Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 901–975

1279 questions total · 18pages · All types, answers revealed

Page 12

Page 13 of 18

Page 14
901
MCQhard

A company deploys Microsoft Entra ID Protection. The security team wants to automatically block sign-ins from anonymous IP addresses. They configure a Conditional Access policy. Which assignment condition should they use?

A.User risk level condition with 'Medium'
B.Device condition with 'Compliant'
C.Sign-in risk level condition with 'High'
D.Location condition with 'Any IP'
AnswerC

The 'Sign-in risk level' condition directly assesses the risk associated with a specific authentication attempt in real-time, leveraging detections from Microsoft Entra ID Protection. An 'Anonymous IP address' is a prominent detection that contributes to a 'High' sign-in risk level, as it often indicates an attempt to obscure the user's true location, which is frequently associated with malicious activity. This condition is precisely designed to respond to such real-time anomalies.

Why this answer

C is correct because the sign-in risk level condition in Conditional Access allows you to target sign-ins that have been assessed by Microsoft Entra ID Protection as risky. Anonymous IP addresses are a specific sign-in risk detection, and configuring the policy to block sign-ins with a 'High' sign-in risk level will automatically block those sign-ins. This directly addresses the security team's requirement to block sign-ins from anonymous IP addresses.

Exam trap

The trap here is that candidates often confuse 'user risk' with 'sign-in risk', mistakenly selecting the user risk level condition when the scenario specifically describes blocking a sign-in event based on the IP address's anonymity.

How to eliminate wrong answers

Option A is wrong because user risk level condition targets the likelihood that a user's identity has been compromised, not the risk of a specific sign-in session from an anonymous IP address. Option B is wrong because the device condition with 'Compliant' is used to require that the device meets compliance policies, which does not block sign-ins based on the IP address's anonymity. Option D is wrong because 'Any IP' in the location condition includes all IP addresses, including trusted ones, and does not specifically target anonymous IP addresses; it would block or allow all sign-ins regardless of IP anonymity.

902
MCQmedium

Your organization is implementing Microsoft Purview to manage data compliance. They need to automatically detect and protect credit card numbers in emails and documents. Which Microsoft Purview feature should they configure?

A.Data Lifecycle Management
B.Data Loss Prevention (DLP)
C.Insider Risk Management
D.Information Protection
AnswerB

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across various locations, including Microsoft 365 services, endpoints, and non-Microsoft cloud apps. These policies leverage sensitive information types (SITs) to automatically detect patterns like credit card numbers, social security numbers, or health records. Upon detection, DLP enforces protective actions such as blocking sharing, notifying users, or encrypting content to prevent data exfiltration and ensure compliance.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the feature designed to automatically detect sensitive information such as credit card numbers in emails, documents, and other workloads, and apply protective actions like blocking, warning, or encrypting. DLP uses sensitive information types (SITs) and trainable classifiers to identify patterns like PCI-DSS credit card numbers and enforce policies across Exchange, SharePoint, OneDrive, Teams, and endpoints.

Exam trap

SC-900 often tests confusion between Information Protection (labels/classification) and DLP (detection/enforcement), catching candidates who pick the labeling feature when the requirement is automatic detection and blocking of sensitive patterns.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management governs retention and deletion of content, not detection and protection of sensitive data in transit or at rest. Option C is wrong because Insider Risk Management detects risky user behavior and potential data exfiltration by insiders, not pattern-based detection of credit card numbers in content. Option D is wrong because Information Protection (sensitivity labels) classifies and protects content but does not automatically detect and block credit card numbers in emails — that enforcement is DLP's role, though labels and DLP often work together.

903
MCQmedium

You are a security analyst using Microsoft Sentinel. You run the following Kusto query: SecurityAlert | where TimeGenerated > ago(7d) | where AlertName contains "MFA" | summarize Count = count() by bin(TimeGenerated, 1d) | render timechart What does this query do?

A.Counts security alerts containing 'MFA' per day for the last 7 days
B.Lists all identities that triggered MFA alerts
C.Counts distinct users with MFA alerts per day
D.Counts alerts by severity over the last week
AnswerA

The query filters SecurityAlert records to the last seven days, then matches alerts whose AlertName contains "MFA". Summarize with count() grouped by bin(TimeGenerated, 1d) aggregates those matches into daily buckets, and render timechart visualises the per-day totals. This satisfies the stem's requirement of counting MFA-related alerts per day.

Why this answer

The query filters the SecurityAlert table to the last 7 days, keeps only alerts whose AlertName contains 'MFA', then summarizes by counting rows grouped into 1-day bins of TimeGenerated, and renders the result as a time chart. The output is therefore a daily count of MFA-related security alerts over the past week.

Exam trap

SC-900 often tests whether candidates read the KQL operators literally — examinees see 'MFA' and 'security alerts' and assume the query lists users or severities, ignoring that 'count()' and the absence of 'by Account' or 'by Severity' limit the output to a raw daily count.

How to eliminate wrong answers

Option B is wrong because the query never projects or summarizes by identity fields such as Account or UserPrincipalName — it only counts rows. Option C is wrong because 'count()' counts alert records, not distinct users; 'dcount()' would be required to count unique identities. Option D is wrong because the query filters on AlertName containing 'MFA' and never references the Severity column, so it does not group by severity.

904
MCQmedium

Your organization is implementing a new policy to ensure that only authorized users can access sensitive financial data stored in Microsoft SharePoint Online. The security team wants to enforce multi-factor authentication (MFA) for all users accessing this data, but only when accessing from outside the corporate network. Which Microsoft Entra ID conditional access policy setting should you configure to meet this requirement?

A.Use app-enforced restrictions for SharePoint
B.Grant access requiring device to be marked as compliant when location is not trusted
C.Grant access requiring multi-factor authentication when the location is not trusted
D.Block access when the location is not trusted
AnswerC

Conditional access evaluates sign-in conditions before granting access. Configuring the grant control to require multi-factor authentication, scoped to the condition where location is not trusted, enforces MFA only for off-network access while trusted corporate connections proceed without the prompt.

Why this answer

The requirement is to enforce MFA for all users accessing sensitive financial data in SharePoint Online, but only when accessing from outside the corporate network. This is achieved by creating a Conditional Access policy that targets the SharePoint Online app, includes all users, and sets the condition to 'any location' excluding trusted locations, then grants access with the requirement of multi-factor authentication.

Exam trap

The trap here is confusing device compliance with MFA, or thinking that blocking access is the only way to secure external access. Candidates might also overlook the need to exclude trusted locations.

How to eliminate wrong answers

Option A is wrong because app-enforced restrictions are used for session control, such as restricting download, not for enforcing MFA. Option B is wrong because requiring a compliant device does not enforce MFA; it checks device compliance, which is a different control. Option D is wrong because blocking access would prevent legitimate access from outside, whereas the requirement is to allow access with MFA.

905
MCQmedium

A company uses Microsoft 365 and sanctioned cloud apps like Salesforce and Box. The security team wants to prevent users from downloading sensitive documents from these apps when accessing from unmanaged personal devices, while still allowing read-only access. They need real-time session monitoring and control. Which Microsoft security solution should they use?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Identity
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Defender for Cloud Apps enforces Conditional Access App Control, a reverse-proxy mechanism that intercepts sessions to sanctioned apps. It applies session policies blocking downloads while permitting read-only access, and provides real-time monitoring. This satisfies the requirement to control unmanaged personal devices without installing agents on them.

Why this answer

Microsoft Defender for Cloud Apps provides real-time session monitoring and control via its Conditional Access App Control feature. This allows administrators to enforce policies that block downloads or restrict access to sensitive data based on device compliance, such as blocking downloads from unmanaged personal devices while permitting read-only access. The solution integrates with sanctioned cloud apps like Salesforce and Box to apply these controls at the session level.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming that Office 365 covers all cloud app security, but Defender for Office 365 is limited to Microsoft 365 services and cannot enforce session policies on third-party SaaS apps like Salesforce or Box.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 focuses on email and collaboration security (e.g., anti-phishing, anti-malware) and does not provide session-level control over third-party cloud apps like Salesforce or Box. Option C is wrong because Microsoft Defender for Identity is designed to detect identity-based threats (e.g., compromised accounts, lateral movement) using on-premises Active Directory signals, not to monitor or control user sessions in cloud apps. Option D is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution that protects devices from malware and attacks, but it does not offer real-time session monitoring or conditional access controls for cloud app sessions.

906
MCQhard

A company uses Microsoft Entra ID. They have a requirement that all administrative role activations must be approved by a designated approver and must be time-bound. Which Microsoft Entra feature should they implement?

A.Microsoft Entra ID Governance
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra Conditional Access
AnswerC

PIM provides just-in-time privileged access with approval workflows and time-bound role assignments. Administrators can activate roles only after approval and for a specified duration. This directly meets the requirement for approval and time-bound activations. PIM also provides audit logs and access reviews, enhancing security and compliance for privileged roles.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) enables just-in-time role activation with approval workflows and time-bound assignments. This ensures that administrative roles are only activated when needed, after approval, and for a limited duration. It is the correct feature to enforce approval and time-bound requirements for privileged roles.

Exam trap

The trap here is assuming that ID Governance or Conditional Access can enforce time-bound role activations with approvals, but only PIM provides just-in-time privileged access management with these controls.

907
Multi-Selectmedium

A company wants to automatically apply a 'Confidential' sensitivity label to any document that contains a credit card number, and also encrypt the document as part of the label. Which two components must be configured to achieve this? (Choose two.)

Select 2 answers
A.A sensitivity label with encryption settings
B.A DLP policy that detects sensitive info
C.An auto-labeling policy
D.A data classification dashboard
AnswersA, C

A sensitivity label with encryption settings supplies the protective action: Azure Information Protection encryption is applied when the label is assigned. This satisfies the stem's requirement to encrypt the document as part of the label, while auto-application to credit card content is handled separately by the other required component.

Why this answer

Option A is correct because the requirement to encrypt the document as part of the label can only be fulfilled by a sensitivity label that has encryption (Azure Rights Management) configured in its protection settings. Option C is correct because automatically applying that label to any document containing a credit card number requires an auto-labeling policy (client-side or service-side) that uses a sensitive information type such as Credit Card Number to trigger the label. Option B is incorrect because a DLP policy detects and can block or warn about sensitive content, but it does not apply sensitivity labels or encrypt documents.

Option D is incorrect because the data classification dashboard is only a reporting/monitoring view of classified content and performs no labeling or encryption.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling policies, thinking DLP can apply labels and encryption, but DLP only detects and acts on content (e.g., block or notify) and does not apply sensitivity labels.

Why the other options are wrong

B

A DLP policy detects sensitive info but does not automatically apply sensitivity labels or encryption; it only triggers alerts or blocks actions. The question requires automatic labeling and encryption, which is handled by auto-labeling policies and sensitivity labels, not DLP.

When would these options actually be correct?

B

A company wants to block emails containing credit card numbers from being sent externally. Which component should be configured? (A DLP policy that detects sensitive info and enforces action.)

Why candidates pick the wrong answer

B

Candidates may confuse DLP's detection of sensitive data with the ability to automatically apply labels, as both involve sensitive info types and can be triggered by content matching.

908
MCQhard

Refer to the exhibit. A Microsoft Purview retention policy is configured as shown. Which statement about this policy is accurate?

A.The policy will delete items after 7 years from the date they were created.
B.The policy will retain items for 7 years from the last modification date.
C.The policy will delete items 7 years after they were last modified.
D.The policy will keep items for 7 years and then delete them.
AnswerC

This statement accurately describes the policy's behavior. The 'RetentionDurationType' is 'ModificationAgeInDays', meaning the the 2557-day (approximately 7 years) period begins from the item's last modification date. Upon reaching this duration, the policy's 'Action' of 'Delete' will be enforced, resulting in the permanent removal of the item.

Why this answer

The exhibit shows a retention policy configured with the action 'Delete items' and a period of '7 years' based on 'When items were last modified.' This means the policy will delete items 7 years after their last modification date, not from creation. Option C correctly states this behavior.

Exam trap

The trap here is that candidates often confuse 'retain items for 7 years then delete' with 'delete items 7 years after last modified,' assuming a retention period exists when the policy is purely deletion-based.

How to eliminate wrong answers

Option A is wrong because the policy is based on the last modification date, not the creation date; items are deleted 7 years after they were last modified, not created. Option B is wrong because the policy deletes items after 7 years from the last modification date, it does not retain them indefinitely; retention implies keeping, but this policy is set to delete. Option D is wrong because it implies a retention period followed by deletion, but the policy is configured to delete based on last modification date, not to retain for a fixed period then delete; the action is 'Delete items' with no retention phase.

909
MCQmedium

A company uses Microsoft 365 and wants to automatically detect when employees attempt to share credit card numbers in emails or Microsoft Teams messages. The company also wants to block the message if it contains such sensitive data, and notify the sender with a policy tip. Which Microsoft Purview solution should the administrator configure?

A.Data Lifecycle Management
B.Data Loss Prevention (DLP)
C.Information Protection (Sensitivity labels)
D.Insider Risk Management
AnswerB

Data Loss Prevention in Microsoft Purview inspects email and Microsoft Teams content for sensitive information types such as credit card numbers, then blocks the message and shows the sender a policy tip. This directly satisfies the detection, blocking and notification requirements.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, block, and notify users when sensitive data—such as credit card numbers—is shared in emails or Teams messages. DLP policies can be configured with built-in sensitive information types (e.g., credit card number) and actions like blocking the message and sending a policy tip to the sender.

Exam trap

The trap here is that candidates often confuse Information Protection (sensitivity labels) with DLP, not realizing that sensitivity labels classify and protect data at rest, while DLP actively monitors and controls data in motion (email and chat).

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management focuses on retaining, deleting, and managing data based on age or compliance requirements, not on real-time detection and blocking of sensitive data sharing. Option C is wrong because Information Protection (Sensitivity labels) is used to classify and protect data at rest (e.g., documents) with encryption or markings, but it does not natively inspect and block messages in transit in email or Teams. Option D is wrong because Insider Risk Management is designed to detect risky user activities (e.g., data theft, policy violations) based on analytics and alerts, not to automatically block messages containing sensitive data in real time.

910
MCQhard

A company stores HR documents in SharePoint Online. The compliance team wants to automatically apply a sensitivity label that encrypts the document whenever it contains a passport number. They do not want users to be able to override this classification. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP) policy
B.Auto-labeling policy for sensitivity labels
C.Retention policy
D.Communication compliance policy
AnswerB

An auto-labeling policy for sensitivity labels automatically applies a pre-defined label to content, such as HR documents in SharePoint Online, when specific conditions are met. These conditions often include the detection of sensitive information types like passport numbers or national ID numbers. The applied label can enforce protection actions, including encryption, and can be configured to prevent users from changing or removing the label, ensuring consistent data protection.

Why this answer

An auto-labeling policy for sensitivity labels can automatically apply a sensitivity label (e.g., 'Highly Confidential') that encrypts documents when they contain sensitive data like passport numbers. This policy can be configured to enforce mandatory labeling without allowing user override, meeting the compliance team's requirement. In contrast, a DLP policy can detect and block sharing of sensitive data but does not apply encryption labels automatically.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, assuming DLP can also apply encryption labels, but DLP only detects and blocks actions—it does not automatically classify or encrypt content.

Why the other options are wrong

A

A DLP policy can detect passport numbers and block sharing, but it cannot automatically apply sensitivity labels that encrypt documents. The requirement is to apply a sensitivity label with encryption, which is a feature of auto-labeling policies, not DLP.

C

A retention policy is used to retain or delete content based on time, not to classify or encrypt documents based on content. It cannot automatically apply sensitivity labels or enforce encryption.

D

Communication compliance policies detect and remediate inappropriate messages (e.g., harassment, sensitive info sharing) in communications like email and Teams, not automatically classify or encrypt documents in SharePoint based on content.

When would these options actually be correct?

A

A DLP policy would be correct if the question asked for a solution to prevent users from sharing documents containing passport numbers via email or external sharing, without requiring encryption or label application.

C

A retention policy would be correct if the question asked: 'The compliance team wants to ensure that HR documents are kept for 7 years and then permanently deleted. Which solution should they configure?'

D

A company wants to detect and prevent employees from sharing passport numbers in email or Teams messages, and automatically flag or quarantine such communications for review by a compliance officer.

Why candidates pick the wrong answer

A

Candidates often confuse DLP with auto-labeling because both can detect sensitive content; they may assume DLP can also apply labels, but DLP focuses on preventing data loss, not on classification and protection via labels.

C

Candidates may confuse retention policies with labeling policies because both involve managing document lifecycle and compliance, but retention policies focus on time-based actions, not content-based classification.

D

Candidates may confuse communication compliance with auto-labeling because both involve detecting sensitive information, but communication compliance focuses on communications rather than document classification and encryption.

911
MCQeasy

Your organization wants to use Microsoft Entra Verified ID to issue digital credentials to employees. Which Microsoft Entra service provides the ability to issue and verify verifiable credentials?

A.Microsoft Entra Entitlement Management
B.Microsoft Entra Verified ID
C.Microsoft Entra Identity Protection
D.Microsoft Entra Privileged Identity Management
AnswerB

Microsoft Entra Verified ID is the dedicated service for implementing decentralized identity and managing verifiable credentials (VCs). It enables organizations to issue digital attestations, such as proof of employment or qualifications, to individuals, who then hold these VCs in a digital wallet. This service facilitates a trust framework where issuers can attest to facts about a user, and verifiers can cryptographically confirm the authenticity of these credentials without relying on a central authority, directly addressing the need for verifiable identity proofs.

