. By applying a sensitivity label to a team, you can block external sharing for specific departments, ensuring compliance with regional regulations. This is the correct solution because it directly controls sharing behavior at the container level based on the label's settings.

Exam trap

The trap here is that candidates often confuse DLP policies (which block sensitive content) with container-level sharing restrictions, not realizing that DLP cannot block all external sharing from a specific department—it only acts on content patterns.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune device compliance policy enforces device-level security requirements (e.g., encryption, OS version) and does not control data sharing restrictions in Teams. Option B is wrong because Microsoft Defender for Cloud Apps session policy monitors and controls user sessions in real-time (e.g., blocking downloads) but cannot restrict external domain sharing at the Teams container level. Option C is wrong because Data Loss Prevention (DLP) policy in Microsoft Purview scans and prevents sharing of sensitive data (e.g., credit card numbers) but does not block all sharing with external domains from specific departments; it is content-based, not department-based.

835
MCQmedium

An organization uses Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared externally. They need to block sharing of credit card numbers in emails and Teams messages. What should they create?

A.A retention label to retain credit card data
B.A DLP policy with a rule that detects credit card numbers and blocks sharing
C.An audit policy to log credit card sharing
D.A sensitivity label that marks credit card data
AnswerB

Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information across various locations, including Microsoft 365 services, endpoints, and cloud apps. A DLP policy configured with a rule to detect credit card numbers (a sensitive information type) can automatically block sharing attempts, notify users, or encrypt content, thereby preventing unauthorized data exfiltration. This directly addresses the requirement to block sharing of sensitive data.

Why this answer

Microsoft Purview DLP policies are specifically designed to detect and automatically block the sharing of sensitive data, such as credit card numbers, across services like Exchange Online (email) and Microsoft Teams. By creating a DLP policy with a rule that includes a sensitive information type for credit card numbers and an action to block external sharing, the organization can enforce the required protection. Retention labels, audit policies, and sensitivity labels do not provide the real-time blocking capability needed for this scenario.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking based on content detection), leading them to select a sensitivity label instead of the DLP policy that actually blocks the sharing.

How to eliminate wrong answers

Option A is wrong because a retention label is used to retain or delete data based on compliance requirements, not to block the sharing of sensitive information in real time. Option C is wrong because an audit policy only logs events for review after they occur, it does not prevent or block the sharing of credit card numbers. Option D is wrong because a sensitivity label applies classification and protection (like encryption or visual markings) but does not include a rule to automatically detect and block sharing of specific data patterns like credit card numbers.

836
MCQmedium

A company must retain all customer service emails in Exchange Online for 7 years for regulatory purposes. After 7 years, the emails must be automatically deleted. Additionally, employees must not be able to permanently delete these emails before the retention period ends. Which Microsoft Purview solution should they configure?

A.Data Lifecycle Management (retention policies and labels)
B.Communication Compliance
C.eDiscovery (Premium)
D.Data Loss Prevention (DLP)
AnswerA

Data Lifecycle Management, specifically through Microsoft 365 retention policies and retention labels, is the precise solution for enforcing long-term data retention requirements. Retention policies can be applied broadly to Exchange mailboxes to ensure all customer service emails are preserved for a specified duration, such as seven years, preventing both accidental and malicious deletion by users. These policies also manage the automatic deletion of content after its retention period expires, ensuring compliance with regulatory and organizational data lifecycle mandates.

Why this answer

Data Lifecycle Management (DLM) via retention policies and labels in Microsoft Purview is the correct solution because it allows you to define a retention period of 7 years for Exchange Online emails and then automatically delete them. Additionally, DLM retention policies prevent users from permanently deleting emails before the retention period ends by locking the items in a 'preservation hold' state, ensuring regulatory compliance.

Exam trap

The trap here is that candidates confuse retention policies (which enforce deletion after a period) with eDiscovery holds (which preserve content indefinitely for legal cases), leading them to select eDiscovery (Premium) instead of Data Lifecycle Management.

How to eliminate wrong answers

Option B is wrong because Communication Compliance is designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading), not to enforce retention or deletion schedules. Option C is wrong because eDiscovery (Premium) is used for legal discovery and holds content for litigation, not for automated lifecycle management or deletion after a fixed period. Option D is wrong because Data Loss Prevention (DLP) prevents unauthorized sharing of sensitive data (e.g., credit card numbers) but does not manage retention periods or enforce deletion.

837
MCQhard

Your organization uses Microsoft Sentinel as its SIEM. You need to create an analytics rule that detects when a user account is created in Azure AD and then, within 10 minutes, that same account is used to grant admin consent to an application. You have a KQL query that joins AuditLogs and SigninLogs. However, the rule is generating too many false positives. You need to refine the query to reduce false positives. What should you do?

A.Change the rule to alert on every admin consent grant event regardless of account creation.
B.Remove the join with SigninLogs and only use AuditLogs.
C.Add a condition to exclude accounts that are known admin accounts or service accounts.
D.Increase the time window from 10 minutes to 30 minutes.
AnswerC

This solution directly addresses the issue of excessive false positives by allowing legitimate administrative and service accounts to perform necessary admin consent grants without triggering alerts. By explicitly excluding these known, authorized entities, the rule focuses on detecting anomalous or unauthorized consent grants from potentially compromised user accounts or malicious actors. This targeted approach significantly reduces alert fatigue, enabling security analysts to concentrate on high-fidelity alerts that indicate actual threats.

Why this answer

Known admin or service accounts are often used for legitimate, automated admin consent grants, which can trigger false positives. By excluding these accounts from the detection logic, the rule focuses on anomalous behavior from non-privileged accounts, reducing noise while preserving the core detection of suspicious account creation followed by admin consent grant.

Exam trap

The trap here is that candidates may think widening the time window or simplifying the query will reduce false positives, but in reality, these changes either increase noise or break the correlation logic, whereas excluding known legitimate accounts directly addresses the root cause of false alerts.

How to eliminate wrong answers

Option A is wrong because alerting on every admin consent grant event would massively increase false positives, as many legitimate admin consent grants occur without a preceding account creation. Option B is wrong because removing the join with SigninLogs would eliminate the temporal correlation between account creation and the subsequent sign-in used for consent, breaking the detection logic entirely. Option D is wrong because increasing the time window from 10 to 30 minutes would allow more unrelated events to match, likely increasing false positives rather than reducing them.

838
MCQeasy

A company's security team configures network firewall rules so that only a dedicated jump server's IP address can initiate RDP connections to production servers. This is an example of which security principle?

A.Least privilege
B.Defense in depth
C.Zero Trust
D.Separation of duties
AnswerA

The principle of least privilege dictates that users and systems should only be granted the minimum necessary permissions to perform their legitimate functions. By configuring firewall rules to restrict Remote Desktop Protocol (RDP) access exclusively to a hardened jump server, the security team ensures that direct administrative access to sensitive internal resources is severely limited. This prevents unauthorized lateral movement and reduces the attack surface, aligning precisely with the goal of minimizing potential harm from compromised credentials or systems.

Why this answer

Restricting RDP access to only a dedicated jump server's IP address ensures that no other hosts or users can directly initiate remote desktop connections to production servers. This enforces the principle of least privilege by granting only the minimum necessary network access (the jump server) required for administrative tasks, reducing the attack surface and limiting lateral movement.

Exam trap

The trap here is that candidates confuse 'least privilege' (limiting access to what is necessary) with 'defense in depth' (multiple layers), because both involve restricting access, but least privilege focuses on the minimal permissions while defense in depth focuses on layered controls.

How to eliminate wrong answers

Option B (Defense in depth) is wrong because defense in depth involves multiple layers of security controls (e.g., firewalls, IDS, encryption) working together, not a single access restriction. Option C (Zero Trust) is wrong because Zero Trust assumes no implicit trust and requires continuous verification of every request, whereas this rule is a static IP-based allowlist that does not verify identity or session context. Option D (Separation of duties) is wrong because separation of duties divides critical tasks among different people to prevent fraud or error, not restrict network access to a specific source IP.

839
Multi-Selecteasy

Which TWO capabilities are provided by Microsoft Entra ID?

Select 2 answers
A.Multifactor authentication
B.Device management
C.Security incident detection
D.Single sign-on
E.Data classification
AnswersA, D

Microsoft Entra ID natively provides robust multifactor authentication (MFA) capabilities, allowing organizations to enforce an additional layer of security beyond just a password. Users can verify their identity through various methods like authenticator apps, biometrics, or security keys, significantly reducing the risk of unauthorized access from compromised credentials. This capability is central to a strong identity and access management strategy within the Microsoft cloud ecosystem.

Why this answer

Microsoft Entra ID (formerly Azure AD) is a cloud-based identity and access management service, and it provides Multifactor Authentication (A) by letting administrators enforce a second verification factor such as the Microsoft Authenticator app, SMS, or a FIDO2 key through Conditional Access policies. It also provides Single sign-on (D), allowing users to authenticate once with their Entra ID account and access federated applications via protocols like SAML 2.0, WS-Federation, or OpenID Connect. Device management (B) is not an Entra ID capability itself; it is delivered by Microsoft Intune (or Configuration Manager) through MDM/MAM, even though Entra ID can register or join devices for identity purposes.

Security incident detection (C) belongs to Microsoft Defender XDR / Microsoft Sentinel, not Entra ID, which only surfaces identity-related signals like risky sign-ins. Data classification (E) is provided by Microsoft Purview (sensitivity labels, DLP), not by Entra ID.

Exam trap

SC-900 often tests the distinction between identity management (Entra ID) and security management (Defender, Sentinel) or compliance (Purview), so candidates may incorrectly attribute device management or incident detection to Entra ID.

840
MCQmedium

A company uses Microsoft Entra ID. The IT department needs to ensure that membership in the 'Global Administrator' role is regularly reviewed. Every quarter, the designated reviewers (e.g., senior managers) receive an email asking them to confirm whether each user in the role should keep their assignment. After the review deadline, any member not approved is automatically removed. Which Microsoft Entra ID feature should they configure?

A.Access Reviews
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerA

Microsoft Entra ID Access Reviews enable organizations to efficiently manage group memberships, access to applications, and role assignments by creating recurring review campaigns. These campaigns empower designated reviewers, often resource owners, to periodically attest to the continued need for access for each member. Upon completion of the review period, Access Reviews can automatically remove users whose access was not approved, ensuring the principle of least privilege and reducing stale access. This directly addresses the need for periodic review and removal of access.

Why this answer

Access Reviews in Microsoft Entra ID are specifically designed for periodic attestation of group memberships, application access, and role assignments. The scenario describes a quarterly review where designated reviewers receive email notifications and unapproved members are automatically removed after the deadline, which is the exact workflow that Access Reviews automate. This feature ensures compliance by requiring explicit confirmation for each user in the Global Administrator role.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with Access Reviews because both deal with privileged roles, but PIM handles activation and approval, while Access Reviews handle periodic attestation and removal of stale assignments.

Why the other options are wrong

B

PIM provides just-in-time privileged access and activation workflows, but it does not include the recurring review and automatic removal process described. The question specifically requires periodic reviews with automatic removal, which is a core feature of Access Reviews, not PIM.

C

Identity Protection is designed to detect and remediate identity-based risks (e.g., compromised accounts, risky sign-ins), not to manage periodic review and removal of role assignments.

D

Conditional Access is used to enforce access controls based on conditions like location or device state, not for reviewing and attesting role memberships. The question specifically requires a review and attestation process, which is handled by Access Reviews.

When would these options actually be correct?

B

PIM would be correct if the question asked: 'The IT department needs to allow users to request temporary elevation to the Global Administrator role, with approval from senior managers and automatic expiration after a set time.'

C

An organization wants to automatically detect and block sign-ins from anonymous IP addresses or locations with atypical travel patterns, and require multi-factor authentication for high-risk users.

D

A company wants to require that all users accessing a sensitive application from outside the corporate network must use multi-factor authentication. They need a policy that evaluates conditions (e.g., location, device compliance) and grants or blocks access accordingly.

Why candidates pick the wrong answer

B

Candidates often confuse PIM with Access Reviews because both are part of Microsoft Entra ID Governance and involve privileged roles. PIM includes review capabilities, but the question's emphasis on recurring reviews and automatic removal points specifically to Access Reviews.

C

Candidates may confuse 'reviewing role membership' with 'protecting identities' because both involve security oversight, but Identity Protection focuses on risk detection, not role governance.

D

Candidates may confuse Conditional Access with access governance features, thinking it can be used to review role assignments, but it is actually a policy engine for enforcing access requirements.

841
MCQmedium

A security team wants to detect when a user downloads an unusually large number of files from a third-party cloud storage app (e.g., Box) after logging in from an unfamiliar location. They also want to automatically suspend the user's account if such behavior is detected. Which Microsoft security solution should they use?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Identity
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and protection across all cloud applications, both sanctioned and unsanctioned. It actively monitors user activities, including file downloads and uploads, across third-party SaaS applications, detecting anomalous behaviors like mass downloads that could indicate data exfiltration. This solution is specifically engineered to identify and respond to threats within the cloud app ecosystem, making it ideal for detecting when a user downloads a file from a cloud service.

Why this answer

Microsoft Defender for Cloud Apps (MDCA) is the correct solution because it provides Cloud Access Security Broker (CASB) capabilities, including anomaly detection for user behavior across third-party cloud apps like Box. It can detect activities such as an unusually large number of file downloads from an unfamiliar location using its built-in behavioral analytics and then automatically apply a governance action, such as suspending the user's account, via policy-driven automated responses.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming that 'cloud apps' only refers to Microsoft 365 services, but MDCA specifically covers third-party SaaS apps like Box, Salesforce, and AWS, while Defender for Office 365 is limited to Microsoft's own collaboration suite.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 focuses on protecting email and collaboration tools within Exchange Online, SharePoint Online, and Teams, not on monitoring third-party cloud storage apps like Box for anomalous download behavior. Option C is wrong because Microsoft Defender for Identity is designed to detect on-premises Active Directory attacks (e.g., lateral movement, privilege escalation) using network traffic and event logs, not to monitor user activity in third-party SaaS applications. Option D is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution that protects devices (Windows, macOS, Linux) from malware and advanced threats, not cloud app usage or user account suspension in SaaS platforms.

842
MCQhard

A multinational organization must comply with GDPR and local data residency requirements. The compliance team needs to ensure that personal data is not stored in regions outside the permitted locations. Which Microsoft Purview capability should they use to discover and map personal data across the organization's data estate?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Compliance Manager
C.Microsoft Purview Data Map
D.Microsoft Purview Audit
AnswerC

Microsoft Purview Data Map provides a unified metadata store that automatically scans, classifies, and maps data across an organization's hybrid data estate, including on-premises, multi-cloud, and SaaS sources. This capability is fundamental for GDPR compliance as it enables organizations to discover where personal data resides, understand its lineage, and identify sensitive information types, which is crucial for fulfilling data subject access requests and demonstrating accountability.

