Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 976–1050

1279 questions total · 18pages · All types, answers revealed

Page 13

Page 14 of 18

Page 15
976
MCQeasy

A company implements a security model where no user or device is automatically trusted, even if they are inside the corporate network. Every access request must be authenticated, authorized, and encrypted before granting access, regardless of the request origin. This model is known as:

A.Defense in depth
B.Perimeter security
C.Zero Trust
D.Least privilege
AnswerC

Zero Trust is the security model that fundamentally assumes no user, device, or application should be automatically trusted, regardless of its location inside or outside the network perimeter. It mandates explicit verification for every access request, ensuring identity and device health are validated before granting access. This model strictly enforces least privilege access and operates under an 'assume breach' mentality, continuously monitoring and re-validating trust throughout a session.

Why this answer

Zero Trust is a security model that explicitly assumes no implicit trust based on network location. Every access request must be authenticated, authorized, and encrypted, regardless of whether it originates from inside or outside the corporate network. This aligns with the core Zero Trust principle of 'never trust, always verify'.

Exam trap

The trap here is that candidates often confuse Zero Trust with Defense in depth, assuming that multiple layers of security automatically remove implicit trust, but Zero Trust specifically targets the assumption of trust based on network location.

Why the other options are wrong

A

Defense in depth is a layered security strategy using multiple controls, but it does not inherently reject automatic trust for internal users or devices. The question specifically describes the core principle of Zero Trust: never trust, always verify.

B

Perimeter security relies on a trusted internal network and a defended boundary, but the question explicitly states that no user or device is automatically trusted even inside the network, which contradicts the perimeter model.

D

Least privilege is a principle that restricts users to only the permissions necessary for their tasks, but it does not address the core concept of never trusting any request by default, regardless of origin, which is the defining characteristic of Zero Trust.

When would these options actually be correct?

A

A question asking: 'Which security model uses multiple layers of controls (e.g., firewalls, antivirus, IDS) to protect assets?' would make Defense in depth the correct answer, as it emphasizes layered defenses rather than trust verification.

B

A question that asks: 'A company uses firewalls, IDS/IPS, and VPNs to protect its network boundary from external threats. Which security model does this describe?' Then perimeter security would be correct.

D

A question that asks: 'Which security principle ensures that users and processes are granted only the minimum access rights needed to perform their job functions?' would have Least privilege as the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse the layered approach of defense in depth with the 'never trust' concept, assuming multiple layers inherently distrust internal traffic, when in fact traditional defense in depth often trusts the internal network.

B

Candidates may confuse perimeter security with Zero Trust because both involve security controls, but they fail to recognize that Zero Trust eliminates implicit trust, whereas perimeter security trusts internal traffic by default.

D

Candidates may confuse least privilege with Zero Trust because both involve limiting access, but they focus on different aspects: least privilege is about permission levels, while Zero Trust is about continuous verification of every request.

977
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Defender for Cloud Apps? (Select TWO.)

Select 2 answers
A.Enforce device compliance policies
B.Provide threat analytics reports
C.Control access with Conditional Access App Control
D.Classify sensitive data across cloud apps
E.Discover shadow IT cloud apps
AnswersC, E

Microsoft Defender for Cloud Apps (MDCA) provides Conditional Access App Control, which enables real-time monitoring and control over user sessions to cloud applications. By integrating with Azure AD Conditional Access policies, MDCA can enforce session-specific controls, such as blocking downloads, requiring step-up authentication, or protecting data exfiltration, based on user, device, location, or app context. This capability ensures that access to sensitive data within sanctioned cloud apps is governed by granular, adaptive policies.

Why this answer

Option C is correct because Defender for Cloud Apps provides Conditional Access App Control, which uses reverse-proxy deployment to enforce session policies (such as block download, block copy/paste, and require MFA) in real time for cloud apps, integrating with Microsoft Entra Conditional Access. Option E is correct because Cloud Discovery in Defender for Cloud Apps analyzes traffic logs from firewalls and proxies to identify shadow IT, risk-rate discovered apps against the Cloud App Catalog, and surface usage and compliance insights. Option A is not a Defender for Cloud Apps capability; device compliance policies are enforced by Microsoft Intune and evaluated by Microsoft Entra Conditional Access.