Why this answer

Microsoft Entra Verified ID is the specific service designed to issue and verify verifiable credentials based on decentralized identity standards such as W3C Verifiable Credentials and Decentralized Identifiers (DIDs). It enables organizations to create, issue, and cryptographically verify digital credentials without relying on a central authority, aligning with the scenario described.

Exam trap

The trap here is that candidates may confuse 'Verified ID' with other identity governance or security services like Entitlement Management or Identity Protection, but only Verified ID directly handles the issuance and verification of verifiable credentials using decentralized identity standards.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Entitlement Management focuses on automating access reviews, access packages, and lifecycle management for applications and groups, not on issuing or verifying verifiable credentials. Option C is wrong because Microsoft Entra Identity Protection is a security tool that detects identity-based risks like compromised accounts and sign-in anomalies, not a credential issuance or verification service. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged role assignments and access approvals, not the creation or verification of digital credentials.

912
MCQmedium

A security team manages a hybrid environment with on-premises Windows servers and Azure VMs. They need a solution that can detect lateral movement attacks, pass-the-hash attempts, and anomalous service account behavior on the on-premises Active Directory environment. They also want these alerts to be integrated into Microsoft Defender for Cloud for centralized monitoring. Which Microsoft security solution should they deploy on their on-premises domain controllers?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Identity
C.Microsoft Defender for Endpoint
D.Microsoft Intune
AnswerB

Microsoft Defender for Identity is a cloud-based security solution specifically engineered to protect hybrid identity environments, integrating deeply with on-premises Active Directory. It leverages network traffic from domain controllers and Windows events to detect suspicious user and entity behavior, identifying advanced threats like reconnaissance, lateral movement, Golden Ticket attacks, and other identity-based attacks. This service provides crucial visibility and detection capabilities for attacks targeting the core authentication system in a hybrid setup.

Why this answer

Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to monitor on-premises Active Directory traffic and detect advanced threats like lateral movement, pass-the-hash, and anomalous service account behavior. It integrates directly with Microsoft Defender for Cloud to provide centralized alerting and investigation across hybrid environments.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Identity with Microsoft Defender for Endpoint, assuming endpoint protection covers identity threats, but MDI is the only solution that directly monitors on-premises Active Directory for lateral movement and pass-the-hash attacks.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 protects against email-based threats (phishing, malware in attachments/links) and does not monitor on-premises Active Directory or detect lateral movement or pass-the-hash attacks. Option C is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices (Windows, Linux, macOS) and does not natively analyze on-premises AD domain controller traffic for identity-based attacks. Option D is wrong because Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) solution; it does not provide security monitoring or threat detection for on-premises Active Directory.

913
MCQmedium

A security operations team investigates a multi-stage attack that began with a phishing email, then moved to credential compromise, and finally to lateral movement on endpoints. They need a single pane of glass to view the entire attack story, including the initial email, the compromised user's sign-in activities, and processes on affected devices. Which Microsoft security solution provides this unified investigation experience?

A.Microsoft Sentinel
B.Microsoft Defender for Cloud
C.Microsoft 365 Defender
D.Microsoft Defender for Identity
AnswerC

Microsoft 365 Defender is the unified XDR (Extended Detection and Response) solution designed to protect an organization's entire digital estate across endpoints, email, identity, and cloud applications. It automatically correlates alerts and incidents from its constituent services (Defender for Endpoint, Office 365, Identity, and Cloud Apps) into a single, comprehensive incident view. This unified perspective is crucial for investigating multi-stage attacks, as it provides a holistic timeline and context across various attack vectors, enabling security operations teams to understand the full scope and impact of sophisticated threats.

Why this answer

Microsoft 365 Defender (now Microsoft Defender XDR) provides a unified investigation experience by correlating signals across email, identity, and endpoint domains into a single incident view. This allows the security team to see the full attack story—from the initial phishing email in Defender for Office 365, to the compromised user's sign-in activities via Defender for Identity, and the lateral movement processes on endpoints through Defender for Endpoint—all within one console.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft 365 Defender (an XDR), assuming that any cross-domain investigation requires a SIEM, when in fact Microsoft 365 Defender provides the native, pre-correlated attack story across email, identity, and endpoints without needing custom log ingestion.

Why the other options are wrong

A

Microsoft Sentinel is a SIEM/SOAR solution that aggregates logs from multiple sources, but it does not natively provide a unified investigation experience across email, identity, and endpoints in a single attack story. The question specifically asks for a single pane of glass for the entire attack chain, which is a core capability of Microsoft 365 Defender.

B

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP), not a unified investigation experience for multi-stage attacks spanning email, identity, and endpoints.

D

Microsoft Defender for Identity focuses on detecting and investigating identity-based threats using on-premises Active Directory signals, but it does not provide a unified view across email, cloud app sign-ins, and endpoint processes as required by this multi-stage attack scenario.

When would these options actually be correct?

A

A question that asks: 'Which Microsoft solution provides a cloud-native SIEM and SOAR platform for security analytics and threat intelligence across the enterprise?' In that context, Microsoft Sentinel would be the correct answer because it ingests data from various sources and enables custom detection and response.

B

A question asking: 'Which Microsoft solution provides security posture management and threat protection for hybrid cloud workloads across Azure, AWS, and GCP?' would make Microsoft Defender for Cloud the correct answer.

D

A question that asks: 'Which Microsoft solution provides advanced threat analytics and alerts for on-premises Active Directory attacks, such as pass-the-hash or golden ticket attacks?' would have Microsoft Defender for Identity as the correct answer.

Why candidates pick the wrong answer

A

Candidates may think Sentinel is the central security tool for all investigations because it can collect data from many sources, but they overlook that Microsoft 365 Defender offers a built-in, unified incident view specifically for the Microsoft 365 ecosystem.

B

Candidates may confuse 'Defender for Cloud' with the broader Microsoft 365 Defender suite, assuming it covers all security scenarios, or they may think it provides a unified investigation pane due to its name containing 'Defender'.

D

Candidates may associate Defender for Identity with identity compromise and lateral movement, but overlook that the question requires a single pane of glass covering email, sign-ins, and endpoints, which is the domain of Microsoft 365 Defender.

914
MCQmedium

A company uses Microsoft 365 and needs to automatically apply a retention label to documents that contain personally identifiable information (PII) in SharePoint Online. The label should retain the documents for 5 years and then delete them. Which Microsoft Purview solution should they use?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview eDiscovery
AnswerC

Microsoft Purview Data Lifecycle Management (DLM) is specifically engineered to manage the lifecycle of information, including its retention and eventual disposition. DLM utilizes retention labels that can be manually applied or automatically assigned to content based on specific conditions, such as sensitive information types, keywords, or content properties. These labels then enforce retention periods, ensuring data is kept for the required duration and automatically deleted when no longer needed, directly addressing the need for automated retention and deletion policies.

Why this answer

Microsoft Purview Data Lifecycle Management (formerly known as Microsoft 365 Records Management) is the solution specifically designed to apply retention labels and policies that automatically retain content for a specified period and then delete it. In this scenario, the requirement to automatically apply a retention label to documents containing PII in SharePoint Online and then retain them for 5 years before deletion is a core capability of Data Lifecycle Management, which uses auto-labeling policies based on sensitive information types.

Exam trap

The trap here is that candidates often confuse the purpose of Data Lifecycle Management (retention and deletion) with Information Protection (sensitivity labels and encryption), especially since both use labels and can be auto-applied based on sensitive content.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying and protecting data through sensitivity labels (e.g., encryption, marking), not on retention and deletion schedules. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental sharing of sensitive data by enforcing policies (e.g., blocking or warning), not to manage retention or deletion. Option D is wrong because Microsoft Purview eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for applying retention labels or managing lifecycle policies.

915
MCQmedium

A company uses Microsoft Defender for Office 365 and wants to protect users from malicious attachments in email. They need a feature that scans email attachments in a sandbox environment before they are delivered to recipients. Which Defender for Office 365 feature should they use?

A.Safe Links
B.Safe Attachments
C.Anti-phishing policies
D.Anti-spam policies
AnswerB

Safe Attachments is a critical component of Microsoft Defender for Office 365 that provides advanced, zero-day protection against unknown malware and viruses in email attachments. It employs a detonation chamber, or sandboxing technology, to open and analyze attachments in a secure, isolated virtual environment. This process determines if an attachment is malicious before it is delivered to the user's inbox, making it the precise solution for scanning email attachments for threats.

Why this answer

Safe Attachments is the correct feature because it specifically detonates email attachments in a sandbox environment before delivery, analyzing them for malicious behavior. This protects users from zero-day threats and advanced malware that signature-based detection might miss.

Exam trap

The trap here is confusing Safe Attachments (which scans attachments in a sandbox) with Safe Links (which scans URLs), as both are part of Microsoft Defender for Office 365 but serve different protection purposes.

How to eliminate wrong answers

Option A is wrong because Safe Links protects users from malicious URLs in email and Office documents, not attachments. Option C is wrong because Anti-phishing policies protect against phishing attempts by analyzing sender reputation and impersonation patterns, not by scanning attachments in a sandbox. Option D is wrong because Anti-spam policies filter unwanted bulk email based on content and sender reputation, not by detonating attachments in a sandbox.

916
MCQhard

Your organization, Contoso, uses Microsoft Entra ID P2. You have a Microsoft Entra tenant with several privileged roles including Global Administrator, Exchange Administrator, and SharePoint Administrator. The security team wants to enforce just-in-time (JIT) access for these roles, requiring users to request activation and get approval before they can use the role. Additionally, all activations must be logged and reviewed monthly. What should you configure?

A.Configure Microsoft Entra Privileged Identity Management (PIM) to require approval for role activation and enable access reviews.
B.Configure Conditional Access policies to require MFA for privileged roles.
C.Use Microsoft Entra Entitlement Management to create access packages for roles.
D.Create an Identity Protection risk policy to block risky sign-ins for privileged users.
AnswerA

Microsoft Entra Privileged Identity Management (PIM) is the dedicated service for managing, controlling, and monitoring access to important resources. It enables just-in-time (JIT) access, meaning users are assigned privileged roles only when needed and for a limited duration. Requiring approval for role activation ensures an additional layer of control, while access reviews provide periodic verification that users still require their assigned privileges, enforcing the principle of least privilege.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by requiring users to activate their role assignments with approval from designated approvers. It also includes access reviews that can be scheduled to audit and confirm active role assignments, meeting the logging and monthly review requirements. This directly addresses the need for activation approval and periodic review of privileged role usage.

Exam trap

The trap here is confusing Conditional Access policies (which control sign-in conditions) with PIM (which controls role activation and approval workflows), leading candidates to select MFA enforcement instead of the JIT and review capabilities unique to PIM.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies enforce authentication requirements (like MFA) during sign-in but do not provide JIT activation workflows, approval processes, or scheduled access reviews for privileged roles. Option C is wrong because Entitlement Management manages access packages for resource access (e.g., groups, apps, sites) but does not handle role activation approval or time-bound JIT elevation for Entra ID administrative roles. Option D is wrong because Identity Protection risk policies block or require MFA for risky sign-ins, but they do not control role activation, require approval, or log/review privileged role usage.

917
Multi-Selecteasy

Your organization is implementing Microsoft Purview to govern data across Microsoft 365 and Azure. Which TWO capabilities should you use to discover and classify sensitive data?

Select 2 answers
A.Microsoft Purview Information Protection
B.Microsoft Purview Data Map
C.Microsoft Purview eDiscovery
D.Microsoft Purview Audit
E.Microsoft Purview Data Lifecycle Management
AnswersA, B

Microsoft Purview Information Protection (MPIP) is a core component for classifying and protecting sensitive data throughout its lifecycle. It enables organizations to define and apply sensitivity labels, which can automatically detect sensitive information types and then apply visual markings, encryption, or access restrictions. This capability directly addresses the need to classify data based on its sensitivity and apply appropriate protective measures.

Why this answer

Microsoft Purview Information Protection (A) enables you to discover, classify, and protect sensitive data by applying sensitivity labels and analyzing content via data loss prevention (DLP) policies. Microsoft Purview Data Map (B) provides automated scanning and classification of data assets across Azure and Microsoft 365, building a unified map of sensitive data locations. Together, they fulfill the discovery and classification requirements.

Exam trap

The trap here is that candidates often confuse eDiscovery or Audit with classification capabilities, but eDiscovery is for legal holds and search, and Audit is for activity logging—neither discovers or classifies sensitive data.

918
MCQhard

You are troubleshooting a Windows device that is reporting as non-compliant in Microsoft Intune. The exhibit shows the output of a PowerShell command run on the device. Based on the output, which component is likely misconfigured?

A.Microsoft Defender for Endpoint sensor onboarding
B.Antivirus protection
C.Antispyware protection
D.Microsoft Defender Antivirus real-time protection
AnswerA

Intune compliance reflects device health signals reported by the Defender for Endpoint sensor; if onboarding is incomplete, the device cannot attest its risk state, so it falls out of compliance. Verifying sensor onboarding in the Defender portal resolves the misconfiguration shown.

Why this answer

The PowerShell output shows the 'OnboardingState' value is 0, which indicates the device is not onboarded to Microsoft Defender for Endpoint. Intune uses the Defender for Endpoint sensor as a compliance signal; if the sensor is not properly onboarded, the device will report as non-compliant regardless of other security settings.

Exam trap

The trap here is that candidates often confuse 'onboarding state' with 'real-time protection' or 'antivirus status', but the PowerShell output explicitly shows the 'OnboardingState' property, which is unique to Microsoft Defender for Endpoint sensor configuration, not to Microsoft Defender Antivirus settings.

How to eliminate wrong answers

Option B is wrong because antivirus protection status is not indicated by the 'OnboardingState' value; it is a separate compliance policy setting. Option C is wrong because antispyware protection is a subset of antivirus protection and is not directly tied to the sensor onboarding state shown in the output. Option D is wrong because real-time protection is a feature of Microsoft Defender Antivirus, not the Defender for Endpoint sensor onboarding process; the output specifically shows the sensor onboarding state, not real-time protection status.

919
MCQmedium

A financial institution is deploying Microsoft Sentinel to monitor security events across its hybrid cloud environment. They want to correlate alerts from multiple sources and automate incident response. Which Microsoft Sentinel feature should they use to create automated workflows?

A.Workbooks
B.Analytics rules
C.Playbooks
D.Hunting queries
AnswerC

Playbooks in Microsoft Sentinel, powered by Azure Logic Apps, are automated, scalable, and customizable workflows designed to orchestrate and automate incident response tasks. They can be triggered by analytics rules, incidents, or manual actions, performing predefined actions such as enriching incident data, blocking malicious IP addresses, isolating compromised hosts, or notifying security teams via various communication channels. This automation significantly reduces manual effort and accelerates response times.

Why this answer

Playbooks in Microsoft Sentinel are built on Azure Logic Apps and allow you to automate incident response by defining a series of actions triggered by alerts. They can orchestrate tasks such as blocking IPs, opening tickets, or notifying teams, making them the correct choice for creating automated workflows.

Exam trap

The trap here is confusing the purpose of Analytics rules (alert generation) with Playbooks (automated response), as both are part of the detection and response pipeline but serve distinct roles.

How to eliminate wrong answers

Option A is wrong because Workbooks are used for visualizing and analyzing data through dashboards, not for automating workflows. Option B is wrong because Analytics rules define conditions for generating alerts from data sources, but they do not execute automated response actions. Option D is wrong because Hunting queries are ad-hoc searches for potential threats in raw log data, not for creating automated incident response workflows.

920
MCQhard

Refer to the exhibit. A Microsoft Graph PowerShell script is shown. What is the purpose of this script?

A.Register a phone authentication method for users.
B.Configure self-service password reset settings.
C.Reset passwords for all users named John.
D.Enable multifactor authentication for the users.
AnswerA

The PowerShell script utilizes the `New-MgUserAuthenticationPhoneMethod` cmdlet, which is specifically designed to add a new phone authentication method to a specified user's authentication methods in Microsoft Entra ID. This action registers a phone number, making it available for use in scenarios such as SMS-based multifactor authentication or passwordless sign-in, but does not inherently enable MFA itself. It's a foundational step for phone-based authentication.

Why this answer

The script uses the `New-MgUserAuthenticationPhoneMethod` cmdlet to register a phone number as an authentication method for a user in Microsoft Entra ID. This cmdlet specifically creates a phone authentication method, which can be used for multifactor authentication or self-service password reset, but its direct purpose is to register the phone method itself.

Exam trap

The trap here is that candidates confuse registering a phone authentication method with enabling MFA or configuring SSPR, because the phone method is a common component of both, but the cmdlet's specific purpose is only to register the method, not to enable the broader feature.

How to eliminate wrong answers

Option B is wrong because configuring self-service password reset (SSPR) settings requires cmdlets like `Update-MgPolicyAuthenticationMethodPolicy` or `Set-MgUserAuthenticationMethodPolicy`, not `New-MgUserAuthenticationPhoneMethod`. Option C is wrong because the script does not perform any password reset operation; it only registers a phone method, and it targets a single user by UserPrincipalName, not all users named John. Option D is wrong because enabling multifactor authentication (MFA) for users is done via Conditional Access policies or per-user MFA settings, not by registering a phone method; the cmdlet only adds a phone as an authentication method, which is a prerequisite but not the act of enabling MFA.