Why this answer

Microsoft Purview Data Map is the correct capability because it provides automated data discovery, classification, and lineage across hybrid and multi-cloud data estates. It enables organizations to scan, map, and catalog personal data, including GDPR-sensitive attributes, and enforce data residency policies by identifying where data is stored. This directly supports the compliance team's need to discover and map personal data across permitted locations.

Exam trap

The trap here is that candidates often confuse Compliance Manager (which assesses compliance posture) with Data Map (which discovers and maps data), leading them to select Compliance Manager because it sounds like it 'manages compliance' for GDPR, but it does not perform data discovery.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management focuses on retaining, deleting, and managing data based on policies (e.g., retention labels), not on discovering or mapping personal data across the data estate. Option B is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance score tool that evaluates controls against regulations like GDPR, but it does not perform data discovery or mapping of personal data. Option D is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities, not the discovery or mapping of personal data across storage locations.

843
MCQmedium

A company wants to block all sign-ins using legacy authentication protocols because these protocols do not support multi-factor authentication (MFA). Which component of a Microsoft Entra ID Conditional Access policy should be configured to achieve this?

A.Cloud apps or actions
B.Conditions (Client apps)
C.Grant
D.Session
AnswerB

In Azure AD Conditional Access, the "Conditions" section allows administrators to define specific criteria for policy application. The "Client apps" condition specifically targets the type of client application attempting to access resources, including options to block "Other clients," which encompasses legacy authentication protocols like POP3, IMAP, SMTP, and older Office clients. By selecting this option, organizations can enforce the exclusive use of modern authentication clients, significantly enhancing security by eliminating vulnerabilities associated with less secure, basic authentication methods.

Why this answer

To block legacy authentication protocols, you configure the 'Client apps' condition in a Conditional Access policy. This setting allows you to target specific authentication clients, such as Exchange ActiveSync, POP3, IMAP, and SMTP, which do not support MFA. By selecting 'Exchange ActiveSync clients' and 'Other clients' under the Client apps condition, you can enforce a block on all sign-ins using these legacy protocols.

Exam trap

The trap here is that candidates often confuse 'Client apps' with 'Cloud apps or actions', thinking they need to select the specific legacy app (like Exchange Online) rather than the authentication client type, which is the correct way to block the protocol itself.

Why the other options are wrong

A

The 'Cloud apps or actions' component specifies which applications or user actions the policy applies to, not the authentication protocol. Blocking legacy authentication requires configuring the 'Client apps' condition under 'Conditions'.

C

The Grant control in a Conditional Access policy is used to enforce requirements like MFA or device compliance after conditions are met, not to block specific authentication protocols. Blocking legacy authentication is done by configuring the Client apps condition under Conditions.

D

The Session control in a Conditional Access policy manages session-level behaviors like app-enforced restrictions or sign-in frequency, not the blocking of authentication protocols. Blocking legacy authentication is done by configuring the Client apps condition under Conditions.

When would these options actually be correct?

A

A question asks: 'A company wants to require MFA for all access to its financial reporting app in Microsoft Entra ID. Which component should be configured?' Here, 'Cloud apps or actions' would be correct to select the specific app.

C

In a scenario where the goal is to require MFA for all cloud app access, the Grant control would be configured to require MFA. For example: 'A company wants to enforce MFA for all users accessing Microsoft 365. Which component should be configured?'

D

A company wants to enforce sign-in frequency for all cloud app sessions, requiring users to re-authenticate every hour. Configuring the Session control with sign-in frequency settings would be the correct approach.

Why candidates pick the wrong answer

A

Candidates may confuse the target of the policy (the app) with the condition that controls the authentication method, thinking that specifying the app is sufficient to block legacy protocols.

C

Candidates may confuse the Grant control with the mechanism to block access, as it includes a 'Block access' option. However, blocking legacy authentication is a condition-based action, not a grant control.

D

Candidates may confuse Session controls with authentication protocol controls, thinking that session settings can block legacy protocols, or they may not clearly distinguish between Conditions and Session in Conditional Access policies.

844
MCQeasy

An organization wants to provide a secure way for external partners to access specific SharePoint sites without creating new user accounts. What Microsoft Entra B2B feature should they use?

A.Azure AD B2C
B.Direct federation
C.Azure AD Domain Services
D.B2B collaboration
AnswerD

Azure AD B2B collaboration allows organizations to securely invite external users, such as partners, vendors, or customers, to access their applications and resources while letting these users sign in with their own identities. This includes identities from other Azure AD tenants, social identity providers (like Google or Microsoft accounts), or even email one-time passcodes. It provides a streamlined and secure method for external users to access shared resources without creating new credentials in the inviting organization's directory, maintaining strong security controls and compliance.

Why this answer

B2B collaboration is the correct Microsoft Entra B2B feature because it allows external partners to access specific SharePoint sites using their own identities (e.g., work or social accounts) without requiring new user accounts or passwords to be created in the organization's tenant. This is achieved through invitation-based redemption, where the partner user is represented as a guest user object in the directory, enabling fine-grained access control via SharePoint site sharing policies.

Exam trap

The trap here is that candidates confuse B2B collaboration (for external partner access with existing identities) with Azure AD B2C (for customer-facing identity management), or mistakenly think Direct federation is required for partner access when B2B collaboration already handles the invitation and redemption process without creating new accounts.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C (Business-to-Consumer) is designed for customer-facing applications with self-service sign-up, not for granting external partners access to internal SharePoint sites without creating accounts. Option B is wrong because Direct federation is an authentication method that establishes a trust relationship with an external IdP for inbound SAML/WS-Fed federation, but it does not provide the invitation-based guest access model needed for ad-hoc partner access to SharePoint. Option C is wrong because Azure AD Domain Services provides managed domain services (e.g., LDAP, Kerberos) for legacy applications, not for external partner identity management or SharePoint access.

845
MCQhard

Refer to the exhibit. You run a Kusto query in Microsoft Defender XDR Advanced Hunting. What does this query return?

A.Top 10 high-severity alert titles by number of distinct affected devices
B.Top 10 alert titles by number of distinct devices, including all severities
C.Top 10 devices with the most high-severity alerts
D.Top 10 high-severity alert titles by total number of alerts
AnswerA

This option accurately describes a Kusto query that would use `where AlertSeverity == 'High'` to filter, then `summarize DistinctDevices = dcount(DeviceName) by AlertTitle`, and finally `top 10 by DistinctDevices desc` to achieve the stated goal. The use of `dcount(DeviceName)` correctly calculates the number of unique devices affected by each alert title, directly matching the 'distinct affected devices' requirement. Grouping by `AlertTitle` ensures the ranking is based on alert types, providing the top 10 most impactful alert titles.

Why this answer

The query filters for high-severity alerts, then summarizes by AlertTitle and counts distinct DeviceName values. It orders by that count descending and takes the top 10, so it returns the top 10 high-severity alert titles ranked by the number of distinct affected devices.

Exam trap

The trap here is that candidates confuse 'distinct devices' with 'total alerts' or 'devices with the most alerts', and overlook the explicit severity filter, leading them to choose options that ignore the high-severity filter or misidentify the aggregation column.

How to eliminate wrong answers

Option B is wrong because the query explicitly filters for high-severity alerts (where Severity == 'High'), so it does not include all severities. Option C is wrong because the query summarizes by AlertTitle, not by DeviceName; it returns alert titles, not device names. Option D is wrong because the query uses dcount(DeviceName) to count distinct devices, not a count of total alerts (which would use count()).

846
Multi-Selecteasy

Which TWO features are part of Microsoft Defender XDR?

Select 2 answers
A.Automated investigation and response
B.Cloud app discovery
C.Endpoint data loss prevention
D.Identity Protection
E.Incident management across workloads
AnswersA, E

Automated investigation and response is a core Defender XDR capability, letting the platform triage alerts and execute remediation actions across endpoints, identities and email automatically. This satisfies the stem's requirement for a genuine cross-workload XDR feature rather than a single-product tool.

Why this answer

Option A is correct because Automated investigation and response (AIR) is a core Microsoft Defender XDR capability that automatically investigates alerts, correlates evidence across endpoints, identities, email, and cloud apps, and applies remediation actions. Option E is correct because incident management across workloads is the defining feature of Defender XDR, which correlates alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into unified incidents in the Microsoft 365 Defender portal. Option B is incorrect because Cloud app discovery is a Microsoft Defender for Cloud Apps (formerly MCAS) capability, not a Defender XDR feature itself.

Option C is incorrect because Endpoint data loss prevention is a Microsoft Purview capability, not part of Defender XDR. Option D is incorrect because Identity Protection is a Microsoft Entra ID feature, distinct from Defender for Identity which is the Defender XDR identity workload.

847
MCQmedium

Your organization, Contoso Ltd., uses Microsoft 365 and Microsoft Defender XDR. You are a security administrator. Recently, a user named John Doe reported that his account is sending phishing emails internally. You suspect his account is compromised. You need to contain the threat immediately while preserving forensic data. The company has the following security solutions: Microsoft Entra ID P2, Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Microsoft Sentinel, and Microsoft Purview. You need to prevent the compromised account from causing further damage. Which action should you take first?

A.Reset the user's password and require a password change
B.Revoke all refresh tokens for the user in Microsoft Entra ID
C.Disable the user account in Microsoft Entra ID
D.Create a mail flow rule in Exchange Online to block the user's emails
AnswerC

Disabling the account in Microsoft Entra ID immediately blocks all sign-ins and token issuance, halting the internal phishing campaign at the identity layer. This contains the threat fastest while leaving the mailbox, audit logs and sign-in history intact for forensic investigation, satisfying the preserve-evidence constraint.

Why this answer

Disabling the user account in Microsoft Entra ID immediately prevents the compromised account from initiating any new actions, including sending phishing emails. This is the fastest containment step while preserving forensic data. Option A (reset password) is incorrect because it does not terminate active sessions; the attacker may still have a valid token.

Option B (revoke refresh tokens) is a useful step but is not as immediate as disabling the account, and it may not stop all sessions. Option D (create mail flow rule) is too slow and may not affect sessions already authenticated.

848
MCQhard

Your organization uses Microsoft Sentinel for SIEM. You receive an alert that a user account was compromised. You need to automatically disable the user's access across all cloud apps (SaaS) and reset their password. What should you use?

A.Create a Microsoft Sentinel automated response playbook
B.Use Microsoft Intune to remote wipe the user's device
C.Manually disable the user in Microsoft Entra ID and reset password
D.Configure a Microsoft Defender for Cloud Apps session policy
AnswerA

Microsoft Sentinel automated response playbooks, built on Azure Logic Apps, are specifically designed for Security Orchestration, Automation, and Response (SOAR). They can be triggered by Sentinel incidents or alerts to execute predefined workflows, such as calling the Microsoft Graph API to disable a user account in Microsoft Entra ID and initiate a password reset. This provides an immediate, automated, and scalable response to detected threats, directly addressing the requirement for revoking user access and resetting passwords without human intervention.

Why this answer

Microsoft Sentinel's automated response playbooks, built on Azure Logic Apps, can trigger an incident-based workflow that disables the user in Microsoft Entra ID and resets their password via the Microsoft Graph API. This provides the necessary cross-cloud automation to remediate a compromised account across all SaaS apps without manual intervention.

Exam trap

The trap here is that candidates confuse the reactive, automated remediation capability of Sentinel playbooks with the proactive, policy-based controls of Defender for Cloud Apps or the device-focused actions of Intune, leading them to choose an option that addresses only a subset of the required actions.

How to eliminate wrong answers

Option B is wrong because remote wiping a user's device only removes corporate data from that specific endpoint and does not disable the user's account or reset their password across cloud apps. Option C is wrong because manual disabling and password reset in Microsoft Entra ID is a valid action but does not meet the requirement for automatic response triggered by a Sentinel alert. Option D is wrong because a Microsoft Defender for Cloud Apps session policy controls real-time access and data exfiltration prevention via reverse proxy, but it cannot directly disable a user account or reset a password.

849
MCQhard

A company deploys a custom web application on Azure App Service (PaaS). The application stores data in Azure SQL Database. The security team needs to identify which security responsibilities fall under the customer according to the Microsoft shared responsibility model. Which of the following is primarily the customer's responsibility for this PaaS deployment?

A.Physical security of the datacenter hosting the App Service
B.Patching the operating system of the App Service host machines
C.Managing user identities and access to the application
D.Network security for the Azure backbone connecting datacenters
AnswerC

While Azure App Service provides the platform, the customer retains full responsibility for managing user identities and controlling access to their custom web application. This includes implementing authentication mechanisms (e.g., integrating with Azure AD, OAuth, or custom identity providers), defining authorization policies, and assigning appropriate roles to users. Microsoft provides the tools and services, but the customer configures and enforces who can access their specific application, which is a key aspect of 'security in the cloud'.

Why this answer

In a PaaS deployment like Azure App Service with Azure SQL Database, the customer is responsible for managing user identities and access to the application, including authentication, authorization, and role-based access control (RBAC). Microsoft manages the underlying infrastructure, including the host OS, physical datacenter security, and network backbone, but the customer must secure application-level access and data plane operations.

Exam trap

The trap here is that candidates often assume PaaS means Microsoft handles all security, but the customer still owns identity and access management for the application and data, which is a frequent exam distraction.

How to eliminate wrong answers

Option A is wrong because physical security of the datacenter is always Microsoft's responsibility under the shared responsibility model, regardless of service model. Option B is wrong because patching the operating system of the App Service host machines is managed by Microsoft as part of the PaaS abstraction; the customer only patches the application code and configuration. Option D is wrong because network security for the Azure backbone connecting datacenters is Microsoft's responsibility, as it is part of the core network infrastructure that the customer cannot control or configure.

850
MCQeasy

A company is migrating its on-premises applications to Azure. The CIO states that the company is fully responsible for managing the security of its own applications and data, while Microsoft is responsible for the security of the underlying physical infrastructure, such as hardware and data centers. This division of security responsibilities is an example of which concept?

A.Defense in depth
B.Shared responsibility model
C.Zero Trust
D.Least privilege
AnswerB

The shared responsibility model clearly delineates security responsibilities between the cloud provider (Microsoft) and the customer. In IaaS, the customer manages more (applications, data) while the provider secures the physical layer; in PaaS/SaaS, the provider takes on more responsibility.

Why this answer

The scenario directly describes the shared responsibility model, which delineates security obligations between the cloud provider and the customer. Microsoft secures the physical infrastructure (hardware, data centers, networking), while the customer is responsible for securing their own applications, data, and identity management. This division is a foundational concept in cloud computing, explicitly defined in Microsoft's documentation for Azure.

Exam trap

The trap here is that candidates confuse the shared responsibility model with defense in depth, because both involve multiple security layers, but the question specifically asks about the division of responsibilities between provider and customer, not the layering of controls.

Why the other options are wrong

A

The question describes a division of security responsibilities between the customer and Microsoft, which is the definition of the shared responsibility model, not defense in depth. Defense in depth is a layered security approach, not a division of responsibilities.

C

Zero Trust is a security model based on the principle of 'never trust, always verify,' not a division of responsibilities between a cloud provider and a customer. The question specifically describes a shared responsibility for security, which is the shared responsibility model.