Option B is not correct because threat analytics reports are a Microsoft Defender XDR/Defender for Endpoint feature, not a Defender for Cloud Apps capability. Option D is not correct because sensitive data classification across cloud apps is performed by Microsoft Purview Information Protection and data classification services, not by Defender for Cloud Apps itself.

Exam trap

The trap here is that candidates confuse the integrated capabilities (like classification via Purview or device compliance via Intune) with Defender for Cloud Apps' native features, leading them to select options that describe adjacent Microsoft security solutions rather than Defender for Cloud Apps' core functionalities.

978
MCQeasy

Your organization needs to retain all email communications with customers for 7 years due to regulatory requirements. Which Microsoft Purview solution should you use?

A.Sensitivity labels
B.eDiscovery (Standard)
C.Retention policies
D.Data Loss Prevention policies
AnswerC

Retention policies in Microsoft Purview apply retention settings across Exchange mailboxes, satisfying the seven-year regulatory requirement without user intervention. Unlike retention labels, which target specific items, policies operate at workload or location level, automatically retaining all customer email communications for the defined period, then deleting them if configured.

Why this answer

Retention policies in Microsoft Purview are designed to retain data for a specified period to meet regulatory or legal requirements. For email communications, a retention policy can be applied to Exchange mailboxes to ensure all messages are preserved for exactly 7 years, regardless of user deletion. This directly addresses the need to retain all customer emails for the mandated duration.

Exam trap

The trap here is that candidates often confuse retention policies (which enforce time-based preservation) with sensitivity labels (which focus on classification and protection), leading them to choose option A when the question explicitly requires a fixed retention duration.

How to eliminate wrong answers

Option A is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., confidential, PII) but do not enforce time-based retention; they can trigger retention via auto-labeling but are not the primary solution for fixed-duration retention. Option B is wrong because eDiscovery (Standard) is used for searching and exporting content for legal or investigative purposes, not for automatically retaining data for a set period. Option D is wrong because Data Loss Prevention (DLP) policies monitor and prevent unauthorized sharing of sensitive data (e.g., credit card numbers) but do not enforce retention schedules.

979
MCQmedium

A company has many guest users in Microsoft Entra ID who collaborate on a project in a specific SharePoint site. The compliance team needs to periodically verify that these guest users still require access to the site. If a reviewer does not respond within 30 days, the guest's access should be automatically removed. Additionally, the company wants to ensure that once access is removed, the guest user object is eventually deleted from the directory after 90 days. Which Microsoft Entra Identity Governance features should they use together?

A.Access Reviews configured to auto-apply results and delete guest users after a specified number of days
B.Entitlement Management access packages with an expiration policy
C.Lifecycle Workflows to schedule a periodic task
D.Privileged Identity Management (PIM) for guest roles
AnswerA

Access Reviews are specifically designed for periodically reviewing user access to resources, including guest users. By configuring an Access Review to auto-apply results, access can be automatically revoked if reviewers do not respond or deny access. Crucially, the 'Delete users' setting within the review can be enabled to automatically remove guest user objects from Microsoft Entra ID after a specified number of days if their access is denied or not re-certified, directly addressing the need for automated guest cleanup.

Why this answer

Access Reviews in Microsoft Entra ID can be configured to automatically apply results, removing guest access when a reviewer does not respond within a specified period (e.g., 30 days). Additionally, the 'Delete guest users not reviewed within' setting allows automatic deletion of the guest user object from the directory after a configurable number of days (e.g., 90 days). This directly meets both requirements: periodic verification of access and eventual cleanup of the directory object.

Exam trap

The trap here is that candidates confuse 'removing access' (which many features can do) with 'deleting the user object from the directory' (which only Access Reviews with the specific deletion setting can do), leading them to choose Entitlement Management or Lifecycle Workflows.