921
MCQeasy

Your organization uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) for all users. Which policy should you create?

A.Conditional Access policy
B.Identity Protection policy
C.Security defaults
D.Privileged Identity Management
AnswerA

Conditional Access policies are the primary method in Microsoft Entra ID for enforcing granular access controls, including multi-factor authentication (MFA). They evaluate conditions such as user, device, location, and application to determine if access should be granted, blocked, or require additional authentication methods like MFA, making them highly flexible for enforcing specific security requirements across an organization.

Why this answer

Conditional Access policies are the correct mechanism to enforce MFA for all users because they allow granular, policy-driven access controls based on signals like user, location, device, and application. By creating a Conditional Access policy that requires MFA for all cloud apps, you can target all users and enforce MFA at authentication time, providing a flexible and scalable solution.

Exam trap

The trap here is that candidates confuse Security defaults (a simple, pre-configured baseline) with a customizable policy, but Security defaults is not a policy you 'create'—it is an all-or-nothing toggle that cannot be scoped or modified, whereas Conditional Access policies are the correct, granular tool for enforcing MFA.

How to eliminate wrong answers

Option B is wrong because Identity Protection policies are designed to detect and respond to risks (e.g., leaked credentials, sign-ins from anonymous IPs) and can automatically trigger MFA based on risk level, but they cannot enforce MFA for all users unconditionally. Option C is wrong because Security defaults is a baseline set of security configurations that includes enforcing MFA for all users, but it is a tenant-wide setting that cannot be customized or scoped; it is not a policy you 'create' but rather enable or disable. Option D is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and approval workflows for roles, not MFA enforcement for all users; it manages role activation, not authentication requirements.

922
MCQmedium

Refer to the exhibit. A Microsoft Purview DLP policy is configured. When a user attempts to share a document containing a credit card number externally, what will happen?

A.The document is shared but the user is notified.
B.The sharing attempt is blocked and the user receives a notification.
C.The document is encrypted before sharing.
D.The policy has no effect because no severity level is set.
AnswerB

This option accurately describes the combined effect of common DLP policy actions. A Microsoft Purview DLP policy can be configured with multiple actions for a single rule. When BlockAccess is specified, it actively prevents the sharing attempt, ensuring the sensitive information remains within the defined boundaries. Concurrently, the NotifyUser action ensures that the individual attempting the prohibited action receives an immediate notification, explaining why their action was blocked and often providing guidance on compliance.

Why this answer

The exhibit shows a Microsoft Purview DLP policy configured with a 'Block' action for sharing documents containing credit card numbers externally. When the action is set to 'Block', the sharing attempt is prevented, and the user receives a notification explaining why the action was blocked. This aligns with the default behavior of DLP policies that enforce restrictive actions on sensitive data.

Exam trap

The trap here is that candidates may assume a missing severity level disables the policy, but in Microsoft Purview DLP, severity is only for reporting and alerting—the configured actions (e.g., Block, Notify) are enforced independently of severity settings.

How to eliminate wrong answers

Option A is wrong because the policy action is set to 'Block', not 'Audit' or 'Notify only', so the document is not shared; the user is notified but the sharing is blocked. Option C is wrong because encryption is a separate action (e.g., 'Encrypt' in sensitivity labels or DLP with Azure Information Protection), and the exhibit shows no encryption action configured—only 'Block' and 'Notify'. Option D is wrong because severity level is optional in DLP policies; the policy still enforces its configured actions (Block and Notify) regardless of whether a severity level is set.

923
MCQeasy

A healthcare organization needs to automatically classify documents containing patient health information (PHI) in Microsoft SharePoint. The solution should apply a 'Confidential - Healthcare' sensitivity label to any document that matches the HIPAA content pattern. Which Microsoft Purview feature should be used?

A.Retention label auto-apply
B.Manual sensitivity labeling
C.Data loss prevention (DLP) policy
D.Auto-labeling for sensitivity labels
AnswerD

Auto-labeling for sensitivity labels scans SharePoint content and applies the 'Confidential - Healthcare' label automatically when a document matches the HIPAA pattern, satisfying the requirement to classify PHI without manual intervention. It uses service-side scanning with exact data match or trainable classifiers, unlike client-side labelling or manual application.

Why this answer

Auto-labeling for sensitivity labels (Option D) is correct because it automatically applies the specified sensitivity label to documents that match a defined pattern (e.g., HIPAA content) in SharePoint. Option A is wrong because retention label auto-apply is for retention, not sensitivity. Option B is wrong because manual labeling requires user action and does not auto-classify.

Option C is wrong because DLP policies enforce rules to prevent data loss, they do not apply sensitivity labels.

924
MCQeasy

A company deploys firewalls, intrusion detection systems, and endpoint antivirus software at multiple layers of its network. This strategy is intended to ensure that if one security control fails, others still provide protection. Which security concept does this approach represent?

A.Defense in depth
B.Least privilege
C.Separation of duties
D.Zero trust
AnswerA

Defense in depth is a cybersecurity strategy that employs multiple, overlapping security controls to protect information and systems. This layered approach ensures that if one security mechanism fails or is bypassed, other controls are in place to prevent or detect unauthorized access. The deployment of firewalls and intrusion detection systems, as described, exemplifies this strategy by creating successive barriers against threats.

Why this answer

Defense in depth is a security strategy that layers multiple independent controls—such as firewalls, intrusion detection systems (IDS), and endpoint antivirus—across different network segments. The core principle is that if one layer is breached or fails, subsequent layers continue to provide protection, ensuring no single point of failure compromises the entire security posture.

Exam trap

The trap here is that candidates confuse 'defense in depth' with 'zero trust' because both involve multiple security controls, but zero trust is specifically about eliminating implicit trust through continuous verification, not about layering independent defenses.

Why the other options are wrong

B

The question describes multiple layers of security controls (firewalls, IDS, antivirus) to ensure protection if one fails, which is the definition of defense in depth, not least privilege.

C

Separation of duties is about dividing responsibilities among different people to prevent fraud or error, not about layering security controls to provide redundancy. The question describes multiple security layers, which is defense in depth, not separation of duties.

D

Zero trust is a security model that assumes no implicit trust and requires continuous verification of every access request, not the layered deployment of security controls described in the question.

When would these options actually be correct?

B

A question that asks: 'A company configures user accounts so that employees can only access files necessary for their job roles. Which security concept does this represent?' — here, least privilege is the correct answer.

C

A question that asks: 'A company requires that no single employee can approve a purchase order and also receive the goods. This policy reduces the risk of fraud. Which security concept does this represent?' In that scenario, separation of duties would be the correct answer.

D

A question that asks: 'A company implements a security model where no user or device is trusted by default, and every access request is authenticated and authorized regardless of location.'

Why candidates pick the wrong answer

B

Candidates may confuse the principle of limiting access (least privilege) with the layered approach of defense in depth, or they might think that implementing multiple controls inherently restricts privileges.

C

Candidates may confuse 'separation of duties' with 'defense in depth' because both involve multiple controls, but separation of duties focuses on task division among people, not layered technical defenses.

D

Candidates may confuse the layered approach of defense in depth with the 'never trust, always verify' principle of zero trust, as both involve multiple security measures.

925
MCQmedium

Contoso Pharmaceuticals is implementing Microsoft Purview to meet regulatory compliance (HIPAA and GDPR). They need to: (1) automatically classify and protect patient health information (PHI) and personally identifiable information (PII) in Exchange Online, SharePoint Online, and OneDrive for Business; (2) detect and prevent unauthorized sharing of sensitive data; (3) retain audit logs for 7 years; and (4) allow users to manually apply classification labels to documents. The company has 5,000 users and uses Microsoft 365 E5 licenses. The security team wants to minimize manual effort and ensure consistent protection. What should the compliance administrator configure first?

A.Configure Data Loss Prevention (DLP) policies to block sharing of content containing PHI and PII.
B.Create sensitivity labels with auto-labeling policies configured to detect PHI and PII, and publish them via label policies.
C.Set up retention policies for Exchange, SharePoint, and OneDrive to retain data for 7 years.
D.Enable auditing for all workloads and configure alert policies for unauthorized access.
AnswerB

Sensitivity labels with auto-labelling policies satisfy the automated classification and protection requirement across Exchange Online, SharePoint Online and OneDrive for Business, detecting PHI and PII at scale. Publishing via label policies makes labels available for manual application, meeting the user-driven labelling requirement with minimal manual effort.

Why this answer

Sensitivity labels with auto-labeling policies are the foundational Purview capability that classifies and protects PHI/PII across Exchange, SharePoint, and OneDrive, and they also enable users to manually apply labels. Auto-labeling uses trainable classifiers and sensitive information types (SITs) to detect content and apply protection (encryption, markings) consistently with minimal manual effort. DLP, retention, and auditing build on top of labels but do not themselves provide the classification-and-protection layer the scenario requires first.

Exam trap

SC-900 often tests the ordering of Purview components, and candidates frequently pick DLP first because it sounds like the most direct 'prevent sharing' control, missing that labels are the prerequisite classification layer.

How to eliminate wrong answers

Option A is wrong because DLP policies enforce sharing restrictions but do not classify or protect content at rest — they depend on labels or SITs to identify sensitive data and cannot apply encryption. Option C is wrong because retention policies only govern data lifecycle and do not classify, protect, or prevent sharing. Option D is wrong because auditing and alert policies provide visibility and detection but do not classify or protect PHI/PII, and they are a monitoring layer, not a protection layer.

926
MCQhard

A financial services firm uses Microsoft Purview Information Barriers to prevent traders from communicating with investment bankers. A new employee in the trading department cannot access a SharePoint site used for compliance training. What should the administrator do?

A.Add the employee to the 'Traders' Microsoft 365 group.
B.Add the employee to the 'Traders' segment in Microsoft Purview Information Barriers.
C.Use the 'Override' option in the Information Barrier policy.
D.Disable the Information Barrier policy for the trading department.
AnswerB

Microsoft Purview Information Barriers operate by defining distinct user segments based on specific user attributes and then applying policies to restrict communication and collaboration between these segments. To allow an employee to legitimately communicate and collaborate with others in the 'Traders' segment, their user account must be correctly assigned to that 'Traders' segment. This is typically achieved by updating the relevant user attribute in Microsoft Entra ID that defines the 'Traders' segment, ensuring compliance with the established IB policies.

Why this answer

Microsoft Purview Information Barriers use segments to group users based on their organizational roles. Adding the new employee to the 'Traders' segment ensures that the Information Barrier policy applies to them correctly, allowing them to access the compliance training SharePoint site while still being blocked from communicating with investment bankers.

Exam trap

The trap here is that candidates confuse Microsoft 365 groups with Purview segments, assuming that adding a user to a group will automatically resolve Information Barrier restrictions, when in fact segments are the only mechanism for defining user roles in these policies.

How to eliminate wrong answers

Option A is wrong because adding the employee to the 'Traders' Microsoft 365 group does not affect Information Barrier segmentation; segments are separate from Microsoft 365 groups and are defined in Purview. Option C is wrong because the 'Override' option in Information Barrier policies is not a standard feature; policies are enforced automatically and cannot be overridden per user. Option D is wrong because disabling the Information Barrier policy for the entire trading department would remove compliance controls for all traders, which is excessive and not the correct solution for granting access to a single site.

927
MCQeasy

A company wants to block users from accessing phishing websites via Microsoft Edge. Which Microsoft security solution should they use?

A.Microsoft Defender for Endpoint
B.Microsoft Purview
C.Microsoft Intune
D.Microsoft Defender SmartScreen
AnswerD

Microsoft Defender SmartScreen is a security feature integrated into Microsoft Edge and other Windows components that provides real-time protection against phishing sites, malicious websites, and potentially unwanted software downloads. It actively checks websites and files against a dynamic list of reported malicious content, alerting users or blocking access to help prevent them from falling victim to social engineering attacks or malware infections. This direct, browser-level intervention is precisely what's needed to block users from accessing phishing websites.

Why this answer

Microsoft Defender SmartScreen is the correct solution because it is specifically designed to protect users from phishing and malicious websites directly within Microsoft Edge. It operates by comparing visited URLs against a dynamic list of reported phishing sites and analyzing site behavior in real time, blocking access before the user can interact with the page.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Endpoint (a broad EDR platform) with the browser-specific anti-phishing feature, assuming that any 'Defender' product covers all security scenarios, when in fact SmartScreen is a distinct, lightweight component built into Edge.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint is an enterprise endpoint detection and response (EDR) solution that focuses on post-breach detection, investigation, and remediation of advanced threats on devices, not on blocking phishing websites in the browser. Option B is wrong because Microsoft Purview is a data governance, compliance, and risk management solution that handles data classification, retention, and eDiscovery, not real-time web threat blocking. Option C is wrong because Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not a browser-based anti-phishing filter.

928
MCQhard

A company wants to gain visibility into the use of unsanctioned cloud applications (shadow IT) within their organization. The security team has access to network proxy logs that show traffic to various cloud services. They want to use a Microsoft security solution to analyze these logs and identify which cloud apps are being used, by whom, and how much data is being consumed. Which capability of Microsoft Defender for Cloud Apps should they use?

A.App governance
B.Cloud Discovery
C.Conditional Access App Control
D.App Connectors
AnswerB

Cloud Discovery, a core component of Microsoft Defender for Cloud Apps (MDCA), is specifically designed to analyze traffic logs from firewalls, proxies, and other network devices to identify all cloud applications accessed by users. This process enables organizations to gain comprehensive visibility into 'shadow IT' – unsanctioned cloud applications – and assess their associated risks, providing crucial insights into usage patterns across the environment.

Why this answer

Cloud Discovery in Microsoft Defender for Cloud Apps analyzes network proxy logs (or traffic logs from firewalls and proxies) to identify unsanctioned cloud app usage (shadow IT). It provides visibility into which cloud apps are being used, by which users, and how much data is consumed, directly matching the company's requirement to analyze logs for shadow IT detection.

Exam trap

The trap here is that candidates confuse Cloud Discovery (log analysis for shadow IT discovery) with App Connectors (API-based integration for managed apps), leading them to select App Connectors because they think 'connecting' to apps is needed to see usage.

Why the other options are wrong

A

App governance focuses on managing and governing app permissions and policies for OAuth-enabled apps, not on analyzing network proxy logs to discover unsanctioned cloud app usage.

C

Conditional Access App Control is used to enforce access policies on cloud apps in real-time, not to analyze proxy logs for discovering unsanctioned app usage. The question specifically requires analyzing network proxy logs to identify shadow IT, which is the function of Cloud Discovery.

D

App Connectors are used to connect to specific cloud apps via APIs for deep visibility and control, not to analyze network proxy logs for discovering unsanctioned cloud apps.

When would these options actually be correct?

A

A question asks: 'Which Microsoft Defender for Cloud Apps capability should an organization use to monitor and control app permissions for third-party OAuth apps connected to Microsoft 365?'

C

An exam scenario where an organization needs to enforce real-time access controls (e.g., block downloads or require multi-factor authentication) for specific cloud apps based on user or device conditions, using Microsoft Defender for Cloud Apps' reverse proxy capabilities.

D

When a company needs to enforce policies and gain granular visibility into sanctioned cloud apps (e.g., Office 365, Salesforce) by connecting directly via APIs to monitor user activities, data, and compliance.

Why candidates pick the wrong answer

A

Candidates may confuse 'governance' with 'discovery' because both involve monitoring cloud apps, but App governance is specifically for OAuth app permissions, not for identifying shadow IT from network logs.

C

Candidates may confuse Conditional Access App Control with Cloud Discovery because both are features of Defender for Cloud Apps, and the term 'control' might seem related to managing unsanctioned apps, but the question asks for analysis, not enforcement.

D

Candidates may think 'App Connectors' is the right tool because it involves connecting to cloud apps, but they overlook that the question specifies analyzing network proxy logs for shadow IT discovery, which is Cloud Discovery's function.

929
MCQhard

An organization's security team needs to investigate a security incident that occurred two months ago. They need to search the unified audit log for specific activities performed by a user, such as file access, email actions, and sign-in events, to understand the scope of the compromise. Which Microsoft Purview solution provides these audit log search capabilities?

A.Microsoft Purview eDiscovery
B.Microsoft Purview Audit
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Communication Compliance
AnswerB

Microsoft Purview Audit (Standard and Premium) is specifically designed to capture, retain, and enable searching of user and administrator activities across Microsoft 365 services via the unified audit log. This capability is crucial for security investigations, allowing organizations to identify who performed what action, when, and from where. It provides the necessary historical data to understand the scope and timeline of a security incident, directly addressing the need to investigate security events.

Why this answer

Microsoft Purview Audit (specifically Audit (Standard) or Audit (Premium)) provides the ability to search the unified audit log for activities like file access, email actions, and sign-in events. This solution is designed for forensic investigation of user and admin activity within Microsoft 365, making it the correct choice for investigating a security incident that occurred two months ago.

Exam trap

The trap here is that candidates often confuse eDiscovery (which deals with legal holds and content search) with Audit (which deals with activity logs), leading them to select eDiscovery when the question specifically asks for searching user activities like file access and sign-in events.

Why the other options are wrong

A

Microsoft Purview eDiscovery is designed for legal discovery and exporting content from mailboxes, SharePoint, and Teams, not for searching the unified audit log for historical user activities like file access, email actions, and sign-in events.