D

The question describes a division of security responsibilities between the customer and Microsoft, which is the definition of the shared responsibility model. Least privilege is a principle of granting only necessary access, not a model for dividing security responsibilities.

When would these options actually be correct?

A

Defense in depth would be correct if the question asked about a security strategy that uses multiple layers of controls (e.g., network, endpoint, application) to protect resources, such as 'An organization implements firewalls, antivirus, and encryption to protect data. This is an example of which concept?'

C

A question asking: 'A company implements a security strategy that requires authentication and authorization for every access request, regardless of the network location. This approach is an example of which concept?' would make Zero Trust the correct answer.

D

Least privilege would be correct in a question about access control, such as: 'A company wants to ensure that employees only have the minimum permissions needed to perform their job functions. Which security concept does this describe?'

Why candidates pick the wrong answer

A

Candidates may confuse defense in depth with shared responsibility because both involve multiple security layers, but defense in depth focuses on layered controls within a single entity's environment, not on dividing responsibilities between parties.

C

Candidates may confuse Zero Trust with the shared responsibility model because both involve security concepts in cloud environments, but Zero Trust focuses on access control rather than responsibility allocation.

D

Candidates may confuse least privilege with the shared responsibility model because both involve distributing security tasks, but least privilege focuses on user permissions, not provider-customer responsibility division.

851
MCQeasy

An organization wants to allow users to classify documents as 'Public', 'Internal', 'Confidential', or 'Highly Confidential' with different levels of protection. Which Microsoft Purview solution should they use?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Communication compliance
D.Retention policies
AnswerA

Sensitivity labels allow organizations to classify and protect data at the document or email level directly by users. When applied, these labels enforce predefined protection actions such as encryption, visual markings (headers, footers, watermarks), and access restrictions, ensuring that sensitive information is handled appropriately throughout its lifecycle, even when shared externally.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection allow organizations to classify and protect documents and emails by applying labels such as 'Public', 'Internal', 'Confidential', or 'Highly Confidential'. These labels can enforce encryption, visual markings (headers/footers/watermarks), and access restrictions based on the classification level, directly meeting the requirement for different levels of protection.

Exam trap

The trap here is confusing Data Loss Prevention (DLP) with classification labels, as DLP also protects data but does not provide the granular, user-selectable classification levels described in the question.

How to eliminate wrong answers

Option B (Data Loss Prevention) is wrong because DLP policies detect and prevent accidental sharing of sensitive information (e.g., credit card numbers) but do not classify documents with custom labels like 'Public' or 'Highly Confidential'. Option C (Communication compliance) is wrong because it focuses on monitoring communications (email, Teams) for policy violations like harassment or insider trading, not on document classification. Option D (Retention policies) is wrong because retention policies manage how long content is kept or deleted, not its classification or protection level.

852
MCQmedium

A company stores critical financial reports in a SharePoint Online library. To ensure that the reports have not been tampered with, the security team compares a calculated hash of each file against a stored baseline. This verification process primarily protects which security goal?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerB

Integrity ensures that data is authentic, accurate, and has not been modified or tampered with since it was last verified. Hashing generates a unique, fixed-size digital fingerprint of the financial reports. If even a single bit of the report is altered, the recomputed hash will be drastically different, immediately signaling unauthorized modification or corruption. Comparing the stored hash with a newly generated hash directly verifies that the file content remains unchanged and authentic.

Why this answer

The verification process uses hash comparison to detect unauthorized changes to files, which directly protects data integrity. Integrity ensures that data has not been altered or tampered with during storage or transit. In SharePoint Online, hashing (e.g., SHA-256) creates a unique fingerprint; if the calculated hash matches the stored baseline, the file is unchanged.

Exam trap

The trap here is confusing integrity with non-repudiation, as both involve cryptographic verification, but non-repudiation requires a digital signature (private key) to prove origin, whereas hash comparison alone only detects changes without identifying who made them.

How to eliminate wrong answers

Option A is wrong because confidentiality is about preventing unauthorized access (e.g., encryption), not detecting tampering. Option C is wrong because availability ensures data is accessible when needed (e.g., uptime, redundancy), not verifying file integrity. Option D is wrong because non-repudiation provides proof of origin or action (e.g., digital signatures, audit logs), not detection of unauthorized modification.

853
MCQmedium

A company uses Microsoft Entra ID. They want to enforce a policy that requires members of the 'Finance' group to use multi-factor authentication and sign in from a compliant device when accessing the financial reporting application. However, they want to exclude members of the 'Finance Admins' group from these requirements. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Conditional Access
C.Privileged Identity Management (PIM)
D.Entitlement Management
AnswerB

Conditional Access policies in Microsoft Entra ID are the primary mechanism for enforcing granular access controls based on specific conditions. These policies evaluate various signals, such as user or group membership, application being accessed, device state (e.g., compliant or hybrid joined), and location, to determine whether to grant access, block access, or require additional authentication like multi-factor authentication (MFA) or a compliant device. This directly addresses the need to enforce a policy based on group membership and device compliance for application access.

Why this answer

Conditional Access is the correct feature because it allows administrators to define policies that enforce specific access requirements, such as multi-factor authentication and compliant device usage, based on conditions like group membership. In this scenario, the policy targets the 'Finance' group while excluding the 'Finance Admins' group, which is a core capability of Conditional Access policies in Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Conditional Access, thinking PIM can enforce MFA or device compliance, when in fact PIM only manages role activation and does not control sign-in conditions for specific applications.

Why the other options are wrong

A

Identity Protection is used to detect and respond to identity-based risks, such as compromised credentials or unusual sign-in behavior, but it does not enforce access policies like requiring MFA or compliant devices for specific groups or applications.

C

Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not device compliance or MFA enforcement for specific groups. The question requires a policy that applies to a group with exclusions, which is a Conditional Access scenario.

D

Entitlement Management is used for managing access packages and identity governance, not for enforcing sign-in conditions like MFA or device compliance. The scenario requires a policy that applies conditions based on group membership and application, which is the domain of Conditional Access.

When would these options actually be correct?

A

A company wants to automatically block sign-ins from anonymous IP addresses or require MFA when a sign-in risk is detected as high. In that scenario, Identity Protection would be the correct feature to configure risk-based policies.

C

A company wants to require approval for activating the 'Global Administrator' role and limit its activation to 4 hours. PIM would be the correct feature to configure for time-bound, approved role activation.

D

Entitlement Management would be correct if the question asked about automating access requests and approvals for the financial reporting application, such as creating an access package that requires manager approval and periodic access reviews for the Finance group.

Why candidates pick the wrong answer

A

Candidates may confuse Identity Protection with Conditional Access because both involve MFA and security policies, but Identity Protection focuses on risk detection rather than granular access control based on group membership and device compliance.

C

Candidates may confuse PIM with Conditional Access because both involve access control and security policies, but PIM focuses on privileged roles rather than user/device conditions.

D

Candidates may confuse Entitlement Management with Conditional Access because both involve controlling access to resources, but Entitlement Management focuses on governance and lifecycle, not real-time sign-in enforcement.

854
MCQhard

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to receive alerts when a user attempts to share a file containing personally identifiable information (PII) via email. Which DLP rule component is used to define the notification action?

A.Actions
B.Conditions
C.Location
D.Exceptions
AnswerA

Actions are the core component of a Microsoft Purview DLP policy that dictates the response when content matches the defined conditions. These actions can include blocking access to the content, notifying users or administrators, encrypting the data, or applying retention labels. For instance, a DLP policy might be configured to block sharing of documents containing sensitive data externally and simultaneously send an alert to the security team. This directly addresses what happens when a DLP match occurs.

Why this answer

In Microsoft Purview DLP, the 'Actions' component defines what happens when a DLP rule is triggered, including sending notifications or alerts to administrators. For the scenario of receiving alerts when a user attempts to share PII via email, the notification action is configured within the rule's Actions section. Conditions define what data to match, Locations specify where to monitor, and Exceptions refine rule scope, but only Actions contain the notification settings.

Exam trap

The trap here is that candidates often confuse 'Conditions' with 'Actions', mistakenly thinking that defining what data to detect (Conditions) inherently includes the notification response, but in DLP rules, Conditions only specify the match criteria, while Actions separately define the enforcement and alerting behavior.

How to eliminate wrong answers

Option B is wrong because Conditions define the criteria for detecting sensitive data (e.g., PII content or context), not the response actions like notifications. Option C is wrong because Location specifies where the DLP policy is applied (e.g., Exchange Online, SharePoint), not the action taken when a match occurs. Option D is wrong because Exceptions allow you to exclude certain activities or users from triggering the rule, but they do not define notification actions.

855
MCQhard

An organization uses Microsoft Entra ID Protection. A user's sign-in is flagged with a risk level of 'High' because of an anonymous IP address. The administrator wants to automatically block the sign-in while allowing the user to self-remediate. Which should be configured?

A.A Conditional Access policy requiring MFA for high-risk sign-ins
B.A user risk policy configured to require a password change
C.A sign-in risk policy configured to block access
D.An MFA registration policy for all users
AnswerC

Microsoft Entra ID Protection's sign-in risk policy directly evaluates the risk associated with a specific sign-in attempt in real-time. When configured to block access for a detected risk level, such as 'High,' it prevents the user from completing the sign-in immediately. This directly addresses the requirement to automatically block a high-risk sign-in, ensuring immediate protection against potentially compromised credentials and unauthorized access.

Why this answer

A sign-in risk policy in Microsoft Entra ID Protection can be configured to automatically block access when a sign-in is detected as high risk (e.g., from an anonymous IP address). This policy operates at the sign-in level, allowing the administrator to block the sign-in while still enabling the user to self-remediate (e.g., by signing in again after the risk is mitigated). Option C directly matches this requirement.

Exam trap

The trap here is confusing sign-in risk policies (which block or challenge at the sign-in event) with user risk policies (which require password changes after a compromise), leading candidates to choose a user risk policy when the scenario explicitly describes a sign-in-level risk from an anonymous IP.

Why the other options are wrong

A

This option requires MFA for high-risk sign-ins but does not block access, which contradicts the administrator's goal to automatically block the sign-in while allowing self-remediation.

B

The question specifies a sign-in risk (anonymous IP address), not user risk. A user risk policy targets user account compromise, not sign-in events, and would not block the sign-in based on sign-in risk.

D

An MFA registration policy requires users to register for MFA but does not block sign-ins or allow self-remediation for high-risk sign-ins. The question specifically asks to block access and allow self-remediation, which is achieved by a sign-in risk policy configured to block access.

When would these options actually be correct?

A

This would be correct if the question asked for a policy that requires additional verification (MFA) for high-risk sign-ins, without blocking access, and the user can self-remediate by completing MFA.

B

A user risk policy requiring a password change would be correct if the question described a user risk (e.g., leaked credentials) and the goal was to force the user to self-remediate by changing their password after the risk is detected.

D

This option would be correct if the question asked: 'An organization wants to ensure all users are registered for MFA before accessing cloud apps. Which policy should be configured?' In that case, an MFA registration policy would enforce registration.

Why candidates pick the wrong answer

A

Candidates may think requiring MFA is sufficient to mitigate risk, but they overlook the explicit requirement to block the sign-in, not just challenge it.

B

Candidates may confuse user risk with sign-in risk, or think that requiring a password change is a common remediation for high-risk events, not realizing that sign-in risk policies handle sign-in blocking directly.

D

Candidates may confuse MFA registration with risk-based policies, thinking that requiring MFA for all users addresses high-risk sign-ins, but it does not block access or provide self-remediation for specific risk events.

856
MCQhard

You are reviewing a Conditional Access policy configuration in Microsoft Entra ID. Based on the exhibit, what is the effect of this policy?

A.Blocks sign-ins for users with high user risk
B.Blocks sign-ins that have a high sign-in risk level
C.Blocks all sign-ins for the assigned users
D.Requires multi-factor authentication for high-risk sign-ins
AnswerB

This statement accurately describes the policy's intended behavior. The conditional access policy is configured to evaluate the "sign-in risk level" condition, specifically targeting "High" risk as detected by Azure AD Identity Protection. When a sign-in attempt is classified as having a high sign-in risk, the policy's grant control, which is set to "Block access," will prevent the user from completing the authentication process.

Why this answer

The policy is configured to target 'All users' and 'All cloud apps' with a condition of 'Sign-in risk level: High' and an access control of 'Block access'. This means any sign-in attempt that Microsoft Entra ID detects as having a high sign-in risk (e.g., from a compromised token or anonymous IP) will be blocked. Option B correctly identifies this effect.

Exam trap

The trap here is confusing 'sign-in risk' with 'user risk'—candidates often pick Option A because they misread the condition, but the exhibit explicitly shows 'Sign-in risk' as the condition, not 'User risk'.

How to eliminate wrong answers

Option A is wrong because the policy targets 'Sign-in risk', not 'User risk'; user risk refers to the likelihood that a user's identity is compromised, which is a separate condition in Conditional Access. Option C is wrong because the policy does not block all sign-ins; it only blocks sign-ins that meet the specific condition of 'High' sign-in risk level, so normal sign-ins are unaffected. Option D is wrong because the access control is set to 'Block access', not 'Require multi-factor authentication'; requiring MFA would grant access after additional verification, not block it.

857
MCQhard

You are deploying Microsoft Entra Verified ID to issue verifiable credentials for employee onboarding. Which component is required to issue credentials?

A.A public key infrastructure (PKI) certificate
B.A custom application registered in Microsoft Entra ID
C.A decentralized identifier (DID) for your organization
D.A blockchain node for the decentralized ledger
AnswerC

A Decentralized Identifier (DID) is the foundational element for an organization to act as an issuer in Microsoft Entra Verified ID. This globally unique, self-owned identifier is published to a decentralized ledger (e.g., ION) and contains the public keys and service endpoints necessary for cryptographic operations, such as signing verifiable credentials. The DID cryptographically anchors the organization's verifiable identity, enabling holders and verifiers to trust the authenticity and integrity of the credentials issued.

Why this answer

Microsoft Entra Verified ID requires a decentralized identifier (DID) for your organization to issue verifiable credentials. The DID serves as the cryptographic anchor that proves your organization's authority to issue credentials, as it is registered on a decentralized ledger (ION) and linked to your public keys. Without a DID, the verifiable credentials cannot be cryptographically signed and verified by relying parties.

Exam trap

The trap here is that candidates often confuse the need for a custom app registration (Option B) as the core requirement, but the DID is the mandatory cryptographic identity anchor without which no credentials can be issued.

How to eliminate wrong answers

Option A is wrong because a public key infrastructure (PKI) certificate is not required; Entra Verified ID uses decentralized public key infrastructure (DPKI) based on DIDs and Verifiable Credentials (VCs), not traditional X.509 PKI certificates. Option B is wrong because while a custom application registered in Microsoft Entra ID is used to interact with the Verified ID API, it is not the component required to issue credentials—the DID is the foundational identity anchor. Option D is wrong because a blockchain node is not required; Microsoft uses the ION (Identity Overlay Network) as a Sidetree-based decentralized ledger, but the organization does not need to run a node—the DID is resolved via the ION network without direct node management.