C

Microsoft Purview Data Lifecycle Management governs data retention and deletion policies, not audit log search. It does not provide the ability to search historical user activities like file access, email actions, or sign-in events.

D

Microsoft Purview Communication Compliance is designed to detect and manage inappropriate communications (e.g., offensive language, conflicts of interest) within an organization, not to search the unified audit log for historical activities like file access or sign-in events.

When would these options actually be correct?

A

A question asking: 'An organization needs to search and export relevant emails, documents, and Teams messages as evidence for a lawsuit. Which Microsoft Purview solution should they use?' — eDiscovery would be correct for legal hold and content search.

C

A question asking which solution manages retention policies for regulatory compliance, such as automatically deleting emails after a set period or preserving data for legal holds, would make Data Lifecycle Management the correct answer.

D

An organization needs to identify and review communications that violate corporate policies, such as insider trading or harassment, by analyzing emails and Microsoft Teams messages for specific keywords or patterns.

Why candidates pick the wrong answer

A

Candidates may confuse eDiscovery's search capabilities with audit log search, as both involve searching for data, but eDiscovery focuses on content retrieval for legal cases, not activity logging.

C

Candidates may confuse data lifecycle management with audit because both involve managing data over time, but lifecycle management focuses on retention and deletion, not investigation of past activities.

D

Candidates may confuse Communication Compliance with Audit because both involve monitoring user activities, but Communication Compliance focuses on communication content rather than audit log events.

930
MCQeasy

A company subscribes to a SaaS human resources application hosted by an external provider. The provider is responsible for maintaining the physical data centers, network infrastructure, and the underlying application software. The company is responsible for managing user accounts, configuring user permissions, and classifying the data they upload. Which security model does this arrangement primarily describe?

A.Defense in depth
B.Zero Trust
C.Shared responsibility model
D.CIA triad
AnswerC

The shared responsibility model correctly defines the split of security tasks between the cloud provider and the customer based on the service model (IaaS, PaaS, SaaS). In this SaaS example, the provider handles infrastructure, and the customer handles data and access.

Why this answer

The scenario explicitly describes a division of security responsibilities between the SaaS provider and the customer. The provider handles physical security, network infrastructure, and application software (security *of* the cloud), while the company manages user accounts, permissions, and data classification (security *in* the cloud). This is the core definition of the shared responsibility model, which is foundational to cloud computing and directly tested in SC-900.

Exam trap

The trap here is that candidates confuse the shared responsibility model with defense in depth or Zero Trust, because all three involve 'security layers' or 'trust boundaries,' but only the shared responsibility model specifically defines the split of security obligations between a cloud provider and a customer.

Why the other options are wrong

A

The question describes a division of security responsibilities between the provider and the company, which is the essence of the shared responsibility model, not defense in depth. Defense in depth refers to multiple layers of security controls, not the allocation of responsibilities.

B

The question describes a clear division of security responsibilities between the provider and the company, which is the essence of the shared responsibility model. Zero Trust is a security framework that assumes no implicit trust and requires continuous verification, but it does not specifically address the division of responsibilities for different components of a cloud service.

D

The CIA triad (Confidentiality, Integrity, Availability) is a security model for guiding information security policies, but it does not describe the division of responsibilities between a cloud provider and customer. The question specifically asks about the arrangement of responsibilities, which is the shared responsibility model.

When would these options actually be correct?

A

A question asks: 'A company implements firewalls, intrusion detection, antivirus software, and employee security training to protect its network. Which security principle does this illustrate?' Defense in depth would be correct because it involves multiple overlapping layers of defense.

B

A question that asks: 'A company implements a policy requiring multi-factor authentication for all users, continuous monitoring of network traffic, and micro-segmentation to limit lateral movement. Which security model does this describe?' In that context, Zero Trust would be correct because it focuses on never trust, always verify.

D

A question asks: 'A security analyst is evaluating a system to ensure that data is not altered by unauthorized parties and that it remains accessible to authorized users. Which security model is the analyst primarily applying?' In this context, the CIA triad would be correct as it directly addresses confidentiality, integrity, and availability.

Why candidates pick the wrong answer

A

Candidates may confuse the layered security approach (defense in depth) with the division of responsibilities, especially since both concepts involve multiple security measures or parties.

B

Candidates may associate Zero Trust with modern cloud security and mistakenly think it applies to any cloud-related security arrangement, overlooking that the question specifically asks about the division of responsibilities.

D

Candidates may confuse the shared responsibility model with the CIA triad because both are fundamental security concepts. They might think that the division of responsibilities is a way to ensure CIA principles, but the question explicitly asks about the arrangement of responsibilities, not the security objectives.

931
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Purview that help organizations manage compliance? (Choose two.)

Select 2 answers
A.Microsoft Entra ID
B.Data Loss Prevention (DLP)
C.Microsoft Defender for Cloud
D.Insider Risk Management
E.Microsoft Intune
AnswersB, D

Data Loss Prevention (DLP) is a core capability of Microsoft Purview, designed to identify, monitor, and protect sensitive information across various locations, including Microsoft 365 services, endpoints, and on-premises file shares. Purview DLP policies can automatically detect sensitive data types, such as credit card numbers or health records, and then apply protective actions like blocking sharing, encrypting files, or notifying administrators to prevent unauthorized exfiltration or accidental data leaks. This proactive protection is crucial for maintaining compliance and safeguarding organizational data.

Why this answer

Data Loss Prevention (DLP) (B) is a core Microsoft Purview capability that helps organizations manage compliance by detecting and preventing the sharing of sensitive information across Exchange Online, SharePoint, OneDrive, Teams, and endpoint devices using policy tips, rules, and sensitive information types. Insider Risk Management (D) is also a Microsoft Purview solution that helps manage compliance by identifying, investigating, and acting on risky user activities such as data theft, leaks, and security policy violations using machine learning and built-in templates. Microsoft Entra ID (A) is an identity and access management service, not a Purview compliance capability, so it does not belong.

Microsoft Defender for Cloud (C) is a cloud security posture management and workload protection service, not a Purview compliance feature. Microsoft Intune (E) is a device and application management service, not a Microsoft Purview compliance capability.

Exam trap

The trap here is that candidates often confuse security solutions (like Defender for Cloud or Intune) with compliance solutions, or mistake identity management (Entra ID) for data governance, when Purview specifically addresses data protection, risk, and lifecycle management.

932
MCQmedium

An organization uses Exchange Online and is concerned about phishing attacks that include malicious hyperlinks. They need a security solution that checks URLs at the time a user clicks them and blocks access to known malicious or suspicious websites. The solution must also provide real-time reputation analysis for link clicks. Which Microsoft security solution should they enable?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Sentinel
AnswerB

Microsoft Defender for Office 365 (MDO) is the correct solution as it provides advanced threat protection specifically for email and collaboration tools like Exchange Online, SharePoint, OneDrive, and Microsoft Teams. Its Safe Links feature proactively rewrites URLs in emails and Office documents, scanning them at the time of click to prevent access to malicious websites. Additionally, Safe Attachments sandboxes email attachments to detect and neutralize zero-day malware before it reaches user inboxes, directly addressing concerns about malicious content.

Why this answer

Microsoft Defender for Office 365 (MDO) provides Safe Links, a feature specifically designed to protect against phishing attacks by scanning URLs at the time of click. It performs real-time reputation analysis against Microsoft's threat intelligence to block access to known malicious or suspicious websites. This directly addresses the requirement for click-time URL verification and blocking.

Exam trap

The trap here is that candidates confuse endpoint security (Defender for Endpoint) with email security (Defender for Office 365), overlooking that the question explicitly mentions Exchange Online and click-time URL analysis, which is a core Safe Links feature of MDO.

Why the other options are wrong

A

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., desktops, servers) and does not provide URL click-time protection for email links in Exchange Online. The question specifically requires a solution for email phishing links, which is covered by Defender for Office 365.

C

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on securing cloud applications and controlling data access, not on real-time URL click-time inspection for phishing links in email. The question specifically requires a solution that checks URLs at click time and provides reputation analysis for link clicks, which is a feature of Defender for Office 365 (Safe Links).

D

Microsoft Sentinel is a cloud-native SIEM/SOAR solution for security analytics and threat intelligence across the enterprise, not a tool for real-time URL click-time protection in Exchange Online. The question specifically requires a solution that checks URLs at click time in email, which is a feature of Defender for Office 365.

When would these options actually be correct?

A

A question asks: 'An organization needs to protect its Windows 10 devices from malware and detect advanced threats on endpoints. Which solution should they use?' In that scenario, Microsoft Defender for Endpoint is the correct answer.

C

A question that asks: 'An organization uses multiple SaaS applications (e.g., Salesforce, Box) and wants to discover shadow IT, control data sharing, and enforce access policies across these apps. Which Microsoft security solution should they use?' In that scenario, Microsoft Defender for Cloud Apps would be the correct answer.

D

An organization needs a centralized security information and event management (SIEM) system to collect and analyze security logs from multiple sources, including on-premises and cloud environments, and to automate incident response. They require advanced threat detection, investigation, and hunting capabilities across their entire digital estate.

Why candidates pick the wrong answer

A

Candidates may confuse Defender for Endpoint with email security because both are part of the Microsoft Defender suite, or they may assume endpoint protection includes email link scanning.

C

Candidates may confuse Defender for Cloud Apps with email security because both involve 'cloud' and 'security,' and they might think it covers all cloud-based threats including phishing, without understanding the specific click-time URL protection feature belongs to Defender for Office 365.

D

Candidates may confuse Sentinel's broad threat detection capabilities with the specific email security features of Defender for Office 365, or assume that any Microsoft security solution can handle phishing link protection.

933
MCQmedium

A company wants to monitor internal communications for inappropriate content such as harassment or threats, and also prevent employees from accidentally sharing credit card numbers via email. Which combination of Microsoft Purview solutions should they use?

A.Use Communication Compliance for both detecting harassment and preventing credit card sharing
B.Use Data Loss Prevention (DLP) for both detecting harassment and preventing credit card sharing
C.Use Communication Compliance for harassment detection and DLP for preventing sharing of credit card numbers
D.Use eDiscovery for both harassment detection and data leak prevention
AnswerC

This option correctly assigns the distinct capabilities of each solution. Microsoft Purview Communication Compliance leverages machine learning and predefined or custom policies to proactively detect inappropriate content, including harassment, threats, and discriminatory language, across various communication channels. Concurrently, Microsoft Purview Data Loss Prevention (DLP) is precisely designed to identify and prevent the unauthorized sharing or leakage of sensitive information, such as credit card numbers, by applying policies that can block, warn, or encrypt data based on its content and context.

Why this answer

Communication Compliance is designed to detect and investigate inappropriate internal communications (e.g., harassment, threats) by analyzing messages against customizable policies. Data Loss Prevention (DLP) is purpose-built to identify and prevent the accidental sharing of sensitive data, such as credit card numbers, by scanning content for predefined patterns (e.g., regex for credit card formats) and enforcing policy actions like blocking the email. Together, they address the two distinct requirements: Communication Compliance for behavioral monitoring and DLP for data protection.

Exam trap

The trap here is that candidates often confuse the overlapping capabilities of Communication Compliance and DLP, assuming one tool can handle both behavioral monitoring and data protection, when in fact each is specialized for a distinct compliance domain.

How to eliminate wrong answers

Option A is wrong because Communication Compliance is not designed to prevent the sharing of sensitive data like credit card numbers; it focuses on communication surveillance and policy violations, not data leak prevention actions. Option B is wrong because DLP is not intended for detecting harassment or threats in communications; it scans for sensitive data patterns (e.g., credit card numbers, PII) and enforces data handling policies, not behavioral monitoring. Option D is wrong because eDiscovery is used for legal discovery and holds, not for real-time monitoring or prevention of harassment or data leaks; it is an investigation tool, not a proactive compliance solution.

934
MCQeasy

A company needs to automatically detect and protect sensitive information such as credit card numbers in emails sent from Exchange Online and documents stored in SharePoint Online. They want to create policies that can block emails if such data is detected, and also automatically encrypt documents with specific labels. Which Microsoft Purview solution should they use?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention
C.Microsoft Purview Audit
D.Microsoft Purview Compliance Manager
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is specifically designed to automatically detect sensitive information types, such as credit card numbers or national IDs, across various Microsoft 365 services and endpoints. It then enforces policy-driven actions, including blocking email transmission, encrypting files, or notifying administrators, to prevent unauthorized sharing or leakage. This proactive capability directly addresses the requirement to automatically detect and protect sensitive information in real-time by preventing its inappropriate use or transfer.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to automatically detect sensitive information (e.g., credit card numbers) in Exchange Online emails and SharePoint Online documents, and then enforce protective actions such as blocking email transmission or applying encryption labels. DLP policies use sensitive information types and policy tips to identify and remediate data exposure risks across these workloads.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling/encryption) with DLP (detection and enforcement), but DLP is the engine that triggers the protective actions, while Information Protection provides the labels and encryption mechanisms that DLP can apply.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting data at rest (e.g., applying sensitivity labels) but does not natively include the automated detection and blocking of sensitive data in transit or the enforcement of DLP actions like email blocking. Option C is wrong because Microsoft Purview Audit is solely for logging and investigating user and admin activities, not for detecting or protecting sensitive data in real time. Option D is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance management tool that helps track regulatory compliance posture, not a solution for detecting or protecting sensitive content in emails or documents.

935
Multi-Selecteasy

A company wants to use Microsoft Intune to manage devices. Which TWO capabilities does Intune provide?

Select 2 answers
A.Mobile device management (MDM)
B.Compliance assessment for cloud resources
C.Endpoint detection and response
D.Mobile application management (MAM)
E.Identity and access management
AnswersA, D

Microsoft Intune's Mobile Device Management (MDM) capabilities are fundamental for organizations to enroll, configure, and secure a diverse range of corporate and personal devices, including Windows, iOS/iPadOS, Android, and macOS. This core feature enables the enforcement of device-level security policies, deployment of settings and certificates, and remote actions like wiping or locking, ensuring devices meet organizational compliance before accessing sensitive resources.

Why this answer

Microsoft Intune provides Mobile Device Management (MDM) capabilities, allowing administrators to enroll devices, enforce configuration policies, and remotely wipe corporate data. Option D is correct because Intune also provides Mobile Application Management (MAM), enabling control over app access and data protection without requiring full device enrollment, using app protection policies.

Exam trap

The trap here is that candidates often confuse Intune's compliance policies (which are device-focused) with cloud resource compliance (Option B), or mistakenly associate Intune with identity management (Option E) because it integrates with Microsoft Entra ID for authentication.

936
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. Which policy should you configure?

A.Device compliance policy in Microsoft Intune
B.Enrollment restrictions in Microsoft Intune
C.App protection policy in Microsoft Intune
D.Conditional Access policy in Microsoft Entra ID
AnswerD

A Conditional Access policy in Microsoft Entra ID is the robust enforcement mechanism that evaluates various signals, including device compliance status reported by Intune, before granting access to cloud apps like email. It acts as the gatekeeper, allowing administrators to define conditions under which users can access resources. If a device is marked as non-compliant by Intune, a Conditional Access policy can then block access to sensitive applications, effectively linking device health to resource access.

Why this answer

Conditional Access policies in Microsoft Entra ID evaluate signals such as device compliance status from Intune before granting access to cloud apps like Exchange Online. By configuring a Conditional Access policy that requires device compliance, only devices marked as compliant by Intune can access corporate email. This is the correct mechanism because Conditional Access acts as the gatekeeper that enforces the compliance requirement at the authentication and authorization layer.

Exam trap

The trap here is that candidates often confuse the policy that defines compliance (Intune Device Compliance) with the policy that enforces access based on that compliance (Entra ID Conditional Access), leading them to pick Option A instead of D.

How to eliminate wrong answers

Option A is wrong because a Device compliance policy in Microsoft Intune defines the security requirements (e.g., encryption, OS version) and marks a device as compliant or non-compliant, but it does not enforce access control to corporate email on its own. Option B is wrong because Enrollment restrictions in Microsoft Intune control which devices can enroll into management (e.g., by platform or manufacturer), not whether already enrolled devices can access email. Option C is wrong because App protection policies in Microsoft Intune manage data protection within apps (e.g., preventing copy/paste or requiring PIN) but do not evaluate device compliance or block access to email based on the device's overall compliance state.

937
MCQeasy

A company wants to collect security logs from on-premises servers, cloud applications, and network devices into a central repository, and then use advanced analytics detect threats and automate incident response. Which Microsoft security solution should they deploy?

A.Microsoft Sentinel
B.Microsoft Defender for Cloud
C.Microsoft 365 Defender
D.Azure Firewall
AnswerA

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is explicitly designed to ingest security logs from diverse sources, including on-premises servers, network devices, and cloud services, through various data connectors like the Log Analytics agent. This centralized collection is fundamental for comprehensive threat detection, investigation, and automated response across hybrid environments.

Why this answer

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. It collects security logs from diverse sources like on-premises servers, cloud apps, and network devices into a central Log Analytics workspace, then uses built-in analytics and machine learning to detect threats and automate incident response via playbooks.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel (a SIEM/SOAR) with Microsoft Defender for Cloud (a CSPM/CWPP), thinking both do log collection and threat detection, but only Sentinel provides a unified SIEM repository with advanced analytics and automated response across hybrid and multi-cloud sources.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP), not a SIEM; it focuses on assessing and hardening cloud resources, not central log collection and advanced threat analytics across hybrid environments. Option C is wrong because Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that correlates signals across Microsoft 365 products (e.g., Defender for Endpoint, Defender for Office 365), but it does not ingest logs from third-party network devices or on-premises servers into a single SIEM repository. Option D is wrong because Azure Firewall is a managed network firewall service that filters traffic based on rules; it provides logging for its own traffic but cannot aggregate logs from multiple sources or perform threat detection analytics.

938
MCQmedium

An organization uses Microsoft Intune to manage devices. They want to ensure that only devices that are compliant with security policies (e.g., encryption enabled, latest patches) can access corporate email. Which Microsoft Entra feature should they use to enforce this requirement?

A.Conditional Access in Microsoft Entra ID
B.Microsoft Defender for Endpoint
C.Device compliance policies in Microsoft Intune
D.Azure AD Join
AnswerA

Conditional Access evaluates signals such as device compliance state from Microsoft Intune and enforces grant controls, so only compliant, encrypted, patched devices reach Exchange Online. This satisfies the requirement to block non-compliant devices from corporate email at authentication time.

Why this answer

Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals (user, device, location, app) and enforces access decisions such as requiring a compliant device before granting access to corporate email. It specifically integrates with Intune's device compliance status via the 'Require device to be marked as compliant' grant control, blocking non-compliant devices from Exchange Online and other cloud apps.

Exam trap

SC-900 often tests the confusion between Intune compliance policies (which define/report compliance) and Conditional Access (which enforces access based on that compliance) — candidates pick Intune because it 'sounds like' the enforcement point.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) platform that provides threat protection and remediation, not an access-control policy engine that gates email access. Option C is wrong because Intune device compliance policies only define and report the compliance state of a device (encryption, patch level, etc.); they do not themselves block or grant access to resources — that enforcement is done by Conditional Access. Option D is wrong because Azure AD Join (now Microsoft Entra Join) only registers a device identity with the directory; it does not evaluate compliance or enforce access conditions.

939
MCQmedium

A financial services company uses Microsoft Purview to manage compliance. They need to automatically apply a 'Confidential' label to all documents containing financial data in SharePoint. What should they configure?

A.Auto-labeling policy for sensitivity labels
B.Data classification dashboard
C.Trainable classifiers for manual labeling
D.Data Loss Prevention (DLP) policy
AnswerA

This policy type in Microsoft Purview is specifically designed to automatically apply sensitivity labels to content at scale, both at rest and in transit. It leverages conditions based on sensitive information types, keywords, or trainable classifiers to identify specific content patterns, ensuring consistent classification and protection without manual intervention. This directly fulfills the requirement for automatic data management.

Why this answer

Auto-labeling policies for sensitivity labels in Microsoft Purview allow organizations to automatically apply labels to documents based on conditions such as sensitive information types (e.g., financial data patterns). This meets the requirement to label documents containing financial data in SharePoint without manual intervention, leveraging built-in or custom sensitive info types.

Exam trap

The trap here is that candidates confuse DLP policies with auto-labeling policies, as both involve content scanning and actions, but DLP does not apply sensitivity labels—it only enforces protection rules like blocking or encryption.

How to eliminate wrong answers

Option B is wrong because the Data Classification dashboard is a monitoring and reporting tool that shows where sensitive data resides, but it does not automatically apply labels. Option C is wrong because Trainable classifiers are used for pattern-based content classification and can be used in auto-labeling policies, but they are not a standalone labeling mechanism; the question asks what to configure, and the policy itself is the auto-labeling policy, not the classifier. Option D is wrong because Data Loss Prevention (DLP) policies enforce actions like blocking or alerting on data sharing, but they do not apply sensitivity labels; labeling is a separate capability.

940
MCQmedium

A company has discovered that many account compromise attacks are using legacy authentication protocols (e.g., IMAP, POP3, SMTP) which do not support multi-factor authentication. They want to block all sign-ins that use these protocols to reduce risk. Which Microsoft Entra ID feature should they use to enforce this block?

A.Conditional Access
B.Identity Protection
C.Azure AD Application Proxy
D.Privileged Identity Management (PIM)
AnswerA

Conditional Access policies are the primary mechanism in Azure AD for enforcing specific access controls based on various conditions, including user attributes, device state, location, and client applications. To effectively block legacy authentication, a Conditional Access policy can be configured to target 'Other clients' or 'Exchange ActiveSync clients' and then apply a 'Block access' grant control. This prevents older protocols such as POP, IMAP, and SMTP from authenticating, thereby mitigating associated security risks by forcing the use of modern authentication.

Why this answer

Conditional Access policies in Microsoft Entra ID can be configured to block access from legacy authentication protocols (such as IMAP, POP3, and SMTP) by targeting the 'Client apps' condition. Since these protocols do not support modern authentication methods like MFA, blocking them directly reduces the attack surface for account compromise. This is the correct feature to enforce the block.

Exam trap

The trap here is that candidates may confuse Identity Protection's risk-based policies with Conditional Access's protocol-level controls, assuming that blocking legacy authentication is a risk-detection feature rather than a conditional access rule.

Why the other options are wrong

B

Identity Protection detects and remediates risks like leaked credentials or anomalous sign-ins, but it does not block legacy authentication protocols. Blocking specific protocols is done via Conditional Access policies.

C

Azure AD Application Proxy is used to provide secure remote access to on-premises web applications, not to block legacy authentication protocols. It does not enforce authentication policies or block specific sign-in methods.

When would these options actually be correct?

B

Identity Protection would be correct in a question asking: 'Which feature should an administrator use to automatically block sign-ins when a user's credentials are found to be leaked on the dark web?'

C

A company needs to provide secure remote access to an internal web application for external users without a VPN. Azure AD Application Proxy would be the correct solution to publish the app and apply pre-authentication and conditional access policies.

Why candidates pick the wrong answer

B

Candidates may confuse Identity Protection's risk-based policies with the ability to block legacy authentication, as both involve security controls for sign-ins.

C

Candidates may confuse Application Proxy with a security feature that controls access, but it is actually a reverse proxy for publishing apps, not a policy engine for blocking authentication protocols.

941
Multi-Selecthard

Which TWO of the following are capabilities of Microsoft Defender for Office 365?

Select 2 answers
A.Scan email attachments in a sandbox environment before delivery
B.Protect against spear-phishing attacks using impersonation protection
C.Enforce device compliance policies for mobile devices
D.Place a legal hold on mailboxes for eDiscovery
E.Monitor user behavior for compromised accounts
AnswersA, B

Microsoft Defender for Office 365, a core component of Microsoft Defender XDR, includes Safe Attachments, which proactively scans email attachments. This capability detonates attachments in a virtual sandbox environment to analyze their behavior for malicious content before they are delivered to the user's inbox, effectively preventing zero-day malware and advanced threats from reaching endpoints.

Why this answer

Option A is correct because Microsoft Defender for Office 365 includes Safe Attachments, which detonates email attachments in a sandbox (virtual environment) to detect malicious behavior before delivering the message. Option B is correct because Defender for Office 365 provides anti-phishing policies with impersonation protection that detect spoofed or impersonated senders (e.g., executives, domains) to defend against spear-phishing. Option C is incorrect because device compliance policies for mobile devices are enforced by Microsoft Intune (part of Microsoft Endpoint Manager), not Defender for Office 365.

Option D is incorrect because legal hold for eDiscovery is a Microsoft Purview (Exchange/Compliance) capability, not a Defender for Office 365 feature. Option E is incorrect because monitoring user behavior for compromised accounts is handled by Microsoft Defender for Identity (or Entra ID Protection), not Defender for Office 365.

Exam trap

The trap here is that candidates confuse the broader Microsoft 365 Defender suite (which includes Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps) with the specific capabilities of Defender for Office 365 alone, leading them to select features like UEBA or device compliance that belong to other security products.

942
MCQmedium

Your organization uses Microsoft Purview Records Management to manage high-value records that must not be deleted. You need to apply a label that marks content as a regulatory record. What label type should you use?

A.Data loss prevention policy
B.Retention label configured for regulatory records
C.Retention label configured for record
D.Sensitivity label
AnswerB

A retention label configured for regulatory records locks content so it cannot be deleted or modified, even by administrators, and records the declaration in the audit log, satisfying the requirement that high-value records remain undeletable.

Why this answer

A retention label configured for regulatory records is the correct choice because it locks the label so that no user, including an administrator, can remove it or reduce the retention period. This meets the requirement to mark content as a regulatory record that must not be deleted, as regulatory records provide the highest level of immutability in Microsoft Purview Records Management.

Exam trap

The trap here is that candidates confuse 'record' with 'regulatory record,' assuming both offer the same immutability, but only regulatory records provide a locked, unchangeable label that prevents any deletion or modification.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy is used to prevent accidental sharing of sensitive data, not to mark content as a regulatory record. Option C is wrong because a retention label configured for 'record' (standard record) allows administrators to modify or delete the label after it is applied, whereas a regulatory record label is locked and immutable. Option D is wrong because a sensitivity label is used for classification and protection (e.g., encryption or visual markings), not for managing retention or declaring content as a regulatory record.

943
MCQhard

An organization has a Microsoft Purview Data Lifecycle Management policy that retains all documents for 5 years. However, legal requires that documents related to a specific lawsuit be preserved indefinitely. What should you do?

A.Configure information barriers
B.Place the relevant sites on litigation hold
C.Apply a retention label with indefinite retention
D.Create a DLP policy to block deletion
AnswerB

Placing relevant sites on litigation hold, also known as an eDiscovery hold, is the precise and legally recognized mechanism within Microsoft Purview to preserve electronically stored information (ESI) indefinitely for legal or investigative purposes. This action overrides all existing retention policies and user deletion actions, ensuring that all content, including documents, emails, and versions, remains immutable and discoverable for the entire duration of the legal matter, regardless of any other retention settings.

Why this answer

Litigation hold (now called legal hold in Microsoft Purview) preserves all content in a SharePoint site or OneDrive account indefinitely, overriding any retention policy. This ensures documents related to the lawsuit are not deleted or altered, even if a Data Lifecycle Management policy would otherwise remove them after 5 years. The hold applies at the site level, not to individual items, and prevents both deletion and modification.

Exam trap

The trap here is that candidates confuse retention labels (which require manual or automatic application to individual items) with litigation hold (which applies to an entire site or OneDrive account), leading them to choose option C despite its impracticality for bulk preservation.

How to eliminate wrong answers

Option A is wrong because information barriers restrict communication and collaboration between specific groups, not preserve data for legal purposes. Option C is wrong because a retention label with indefinite retention would need to be applied manually to each document, which is impractical for a large set of lawsuit-related files; litigation hold automatically covers all content in the site. Option D is wrong because a DLP policy blocks sharing of sensitive data but does not prevent deletion or retention of documents; it is designed for data loss prevention, not legal preservation.

944
MCQhard

The exhibit shows a Conditional Access policy named 'Block Legacy Auth'. The admin notices that the policy is not blocking legacy authentication as intended. Based on the output, what is the most likely reason?

A.The policy name is incorrect.
B.The policy does not have any client app types configured to block.
C.The policy is assigned to no users.
D.The policy is disabled.
AnswerB

For a Conditional Access policy to effectively target and block specific client application types, such as "Exchange ActiveSync clients" or "Other clients" (which often represent legacy authentication protocols), the `ClientAppTypes` condition must be explicitly configured. If this condition is empty or not selected, the policy will not apply to any particular client application type, thus failing to block legacy authentication attempts originating from those specific clients.

Why this answer

The policy is not blocking legacy authentication because it lacks configured client app types. Conditional Access policies require explicit selection of client apps (e.g., Exchange ActiveSync, other clients) to target legacy authentication protocols like POP3, IMAP, and SMTP. Without this configuration, the policy has no conditions to enforce, so it cannot block any authentication attempts.

Exam trap

The trap here is that candidates assume a Conditional Access policy with 'Block access' grant will automatically block all authentication, but they overlook the critical requirement to explicitly configure client app types to cover legacy protocols.

How to eliminate wrong answers

Option A is wrong because the policy name is irrelevant to its functionality; Conditional Access policies enforce based on conditions and controls, not names. Option C is wrong because the policy is assigned to 'All users' as shown in the exhibit, so user assignment is not the issue. Option D is wrong because the policy is enabled (status 'On' in the exhibit), so a disabled state is not the reason for failure.

945
MCQeasy

An organization wants to allow users to sign in using their mobile phone number and a verification code. Which Microsoft Entra ID feature enables this?

A.FIDO2 security keys
B.App passwords
C.SMS-based authentication
D.Password hash synchronization
AnswerC

SMS-based authentication in Azure AD allows users to sign in to cloud applications by entering their registered phone number instead of a traditional username and password. Upon entering the phone number, a one-time passcode (OTP) is sent via SMS to that number, which the user then enters to complete authentication. This method provides a convenient, passwordless experience, directly leveraging the ubiquity of mobile phones and SMS for identity verification and fulfilling the requirement to sign in using a phone number.

Why this answer

SMS-based authentication allows users to sign in to Microsoft Entra ID by entering their mobile phone number and receiving a verification code via text message. This is a form of passwordless authentication that leverages the user's phone number as the primary identifier and the SMS-delivered code as the second factor, meeting the organization's requirement for phone number and verification code sign-in.

Exam trap

The trap here is that candidates often confuse SMS-based authentication with App passwords, mistakenly thinking App passwords are used for phone-based sign-in, when in fact App passwords are a legacy workaround for non-MFA-aware apps and have nothing to do with phone number verification.

How to eliminate wrong answers

Option A is wrong because FIDO2 security keys are hardware-based passwordless authentication devices that use public-key cryptography (WebAuthn) and do not involve a mobile phone number or SMS verification codes. Option B is wrong because App passwords are legacy 16-character codes used only for apps that do not support modern authentication (e.g., older Office clients) when MFA is enforced; they are not a sign-in method using a phone number and verification code. Option D is wrong because Password hash synchronization is a synchronization feature that syncs password hashes from on-premises Active Directory to Microsoft Entra ID for hybrid identity, not a user-facing authentication method for signing in with a phone number and code.

946
Multi-Selectmedium

Which THREE components are part of Microsoft Entra Permissions Management (CIEM)?

Select 3 answers
A.Activity trail
B.Audit trail
C.Identity Protection
D.Access reviews
E.Permissions Analytics Report
AnswersA, B, E

Within Microsoft Entra Permissions Management, the Activity trail component meticulously records all user and resource actions performed across connected cloud environments, including AWS, Azure, and GCP. This comprehensive log details who accessed what resource, when, and how, providing critical visibility into the actual usage of granted permissions. It is essential for detecting anomalous behavior, identifying potential misuse of entitlements, and understanding the real-world impact of permission policies.

Why this answer

Activity trail (A) is correct because Microsoft Entra Permissions Management (CIEM) captures a detailed log of all user actions and resource access events across multi-cloud environments (AWS, Azure, GCP). This trail is essential for forensic analysis and identifying anomalous behavior, directly supporting the CIEM goal of providing visibility into permissions usage.

Exam trap

The trap here is that candidates confuse the CIEM components (Activity trail, Audit trail, Permissions Analytics Report) with broader Microsoft Entra features like Identity Protection or Access reviews, which serve different governance and security functions.

947
MCQhard

Your organization uses Microsoft Purview to classify sensitive data. You need to create a custom sensitive information type that detects employee IDs matching the pattern 'EMP-XXXXX' (where X is a digit). Which rule pack element must you define?

A.Keyword list
B.Regular expression
C.Data store reference
D.Function
AnswerB

Employee IDs follow the fixed pattern EMP- followed by five digits, so a regular expression defines that structure precisely. Rule pack elements such as keywords or dictionaries cannot match positional digit patterns; the regex element supplies the pattern-matching logic Microsoft Purview requires for this custom sensitive information type.

Why this answer

A custom sensitive information type (SIT) in Microsoft Purview is built from one or more pattern-matching elements; to detect a structured pattern like 'EMP-XXXXX' where X is a digit, you must define a regular expression (regex) that matches the literal 'EMP-' followed by exactly five digits. Regex is the only rule-pack element that can express this positional, character-class pattern. Supporting elements like keyword lists or functions can raise confidence but cannot define the pattern itself.

Exam trap

The trap is picking 'keyword list' because the pattern contains a literal prefix ('EMP-'), but keyword lists cannot enforce the numeric structure — only regex can.

How to eliminate wrong answers

Option A is wrong because a keyword list matches literal words or phrases (e.g., 'employee ID') and cannot express the 'EMP-' plus five-digit structure or enforce digit-only characters. Option C is wrong because a data store reference is not a rule-pack element for pattern detection — it is a scoping concept for where SITs are evaluated, not how a pattern is matched. Option D is wrong because a function is a supporting element (e.g., checksum validation like Luhn for credit cards) that validates or augments a match; it does not define the primary pattern and cannot by itself detect 'EMP-XXXXX'.

948
Multi-Selectmedium

Which TWO capabilities are provided by Microsoft Entra Identity Protection?

Select 2 answers
A.Enforcing session timeouts for applications
B.Self-service password reset
C.Detecting sign-in risks such as anonymous IP addresses
D.Automatically remediating risk by blocking sign-ins
E.Managing privileged role assignments
AnswersC, D

Microsoft Entra ID Identity Protection actively monitors and analyzes sign-in attempts and user behavior to identify potential threats. This capability includes detecting various anomalies, such as sign-ins from anonymous IP addresses, unfamiliar locations, or impossible travel scenarios, which are strong indicators of compromised credentials or malicious activity. It continuously assesses risk levels for each identity.