858
MCQmedium

Your organization uses Microsoft Sentinel as a SIEM. You need to collect security events from on-premises servers. Which connector should you use?

A.Azure Monitor Agent (AMA)
B.Azure Security Center connector
C.Microsoft 365 Defender connector
D.Log Analytics workspace
AnswerA

The Azure Monitor Agent (AMA) is the primary agent for collecting logs and performance data from virtual machines and physical servers, including those located on-premises. It replaces the legacy Log Analytics agent (MMA) and offers enhanced security, cost management, and multi-homing capabilities. AMA sends this collected data directly to a Log Analytics workspace, which serves as Sentinel's data repository for analysis and threat detection.

Why this answer

The Azure Monitor Agent (AMA) is the correct connector because it is the primary agent for collecting security events from on-premises Windows and Linux servers into a Log Analytics workspace, which Microsoft Sentinel uses as its data source. AMA supports data collection rules (DCRs) to filter and route specific security event IDs, replacing the legacy Log Analytics agent. This enables Sentinel to ingest Windows Security Events (e.g., Event ID 4625 for failed logons) for threat detection and incident creation.

Exam trap

The trap here is that candidates confuse the Log Analytics workspace (a storage container) with a data connector, or assume the Azure Security Center connector can collect raw event logs, when in fact only the Azure Monitor Agent (AMA) provides the direct, agent-based collection of security events from on-premises servers.

How to eliminate wrong answers

Option B is wrong because the Azure Security Center connector is used to ingest security alerts and recommendations from Microsoft Defender for Cloud, not raw security events from on-premises servers. Option C is wrong because the Microsoft 365 Defender connector ingests alerts and incidents from Microsoft 365 Defender (e.g., Defender for Endpoint, Defender for Office 365), not from on-premises server event logs. Option D is wrong because a Log Analytics workspace is the destination storage and query environment, not a connector; it cannot collect data directly from servers without an agent like AMA.

859
MCQmedium

A company runs critical applications on Azure virtual machines and on-premises SQL servers. The security team wants to reduce VM attack surface by allowing just-in-time (JIT) access to RDP and SSH ports only when needed. Additionally, they need to monitor changes to important registry keys and system files on the SQL servers. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Cloud provides comprehensive security posture management and threat protection for Azure resources, including virtual machines. It offers Just-in-Time (JIT) VM access, which significantly reduces the attack surface by locking down inbound traffic to VMs and only opening necessary ports for a limited, controlled period. Furthermore, its File Integrity Monitoring (FIM) capability continuously monitors operating system files, application files, and registry keys for suspicious modifications, alerting administrators to unauthorized changes that could indicate a compromise or misconfiguration.

Why this answer

Microsoft Defender for Cloud provides just-in-time (JIT) VM access to reduce the attack surface by locking down inbound traffic to RDP (port 3389) and SSH (port 22) until a user requests access. It also includes adaptive application controls and file integrity monitoring (FIM) to track changes to registry keys and system files on both Azure VMs and on-premises SQL servers. This makes it the single solution that addresses both requirements.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Endpoint's broader device protection capabilities with the specific JIT and FIM features that are exclusive to Microsoft Defender for Cloud.

How to eliminate wrong answers

Option B (Microsoft Defender for Endpoint) is wrong because it focuses on endpoint detection and response (EDR) for devices, including antivirus and behavioral analysis, but does not natively provide JIT VM access or file integrity monitoring for registry keys and system files. Option C (Microsoft Defender for Identity) is wrong because it is designed to detect identity-based threats using on-premises Active Directory signals, not to manage VM network access or monitor file/registry changes. Option D (Microsoft Defender for Cloud Apps) is wrong because it is a cloud access security broker (CASB) that controls and monitors cloud app usage, not VM access or on-premises SQL server file integrity.

860
MCQeasy

A company uses Microsoft Purview Information Protection to classify and label sensitive documents. The compliance team wants to automatically apply a 'Confidential' label to documents containing an employee's passport number. Which method should they use?

A.Manual labeling by users
B.Trainable classifiers
C.Auto-labeling policy
D.DLP policy
AnswerC

An auto-labeling policy in Microsoft Purview Information Protection is specifically designed to automatically detect sensitive information types, such as passport numbers, within content stored in SharePoint, OneDrive, or Exchange. Upon detection, the policy can then apply a pre-configured sensitivity label to the document or email, ensuring consistent classification and protection without requiring any user intervention. This capability directly addresses the need for automatic application of labels based on specific data patterns.

Why this answer

An auto-labeling policy in Microsoft Purview Information Protection automatically applies sensitivity labels to documents and emails based on sensitive information types (e.g., passport numbers) without user intervention. This method uses content scanning to detect patterns and enforce labeling rules, making it the correct choice for the compliance team's requirement.

Exam trap

The trap here is that candidates confuse DLP policies with auto-labeling, but DLP focuses on preventing data loss through actions like blocking or encryption, not on automatically applying sensitivity labels to content.

How to eliminate wrong answers

Option A is wrong because manual labeling relies on users to apply labels themselves, which is inconsistent and does not meet the requirement for automatic application. Option B is wrong because trainable classifiers use machine learning to identify content based on patterns or context, not specific sensitive information types like passport numbers; they are designed for more complex or ambiguous content. Option D is wrong because a DLP policy detects and prevents unauthorized sharing of sensitive data but does not apply sensitivity labels; it enforces actions like blocking or alerting, not labeling.

861
MCQmedium

An organization wants to detect and respond to threats across their cloud infrastructure, including Azure, AWS, and GCP. Which Microsoft security solution should they centralize their security monitoring in?

A.Microsoft Purview
B.Microsoft Sentinel
C.Microsoft Defender for Cloud
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It ingests security data from virtually any source, including users, devices, applications, and infrastructure, across multi-cloud and on-premises environments. Sentinel then uses AI and machine learning to detect advanced threats, investigate incidents, and automate responses, providing comprehensive threat detection and response capabilities.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution designed to ingest logs and alerts from multiple cloud providers, including Azure, AWS, and GCP, via native connectors and industry-standard protocols like Syslog and CEF. It centralizes threat detection and response across heterogeneous cloud environments, whereas the other options focus on specific security domains or single-cloud protection.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) with a SIEM, but Defender for Cloud does not provide the centralized log ingestion, correlation, and incident response across multiple cloud providers that Sentinel offers.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance and compliance solution focused on data classification, labeling, and risk management, not on detecting and responding to threats across cloud infrastructure. Option C is wrong because Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) that primarily secures Azure resources and can extend to AWS and GCP via connectors, but it lacks the centralized SIEM/SOAR capabilities for multi-cloud threat detection and response that Sentinel provides. Option D is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that focuses on shadow IT discovery and SaaS application security, not on ingesting and correlating security logs from IaaS and PaaS workloads across Azure, AWS, and GCP.

862
Multi-Selecthard

Which THREE of the following are capabilities of Microsoft Purview Information Protection? (Select three.)

Select 3 answers
A.Rights management
B.eDiscovery
C.Data classification
D.Sensitivity labels
E.Data loss prevention policies
AnswersA, C, D

Rights management in Microsoft Purview Information Protection applies encryption and usage restrictions that travel with the content, enforcing access even after files leave the tenant. This satisfies the stem by naming a core capability that protects data wherever it resides.

Why this answer

Microsoft Purview Information Protection provides rights management (A), which uses Azure Rights Management encryption to protect content both inside and outside the organization, so it is correct. It also delivers data classification (C), automatically identifying and categorizing sensitive content through trainable classifiers and sensitive information types, making it correct. Sensitivity labels (D) are the core capability of Information Protection, allowing users and admins to apply protection settings like encryption and content marking to files and emails, so it is correct. eDiscovery (B) belongs to the Microsoft Purview eDiscovery solution rather than Information Protection, and data loss prevention policies (E) are part of the separate Microsoft Purview Data Loss Prevention workload, so neither belongs to Information Protection's capabilities.

Exam trap

SC-900 often tests the boundary between Information Protection (classification, labels, rights management) and other Purview solutions like DLP and eDiscovery, tricking candidates who conflate all Purview capabilities.

863
MCQmedium

A user reports that they are repeatedly prompted for multifactor authentication when accessing Microsoft 365 apps from the same trusted device. What should you do to reduce the number of prompts?

A.Disable MFA for the user
B.Change the user's MFA method to text message
C.Configure 'Remember MFA' settings in Conditional Access
D.Reset the user's MFA registration
AnswerC

Configuring 'Remember MFA' settings, typically through the 'Sign-in frequency' control within a Conditional Access policy, allows administrators to specify how often users are prompted for MFA. By setting a longer duration, such as 90 days, users on trusted devices can remain authenticated without repeated MFA challenges for that period. This balances security with user experience by reducing prompt fatigue while maintaining strong authentication.

Why this answer

The 'Remember MFA' setting in Conditional Access allows administrators to configure the session lifetime for MFA prompts on trusted devices. By extending the 'MFA reauthentication frequency' or enabling 'Remember Multifactor Authentication' for a longer period (e.g., 30 days), users will not be repeatedly challenged on the same device, reducing friction while maintaining security.

Exam trap

The trap here is that candidates often confuse 'changing the MFA method' (Option B) with reducing prompt frequency, not realizing that the method type has no impact on how often the prompt appears—only the session persistence settings control that.

How to eliminate wrong answers

Option A is wrong because disabling MFA entirely removes the security control, which violates the principle of least privilege and exposes the account to credential theft. Option B is wrong because changing the MFA method to text message does not affect the frequency of prompts; it only changes the delivery mechanism, and the user would still be prompted repeatedly on the same device. Option D is wrong because resetting the user's MFA registration would force them to re-register all authentication methods, which does not address the prompt frequency issue and could actually increase prompts until the new methods are verified.

864
MCQeasy

A financial institution uses digital signatures to sign all transaction records. This ensures that the records have not been altered after signing. Which security goal does this primarily protect?

A.Confidentiality
B.Non-repudiation
C.Integrity
D.Availability
AnswerC

Integrity ensures that data remains accurate, complete, and has not been modified or tampered with by unauthorized parties. Digital signatures achieve this by generating a unique cryptographic hash of the document's content, which is then encrypted with the signer's private key. Any subsequent alteration to the document, even a single character, will cause a mismatch between the recomputed hash and the decrypted hash from the signature, thereby immediately indicating that the record's integrity has been compromised.

Why this answer

Digital signatures use asymmetric cryptography (e.g., RSA or ECDSA) to create a hash of the transaction record, which is then encrypted with the signer's private key. Any alteration to the record after signing would cause the hash verification to fail, directly protecting the integrity of the data. While digital signatures also support non-repudiation, the question specifically asks which goal is primarily protected by ensuring records have not been altered, which is integrity.

Exam trap

The trap here is that candidates confuse the secondary property of non-repudiation with the primary property of integrity, because digital signatures provide both, but the question's wording 'have not been altered after signing' directly points to integrity, not the ability to prove the signer's identity.

How to eliminate wrong answers

Option A is wrong because confidentiality is about preventing unauthorized access to data, typically achieved through encryption (e.g., AES), not through digital signatures which do not hide the content. Option B is wrong because non-repudiation ensures the signer cannot deny having signed the document, which is a secondary benefit of digital signatures, but the question explicitly focuses on preventing alteration after signing, which is integrity. Option D is wrong because availability ensures systems and data are accessible when needed, often via redundancy or disaster recovery, and digital signatures do not address uptime or access.

865
MCQmedium

A company is involved in litigation and needs to preserve all Exchange Online mailboxes and SharePoint sites related to the case. The legal team also requires the ability to search, review, and export relevant content. Which Microsoft Purview solution should they use?

A.Microsoft Purview eDiscovery (Premium)
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Audit (Premium)
AnswerA

Microsoft Purview eDiscovery (Premium) is the comprehensive solution designed for managing legal, regulatory, and internal investigations. It provides an end-to-end workflow that includes placing legal holds on content, such as all Exchange Online mailboxes, to prevent alteration or deletion. This capability ensures that all relevant data is preserved, collected, reviewed, and exported in a defensible manner for litigation purposes, directly addressing the need to preserve content.

Why this answer

Microsoft Purview eDiscovery (Premium) is the correct solution because it provides end-to-end workflow for preserving, searching, reviewing, and exporting content from Exchange Online mailboxes and SharePoint sites. It supports legal hold placement on custodians and data sources, advanced search with keyword and proximity queries, review sets with analytics, and export in a format suitable for litigation. This directly matches the requirement to preserve all relevant mailboxes and sites while enabling the legal team to search, review, and export content.

Exam trap

The trap here is that candidates confuse eDiscovery (Premium) with Audit (Premium) because both involve searching, but Audit only searches activity logs, not the actual content of mailboxes and sites, and cannot place legal hold or export content.

How to eliminate wrong answers

Option B (Microsoft Purview Communication Compliance) is wrong because it is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) by analyzing messages and patterns, not for preserving and exporting content for litigation. Option C (Microsoft Purview Data Lifecycle Management) is wrong because it focuses on retention and deletion policies based on data lifecycle, not on preserving content for legal hold or providing search/review/export capabilities. Option D (Microsoft Purview Audit (Premium)) is wrong because it provides detailed audit log search and investigation of user and admin activities, but does not offer legal hold, content preservation, or export of mailbox and site content.

866
MCQmedium

A company must retain all HR documents stored in SharePoint Online for exactly 7 years. After 7 years, the documents must be automatically deleted. Additionally, employees must not be able to permanently delete these documents before the retention period ends. Which Microsoft Purview solution should they configure?

A.Data Lifecycle Management
B.Records Management
C.Data Loss Prevention
D.Audit
AnswerA

Data Lifecycle Management (DLM) in Microsoft Purview is the correct solution for managing HR documents. It allows the creation of retention labels and policies that automatically retain content for a specified period, preventing premature deletion or modification by users. Once the retention period expires, these policies can then automatically initiate the deletion of the content, ensuring compliance with data retention schedules and organizational policies.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview is designed to retain content for a specified period and then automatically delete it. By applying a retention policy with a 7-year retention period and a deletion action at the end, DLM ensures HR documents are kept exactly as required. Additionally, DLM prevents users from permanently deleting documents during the retention period by locking the retention settings, which overrides user delete permissions.

Exam trap

The trap here is that candidates often confuse Records Management with Data Lifecycle Management, assuming that 'records' automatically implies retention and deletion, but Records Management focuses on declaring records and managing disposition reviews, not automatic time-based deletion without user intervention.

How to eliminate wrong answers

Option B (Records Management) is wrong because Records Management is focused on declaring content as records for legal or regulatory compliance, often with immutability and disposition reviews, but it does not inherently enforce automatic deletion after a fixed period without additional configuration; it is more about managing records throughout their lifecycle with manual or review-based disposition. Option C (Data Loss Prevention) is wrong because DLP is designed to prevent sensitive information from being shared or leaked, not to manage retention or deletion schedules. Option D (Audit) is wrong because Audit provides logging and monitoring of user activities, but it does not enforce retention or deletion policies.