Why this answer

Microsoft Entra Identity Protection is a risk-detection and remediation service, so option C is correct: it detects sign-in risks such as anonymous IP addresses (along with other detections like atypical travel, malware-linked IPs, and leaked credentials) and surfaces them as risk detections and risky sign-ins. Option D is also correct because Identity Protection can automatically remediate risk by blocking sign-ins through risk-based Conditional Access policies (for example, requiring MFA or blocking when sign-in risk is Medium/High), and it can also require password changes for risky users. Option A is incorrect because session timeouts are enforced through Conditional Access session controls (such as sign-in frequency), not Identity Protection.

Option B is incorrect because self-service password reset is a separate Microsoft Entra ID feature, not a capability of Identity Protection. Option E is incorrect because managing privileged role assignments is handled by Privileged Identity Management (PIM), not Identity Protection.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk detection and automated remediation with other Entra features like Conditional Access (session controls) or Privileged Identity Management (role assignments), leading them to select options that describe those separate services.

949
MCQeasy

A company uses Microsoft 365 and wants to protect its users from clicking malicious links in phishing emails. The security team needs a solution that rewrites URLs in email messages to check the link at the time of click, and blocks access if the link is malicious. Which Microsoft security solution should they use?

A.Azure Firewall
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Office 365 is specifically engineered to protect against advanced threats in email and collaboration services like Exchange Online, SharePoint, OneDrive, and Microsoft Teams. Its Safe Links feature proactively rewrites URLs in emails and Office documents, then scans them at the time of click to prevent users from accessing malicious websites. Additionally, Safe Attachments sandboxes suspicious attachments, ensuring comprehensive protection against phishing and malware delivered via email.

Why this answer

Microsoft Defender for Office 365 includes Safe Links, a feature specifically designed to protect users from malicious URLs in email messages. Safe Links rewrites URLs at the time of delivery, and when a user clicks a link, it checks the destination in real time against threat intelligence; if the link is malicious, access is blocked. This directly matches the requirement to rewrite URLs and perform click-time verification.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (which includes Safe Links and Safe Attachments for email security) with Microsoft Defender for Endpoint (which protects devices) or Azure Firewall (which protects network traffic), leading them to select a solution that does not address the specific email URL rewriting requirement.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a network-layer firewall that filters traffic based on IP addresses, ports, and protocols; it does not rewrite URLs in email messages or perform click-time link inspection. Option C is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR), antivirus, and vulnerability management on devices; it does not rewrite URLs in email or provide click-time URL protection. Option D is wrong because Microsoft Defender for Identity monitors on-premises Active Directory signals to detect identity-based attacks (e.g., lateral movement, privilege escalation); it does not inspect or rewrite URLs in email messages.

950
MCQmedium

A law firm needs to retain client documents for 10 years after case closure, but automatically delete drafts after 30 days. Which two Microsoft Purview solutions should be combined?

A.Microsoft Purview Data Loss Prevention and eDiscovery
B.Microsoft Purview eDiscovery and Audit
C.Microsoft Purview Audit and Data Loss Prevention
D.Microsoft Purview Records Management and Data Lifecycle Management
AnswerD

Records Management applies retention labels declaring documents as records for the ten-year period after case closure, preventing alteration or premature deletion. Data Lifecycle Management handles the separate 30-day draft deletion, so combining both satisfies the distinct retention requirements.

Why this answer

Microsoft Purview Records Management enables the firm to mark client documents as records and enforce a 10-year retention period after case closure, while Data Lifecycle Management allows automatic deletion of drafts after 30 days. Together, they provide both long-term retention for compliance and short-term cleanup for non-record content, aligning with the firm's specific requirements.

Exam trap

The trap here is that candidates confuse Data Lifecycle Management with Data Loss Prevention or eDiscovery, mistakenly thinking DLP or eDiscovery can enforce retention or deletion policies, when in fact only Records Management and Data Lifecycle Management provide the necessary lifecycle controls.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) focuses on preventing unauthorized sharing of sensitive data, not on retention or deletion policies, and eDiscovery is used for searching and exporting content for legal cases, not for automated lifecycle management. Option B is wrong because eDiscovery handles content search and export for litigation, while Audit tracks user and admin activities; neither solution enforces retention or deletion schedules. Option C is wrong because Audit logs activities but does not manage data retention or deletion, and DLP again addresses data protection, not lifecycle policies.

951
MCQeasy

Your company wants to use Microsoft Defender for Identity to detect security threats from on-premises Active Directory. What is a prerequisite for deploying Defender for Identity?

A.Obtain Microsoft 365 E3 licenses
B.Install a sensor on each user's workstation
C.Install a sensor on a domain controller
D.Configure Azure AD Connect
AnswerC

Installing a sensor on a domain controller is the correct action for deploying Microsoft Defender for Identity. The Defender for Identity sensor passively monitors network traffic to and from the domain controller, as well as Windows events directly from the domain controller itself. This strategic placement allows it to detect suspicious activities, lateral movement paths, and advanced persistent threats targeting Active Directory, providing critical insights into identity-based attacks.

Why this answer

Microsoft Defender for Identity requires a sensor installed on a domain controller to capture and analyze on-premises Active Directory traffic, including authentication events and Kerberos requests. Without this sensor, Defender for Identity cannot monitor AD activities or detect threats like pass-the-hash or Golden Ticket attacks.

Exam trap

The trap here is that candidates confuse the licensing requirement (E5 vs. E3) with a deployment prerequisite, or mistakenly think Azure AD Connect is needed because Defender for Identity integrates with cloud services, but the sensor installation on a domain controller is the actual technical prerequisite.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 E3 licenses do not include Defender for Identity; it requires a standalone license or an E5/A5/G5 subscription. Option B is wrong because sensors are installed on domain controllers, not on user workstations, as the sensor must capture domain-level network traffic and AD logs. Option D is wrong because Azure AD Connect is used for hybrid identity synchronization, not as a prerequisite for Defender for Identity deployment.

952
MCQhard

A financial institution uses Microsoft Purview to manage compliance. They need to ensure that all documents containing the sensitive information type 'SWIFT Code' are retained for seven years and then deleted. The documents are stored in SharePoint Online and OneDrive for Business. The compliance team wants to automate the application of a retention label based on the presence of SWIFT codes. Which Microsoft Purview feature should they use?

A.Microsoft Purview Data Loss Prevention (DLP) policy with a retention action
B.Microsoft Purview retention policy applied to SharePoint Online and OneDrive for Business
C.Microsoft Purview auto-apply retention label policy based on sensitive information type
D.Microsoft Purview eDiscovery hold with a retention period
AnswerC

Auto-apply retention label policies can automatically apply a retention label to content that matches specific conditions, such as containing a sensitive information type like SWIFT Code. This allows the organization to retain documents for seven years and then delete them without manual intervention. This feature is designed exactly for this scenario, making it the correct choice.

Why this answer

An auto-apply retention label policy can automatically apply a retention label to documents containing SWIFT codes, ensuring they are retained for seven years and then deleted. This is the only option that combines automatic detection of sensitive information types with retention and deletion actions. The other options either do not support retention or cannot automatically apply based on sensitive information types.

Exam trap

The trap here is confusing retention policies with auto-apply retention labels; retention policies apply to locations, while auto-apply labels can target content based on sensitive information types.

953
MCQeasy

Your organization uses Microsoft Entra ID to manage user identities. A new employee named John joins the company and needs access to Microsoft 365 apps. You want to ensure John's identity is verified using a phone call. Which authentication method should you configure?

A.Time-based one-time password (TOTP)
B.Email one-time passcode
C.Text message (SMS)
D.Phone call (voice call)
E.FIDO2 security key
AnswerD

Phone call (voice call) is a supported multi-factor authentication method where Microsoft Entra ID initiates an automated voice call to a user's registered phone number. To complete authentication, the user must answer the incoming call and typically press a specific key, such as the # key, on their phone's keypad to confirm their identity. This directly fulfills the requirement of a phone call for user verification.

Why this answer

The question explicitly requires verification using a phone call. The Phone call (voice call) authentication method in Microsoft Entra ID delivers an automated voice call to the user's registered phone number, prompting them to press a key to confirm their identity. This directly matches the requirement, making D the correct choice.

Exam trap

The trap here is that candidates may confuse 'phone call' with 'text message (SMS)' because both involve a phone, but the question explicitly specifies 'phone call (voice call)', not a text-based code delivery.

How to eliminate wrong answers

Option A is wrong because Time-based one-time password (TOTP) uses a software or hardware token to generate a code, not a phone call. Option B is wrong because Email one-time passcode sends a code via email, which is not a phone-based voice call. Option C is wrong because Text message (SMS) delivers a code via text, not a voice call.

Option E is wrong because FIDO2 security key is a hardware-based passwordless authentication method that uses public-key cryptography, not a phone call.

954
MCQeasy

Your organization needs to monitor Microsoft Teams chats for inappropriate language and alert compliance officers. Which Microsoft Purview solution should you implement?

A.Communication Compliance
B.eDiscovery
C.Auditing
D.Information Protection
AnswerA

Microsoft 365 Communication Compliance is specifically designed to proactively detect, investigate, and remediate policy violations within an organization's communications, including Microsoft Teams chats. It leverages machine learning to identify sensitive information, regulatory compliance issues, or inappropriate conduct based on customizable policies. This tool enables organizations to monitor ongoing conversations for potential risks and take corrective actions before they escalate.

Why this answer

Communication Compliance is the correct solution because it is specifically designed to detect inappropriate language, such as profanity, harassment, or sensitive content, in Microsoft Teams chats and other communication channels. It uses built-in trainable classifiers and customizable policies to automatically flag violations and alert compliance officers, enabling proactive remediation.

Exam trap

The trap here is that candidates often confuse Communication Compliance with eDiscovery or Auditing, assuming any monitoring or alerting feature falls under those broader categories, but Communication Compliance is the only solution that specifically analyzes message content for policy violations like inappropriate language.

How to eliminate wrong answers

Option B (eDiscovery) is wrong because it is used for legal discovery and litigation support, not for real-time monitoring of inappropriate language; it focuses on searching, holding, and exporting content for legal cases. Option C (Auditing) is wrong because it logs user and admin activities for security and compliance investigations, but it does not analyze message content for inappropriate language or trigger alerts based on policy violations. Option D (Information Protection) is wrong because it applies sensitivity labels and encryption to protect data based on classification, not to monitor or detect inappropriate language in communications.

955
MCQhard

An organization needs to automatically apply a 'Highly Confidential' sensitivity label to all documents that contain a specific custom sensitive information type. The label should be applied when the document is created or modified. Which feature of Microsoft Purview Information Protection should be used?

A.Manual sensitivity labeling
B.Data Loss Prevention (DLP) policies
C.Auto-labeling policies
D.Communication Compliance policies
AnswerC

Auto-labeling policies are specifically engineered to automatically apply sensitivity labels to content based on predefined conditions, such as the presence of specific sensitive information types, keywords, or patterns. These policies can be configured to apply labels to files at rest in SharePoint and OneDrive, or to emails and documents in Exchange, ensuring consistent classification without manual intervention. This direct application of labels fulfills the requirement for automatically classifying highly confidential information.

Why this answer

Auto-labeling policies in Microsoft Purview Information Protection are designed to automatically apply sensitivity labels to documents and emails based on conditions such as the presence of sensitive information types. This feature supports both simulation and real-time enforcement, and it can be triggered when documents are created or modified, meeting the organization's requirement exactly.

Exam trap

The trap here is that candidates often confuse auto-labeling policies with DLP policies, mistakenly thinking DLP can apply labels, when in fact DLP only monitors and protects data in transit or at rest without modifying the label itself.

How to eliminate wrong answers

Option A is wrong because manual sensitivity labeling requires users to manually select and apply a label, which does not meet the requirement for automatic application. Option B is wrong because Data Loss Prevention (DLP) policies are focused on preventing unauthorized sharing or leakage of sensitive data through actions like blocking or alerting, not on automatically applying sensitivity labels to content. Option D is wrong because Communication Compliance policies are designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) and do not apply sensitivity labels based on sensitive information types.

956
MCQmedium

Your organization uses Microsoft Entra ID P2 and wants to reduce the risk of identity compromise by requiring multifactor authentication (MFA) for all users, but excluding users when they are on the corporate network. Which policy type should you configure?

A.Conditional Access policy
B.Self-service password reset (SSPR) policy
C.Identity Protection risk policy
D.Privileged Identity Management (PIM) activation policy
AnswerA

Microsoft Entra Conditional Access policies are the primary mechanism for enforcing access controls based on specific conditions, such as user location, device state, or application being accessed. By defining a policy that targets all users and requires MFA, an administrator can then create an exception for trusted IP ranges, effectively bypassing MFA when users are on the corporate network. This granular control over access based on real-time signals is central to Microsoft Entra ID P2 security capabilities.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA based on conditions such as user group, location, device, and application. You can create a policy that requires MFA for all users but excludes trusted corporate network locations.

Exam trap

SC-900 often tests the confusion between Conditional Access and Identity Protection risk policies, where the latter is for risk-based automation, not location-based MFA.

How to eliminate wrong answers

Option B is wrong because SSPR policies manage password reset, not MFA enforcement. Option C is wrong because Identity Protection risk policies are used to automate risk-based responses (e.g., require password change on risky sign-ins), not to enforce MFA based on network location. Option D is wrong because PIM activation policies govern just-in-time privileged role activation, not general MFA requirements.

957
MCQmedium

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers. You need to ensure that when a user attempts to share a document containing a credit card number via email, the email is blocked and the user receives a policy tip. Which action should you configure in the DLP policy?

A.Notify user
B.Audit only
C.Block with user notification
D.Block override
AnswerC

The "Block with user notification" action is a robust enforcement mechanism that actively prevents the sharing of sensitive information, such as blocking an email from being sent or a file from being shared. Simultaneously, it displays a policy tip to the end-user, clearly informing them why the action was blocked and providing guidance on how to comply with organizational policies or remediate the issue. This combination effectively enforces data protection while educating users on acceptable data handling practices.

Why this answer

The 'Block with user notification' action in a Microsoft Purview DLP policy blocks the email when sensitive data like credit card numbers is detected and simultaneously shows the user a policy tip explaining why. This matches both requirements: blocking the email and notifying the user.

Exam trap

SC-900 often tests the distinction between 'Notify user' (tip only) and 'Block with user notification' (block plus tip), where candidates incorrectly choose the softer action.

How to eliminate wrong answers

Option A is wrong because 'Notify user' only shows a policy tip without blocking the email, so the message would still be sent. Option B is wrong because 'Audit only' logs the activity without blocking or notifying, providing no enforcement. Option D is wrong because 'Block override' allows the user to override the block with a justification, which does not guarantee the email is blocked as required.

958
MCQmedium

A company uses digital signatures to ensure that a sender cannot later deny having sent a message. Which security principle does this primarily address?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerD

Digital signatures achieve non-repudiation by cryptographically binding a sender's identity to a message. The sender uses their unique private key to sign a hash of the document, creating a verifiable digital fingerprint. This signature, which can be validated by anyone with the sender's corresponding public key, provides irrefutable proof of origin and consent, ensuring the sender cannot legitimately deny having sent the message or performed the action.

Why this answer

Digital signatures use asymmetric cryptography (e.g., RSA or ECDSA) to bind a signer's identity to a message. The signature is created with the sender's private key and verified with their public key, providing cryptographic proof of origin. This directly enforces non-repudiation because the sender cannot plausibly deny having signed the message, as only they possess the private key.

Exam trap

The trap here is that candidates often confuse digital signatures with encryption, assuming they primarily provide confidentiality, when in fact signatures focus on authentication and non-repudiation, while encryption (e.g., using the recipient's public key) is what ensures confidentiality.

Why the other options are wrong

A

Digital signatures prevent a sender from denying having sent a message, which is non-repudiation, not confidentiality. Confidentiality ensures that data is not disclosed to unauthorized parties, which is not the primary concern here.

B

Digital signatures primarily ensure non-repudiation, not integrity. While digital signatures do provide integrity by detecting tampering, the question specifically asks about preventing the sender from denying having sent the message, which is the definition of non-repudiation.

C

Non-repudiation ensures the sender cannot deny sending a message, which is not addressed by availability. Availability ensures systems and data are accessible when needed, not the undeniability of actions.

When would these options actually be correct?

A

Confidentiality would be correct in a question like: 'Which security principle is primarily addressed by encrypting the contents of an email so that only the intended recipient can read it?'

B

Integrity would be correct if the question asked: 'Which security principle ensures that a message has not been altered during transmission?' or 'Which principle is primarily addressed by hashing algorithms?'

C

A question asking which security principle is primarily addressed by ensuring that a system remains operational and accessible during a denial-of-service attack would have availability as the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse digital signatures with encryption, thinking that signing a message also keeps it secret, or they may not clearly distinguish between integrity/non-repudiation and confidentiality.

B

Candidates may confuse integrity with non-repudiation because digital signatures also provide integrity, and they might think that ensuring the message hasn't been altered is the same as proving the sender's identity.

C

Candidates may confuse the concept of preventing denial of action (non-repudiation) with preventing denial of service (availability), or they may think that digital signatures also ensure the message is available, but that is not their primary purpose.

959
MCQeasy

An organization uses Microsoft 365 Defender and wants to automate the investigation and response to common email-based phishing attacks. They want the system to automatically take actions such as deleting malicious emails from user inboxes across the organization after analysis. Which Microsoft 365 Defender component provides this automated capability?

A.Azure AD Identity Protection
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Defender for Office 365 is the correct solution because it provides advanced protection against sophisticated email and collaboration threats, including phishing, business email compromise, and malware delivered via email, Microsoft Teams, SharePoint, and OneDrive. It utilizes capabilities like Safe Attachments and Safe Links to scan content in real-time and includes automated investigation and response (AIR) for email-borne attacks, directly addressing the need to protect against email threats.

Why this answer

Microsoft Defender for Office 365 includes automated investigation and response (AIR) capabilities specifically designed for email-based threats like phishing. When a phishing email is detected, AIR can automatically trigger remediation actions—such as soft-deleting or hard-deleting the malicious message from user mailboxes—based on predefined playbooks, without requiring manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 with Microsoft Defender for Endpoint, mistakenly thinking endpoint protection can handle email threats, but only Defender for Office 365 includes the email-specific automated investigation and response (AIR) engine.

Why the other options are wrong

A

Azure AD Identity Protection focuses on user identities and sign-in risks, not on email content or automated remediation of phishing emails in user mailboxes.

C

Microsoft Defender for Endpoint focuses on protecting devices (endpoints) from threats like malware and exploits, not on automating investigation and response to email-based phishing attacks, which is the domain of Defender for Office 365.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on securing cloud applications and services, not on automating investigation and response to email-based phishing attacks within Microsoft 365 Defender.

When would these options actually be correct?

A

A question asking which Microsoft 365 Defender component automatically responds to identity-based risks, such as blocking compromised accounts or requiring MFA re-enrollment based on user risk level.

C

A question asks: 'An organization wants to automatically investigate and respond to threats detected on employee laptops, such as isolating compromised devices from the network. Which Microsoft 365 Defender component provides this automated capability?'

D

An organization wants to detect and control the use of unsanctioned cloud apps, enforce data loss prevention policies, and investigate user activities across cloud services like Salesforce or Box. In that scenario, Microsoft Defender for Cloud Apps would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse identity protection with email security, assuming that automated response to phishing attacks is handled by identity protection because phishing often targets user credentials.

C

Candidates may confuse the general 'automated investigation and response' capability of Microsoft 365 Defender with the specific component for endpoints, overlooking that the question explicitly mentions email-based phishing attacks.

D

Candidates may confuse the broad 'cloud security' scope of Defender for Cloud Apps with the email security capabilities of Defender for Office 365, assuming it covers all cloud-based threats including email phishing.

960
Multi-Selectmedium

Your organization uses Microsoft Defender for Cloud to assess the security posture of its Azure resources. Which two actions can be taken to improve the Secure Score? (Choose two.)

Select 2 answers
A.Delete unused Azure resources to simplify management
B.Disable diagnostic logging for storage accounts
C.Implement security recommendations by remediating unhealthy resources
D.Disable non-critical virtual machines to reduce attack surface
E.Enable Microsoft Defender for Cloud plans for all supported resource types
AnswersC, E

Implementing security recommendations by remediating unhealthy resources is the most direct and effective method for improving Microsoft Defender for Cloud's Secure Score. The Secure Score is a quantitative measurement derived from the successful completion of security recommendations across various controls. By actively addressing and resolving identified vulnerabilities, misconfigurations, and compliance gaps on resources flagged as "unhealthy," organizations directly fulfill the criteria for these controls, thereby increasing their overall security posture and elevating the Secure Score.

Why this answer

Option C is correct because Microsoft Defender for Cloud's Secure Score is calculated from the percentage of passed security assessments (recommendations) versus total applicable assessments, so remediating unhealthy resources to implement recommendations directly raises the score. Option E is correct because enabling Defender for Cloud plans (such as Defender for Servers, Storage, Containers, etc.) activates additional security assessments and recommendations for those resource types, increasing the number of controls that contribute to and can improve the Secure Score. Option A is not correct because simply deleting unused resources is not a Secure Score control; the score improves through remediation of specific recommendations, not general cleanup.

Option B is not correct because disabling diagnostic logging for storage accounts removes a security control and would lower, not raise, the Secure Score. Option D is not correct because powering off non-critical VMs is not a Defender for Cloud recommendation that increases the Secure Score and does not remediate an unhealthy assessment.

Exam trap

The trap here is that candidates may confuse operational security actions (like deleting resources or disabling VMs) with the specific security controls and recommendations that directly influence the Secure Score calculation.

961
MCQhard

Refer to the exhibit. You are configuring a sensitivity label in Microsoft Purview. The label is set to automatically apply when credit card numbers are detected. However, users report that the label is not being applied to documents containing credit card numbers. What is the most likely cause?

A.The encryption is misconfigured
B.The label is not published to a label policy
C.The auto-labeling condition is incorrect
D.The user permissions are missing
AnswerB

A sensitivity label, once created and configured, must be explicitly published through a label policy to become active and available for users or automatic application. Without being included in a policy and assigned to specific users or groups, the label remains in a draft state and cannot be applied, either manually or automatically, to documents or emails. This publishing step is critical for the label's operational deployment and is the most common reason for a configured label not being applied.

Why this answer

For a sensitivity label to be applied — whether manually or automatically — it must be published to a label policy that targets the relevant users and locations. If the label exists in the compliance portal but is not included in a published label policy, it will not be available to the client apps or the auto-labeling service, so documents with credit card numbers will never receive it. This is the most likely cause of the reported behavior.

Exam trap

SC-900 often tests the distinction between creating a label and publishing it — candidates assume a label works as soon as it is created, forgetting that label policies are required to make it available and to enable auto-labeling.

How to eliminate wrong answers

Option A is wrong because encryption misconfiguration would affect the protection applied by the label, not whether the label is applied at all — and encryption is optional for auto-labeling. Option C is wrong because if the auto-labeling condition (credit card number SIT) were incorrect, the label would still be published and available; the symptom of 'not applied' points to publication, not condition logic. Option D is wrong because missing user permissions would typically block access to the label or the document, not silently prevent auto-labeling for all users.

962
MCQhard

Your organization, Contoso Ltd., has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You are deploying Microsoft Defender for Identity (MDI) to protect against identity-based attacks. You have installed the MDI sensor on domain controllers and configured the service with the necessary permissions. After installation, you notice that MDI is not generating alerts for pass-the-hash attacks. You have verified that the sensors are healthy and that audit policies are correctly configured. You need to ensure that MDI can detect pass-the-hash attacks. What should you do?

A.Enable password hash synchronization in Microsoft Entra Connect
B.Install the Azure ATP agent on all servers
C.Enable Kerberos event logging on domain controllers
D.Configure multi-factor authentication for all users
AnswerA

Enabling password hash synchronization in Microsoft Entra Connect is correct because it allows Microsoft Defender for Identity to analyze NTLM hashes and detect pass-the-hash attacks.

Why this answer

The current explanation states: "Enabling password hash synchronization (PHS) in Entra Connect allows MDI to analyze NTLM hashes and detect pass-the-hash attacks." This is incorrect. Password Hash Synchronization (PHS) is a method for synchronizing user password hashes from on-premises Active Directory to Microsoft Entra ID for cloud authentication purposes. MDI's detection of pass-the-hash attacks relies on monitoring NTLM authentication traffic and relevant security events on domain controllers, not on the hashes synchronized to Microsoft Entra ID via PHS. Therefore, enabling PHS does not enable or enhance MDI's ability to detect pass-the-hash attacks on-premises.

Option B is wrong because the MDI sensor is already installed on domain controllers, and installing it on all servers is not the specific missing step for pass-the-hash detection.

Option C is wrong because pass-the-hash attacks primarily leverage NTLM hashes, and while Kerberos logging is important for other attacks, it's not the primary mechanism for pass-the-hash detection. The stem also states audit policies are correctly configured.

Option D is wrong because multi-factor authentication is a preventative control that strengthens authentication; it does not enable MDI to detect pass-the-hash attacks. Given that the sensors are healthy and audit policies are correctly configured, none of the provided options directly address a common missing configuration for MDI to detect pass-the-hash attacks.

963
MCQeasy

Your company uses Microsoft 365 E5 and wants to provide a unified security dashboard showing alerts from endpoints, email, identity, and cloud apps. Which solution should you use?

A.Microsoft Defender XDR portal (security.microsoft.com)
B.Microsoft Sentinel
C.Microsoft Intune admin center
D.Microsoft Purview Compliance Portal
AnswerA

The Microsoft Defender XDR portal, accessible at security.microsoft.com, is the centralized console for managing and responding to threats across an organization's entire digital estate. It provides a unified security dashboard by integrating signals from Microsoft Defender for Endpoint, Identity, Office 365, and Cloud Apps. This comprehensive view enables security analysts to correlate alerts, investigate incidents, and automate responses, making it the ideal solution for a unified security experience within Microsoft 365 E5.

Why this answer

Microsoft Defender XDR portal (security.microsoft.com) aggregates alerts from endpoints (Microsoft Defender for Endpoint), email (Microsoft Defender for Office 365), identity (Microsoft Defender for Identity), and cloud apps (Microsoft Defender for Cloud Apps) into a single unified dashboard. This is the correct solution because it provides cross-domain correlation and a centralized view of security incidents across these Microsoft 365 E5 workloads without requiring additional licensing or data ingestion.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (a unified security operations platform), but Sentinel is for ingesting third-party and custom logs, whereas Defender XDR natively aggregates alerts from Microsoft 365 E5 workloads without extra licensing or setup.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that ingests logs from multiple sources, but it requires additional licensing and configuration to collect and correlate alerts; it is not a pre-built unified dashboard for Microsoft 365 E5 native alerts. Option C is wrong because the Microsoft Intune admin center focuses on endpoint management, device compliance, and mobile device management (MDM), not on aggregating security alerts from email, identity, and cloud apps. Option D is wrong because the Microsoft Purview Compliance Portal is designed for data governance, compliance management, and eDiscovery, not for real-time security alert correlation across endpoints, email, identity, and cloud apps.

964
MCQeasy

Your organization needs to audit all changes to sensitive files in SharePoint Online for at least 180 days. Which Microsoft Purview feature should be enabled?

A.Microsoft Purview eDiscovery
B.Microsoft Purview Audit (Premium)
C.Microsoft Purview Data Loss Prevention
D.Microsoft Purview Data Lifecycle Management
AnswerB

Microsoft Purview Audit (Premium) is the correct solution because it provides advanced auditing capabilities specifically designed to capture and retain detailed user and admin activities across Microsoft 365 services. It offers extended retention of audit logs for up to one year (or 10 years with an add-on license) and access to crucial audit events like file and folder activities, enabling organizations to perform forensic investigations, respond to regulatory requests, and proactively monitor changes to sensitive files with high fidelity.

Why this answer

Microsoft Purview Audit (Premium) provides the extended retention of audit logs (up to 10 years) and the ability to search for high-value events such as changes to sensitive files. For a requirement of at least 180 days, Audit (Premium) is necessary because standard audit logs are retained for only 90 days. This feature logs all modifications to SharePoint Online files, including who changed what and when, meeting the auditing requirement.

Exam trap

The trap here is that candidates confuse the 90-day default retention of standard audit with the extended retention of Audit (Premium), and mistakenly choose eDiscovery because it sounds like it involves logs, but eDiscovery is for content search, not audit log retention.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview eDiscovery is used for searching and exporting content from Exchange, SharePoint, and Teams for legal or investigative purposes, not for auditing changes to sensitive files over a retention period. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent unauthorized sharing or leakage of sensitive data by applying policies, not to audit historical changes. Option D is wrong because Microsoft Purview Data Lifecycle Management (formerly Records Management) focuses on retaining or deleting data based on policies (e.g., retention labels), not on logging and auditing changes to files.

965
MCQmedium

A company uses Azure virtual machines (IaaS) and on-premises Windows servers. The security team needs a single solution that provides a continuous assessment of security posture, a regulatory compliance dashboard for NIST SP 800-53, and integrated threat detection for hybrid workloads (e.g., brute force attacks on SSH). Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Identity
D.Microsoft Sentinel
AnswerA

Microsoft Defender for Cloud delivers continuous secure score posture assessment, a regulatory compliance dashboard covering NIST SP 800-53, and Defender plans providing hybrid threat detection such as SSH brute force alerts. It satisfies all three stem requirements across Azure VMs and on-premises Windows servers from one solution.

Why this answer

Microsoft Defender for Cloud is the correct choice because it provides continuous assessment of security posture (via the Secure Score), a regulatory compliance dashboard with built-in standards like NIST SP 800-53, and integrated threat detection for hybrid workloads, including brute force attacks on SSH for Azure VMs and on-premises servers. It unifies these capabilities across IaaS, on-premises, and other cloud environments, making it the single solution the security team needs.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (which covers infrastructure security posture and threat detection for workloads) with Microsoft Sentinel (a SIEM), but Sentinel requires manual configuration of data connectors and workbooks to achieve the same compliance dashboard and does not provide continuous posture assessment out of the box.

How to eliminate wrong answers

Option B (Microsoft Defender for Cloud Apps) is wrong because it is a Cloud Access Security Broker (CASB) focused on shadow IT discovery, app permissions, and data protection for SaaS applications, not on infrastructure-level security posture or compliance dashboards for NIST SP 800-53. Option C (Microsoft Defender for Identity) is wrong because it is an identity-based threat detection solution that monitors on-premises Active Directory signals (e.g., Kerberos, NTLM) for attacks like pass-the-hash, not for brute force attacks on SSH or VM-level security posture. Option D (Microsoft Sentinel) is wrong because it is a Security Information and Event Management (SIEM) solution that ingests logs from multiple sources for advanced analytics and incident response, but it does not natively provide a continuous security posture assessment or a built-in regulatory compliance dashboard for NIST SP 800-53 without additional workbooks and configurations.

966
MCQhard

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the most likely purpose of this query?

A.To identify successful logins after multiple failures
B.To detect privilege escalation events
C.To detect accounts that have been locked out
D.To identify potential brute-force attack attempts
AnswerD

A KQL query that aggregates and counts EventID 4625 (failed login attempts) for individual user accounts within a specific timeframe is highly effective for detecting potential brute-force attacks. A significantly elevated number of failed login attempts against a single account or a small set of accounts strongly indicates an attacker systematically trying multiple password combinations. This pattern is a hallmark of brute-force activity.

Why this answer

The query filters for Windows Event ID 4625 (failed logon) and then counts occurrences per account and source IP within a 5-minute window, keeping only those with more than 10 failures. This pattern is the classic signature of a brute-force attack, where an attacker attempts many passwords against the same account or from the same IP. Option D is correct because the query is specifically designed to identify potential brute-force attempts by aggregating failed logons.

Exam trap

The trap here is that candidates may confuse the aggregation of failed logons (Event ID 4625) with account lockout events (Event ID 4740), but the query lacks any reference to lockout status or successful logins, making brute-force detection the only logical purpose.

How to eliminate wrong answers

Option A is wrong because the query only looks at Event ID 4625 (failed logon) and does not include Event ID 4624 (successful logon) to correlate successes after failures. Option B is wrong because privilege escalation events are typically detected via Event ID 4672 (special privileges assigned to new logon) or 4688 (process creation with elevated token), not by counting failed logons. Option C is wrong because account lockouts are tracked via Event ID 4740 (account locked out), not by aggregating failed logon attempts; the query does not reference lockout events.

967
MCQmedium

A security operations team needs to protect their organization's Windows 10 and Windows 11 devices from advanced persistent threats (APTs), ransomware, and fileless malware. They also require a centralized dashboard to view device security posture, investigate incidents, and perform proactive threat hunting using advanced queries. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Endpoint is purpose-built for comprehensive endpoint security, offering advanced capabilities like Endpoint Detection and Response (EDR), vulnerability management, and automated investigation and remediation. It provides security operations teams with the tools to proactively hunt for threats across Windows devices, respond to incidents, and maintain a strong security posture against sophisticated cyberattacks, directly addressing the need for device protection and threat hunting.

Why this answer

Microsoft Defender for Endpoint (MDE) is the correct solution because it provides endpoint detection and response (EDR) capabilities specifically designed to protect Windows 10 and Windows 11 devices against advanced persistent threats (APTs), ransomware, and fileless malware. It includes a centralized dashboard (Microsoft 365 Defender portal) for viewing device security posture, investigating incidents, and performing proactive threat hunting using advanced hunting queries based on Kusto Query Language (KQL).

Exam trap

The trap here is that candidates often confuse the scope of each Defender product, mistakenly selecting Defender for Office 365 or Defender for Identity because they see 'threat protection' in the question, but fail to recognize that the requirement specifically mentions endpoint devices (Windows 10/11) and advanced hunting queries, which are exclusive to Defender for Endpoint.

Why the other options are wrong

B

Microsoft Defender for Office 365 protects email and collaboration tools (Exchange, SharePoint, Teams) from threats like phishing and malware, not Windows 10/11 endpoints from APTs, ransomware, or fileless malware.

C

Microsoft Defender for Identity focuses on protecting on-premises Active Directory identities and detecting identity-based attacks, not on endpoint device protection against APTs, ransomware, or fileless malware.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that protects cloud applications, not Windows 10/11 endpoints. It does not provide device-level protection against APTs, ransomware, or fileless malware, nor does it offer a centralized dashboard for device security posture and advanced threat hunting on endpoints.