867
MCQmedium

A security operations team is using Microsoft Sentinel and needs to automate responses to incidents, such as blocking an IP address when a specific alert is triggered. They want to create a playbook that runs automatically. Which component should they use to build the playbook?

A.Azure Functions
B.Azure Automation runbooks
C.Microsoft Power Automate
D.Azure Logic Apps
AnswerD

Microsoft Sentinel playbooks are built on Azure Logic Apps. Logic Apps provide a visual designer and connectors to hundreds of services, enabling automated workflows. To automate incident response, you create a Logic App and then associate it with an analytics rule in Sentinel. This is the correct component for building playbooks.

Why this answer

Microsoft Sentinel playbooks are automated workflows built on Azure Logic Apps. They allow you to orchestrate responses to incidents using a visual designer and connectors to various services. While other automation tools exist, Logic Apps is the designated platform for Sentinel playbooks, making it the correct choice for this scenario.

Exam trap

The trap here is confusing Azure Logic Apps with other automation services like Power Automate or Azure Functions, which are not used for Sentinel playbooks.

868
MCQhard

A security analyst is using Microsoft 365 Defender to investigate a sophisticated multi-stage attack. The analyst needs to query data across endpoints, email, and identity logs to identify the attacker's behavior patterns and correlate events. Which Microsoft 365 Defender capability should the analyst use?

A.Automated investigation and response
B.Threat analytics
C.Advanced hunting
D.Action center
AnswerC

Advanced hunting is a powerful, proactive threat hunting tool within Microsoft 365 Defender that allows security analysts to explore raw organizational data using Kusto Query Language (KQL). It aggregates data from endpoints, email, identity, and cloud apps, enabling custom queries to uncover sophisticated threats, identify anomalous behaviors, and correlate events across diverse security domains that automated systems might miss. This capability is crucial for deep investigations and creating custom detection rules.

Why this answer

Advanced hunting is the correct capability because it provides a Kusto Query Language (KQL)-based query interface that allows the security analyst to perform custom, cross-domain searches across data from endpoints (Microsoft Defender for Endpoint), email (Microsoft Defender for Office 365), and identity logs (Microsoft Defender for Identity). This enables the correlation of events and identification of attacker behavior patterns across a multi-stage attack, which is not possible with the other options.

Exam trap

The trap here is that candidates often confuse 'Advanced hunting' with 'Threat analytics' because both involve investigating threats, but Threat analytics is a passive reading tool for pre-built reports, while Advanced hunting is an active, custom query engine for raw data correlation.

Why the other options are wrong

A

Automated investigation and response (AIR) automates incident response actions, but the question requires querying and correlating data across endpoints, email, and identity logs, which is the purpose of Advanced hunting, not AIR.

B

Threat analytics provides threat intelligence reports and insights about known threats, but it does not allow the analyst to query raw data across endpoints, email, and identity logs for custom correlation and pattern identification.

D

The Action center is used to view and manage remediation actions taken by automated investigations, not for querying raw data across endpoints, email, and identity logs to correlate events.

When would these options actually be correct?

A

A security analyst needs to automatically contain a confirmed malware outbreak across multiple endpoints. In that scenario, Automated investigation and response would be the correct answer because it triggers automated remediation actions based on alerts.

B

A security analyst wants to understand the latest threat landscape and review detailed reports on active threat actors, including their techniques and recommended mitigations. Threat analytics would be the correct capability to use.

D

An exam question asks: 'After an automated investigation in Microsoft 365 Defender has completed, where should an analyst go to review and approve pending remediation actions such as deleting malicious files or blocking IP addresses?'

Why candidates pick the wrong answer

A

Candidates may confuse automated investigation with manual hunting, thinking that 'investigation' includes querying logs, but AIR is about automated response, not ad-hoc data exploration.

B

Candidates may confuse threat analytics with advanced hunting because both involve investigating threats, but threat analytics focuses on pre-built intelligence rather than custom queries.

D

Candidates may confuse the Action center with a central place for all security operations, including data querying, because it aggregates actions from multiple Microsoft 365 Defender components.

869
MCQmedium

A company uses Microsoft 365. The security team wants to protect users from clicking malicious URLs in email messages. The solution should rewrite all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites. Which Microsoft Defender for Office 365 feature should they enable?

A.Anti-phishing policies
B.Safe Attachments
C.Safe Links
D.Anti-spam policies
AnswerC

Safe Links is a critical component of Microsoft Defender for Office 365 that provides time-of-click protection against malicious URLs. It dynamically rewrites URLs in emails and Office documents, then scans them in real-time when a user clicks, blocking access to known malicious sites or warning the user if the link's destination has changed to become malicious since initial delivery. This proactive scanning helps prevent users from accessing compromised websites, even if the link was initially benign.

Why this answer

Safe Links is the correct feature because it is specifically designed to protect users from malicious URLs in email messages and Office documents. It rewrites all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites, providing time-of-click protection.

Exam trap

The trap here is that candidates often confuse Safe Links with Anti-phishing policies, but Anti-phishing policies handle impersonation and spoofing detection, not URL rewriting and real-time click verification.

Why the other options are wrong

A

Anti-phishing policies protect against phishing attempts by analyzing email content and sender reputation, but they do not rewrite URLs or perform real-time link checking against a dynamic list of malicious sites.

B

Safe Attachments protects against malicious attachments by detonating them in a sandbox, not by rewriting and checking URLs in real time. The question specifically requires URL rewriting and real-time link checking, which is the function of Safe Links.

When would these options actually be correct?

A

An exam question asks: 'Which Microsoft Defender for Office 365 feature should be configured to block users from entering credentials on a fake login page that mimics a trusted site?' In that scenario, anti-phishing policies with impersonation protection would be correct.

B

Safe Attachments would be correct if the question asked for a feature that scans email attachments for malware by opening them in a virtual environment before delivery, or if the requirement was to block malicious files in email and SharePoint.

Why candidates pick the wrong answer

A

Candidates may confuse anti-phishing policies with Safe Links because both deal with malicious URLs, but anti-phishing focuses on the email content and sender, not on rewriting and real-time URL scanning.

B

Candidates may confuse Safe Attachments with Safe Links because both are part of Microsoft Defender for Office 365 and deal with malicious content, but they target different threat vectors: attachments vs. links.

870
Multi-Selecthard

Which THREE of the following are capabilities of Microsoft Purview Compliance Manager? (Choose three.)

Select 3 answers
A.Automated testing of controls
B.Manage user identities
C.Improvement actions
D.Create data loss prevention policies
E.Compliance score
AnswersA, C, E

Compliance Manager performs automated testing of controls against your Microsoft 365 environment, continuously assessing configurations and comparing them with regulatory standards. This satisfies the requirement by identifying which controls pass or fail without manual evidence collection, feeding results into the compliance score.

Why this answer

Option A (Automated testing of controls) is correct because Compliance Manager can automatically test certain Microsoft cloud controls against your tenant configuration — for example, verifying MFA enforcement or password policies — and update their status without manual evidence collection. Option C (Improvement actions) is correct because Compliance Manager provides a catalog of improvement actions that map to controls and standards, letting you assign owners, set implementation status, and track remediation steps to raise your compliance posture. Option E (Compliance score) is correct because Compliance Manager calculates a compliance score that quantifies your progress based on completed improvement actions and passed assessments, weighted by control importance.

Option B (Manage user identities) is not a Compliance Manager capability; identity lifecycle and authentication are handled by Microsoft Entra ID. Option D (Create data loss prevention policies) is not a Compliance Manager capability; DLP policies are authored and enforced through Microsoft Purview Data Loss Prevention in the compliance portal, not through Compliance Manager.

Exam trap

SC-900 often tests the boundary between Purview Compliance Manager and other Purview/Entra features — candidates pick 'manage user identities' or 'create DLP policies' because they sound compliance-related, but those belong to Entra ID and Purview DLP respectively.

871
MCQhard

An organization has deployed Microsoft Entra ID Governance and wants to automate the process of revoking access to a critical application when an employee leaves the company. Which feature should they configure?

A.Microsoft Entra ID Governance Lifecycle Workflows
B.Microsoft Entra Privileged Identity Management
C.Microsoft Entra Access Reviews
D.Microsoft Entra Terms of Use
AnswerA

Microsoft Entra ID Governance Lifecycle Workflows provide automated identity lifecycle management, enabling organizations to define and execute tasks based on HR-driven events like joining, moving, or leaving. This feature can automatically provision or deprovision access to applications and resources, ensuring that when an employee departs, their access is systematically revoked without manual intervention, aligning directly with the requirement to remove access based on HR events.

Why this answer

Microsoft Entra ID Governance Lifecycle Workflows enable automated workflows triggered by HR events like employee termination. When an employee leaves, a lifecycle workflow can be configured to automatically remove the user from the application's access group or disable their account, ensuring immediate revocation of access without manual intervention.

Exam trap

The trap here is confusing automated offboarding (Lifecycle Workflows) with periodic access review (Access Reviews) or privileged role management (PIM), as candidates often think any governance feature can handle termination-based revocation.

How to eliminate wrong answers

Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval, not automated offboarding workflows for standard application access. Option C is wrong because Access Reviews are periodic attestation processes that require manual or scheduled review decisions, not automated revocation triggered by a lifecycle event like termination. Option D is wrong because Terms of Use present acceptance policies to users but do not enforce any automated access revocation actions.

872
MCQhard

A company uses Microsoft Defender for Cloud to secure its hybrid cloud environment. They need to continuously assess compliance with regulatory standards like ISO 27001 and receive recommendations for remediation. Which feature should they enable?

A.Defender for Cloud’s regulatory compliance dashboard
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Identity
D.Defender for Cloud’s Secure Score
AnswerA

Microsoft Defender for Cloud's regulatory compliance dashboard is specifically designed to help organizations meet various industry and regulatory standards. It continuously assesses the compliance posture of resources against built-in and custom compliance standards, such as Azure Security Benchmark, PCI DSS, ISO 27001, and HIPAA. The dashboard provides a centralized view of compliance status, offering actionable recommendations and remediation steps to address non-compliant controls and improve overall adherence to regulatory requirements. This direct alignment with compliance frameworks makes it the ideal tool for assessing regulatory posture.

Why this answer

Microsoft Defender for Cloud's regulatory compliance dashboard continuously assesses resources against built-in or custom standards such as ISO 27001, PCI DSS, and NIST, showing compliance posture and providing remediation recommendations. This directly matches the requirement to assess compliance with regulatory standards and receive remediation guidance.

Exam trap

SC-900 often tests confusion between Secure Score (overall posture metric) and the regulatory compliance dashboard (standards-specific assessment) — candidates pick Secure Score thinking it covers compliance.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Cloud Apps is a CASB (Cloud Access Security Broker) for SaaS application visibility and control, not a regulatory compliance assessment tool for hybrid cloud resources. Option C is wrong because Microsoft Defender for Identity protects on-premises Active Directory from identity-based attacks, not compliance assessment. Option D is wrong because Secure Score measures overall security posture and prioritizes improvements, but it does not map to specific regulatory standards like ISO 27001.

873
MCQmedium

Your organization uses Microsoft Sentinel. You need to create an automation rule that automatically closes a low-severity incident after 24 hours of inactivity. Which action should you include in the rule?

A.Run playbook
B.Create incident
C.Add comment
D.Change status to Closed
AnswerD

The 'Change status to Closed' action is the direct and appropriate method within Microsoft Sentinel to formally conclude an incident investigation. This action explicitly updates the incident's lifecycle state, marking it as resolved and no longer requiring active attention from analysts. It is commonly utilized within automation rules or playbooks to automatically close incidents that meet specific criteria, such as after a period of inactivity, successful remediation, or identification as a false positive.

Why this answer

Changing the status to 'Closed' is the direct action needed to automatically resolve a low-severity incident after a period of inactivity in Microsoft Sentinel. Automation rules can trigger status changes based on conditions like time elapsed, and closing the incident removes it from the active queue without manual intervention.

Exam trap

The trap here is that candidates confuse 'automation rule actions' with 'playbook capabilities', assuming a playbook is required to close an incident, when in fact a simple status change action suffices and is more efficient.

How to eliminate wrong answers

Option A is wrong because running a playbook is an action that executes a set of automated tasks (e.g., sending emails or enriching data), but it does not directly close the incident; you would still need a separate status change action. Option B is wrong because creating an incident would generate a new alert or incident, which is the opposite of closing an existing one. Option C is wrong because adding a comment only appends a note to the incident timeline and does not alter its status or lifecycle.

874
MCQmedium

A company uses Microsoft Entra ID and wants to ensure that guest users who are inactive for 90 days have their access to internal resources automatically revoked. Additionally, a manager must review all guest accounts annually. Which Microsoft Entra feature should be used to implement these requirements?

A.Microsoft Entra Identity Governance Access Reviews
B.Conditional Access policies
C.Privileged Identity Management (PIM)
D.Self-Service Password Reset (SSPR)
AnswerA

Microsoft Entra Identity Governance Access Reviews enable organizations to manage the lifecycle of user access, particularly for guest accounts. They facilitate periodic reviews by resource owners or managers to certify continued access, ensuring compliance and security. These reviews can be automated to remove access for users who are not re-approved or have shown no activity for a defined period, directly addressing the need for guest account management and cleanup. This capability is crucial for maintaining a clean and secure identity posture by preventing stale accounts.

Why this answer

Microsoft Entra Identity Governance Access Reviews enables administrators to create recurring reviews of guest user access and automatically remove access for inactive users. By configuring an access review with a duration of 90 days and enabling automatic revocation, guest users who have not signed in for that period will have their access removed. Additionally, the annual manager review requirement is met by scheduling a recurring review for all guest accounts, ensuring compliance with governance policies.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with identity governance features, mistakenly thinking that Conditional Access can enforce inactivity-based revocation, when in fact it only controls access at sign-in time and cannot perform periodic reviews or automatic removal of stale accounts.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies enforce real-time access controls based on conditions like location or device state, but they cannot automatically revoke access based on inactivity duration or schedule periodic manager reviews. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time activation and approval for privileged roles, not guest user access reviews or inactivity-based revocation. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords and does not provide any mechanism for reviewing or revoking guest access based on inactivity.

875
MCQhard

You are reviewing a Microsoft Sentinel KQL query. What is the primary purpose of this query? ```kql SigninLogs | where TimeGenerated > ago(7d) | where AppDisplayName == "Microsoft Teams" | summarize TotalAttempts = count(), FailedAttempts = countif(ResultType != 0) by UserPrincipalName | where TotalAttempts > 10 and FailedAttempts > 5 | project UserPrincipalName, TotalAttempts, FailedAttempts ```

A.Identify all users who have attempted to log on to Microsoft Teams more than 10 times in the last 7 days and who are global administrators
B.Identify users with high logon attempts to Teams and high failed sign-ins, possibly indicating a brute-force attack
C.Identify users with high failed sign-ins and check if they have conditional access policies applied
D.Identify users with high successful logon attempts to Teams and correlate with failed sign-ins to detect account compromise
AnswerB

This option accurately describes a common security analysis scenario. A KQL query designed to identify users with a high total number of logon attempts to Microsoft Teams, coupled with a significant count of failed sign-ins for the same user, strongly indicates a potential brute-force attack. This correlation is crucial as it highlights malicious actors repeatedly trying to guess credentials, distinguishing it from legitimate user errors or occasional failed attempts.