When would these options actually be correct?

B

A question asking for a solution to protect an organization's email and Office 365 workloads from phishing, malware, and malicious links, with a centralized dashboard for email security and threat investigation.

C

A question asking for a solution to monitor and protect on-premises Active Directory environments from advanced identity threats like pass-the-hash, golden ticket attacks, or compromised credentials would make Defender for Identity the correct answer.

D

This option would be correct in a scenario where an organization needs to discover and control the use of cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. For example, a question asking for a solution to monitor and secure Shadow IT in Office 365 or other cloud services.

Why candidates pick the wrong answer

B

Candidates may confuse the 'Defender' branding and assume all Defender products provide endpoint protection, or they may think Office 365 protection covers all devices.

C

Candidates may confuse 'identity' with 'endpoint' security, or assume that protecting identities inherently protects devices, overlooking the specific endpoint-focused requirements in the question.

D

Candidates may confuse Defender for Cloud Apps with endpoint protection because both involve security monitoring and threat detection, and the name 'Defender' suggests a broad security suite. They might overlook that this product is specifically for cloud applications, not endpoints.

968
MCQhard

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to prevent users from sharing credit card numbers via email, but allow sharing via Microsoft Teams messages. What should they configure?

A.Create a DLP policy scoped to Exchange Online with a block action, and a separate DLP policy scoped to Teams with an audit-only action
B.Create a single DLP policy that blocks credit card numbers in both Exchange and Teams
C.Configure an exception in the DLP policy for Teams using a rule exception
D.Use Microsoft Purview Insider Risk Management to block sharing in Teams
AnswerA

Microsoft Purview DLP policies offer granular control, allowing administrators to define distinct policies for different service locations. By creating one policy specifically scoped to Exchange Online with a "block" action and a separate policy for Microsoft Teams with an "audit-only" action, the company can precisely meet the requirement. This approach leverages DLP's ability to apply varied enforcement levels based on the communication channel, ensuring sensitive data is protected appropriately in each context.

Why this answer

Microsoft Purview DLP allows you to create separate policies scoped to different workloads. By creating a DLP policy for Exchange Online with a block action, you prevent credit card numbers from being shared via email. A separate DLP policy scoped to Microsoft Teams with an audit-only action allows sharing in Teams while still logging the activity for monitoring.

Exam trap

The trap here is that candidates assume a single DLP policy with multiple locations can have different actions per location, but in reality, the action is applied uniformly across all selected locations unless separate policies are created.

How to eliminate wrong answers

Option B is wrong because a single DLP policy scoped to both Exchange and Teams would apply the same action (block) to both workloads, which would prevent sharing in Teams as well. Option C is wrong because DLP policies do not support rule exceptions that exempt an entire workload like Teams; exceptions are typically used for specific conditions like trusted domains or IP ranges. Option D is wrong because Microsoft Purview Insider Risk Management is designed to detect and investigate risky user activities, not to enforce real-time blocking of sensitive data sharing in Teams.

969
MCQmedium

An organization is redesigning its security architecture based on the Zero Trust model. Which principle requires that every access request must be fully authenticated, authorized, and encrypted before granting access, regardless of the network location?

A.Assume breach
B.Least privilege
C.Verify explicitly
D.Trust but verify
AnswerC

The 'Verify explicitly' principle is a cornerstone of the Zero Trust model, mandating that every access request to any resource must be fully authenticated, authorized, and validated based on all available contextual signals. This includes user identity, device health, location, service, and data classification, ensuring no implicit trust is ever granted. It requires continuous, real-time evaluation before granting access, regardless of whether the request originates inside or outside the traditional network perimeter.

Why this answer

The Zero Trust model is built on three core principles: verify explicitly, least privilege, and assume breach. The principle that mandates every access request—regardless of whether it originates from inside or outside the corporate network—must be fully authenticated, authorized, and encrypted before granting access is 'verify explicitly'. This means using strong authentication methods (e.g., multifactor authentication), continuous validation of authorization (e.g., Conditional Access policies), and enforcing encryption (e.g., TLS 1.3) for every request, not just those from untrusted locations.

Exam trap

Microsoft often tests the distinction between 'verify explicitly' and 'trust but verify', where candidates mistakenly choose 'trust but verify' because it sounds like a security principle, but the Zero Trust model explicitly rejects any form of implicit trust, requiring verification for every request regardless of network location.

How to eliminate wrong answers

Option A is wrong because 'assume breach' is a Zero Trust principle that focuses on minimizing the blast radius and segmenting access, not on the upfront verification of each request; it assumes a breach has already occurred and designs defenses accordingly. Option B is wrong because 'least privilege' is a principle that limits user and device access rights to only what is necessary to perform a task, but it does not address the requirement for full authentication, authorization, and encryption of every request. Option D is wrong because 'trust but verify' is an outdated security model that implicitly trusts users or devices inside the network perimeter and only verifies when necessary, which contradicts the Zero Trust mandate to never trust and always verify explicitly.

970
MCQmedium

A company has several on-premises web-based applications that need to be securely accessed by remote employees without requiring a VPN. The IT team wants to provide single sign-on (SSO) using Microsoft Entra ID. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra Application Proxy
B.Microsoft Entra Self-Service Password Reset (SSPR)
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra Identity Protection
AnswerA

Microsoft Entra Application Proxy is the correct solution for securely publishing on-premises web applications to external users. It achieves this by deploying a lightweight connector within the on-premises network, which establishes an outbound connection to Azure, creating a secure tunnel. This allows users to access internal web apps remotely with single sign-on capabilities, leveraging Entra ID's conditional access policies without requiring a VPN or opening inbound firewall ports.

Why this answer

Microsoft Entra Application Proxy enables secure remote access to on-premises web applications without a VPN by acting as a reverse proxy. It integrates with Microsoft Entra ID to provide single sign-on (SSO) for users, leveraging pre-authentication and conditional access policies. This directly meets the requirement for VPN-less, SSO-enabled access.

Exam trap

The trap here is that candidates often confuse Application Proxy with a VPN solution or think SSPR or PIM can provide remote access, but only Application Proxy specifically proxies on-premises web apps with SSO integration.

Why the other options are wrong

B

SSPR allows users to reset their own passwords without admin intervention, but it does not provide secure remote access to on-premises web applications or enable SSO. The question specifically requires a solution for accessing on-premises apps without a VPN, which SSPR does not address.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, not remote access to on-premises web apps without a VPN.

D

Microsoft Entra Identity Protection is a tool for detecting and responding to identity-based risks, such as compromised credentials or suspicious sign-ins, not for providing secure remote access to on-premises applications without a VPN.

When would these options actually be correct?

B

A company wants to reduce helpdesk calls by enabling employees to reset their own passwords securely. The IT team needs a Microsoft Entra ID feature that supports self-service password changes with security verification. In that scenario, SSPR would be the correct answer.

C

A company needs to provide just-in-time privileged access to Azure AD roles and monitor privileged account usage. Which Microsoft Entra feature should they implement?

D

A company wants to automatically detect and block risky sign-in attempts, such as those from anonymous IP addresses or unfamiliar locations, to protect user accounts. Which Microsoft Entra feature should they implement?

Why candidates pick the wrong answer

B

Candidates may confuse SSPR's authentication capabilities with access control, or think that password reset is a prerequisite for SSO, leading them to select this option without recognizing it does not solve the remote access requirement.

C

Candidates may confuse PIM's 'access management' with the access needed for remote application access, or think PIM can handle all access scenarios including application access.

D

Candidates may confuse 'protection' with 'secure access' and think Identity Protection can secure remote access, but it focuses on risk detection, not proxying applications.

971
MCQmedium

A company uses Microsoft Entra ID (Azure AD). The IT team has created a security group named 'SalesTeam' that contains all sales department users. They want to ensure that only members of this group can access the company's CRM application, which is registered as an enterprise application in Entra ID. What should the IT team configure?

A.A Conditional Access policy that requires group membership
B.Self-service group management settings
C.Enterprise application user and group assignment
D.Application registration settings
AnswerC

This is the fundamental and most direct method to control which users or groups are authorized to access a specific enterprise application in Microsoft Entra ID. By assigning a group like 'SalesTeam' to the CRM application, you explicitly provision access for all members of that group, ensuring only authorized individuals can sign in and utilize the application. This method establishes the baseline access permissions for the application.

Why this answer

Enterprise applications in Microsoft Entra ID can be configured to require user or group assignment, which restricts access to only assigned users or groups. By assigning the 'SalesTeam' security group to the CRM enterprise application, the IT team ensures that only members of that group can authenticate and access the application. This is the standard method for controlling access to gallery or custom enterprise applications in Entra ID.

Exam trap

The trap here is confusing Conditional Access (which controls conditions and grants during authentication) with user/group assignment (which controls the fundamental ability to authenticate to the application), leading candidates to select A when C is the direct and correct configuration for restricting access.

Why the other options are wrong

A

Conditional Access policies control access based on conditions like location or device state, not direct user-to-app assignment. The requirement is to restrict access to only SalesTeam members, which is achieved by assigning the group to the enterprise application, not by a Conditional Access policy.

B

Self-service group management settings allow users to create and manage their own groups, but do not control access to an enterprise application. Access to the CRM app requires explicit user/group assignment, not group management features.

D

Application registration settings define how an app authenticates (e.g., redirect URIs, certificates), not which users can access it. User assignment for access is configured in the enterprise application's 'Users and groups' blade.

When would these options actually be correct?

A

A Conditional Access policy requiring group membership would be correct if the question asked for a way to enforce additional security controls, such as requiring multi-factor authentication or blocking access from untrusted locations, specifically for members of the SalesTeam group accessing the CRM app.

B

A company wants to allow sales managers to create and manage their own security groups without IT intervention. The IT team would configure self-service group management settings to delegate group creation and membership management to non-administrators.

D

A developer registers a new custom app in Entra ID and needs to configure its authentication endpoints, API permissions, or client credentials. The question would ask: 'What should the developer configure to allow the app to authenticate users?'

Why candidates pick the wrong answer

A

Candidates may confuse Conditional Access with direct assignment because both involve groups and access control, but Conditional Access is for conditions and policies, not for granting basic access to an application.

B

Candidates may confuse the concept of managing group membership with controlling access to applications, thinking that enabling self-service for the SalesTeam group would automatically grant access to the CRM app.

D

Candidates confuse the initial registration of an application with the post-registration access control, assuming that settings during registration include user assignment.

972
MCQmedium

A company is using Microsoft Entra ID to manage identities for a multi-tenant SaaS application. They want to allow users from partner organizations to access the application using their own corporate credentials, without needing to manage separate accounts. Which solution should they implement?

A.Microsoft Entra B2C
B.Microsoft Entra federation with the partner's identity provider
C.Microsoft Entra B2B collaboration
D.Microsoft Entra provisioning service
AnswerC

Microsoft Entra B2B (Business-to-Business) collaboration is the appropriate solution for enabling partner users to access applications and resources within your organization using their existing corporate or social identities. This feature creates guest user objects in your directory, allowing external users to authenticate with their home identity provider while granting them controlled access to your Microsoft Entra ID-protected resources without requiring complex federation setup.

Why this answer

Microsoft Entra B2B collaboration is the correct solution because it enables partner users to access the company's multi-tenant SaaS application using their own corporate credentials, without requiring separate accounts. B2B collaboration supports cross-tenant access by creating lightweight guest user objects in the resource tenant, which can authenticate via their home tenant's identity provider. This aligns with the requirement to allow partner organizations to use their existing credentials while avoiding account management overhead.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C, mistakenly thinking both handle external users, but B2C is for customer identities (social/local accounts) while B2B is for partner identities (corporate credentials).

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2C is designed for customer-facing identity management, allowing external users (e.g., consumers) to sign up and sign in with social or local accounts, not for partner organizations using their own corporate credentials. Option B is wrong because federation with a partner's identity provider typically establishes a trust between two organizations' identity systems, but it requires complex configuration and often involves setting up a federation trust (e.g., using SAML or WS-Federation) for the entire domain, which is overkill for simple guest access and does not natively support the lightweight, invitation-based model of B2B collaboration. Option D is wrong because the Microsoft Entra provisioning service automates the creation, update, and deletion of user accounts in SaaS applications (e.g., via SCIM), but it does not enable external users to authenticate with their own credentials; it manages identity lifecycle, not cross-tenant authentication.

973
MCQhard

Your organization, Fabrikam Inc., uses Microsoft 365 E5 licenses. The security team is deploying Microsoft Purview to protect sensitive data. They need to ensure that when a user attempts to share a document containing credit card numbers with an external partner, the action is blocked and the user receives a policy tip. Additionally, the incident should be logged for investigation. You have already created a sensitivity label for credit card data and auto-labeled documents. Which Microsoft Purview feature should you configure to meet these requirements?

A.Enable Microsoft Purview Insider Risk Management to detect the sharing activity.
B.Implement Microsoft Purview Records Management with a retention label that prevents sharing.
C.Create a Data Loss Prevention (DLP) policy that applies to documents containing credit card numbers, with an action to block sharing and notify users via policy tip.
D.Configure a sensitivity label policy that blocks external sharing when the label is applied.
AnswerC

Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information such as credit card numbers across various locations. A DLP policy can be precisely configured to detect this sensitive data within documents and then automatically enforce actions like blocking external sharing. Furthermore, it can provide immediate, user-facing policy tips to educate individuals about the policy violation, making it the ideal solution for both prevention and user notification.

Why this answer

DLP policies in Microsoft Purview are purpose-built to detect sensitive information types (like credit card numbers matching the PCI-DSS pattern) in Exchange, SharePoint, OneDrive, and Teams, and to take enforcement actions such as blocking external sharing. The policy can simultaneously surface a policy tip to the end user explaining why the action is blocked and generate an alert/incident in the DLP alerts dashboard for investigation. This directly satisfies all three requirements: block, notify, and log.

Exam trap

SC-900 often tests the confusion between sensitivity labels (which classify and encrypt) and DLP policies (which detect and enforce) — candidates incorrectly assume a sensitivity label alone can block external sharing based on content inspection.

How to eliminate wrong answers

Option A is wrong because Insider Risk Management is a behavioral analytics and investigation tool that surfaces risky user activity after the fact — it does not block sharing actions in real time or display policy tips. Option B is wrong because Records Management retention labels govern the lifecycle and disposition of content (retain/delete), not real-time sharing enforcement, and they cannot block external sharing. Option D is wrong because sensitivity labels alone (even with encryption) control access via encryption permissions, but they do not natively detect credit card numbers in content, do not produce DLP-style policy tips, and do not generate DLP incident logs — content inspection and blocking require a DLP policy.

974
Multi-Selecthard

Your company uses Microsoft Purview to meet data privacy regulations. You need to discover and classify personal data stored in Azure SQL Database. Which THREE tools or features can you use?

Select 3 answers
A.Microsoft 365 compliance center
B.Azure Information Protection
C.Microsoft Purview Data Estate Insights
D.Data Classification in Azure SQL Database
E.Microsoft Purview Data Map
AnswersC, D, E

Microsoft Purview Data Estate Insights provides a comprehensive, high-level view of an organization's entire data landscape, including data sources like Azure SQL. It offers pre-built reports and metrics that highlight data classification, sensitivity label distribution, data ownership, and glossary adherence across the data estate. This enables organizations to monitor and demonstrate compliance with data privacy regulations by understanding where sensitive data resides and how it's governed.

Why this answer

Microsoft Purview Data Estate Insights (C) provides a centralized dashboard to monitor data estate health, including scanning and classification of personal data across sources like Azure SQL Database. It integrates with the Purview Data Map to track data lineage and sensitivity labels, enabling compliance with data privacy regulations.

Exam trap

The trap here is that candidates confuse Microsoft Purview's centralized data governance tools (Data Map, Data Estate Insights) with Microsoft 365 compliance center or Azure Information Protection, which are designed for different scopes and do not natively discover personal data in Azure SQL Database.

975
MCQeasy

Your organization wants to automatically investigate and remediate email-based threats in Microsoft 365. Which security solution should you use?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Sentinel
AnswerB

Microsoft Defender for Office 365 is specifically engineered to protect an organization from sophisticated threats in email, links, and collaboration tools like Microsoft Teams. It leverages advanced anti-phishing, anti-malware, and Safe Attachments/Safe Links technologies to detect and block threats. Crucially, it includes Automated Investigation and Response (AIR) capabilities that automatically investigate alerts, determine the scope of a threat, and take recommended or approved remediation actions for email-borne attacks, directly addressing the requirement.

Why this answer

Microsoft Defender for Office 365 is the correct solution because it is specifically designed to protect against email-based threats such as phishing, malware, and business email compromise (BEC). It provides automated investigation and remediation capabilities through features like Automated Investigation and Response (AIR) and Threat Explorer, which can automatically analyze and remediate malicious emails, attachments, and URLs in Exchange Online.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 with Microsoft Defender for Endpoint, assuming endpoint protection covers email threats, but email security is a separate workload requiring dedicated protection for Exchange Online and SharePoint Online.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint focuses on protecting endpoints (e.g., devices, servers) from threats like malware and ransomware, not on email-based threats. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that governs and protects cloud applications, not specifically email threats. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution for enterprise-wide threat detection and response, not a dedicated email security solution.

Page 12

Page 13 of 18

Page 14