Why this answer

The query filters Microsoft Teams sign-ins from the last 7 days, aggregates total and failed sign-in attempts per user, and returns users with more than 10 total attempts and more than 5 failed attempts. This pattern of high volume and repeated failure is indicative of a brute-force attack, making option B correct. The query does not filter for global administrator role or conditional access policies.

Exam trap

A common trap is confusing brute-force detection with account compromise detection. This query focuses on high failed sign-ins combined with high overall attempts, which points to brute force, not to successful logon anomalies, global admin role checks, or conditional access policy evaluation.

How to eliminate wrong answers

Option A is wrong because the query focuses on failed sign-ins and high logon attempts, not on global administrator role membership or a specific threshold of 'more than 10 times'—the query uses aggregate counts without filtering by role. Option C is wrong because the query does not check for conditional access policies; it only correlates logon attempts with failed sign-ins, not policy application status. Option D is wrong because the query targets high failed sign-ins, not high successful logon attempts; correlating successful logons with failures would indicate account compromise after a breach, not a brute-force attack in progress.

876
Multi-Selecthard

Which THREE of the following are identity protection features in Microsoft Entra ID Protection?

Select 3 answers
A.Self-service password reset
B.Risk detections such as leaked credentials and anonymous IP address
C.Conditional access policies
D.Investigation and remediation of risk incidents
E.Risk policies for user risk and sign-in risk
AnswersB, D, E

Azure AD Identity Protection's primary function involves identifying various identity-based risks in real-time through sophisticated machine learning and heuristics. This includes detecting suspicious activities such as sign-ins from anonymous IP addresses, impossible travel scenarios, or the use of leaked credentials found on the dark web. These granular risk detections are crucial for understanding potential compromises and informing subsequent security actions.

Why this answer

Option B is correct because Microsoft Entra ID Protection natively generates risk detections such as leaked credentials, anonymous IP address, atypical travel, and unfamiliar sign-in properties, which are the core signals the service evaluates. Option D is correct because ID Protection provides investigation and remediation capabilities, including the Risky users, Risky sign-ins, and Risk detections reports, plus remediation actions like password reset, blocking sign-in, or dismissing risk. Option E is correct because ID Protection lets administrators configure risk policies for user risk and sign-in risk that automatically enforce remediation (for example, require password change or MFA) when a configured risk level is reached.

Option A is not correct because self-service password reset is an authentication/credential-management feature of Microsoft Entra ID, not an ID Protection risk feature, even though it can be used as a remediation action. Option C is not correct because Conditional Access is a separate policy engine that can consume ID Protection risk signals as conditions, but the policies themselves are not an ID Protection feature.

Exam trap

The trap here is that candidates often confuse conditional access policies (option C) as a feature of ID Protection, when in fact ID Protection provides risk detections and risk policies that can be used as conditions within conditional access, but the policies themselves are not a feature of ID Protection.

877
Multi-Selectmedium

Which TWO capabilities are provided by Microsoft Defender for Cloud Apps?

Select 2 answers
A.Email security
B.Cloud Discovery to identify shadow IT
C.Data loss prevention for cloud apps
D.Endpoint detection and response
E.Identity protection
AnswersB, C

Microsoft Defender for Cloud Apps provides Cloud Discovery capabilities to identify and assess shadow IT within an organization. This feature analyzes network traffic logs from firewalls and proxies to discover all cloud applications being used, including those not explicitly sanctioned by IT. It then provides risk assessments for these discovered apps, enabling organizations to gain visibility and control over their cloud app landscape.

Why this answer

Microsoft Defender for Cloud Apps provides Cloud Discovery (option B), which analyzes traffic logs from firewalls and proxies to detect and identify shadow IT and unsanctioned cloud apps in use across the organization. It also provides data loss prevention for cloud apps (option C) through its DLP policies and session controls, which can detect and block sensitive data sharing in sanctioned SaaS apps via Conditional Access App Control. Email security (option A) is delivered by Microsoft Defender for Office 365, not Defender for Cloud Apps.

Endpoint detection and response (option D) is a capability of Microsoft Defender for Endpoint. Identity protection (option E) is provided by Microsoft Entra ID Protection, not Defender for Cloud Apps.

Exam trap

The trap here is that candidates often confuse the overlapping security products in Microsoft's portfolio, mistakenly attributing email security (Defender for Office 365) or identity protection (Entra ID Protection) to Defender for Cloud Apps because all are part of the Microsoft 365 Defender suite.

878
Multi-Selectmedium

Which TWO Microsoft Purview features can be used to automatically classify and protect sensitive data in documents?

Select 2 answers
A.Data loss prevention policies
B.eDiscovery (Premium)
C.Trainable classifiers
D.Retention labels
E.Sensitive information types
AnswersC, E

Trainable classifiers use machine learning to identify content by example rather than fixed patterns, automatically classifying documents that fit a trained category. This satisfies the stem's requirement for automatic classification and protection of sensitive data in documents.

Why this answer

Sensitive information types (E) are the built-in or custom pattern-based definitions in Microsoft Purview that automatically detect and classify sensitive data such as credit card numbers, national ID numbers, or health records, making them a core automatic classification mechanism. Trainable classifiers (C) use machine learning to automatically identify and classify sensitive content by category (for example, source code, resumes, or contracts) when pattern matching alone is insufficient. Together, these two features feed the classification engine that can then trigger protection such as encryption or DLP.

Data loss prevention policies (A) act on already-classified sensitive data to prevent sharing, but they are a protection/enforcement mechanism rather than a classification feature. eDiscovery (Premium) (B) is used for identifying, collecting, and reviewing content for legal cases, not for automatic classification and protection. Retention labels (D) govern how long content is kept or deleted, which is a lifecycle function, not automatic classification of sensitive data.

Exam trap

Microsoft often tests the misconception that Data loss prevention policies (A) perform automatic classification, when in fact they enforce actions based on pre-existing classifications or sensitive information types, not the classification itself.

879
MCQhard

A legal team is preparing for an internal investigation related to a potential policy violation. They need to identify all relevant documents stored in Exchange Online and SharePoint Online, but there are millions of items across the organization. The team wants to use a machine learning model that learns from a set of manually reviewed relevant and non-relevant documents to predict relevance and prioritize review. Which Microsoft Purview solution provides this capability?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Audit (Premium)
C.Microsoft Purview eDiscovery (Advanced)
D.Microsoft Purview Insider Risk Management
AnswerC

Microsoft Purview eDiscovery (Advanced) is the correct solution for internal investigations requiring efficient document review. It incorporates advanced machine learning capabilities, such as predictive coding (also known as Technology Assisted Review or TAR), to intelligently identify and prioritize relevant documents from vast, unstructured data sets. This significantly accelerates the review process by reducing the volume of data human reviewers must examine, ensuring legal teams can focus on the most pertinent information for their case.

Why this answer

Microsoft Purview eDiscovery (Advanced) provides predictive coding capabilities that use machine learning to analyze a seed set of manually reviewed relevant and non-relevant documents. The model learns from this training to predict the relevance of millions of items across Exchange Online and SharePoint Online, prioritizing review for internal investigations. This directly matches the need for a machine learning model to identify and prioritize relevant documents.

Exam trap

The trap here is that candidates often confuse Insider Risk Management (which also uses machine learning for risk detection) with eDiscovery's predictive coding, but Insider Risk Management targets behavioral patterns and alerts, not document relevance prediction for legal hold and review.

Why the other options are wrong

A

Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data, not to identify and prioritize relevant documents for legal investigations using machine learning.

B

Microsoft Purview Audit (Premium) provides detailed auditing and investigation of user and admin activities, but it does not include machine learning models to predict document relevance for eDiscovery. The question specifically requires a solution that learns from manually reviewed documents to prioritize review, which is a feature of Advanced eDiscovery, not Audit.

D

Insider Risk Management is designed to detect, investigate, and act on risky user activities (e.g., data theft, policy violations) using analytics, but it does not provide a machine learning model to predict document relevance for eDiscovery review based on manually labeled samples.

When would these options actually be correct?

A

A question asking which Microsoft Purview solution helps prevent sensitive information from being shared via email or SharePoint by applying policies to detect and block unauthorized transfers would make DLP the correct answer.

B

An organization needs to investigate a security incident and must identify all user activities (e.g., file access, email sends) within a specific time frame across Exchange Online and SharePoint Online. The team requires long-term retention of audit logs and high-bandwidth APIs to export audit data for analysis. In this scenario, Microsoft Purview Audit (Premium) would be the correct answer.

D

A scenario where an organization needs to identify and investigate users who may be engaging in risky activities (e.g., unauthorized data exfiltration, policy violations) by correlating signals from various sources (e.g., DLP alerts, user behavior) would make Insider Risk Management the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse DLP's content analysis capabilities with eDiscovery's relevance prediction, assuming that any tool analyzing content can perform document relevance ranking for legal review.

B

Candidates may confuse Audit (Premium) with eDiscovery because both involve investigation and compliance. The term 'Audit' suggests reviewing records, which seems related to identifying relevant documents, but it lacks the predictive coding and machine learning capabilities required by the question.

D

Candidates may confuse the 'investigation' aspect of Insider Risk Management with the legal investigation described in the question, or they may think that machine learning for risk detection is the same as machine learning for relevance prediction in eDiscovery.

880
MCQmedium

A company uses Microsoft Entra ID. They want to require multi-factor authentication (MFA) for users who sign in from locations with a high risk score, as determined by Microsoft's analysis of the sign-in's IP address and other behavioral signals. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Conditional Access
C.Privileged Identity Management
D.Entitlement Management
AnswerA

Microsoft Entra ID Protection is the dedicated service for detecting identity-based risks, including both sign-in risk and user risk, using adaptive machine learning and heuristics. It continuously monitors sign-in attempts and user behavior for anomalies like impossible travel, unfamiliar sign-in properties, or leaked credentials. Based on these detections, Identity Protection can automatically trigger responses such as requiring multi-factor authentication, enforcing a password change, or blocking access, thereby directly addressing the need for risk-based MFA.

Why this answer

Identity Protection is the correct feature because it provides risk-based detection and remediation, including the ability to automatically enforce MFA when a sign-in is flagged with a high risk score. It uses machine learning models to analyze signals such as anonymized IP addresses, atypical travel, and leaked credentials to assign a risk level. This directly matches the requirement to require MFA based on Microsoft's analysis of the sign-in's IP address and behavioral signals.

Exam trap

The trap here is that candidates often confuse Conditional Access as the feature that evaluates risk, when in fact Conditional Access is the policy engine that enforces controls, but Identity Protection is the service that generates the risk scores used as conditions.

Why the other options are wrong

B

Conditional Access is the policy engine that enforces MFA, but it relies on a risk assessment from Identity Protection. The question asks for the feature that determines the risk score, which is Identity Protection, not Conditional Access.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Azure AD, not risk-based MFA policies. The question asks for a feature that enforces MFA based on sign-in risk scores, which is handled by Identity Protection, not PIM.

D

Entitlement Management is used for managing access packages and identity governance, not for enforcing MFA based on risk signals from sign-in behavior.

When would these options actually be correct?

B

A company wants to enforce MFA for all users accessing a sensitive app from outside the corporate network. They should configure a Conditional Access policy to require MFA based on location or network conditions.

C

A company needs to provide just-in-time privileged access to Azure AD roles, requiring approval and time-bound activation for administrators. In this scenario, Privileged Identity Management would be the correct feature to configure.

D

An exam scenario where the question asks: 'Which Microsoft Entra ID feature should be used to create and manage access packages for internal and external users to govern access to resources?'

Why candidates pick the wrong answer

B

Candidates often confuse Conditional Access as the feature that provides risk detection, when in fact it only consumes risk signals from Identity Protection to enforce policies.

C

Candidates may confuse PIM's role in securing privileged accounts with risk-based MFA, thinking that managing privileged roles inherently includes risk-based authentication controls.

D

Candidates may confuse Entitlement Management with broader identity protection features, thinking it includes risk-based policies, or they may misassociate 'entitlements' with access controls like MFA.

881
Multi-Selectmedium

Which TWO conditions can be used in a Microsoft Entra Conditional Access policy? (Choose two.)

Select 2 answers
A.MFA registration status
B.Password complexity
C.Device platform
D.User risk level
E.Login frequency
AnswersC, D

Device platform is a fundamental condition in Microsoft Entra Conditional Access, enabling administrators to specify which operating systems a policy applies to. This condition allows for highly granular control, such as requiring compliant devices only for specific platforms like iOS and Android, while potentially blocking access from less secure or unsupported platforms like Linux or macOS unless they meet additional criteria. It directly evaluates the OS of the device initiating the access request.

Why this answer

Device platform is a standard condition in Microsoft Entra Conditional Access policies, allowing administrators to target policies based on the operating system (e.g., Windows, iOS, Android). Option D is correct because User risk level is a condition derived from Microsoft Entra ID Protection, reflecting the probability that a user's identity has been compromised, and can be used to trigger step-up authentication or block access.

Exam trap

The trap here is that candidates confuse conditions (e.g., device platform, user risk) with grant controls (e.g., require MFA, sign-in frequency) or configuration settings (e.g., password complexity), leading them to select options that are not valid conditions in the Conditional Access policy editor.

882
MCQhard

A compliance officer needs to identify and monitor potentially risky user activities, such as users copying large amounts of data to external devices or sharing sensitive files with unauthorized recipients. They want to create a policy that detects these activities and automatically escalates them for investigation. Which Microsoft Purview solution should they use?

A.Microsoft Purview Insider Risk Management
B.Microsoft Purview Audit
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Compliance Manager
AnswerA

Microsoft Purview Insider Risk Management is the correct solution as it proactively identifies, analyzes, and acts on risky activities within an organization. It leverages machine learning and adaptive analytics to detect potential data exfiltration, intellectual property theft, and policy violations by employees, assigning risk scores and automatically generating cases for investigation by security teams. This capability directly addresses the need to identify and monitor potentially risky insider activities.

Why this answer

Microsoft Purview Insider Risk Management is specifically designed to detect and investigate malicious or inadvertent insider risks based on activities like data exfiltration, unusual file sharing, or violations of corporate policies. It uses indicators and adaptive policies to assign risk scores and trigger alerts for review. Audit (option B) only provides logging and does not have built-in risk analysis.

Communication Compliance (option C) focuses on inappropriate communications, not data-related risks. Compliance Manager (option D) assesses compliance posture but does not detect risky user activities. Therefore, Insider Risk Management is the correct solution.

883
MCQhard

A manufacturing company experiences repeated ransomware attacks targeting their on-premises file servers. They have Microsoft 365 E5 and want to implement a solution to detect and automatically respond to such threats across hybrid environments. What should they deploy?

A.Microsoft Defender for Identity
B.Microsoft Purview Communication Compliance
C.Microsoft Defender for Office 365
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Identity is specifically designed to monitor on-premises Active Directory (AD) environments for suspicious activities and advanced threats. Ransomware attacks frequently involve compromising AD credentials for lateral movement and privilege escalation. Defender for Identity detects these attacker behaviors, such as Pass-the-Hash, Golden Ticket attacks, or unusual account access patterns, by analyzing network traffic and AD logs, providing crucial early detection against sophisticated ransomware campaigns targeting an organization's core identity infrastructure.

Why this answer

Microsoft Defender for Identity is the correct solution because it uses on-premises Active Directory signals to detect, investigate, and respond to advanced threats like ransomware targeting hybrid environments. It integrates with Microsoft 365 Defender to automatically initiate response actions (e.g., disabling compromised accounts) when suspicious lateral movement or credential theft is detected, directly addressing the scenario of repeated ransomware attacks on on-premises file servers.

Exam trap

The trap here is that candidates often confuse Defender for Identity (on-premises AD protection) with Defender for Office 365 (email protection) or Defender for Cloud Apps (SaaS shadow IT), failing to recognize that the question explicitly mentions on-premises file servers and hybrid environments, which require identity-based detection and response.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Communication Compliance is designed to detect policy violations in communications (e.g., insider trading, harassment), not to detect or respond to ransomware attacks on file servers. Option C is wrong because Microsoft Defender for Office 365 protects email and collaboration tools (e.g., Exchange Online, SharePoint Online) from phishing and malware, but does not monitor on-premises file servers or Active Directory for ransomware activity. Option D is wrong because Microsoft Defender for Cloud Apps focuses on shadow IT and data protection in cloud applications (e.g., SaaS apps), not on-premises file servers or hybrid identity threats.

884
MCQhard

An organization wants to implement a zero-trust security model. They plan to require multi-factor authentication (MFA) for all users accessing sensitive applications, but only when the sign-in risk is medium or higher. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Conditional Access policy with risk condition
C.Microsoft Defender for Cloud Apps access policy
D.Microsoft Entra ID Protection risk detection policy
AnswerB

Microsoft Entra ID Conditional Access policies are the core enforcement engine for Zero Trust principles, allowing organizations to define precise conditions under which users can access resources. By incorporating a "sign-in risk" condition, these policies leverage real-time risk assessments from Microsoft Entra ID Protection. If the sign-in risk meets a predefined threshold, the policy can dynamically enforce specific controls, such as requiring multi-factor authentication (MFA) or blocking access, directly aligning with a risk-based Zero Trust model.

Why this answer

B is correct because Microsoft Entra ID Conditional Access policies allow administrators to enforce MFA based on sign-in risk level, which is evaluated by Microsoft Entra ID Protection. By configuring a policy with a risk condition (e.g., medium or higher), the organization can require MFA only when the sign-in risk meets that threshold, aligning with a zero-trust model that grants access based on real-time risk assessment rather than a static rule.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Protection (which detects risk) with the actual policy engine (Conditional Access) that enforces actions like MFA, leading them to select option D instead of B.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and access reviews, not for evaluating sign-in risk or enforcing MFA based on risk level. Option C is wrong because Microsoft Defender for Cloud Apps access policies control session-level actions (e.g., blocking downloads) based on app context or user behavior, but they do not natively evaluate Microsoft Entra ID sign-in risk to trigger MFA. Option D is wrong because Microsoft Entra ID Protection risk detection policy is a misnomer; Entra ID Protection provides risk detections and risk scores, but the actual enforcement (e.g., requiring MFA) must be configured through a Conditional Access policy that uses those risk conditions.

885
MCQhard

A tenant administrator runs the PowerShell cmdlet shown in the exhibit. The output shows that some compliance policies have IsAssigned = $false. What does this indicate?

A.The compliance policy is scheduled to be assigned in the future
B.The compliance policy is not assigned to any user or device group
C.The compliance policy has been evaluated and found non-compliant
D.The compliance policy is a built-in policy that cannot be assigned
AnswerB

When the IsAssigned property for an Intune compliance policy returns False, it directly and unambiguously indicates that the policy has not been targeted or deployed to any user groups, device groups, or the entire tenant. For a compliance policy to become active, enforce settings, and report on device or user compliance, it must be explicitly assigned to the relevant scope within Microsoft Intune.

Why this answer

The `IsAssigned` property in the output of a compliance policy PowerShell cmdlet (such as `Get-DeviceCompliancePolicy`) directly indicates whether the policy has been assigned to any user or device group. When `IsAssigned = $false`, it means the policy exists in the tenant but has not been linked to any group via an assignment, so it is not being enforced on any devices. This is a core concept in Microsoft Intune and Microsoft 365 compliance: a policy must be assigned to a group to take effect.

Exam trap

The trap here is that candidates confuse `IsAssigned` with compliance evaluation status or policy type, mistakenly thinking it indicates future scheduling, non-compliance, or built-in restrictions, rather than understanding it simply reflects whether the policy has been assigned to a group.

How to eliminate wrong answers

Option A is wrong because a future scheduled assignment would still show `IsAssigned = $true` once the assignment is configured; the property reflects the existence of an assignment, not its activation time. Option C is wrong because `IsAssigned` has nothing to do with compliance evaluation results—non-compliant devices are tracked via the `ComplianceStatus` property, not `IsAssigned`. Option D is wrong because built-in policies (like default compliance policies) can still be assigned and would show `IsAssigned = $true` if they are; the property does not indicate whether a policy is built-in or custom.

886
Multi-Selecteasy

Which TWO of the following are valid uses for Microsoft Purview eDiscovery?

Select 2 answers
A.Placing legal holds on content
B.Classifying content with sensitivity labels
C.Reviewing audit logs for user activity
D.Applying retention policies to prevent deletion
E.Searching for content across mailboxes and sites
AnswersA, E

Microsoft Purview eDiscovery provides the functionality to place legal holds on content, ensuring that data relevant to litigation or investigations is preserved and cannot be altered or deleted. These holds are crucial for maintaining the integrity of electronically stored information (ESI) across various Microsoft 365 services, including Exchange mailboxes, SharePoint sites, and Teams. This capability prevents data spoliation, which is essential for regulatory compliance and legal proceedings.

Why this answer

Option A is correct because Microsoft Purview eDiscovery (Standard and Premium) supports creating holds, including Litigation Hold and eDiscovery Hold, to preserve mailbox and site content in place for legal or investigative purposes. Option E is correct because eDiscovery provides Content Search and search-and-collection tools that query Exchange mailboxes, SharePoint sites, OneDrive accounts, and Teams content using keyword, KQL, and condition-based queries. Option B is not an eDiscovery use; sensitivity labels are configured through Microsoft Purview Information Protection to classify and protect content, not to identify or preserve it for legal matters.

Option C is not an eDiscovery use; reviewing audit logs is performed with Microsoft Purview Audit (Standard/Premium) via the unified audit log, not through eDiscovery cases. Option D is not an eDiscovery use; retention policies and retention labels are managed through Microsoft Purview Data Lifecycle Management to govern content lifecycle, whereas eDiscovery holds are case-scoped preservation mechanisms.

Exam trap

The trap here is that candidates often confuse eDiscovery's legal hold capability with retention policies, or mistakenly think eDiscovery includes classification or audit log review, because all are part of Microsoft Purview but serve distinct compliance roles.

887
MCQeasy

An organization wants to automatically retain all financial documents for seven years and then delete them. Which Microsoft Purview solution should be used to create the retention policy?

A.Microsoft Purview Information Protection
B.Microsoft Purview Audit
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Communication Compliance
AnswerC

Microsoft Purview Data Lifecycle Management (formerly Microsoft 365 Retention) is the correct service for automatically retaining and deleting content based on an organization's policies and regulatory requirements. It allows administrators to create retention labels and policies that can be applied to content across various locations, ensuring that financial data, for example, is kept for a specific duration and then disposed of appropriately. This directly addresses the need for automated retention scheduling to meet compliance obligations.

Why this answer

Microsoft Purview Data Lifecycle Management (formerly Microsoft 365 Retention) is the correct solution because it provides retention and deletion policies that can automatically retain data for a specified period (e.g., seven years) and then permanently delete it. This solution is designed specifically for managing the lifecycle of content across Exchange, SharePoint, OneDrive, and Teams, making it ideal for regulatory compliance requirements like financial document retention.

Exam trap

The trap here is that candidates often confuse 'retention policies' with 'information protection' (labeling) or 'audit' (logging), but the SC-900 exam specifically tests that Data Lifecycle Management is the sole solution for automated retention and deletion based on time-based rules.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management) rather than automating retention and deletion schedules. Option B is wrong because Microsoft Purview Audit is used for logging and investigating user and admin activities, not for creating retention policies that enforce data lifecycle rules. Option D is wrong because Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) and does not provide retention or deletion capabilities.

888
MCQhard

A healthcare organization stores patient records in SharePoint Online. The compliance officer needs to ensure that records containing Protected Health Information (PHI) are retained for 7 years per regulatory requirements. Which Microsoft Purview solution should they implement?

A.Microsoft Purview Audit
B.Microsoft Purview eDiscovery
C.Microsoft Purview Records Management
D.Microsoft Purview Data Lifecycle Management
AnswerC

Microsoft Purview Records Management is precisely engineered to help organizations meet their legal, business, and regulatory obligations for records retention and disposition, particularly for highly sensitive data like patient records. This solution enables the classification of content as a formal record, applying immutable retention labels that prevent modification or deletion, even by administrators, and managing the entire lifecycle from creation to final disposition. It ensures that critical information is preserved according to specific healthcare regulations, providing the necessary legal defensibility and compliance.

Why this answer

Microsoft Purview Records Management is the correct solution because it enables organizations to apply retention labels and policies that enforce mandatory retention periods for regulatory compliance. For patient records containing PHI, a retention label can be configured to retain the data for exactly 7 years and then trigger a disposition review or automatic deletion, ensuring the organization meets healthcare regulatory requirements.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management (which handles non-record content like temporary files) with Records Management (which handles declarative records with immutable retention), leading them to choose D instead of C.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities, not the ability to enforce retention periods on content. Option B is wrong because Microsoft Purview eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for setting retention schedules. Option D is wrong because Microsoft Purview Data Lifecycle Management (now part of Records Management) focuses on managing data lifecycle for non-records content (e.g., temporary files) and does not provide the declarative record declaration and immutable retention required for regulatory compliance with PHI.

889
MCQmedium

A company's security team discovers that several recent account compromises originated from attackers using legacy mail protocols (POP3, IMAP) which do not support multi-factor authentication. The team wants to immediately prevent any sign-in attempts using these protocols. Which Microsoft Entra ID feature should they configure to enforce this restriction?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Microsoft Entra Password Protection
AnswerA

Conditional Access policies provide the precise control needed to block legacy authentication by evaluating various conditions, including the client application used for access. Administrators can configure a policy to specifically target and block client apps that utilize legacy authentication protocols, such as Exchange ActiveSync or 'Other clients' (which often encompasses protocols like POP3, IMAP, and SMTP AUTH). This ensures that only modern authentication methods, which support features like multi-factor authentication, are permitted for accessing corporate resources.

Why this answer

Conditional Access in Microsoft Entra ID allows administrators to create policies that control access based on conditions such as client apps. By configuring a policy to block authentication requests from legacy authentication protocols (POP3, IMAP, SMTP, etc.), the security team can immediately prevent sign-in attempts that do not support multi-factor authentication, effectively mitigating the risk of account compromise via these outdated protocols.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based policies with the ability to block legacy protocols, but Identity Protection only triggers MFA or block based on risk scores, not on the protocol type itself.

Why the other options are wrong

B

Identity Protection detects and remediates risks but does not block legacy authentication protocols directly; it requires Conditional Access policies to enforce such blocks.

C

Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not authentication protocol restrictions. It cannot block legacy mail protocols like POP3/IMAP.

When would these options actually be correct?

B

When the question asks for a feature that automatically detects and responds to compromised accounts or risky sign-ins (e.g., requiring MFA or password reset based on risk level), Identity Protection is the correct answer.

C

A question asks: 'The security team needs to reduce standing administrative access and require approval for role activation in Microsoft Entra ID. Which feature should they use?' — PIM would be the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse Identity Protection's risk-based policies with the ability to block specific authentication methods, not realizing that Conditional Access is needed to enforce protocol-level restrictions.

C

Candidates may confuse PIM's role-based access controls with broader security policies, assuming it can enforce authentication restrictions because it manages privileged accounts.

890
Multi-Selectmedium

Which TWO features are part of Microsoft Entra ID Governance? (Choose two.)

Select 2 answers
A.Entitlement Management
B.Access Reviews
C.Conditional Access
D.Self-Service Password Reset
E.Identity Protection
AnswersA, B

Microsoft Entra Entitlement Management is a core component of identity governance, automating the lifecycle of access to groups, applications, and SharePoint sites. It allows organizations to define access packages, specify approval workflows, and enable self-service requests, ensuring users gain and lose access appropriately and efficiently based on their roles and projects. This capability streamlines the process of granting and revoking access, reducing manual overhead and improving compliance.

Why this answer

Entitlement Management (A) is a core Microsoft Entra ID Governance capability that lets organizations manage the lifecycle of access through access packages, catalogs, connected organizations, and policies for internal and external users, automating assignment and removal of resource access. Access Reviews (B) is also part of Entra ID Governance, enabling periodic recertification of group memberships, application assignments, and privileged role assignments so that access is reviewed and revoked when no longer needed. Conditional Access (C) is a Microsoft Entra ID access-control policy engine that enforces signals and conditions at sign-in, but it is not classified as an Entra ID Governance feature.

Self-Service Password Reset (D) is an authentication/credential-management feature in Entra ID, not a governance workload. Identity Protection (E) is a risk-detection and remediation service for identity risk signals, and while related to security, it is not one of the Entra ID Governance features asked for here.

Exam trap

The trap here is that candidates often confuse security features (Conditional Access, Identity Protection) with governance features, but Entra ID Governance specifically focuses on managing the lifecycle of access—who gets access, for how long, and with periodic review—not on enforcing security controls or mitigating threats.

891
Matchingmedium

Match each Microsoft Defender product to its focus area.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Protect on-premises Active Directory

Secure email and collaboration tools

Protect cloud workloads and resources

Secure Internet of Things devices

SaaS application security

Why these pairings

Microsoft Defender for Cloud secures cloud workloads; Defender for Endpoint secures endpoints; Defender for Identity secures identities; Defender for Office 365 secures email and collaboration; Defender for Cloud Apps secures shadow IT and app permissions.

892
MCQhard

A company uses Microsoft Defender for Cloud Apps to monitor their cloud environment. The security team wants to detect when a user downloads an unusually large amount of data from SharePoint Online compared to their normal behavior. They need to configure a policy that triggers an alert based on this anomaly. Which type of policy should they create in Defender for Cloud Apps?

A.Anomaly detection policy
B.File policy
C.Session policy
D.Activity policy
AnswerA

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish baseline behavior and detect deviations, such as mass downloads. They can be configured to trigger alerts when activities like download volume significantly exceed a user's normal pattern. This directly addresses the requirement to detect unusual data downloads.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps leverage machine learning to identify deviations from normal user behavior, such as mass downloads. They are designed to detect threats like data exfiltration. Other policy types are rule-based or content-focused and do not provide behavioral anomaly detection, making them unsuitable for this scenario.

Exam trap

The trap here is confusing anomaly detection policies with activity policies, which are also used to monitor activities but do not use machine learning to detect behavioral anomalies.

893
MCQmedium

An organization wants to enable passwordless authentication for its users by using a mobile app. Which Microsoft Entra ID authentication method should they implement?

A.Temporary Access Pass
B.Windows Hello for Business
C.FIDO2 security keys
D.Microsoft Authenticator (passwordless sign-in)
AnswerD

Microsoft Authenticator's passwordless sign-in feature allows users to authenticate to Azure AD-connected services by simply approving a notification on their registered mobile device, eliminating the need to type a password. This method leverages public-key cryptography, where the user's mobile phone acts as a secure authenticator, providing a convenient and phishing-resistant multi-factor authentication experience. It is a primary example of a passwordless method delivered through a dedicated mobile application.

Why this answer

Microsoft Authenticator's passwordless sign-in feature allows users to authenticate using their phone's biometric or PIN instead of a password, satisfying the requirement for passwordless authentication via a mobile app. It works by binding the user's account to the Authenticator app, which then receives push notifications or generates one-time codes for sign-in. This is the only option that specifically uses a mobile app as the authentication method.

Exam trap

SC-900 often tests the distinction between passwordless methods — candidates confuse Windows Hello for Business (device-bound) and FIDO2 keys (hardware) with Microsoft Authenticator (mobile app), and the question's 'mobile app' keyword is the deciding factor.

How to eliminate wrong answers

Option A is wrong because Temporary Access Pass is a time-limited passcode used for onboarding or recovery, not a passwordless authentication method for everyday sign-in. Option B is wrong because Windows Hello for Business uses biometrics or PIN on Windows devices, not a mobile app, and is device-bound rather than app-based. Option C is wrong because FIDO2 security keys are physical hardware tokens (USB/NFC), not a mobile app, though they do support passwordless authentication.

894
MCQmedium

A company uses Microsoft 365 and needs to automatically detect documents in SharePoint Online that contain personally identifiable information (PII) such as social security numbers. When such documents are detected, they want to apply a sensitivity label that encrypts the document and restricts access to only the compliance team. Which Microsoft Purview solution should they use?

A.Data Lifecycle Management
B.Records Management
C.Data Loss Prevention (DLP)
D.Communication Compliance
AnswerC

Data Loss Prevention (DLP) is the correct solution as it proactively identifies, monitors, and protects sensitive information across Microsoft 365 services, including SharePoint. DLP policies leverage sensitive information types, trainable classifiers, and exact data match to automatically detect specific content (e.g., PII, credit card numbers). Upon detection, DLP can enforce various actions, such as blocking sharing, encrypting files, or notifying administrators, thereby preventing unauthorized disclosure and protecting sensitive data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it can automatically scan documents in SharePoint Online for sensitive information types (e.g., social security numbers) using built-in or custom sensitive info types. When a match is found, DLP policies can trigger an action to apply a sensitivity label that encrypts the document and restricts access, such as limiting it to the compliance team. This combines content detection with automated protection, which is exactly the scenario described.

Exam trap

The trap here is that candidates often confuse DLP with Data Lifecycle Management or Records Management, thinking those solutions handle content classification, but DLP is the only one that combines real-time content inspection with automated label application for protection.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management focuses on retaining or deleting content based on age or policy, not on detecting PII or applying sensitivity labels. Option B is wrong because Records Management is designed to mark content as records for legal or regulatory retention, not to scan for PII or enforce encryption via labels. Option D is wrong because Communication Compliance monitors internal and external communications (e.g., email, Teams) for policy violations like harassment or insider trading, not for scanning SharePoint documents for PII.

895
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Entra Identity Protection? (Choose three.)

Select 3 answers
A.Detect leaked credentials
B.Enable risk-based conditional access policies
C.Allow users to reset their own passwords
D.Provide just-in-time privileged access
E.Provide a risk investigation report
AnswersA, B, E

Microsoft Entra ID Protection actively monitors public and dark web sources for compromised user credentials associated with your tenant. When a username and password pair is found to be leaked, ID Protection flags the affected user as having a "leaked credentials" risk, enabling administrators to force password resets or block sign-ins to prevent unauthorized access. This proactive monitoring is a critical defense against credential stuffing attacks.

Why this answer

Microsoft Entra Identity Protection includes leaked credential detection (A), which scans for compromised credentials exposed in breaches or dark web dumps and surfaces them as user risk detections. It also enables risk-based Conditional Access policies (B), allowing sign-in and user risk levels to drive access decisions such as requiring MFA or password change. Its risk investigation reports (E) give administrators visibility into risky users, risky sign-ins, and detections for triage and remediation.

Self-service password reset (C) is a separate Microsoft Entra ID feature, and just-in-time privileged access (D) is provided by Privileged Identity Management, not Identity Protection.

Exam trap

The trap here is that candidates confuse the risk-based Conditional Access integration (which is part of Identity Protection) with the password reset and JIT access features that belong to separate Microsoft Entra services like SSPR and PIM.

896
MCQmedium

An organization wants to allow users to reset their own passwords without help desk intervention. They also need to enforce multifactor authentication during the reset process. Which Microsoft Entra feature should they configure?

A.Microsoft Entra Self-Service Password Reset
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra Multifactor Authentication
AnswerA

Microsoft Entra Self-Service Password Reset (SSPR) is the correct solution because it directly addresses the need for users to reset their own passwords without requiring administrator intervention. This feature allows users to verify their identity using pre-registered authentication methods, such as mobile app notifications, phone calls, or email verification, to securely regain access to their accounts. SSPR significantly reduces helpdesk call volumes related to password resets and improves user productivity by providing immediate self-service access restoration.

Why this answer

Microsoft Entra Self-Service Password Reset (SSPR) allows users to reset their own passwords without help desk intervention. By integrating with Microsoft Entra Multifactor Authentication, SSPR can enforce MFA during the reset process, satisfying both requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Multifactor Authentication as a standalone solution for password reset, when in fact it is only a component that must be integrated with SSPR to achieve both self-service reset and MFA enforcement.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Identity Protection is a risk-based detection and remediation tool that can trigger automated responses like requiring MFA or blocking sign-ins, but it does not directly provide self-service password reset capabilities. Option C is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not general user password reset workflows. Option D is wrong because Microsoft Entra Multifactor Authentication is an authentication method that can be used as part of SSPR, but by itself it does not provide the self-service password reset functionality; it must be combined with SSPR to meet both requirements.

897
MCQmedium

A company uses Microsoft Entra ID. The IT team wants to provide remote employees with secure, single sign-on (SSO) access to a critical on-premises web application that uses password-based authentication, without requiring a VPN connection. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra Application Proxy
B.Microsoft Entra Connect
C.Microsoft Entra Domain Services
D.Microsoft Entra ID P2 license
AnswerA

Microsoft Entra Application Proxy enables secure remote access to on-premises web applications from any device, without requiring a VPN or opening inbound firewall ports. It works by deploying a lightweight connector within the private network that establishes an outbound connection to the Microsoft Entra service. This allows users to access internal applications using their Microsoft Entra ID credentials, benefiting from single sign-on and Microsoft Entra's robust security features like Conditional Access.

Why this answer

Microsoft Entra Application Proxy enables secure remote access to on-premises web applications by publishing them through an external endpoint, without requiring a VPN. It supports password-based SSO by securely storing and replaying credentials to the legacy application, allowing users to authenticate once via Entra ID. This makes it the correct choice for providing SSO to a password-based on-premises app without a VPN.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect (a sync tool) with Application Proxy, mistakenly thinking that syncing identities alone provides remote access and SSO to on-premises apps.

Why the other options are wrong

B

Microsoft Entra Connect is used for synchronizing on-premises directories with Entra ID, not for proxying access to on-premises web applications. It does not provide SSO or eliminate the need for a VPN.

C

Microsoft Entra Domain Services provides managed domain services like domain join and LDAP, not secure remote access to on-premises web apps without VPN. The question requires a reverse proxy solution for password-based SSO, which is Application Proxy's role.

D

The question asks for a specific feature to provide SSO access to an on-premises web app without VPN. A Microsoft Entra ID P2 license is a licensing tier, not a feature; it does not directly enable SSO or remote access to on-premises apps.

When would these options actually be correct?

B

A company wants to synchronize user accounts and passwords from an on-premises Active Directory to Microsoft Entra ID to enable cloud-based authentication and management. The question would ask: 'Which tool should they use to sync on-premises identities to the cloud?'

C

A company needs to lift-and-shift on-premises applications to Azure without re-architecting, and requires domain-joined VMs with managed domain services like Group Policy. Entra Domain Services would be correct for providing AD DS compatibility in Azure.

D

A question that asks which license is required to use Microsoft Entra ID Protection, Identity Governance (e.g., Privileged Identity Management), or Conditional Access policies with risk-based conditions. For example: 'Which license is needed to implement risk-based Conditional Access policies?'

Why candidates pick the wrong answer

B

Candidates may confuse Entra Connect with Application Proxy because both involve on-premises integration, and 'Connect' sounds like it provides connectivity for remote access.

C

Candidates may confuse 'Domain Services' with providing access to on-premises resources, or think that domain services are needed for authentication to on-premises apps, not realizing Application Proxy handles this without domain join.

D

Candidates may think that a higher license tier (P2) is necessary for any advanced security feature, including Application Proxy, or they confuse licensing requirements with functional capabilities.

898
MCQeasy

A security architect is designing a system where user access rights are reviewed and certified on a regular basis by data owners. The goal is to ensure that users continue to have only the permissions necessary to perform their job functions and that no excessive permissions exist. Which security principle is primarily being implemented through these regular reviews?

A.Defense in depth
B.Zero trust
C.Least privilege
D.Separation of duties
AnswerC

Periodic access reviews by data owners certify that each user retains only the permissions their job requires, removing accumulated excess rights. This directly enforces least privilege by continuously validating and revoking unnecessary entitlements rather than granting standing access.

Why this answer

Regular access reviews directly enforce the principle of least privilege by ensuring users retain only the permissions necessary for their current job functions. This process identifies and removes excessive permissions that may have accumulated over time, aligning with the core goal of minimizing the attack surface. In Microsoft 365, this is often implemented through Azure AD access reviews, where data owners certify or revoke user access.

Exam trap

The trap here is that candidates may confuse the periodic review of permissions with the zero trust model, but zero trust focuses on continuous verification at each access request rather than periodic certification of existing rights.

Why the other options are wrong

A

Defense in depth is a layered security strategy using multiple controls (e.g., firewalls, antivirus, encryption) to protect assets, not specifically about reviewing and certifying user permissions to enforce minimal access.

B

Zero trust is a security model that assumes no implicit trust and continuously verifies every access request, but the question specifically focuses on regular reviews and certifications to enforce minimal permissions, which is the principle of least privilege.

D

Separation of duties prevents fraud by requiring multiple people to complete a sensitive task, but it does not directly address the regular review and certification of user permissions to remove excessive access, which is the core of least privilege.

When would these options actually be correct?

A

A question asks: 'An organization implements multiple security controls at different layers (network, endpoint, application) to protect against threats. Which principle is being applied?' Then defense in depth would be correct.

B

A question describing a network architecture where every access request is authenticated and authorized regardless of origin, such as 'An organization implements micro-segmentation and continuous verification for all network traffic. Which security principle is being applied?'

D

An exam question asks: 'Which security principle ensures that no single individual has the authority to both approve and process a financial transaction, thereby reducing the risk of fraud?' In that context, separation of duties is the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse 'regular reviews' as part of a comprehensive security posture, mistakenly associating the layered approach of defense in depth with the periodic review process.

B

Candidates may confuse zero trust with least privilege because both involve restricting access, but zero trust is broader and includes continuous verification, while least privilege specifically limits permissions to the minimum necessary.

D

Candidates may confuse separation of duties with least privilege because both involve controlling access, but separation of duties focuses on dividing tasks among multiple users, not on minimizing permissions per user.

899
Multi-Selecteasy

A company wants to enforce multifactor authentication for all users. Which TWO Microsoft Entra ID features can be used together to achieve this?

Select 2 answers
A.Conditional Access
B.Identity Protection
C.Security defaults
D.Authentication methods (Settings)
E.Password protection
AnswersA, D

Conditional Access policies are the primary method in Microsoft Entra ID to enforce specific access requirements, such as multifactor authentication (MFA), based on various conditions like user location, device state, or application being accessed. These policies evaluate conditions in real-time and grant or block access, or require additional steps like MFA, ensuring robust security tailored to risk.

Why this answer

Conditional Access policies allow you to enforce multifactor authentication (MFA) based on specific conditions such as user, location, or device state. Authentication methods define the MFA verification options (e.g., Microsoft Authenticator, SMS, OATH tokens) that users can register and use. Together, Conditional Access triggers the MFA requirement, while Authentication methods control which verification methods are available.

Exam trap

The trap here is that candidates often confuse Identity Protection (which can trigger MFA based on risk) as a direct MFA enforcement feature, when in fact it only provides risk signals that must be used with Conditional Access to enforce MFA.

900
MCQmedium

A company wants to offer a secure sign-in experience for external customers who may use personal accounts from Facebook, Google, or any OpenID Connect provider. They also need to customize the sign-in pages with their company logo and colors. Which Microsoft Entra capability should they use?

A.Microsoft Entra ID (formerly Microsoft Entra ID) — free edition
B.Microsoft Entra External ID (formerly Microsoft Entra ID B2C)
C.Microsoft Entra Domain Services
D.Microsoft Entra Permissions Management
AnswerB

Microsoft Entra External ID is purpose-built as a robust Customer Identity and Access Management (CIAM) solution, specifically engineered to manage identities for millions of external customers accessing applications and services. It natively supports a wide array of identity providers, including popular social accounts (e.g., Google, Facebook), enterprise accounts, and local accounts. Furthermore, it offers extensive customization capabilities for sign-up, sign-in, and profile management pages, ensuring a fully branded and user-friendly experience tailored for external customers.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2C) is the correct choice because it is specifically designed for customer-facing identity scenarios, supporting social identity providers (Facebook, Google) and any OpenID Connect provider. It also provides full customization of sign-in pages, including company branding like logos and colors, which is not available in the free edition of Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse Microsoft Entra External ID with the free edition of Microsoft Entra ID, assuming that 'free' includes external identity support, but the free edition is strictly for internal users and lacks social identity federation and UI customization capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (free edition) is intended for internal organizational users and does not support external customer identities with social or OpenID Connect providers, nor does it allow customization of sign-in pages for external users. Option C is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., Kerberos, NTLM) for legacy applications, not identity federation or customer sign-in customization. Option D is wrong because Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) tool for managing permissions across multi-cloud environments, unrelated to customer authentication or branding.

Page 11

Page 12 of 18

Page 13