How to eliminate wrong answers

Option B is wrong because Entitlement Management access packages with an expiration policy can remove a user's assignment to a resource (like the SharePoint site) but do not automatically delete the guest user object from the directory after a specified number of days; they only expire the package assignment. Option C is wrong because Lifecycle Workflows are designed for automating joiner, mover, and leaver processes for employees, not for periodic guest access reviews or automatic deletion of guest objects. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time activation and approval for privileged roles, not periodic access reviews or automatic removal of guest user objects from the directory.

980
MCQhard

A company is implementing a Microsoft Entra ID tenant for a new subsidiary. They require that all users authenticate using passwordless methods, specifically the Microsoft Authenticator app. What is the minimum configuration required to enforce this?

A.Enable Microsoft Entra ID Protection and configure MFA registration policy
B.Turn on Security defaults
C.Configure Microsoft Entra Hybrid Join for all devices
D.Create a Conditional Access policy targeting all users that requires 'Require authentication strength' and select the 'Passwordless MFA' authentication strength
AnswerD

This is the correct approach because Microsoft Entra Conditional Access policies, combined with authentication strengths, are designed to enforce specific authentication methods. By configuring a policy to 'Require authentication strength' and selecting 'Passwordless MFA', administrators can explicitly mandate that users authenticate using only passwordless methods, such as FIDO2 security keys or Windows Hello for Business. This effectively blocks any sign-in attempt that relies on a password as the primary credential, thereby achieving a truly passwordless environment.

Why this answer

A Conditional Access policy with the 'Require authentication strength' setting allows you to select the 'Passwordless MFA' authentication strength, which enforces passwordless methods like the Microsoft Authenticator app. This is the minimum configuration that directly targets all users and mandates passwordless authentication, as opposed to broader or less specific settings.

Exam trap

The trap here is that candidates often confuse 'MFA registration' or 'Security defaults' with enforcing a specific authentication method, but neither restricts the method to passwordless only, which is the key requirement in the question.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection and MFA registration policy only enforce that users register for MFA, not that they use passwordless methods specifically. Option B is wrong because Security defaults enforce MFA using any method (including passwords), not exclusively passwordless authentication. Option C is wrong because Microsoft Entra Hybrid Join is a device state requirement for scenarios like Windows Hello for Business, but it does not enforce passwordless authentication via the Authenticator app and is not the minimum configuration for this requirement.

981
MCQmedium

A company runs a consumer-facing e-commerce website and wants to allow customers to sign in using their existing social media accounts such as Google, Facebook, or LinkedIn. Which Microsoft Entra ID solution should they implement?

A.Microsoft Entra External ID (B2C)
B.Microsoft Entra External ID (B2B)
C.Microsoft Entra Identity Protection
D.Microsoft Entra Conditional Access
AnswerA

Microsoft Entra External ID (B2C) is specifically engineered to manage customer identities for consumer-facing applications and services, such as an e-commerce website. It enables users to sign up and sign in using their preferred social identity providers, such as Google, Facebook, or Apple, or by creating a local account. This service provides highly customizable user experiences for registration, sign-in, and profile management, scaling to millions of users while integrating seamlessly with your platform.

Why this answer

Microsoft Entra External ID (B2C) is the correct solution because it is specifically designed for consumer-facing applications, allowing customers to sign in using social identity providers (IdPs) like Google, Facebook, and LinkedIn via OAuth 2.0 and OpenID Connect protocols. It provides a customizable authentication experience for external users, distinct from B2B which targets organizational collaboration.

Exam trap

The trap here is that candidates confuse B2B with B2C, assuming 'External ID' covers all external users, but B2B strictly targets organizational partners (e.g., using their work accounts) while B2C is for consumer social logins.

Why the other options are wrong

B

B2B is designed for business-to-business collaboration, allowing external partners to access internal resources, not for consumer-facing identity management with social identity providers.

C

Microsoft Entra Identity Protection is a security tool for detecting and responding to identity risks, not for enabling social identity federation for consumer sign-in.

D

Microsoft Entra Conditional Access is a policy engine for enforcing access controls based on signals like user location or device state, not a solution for enabling social identity federation for external customers.

When would these options actually be correct?

B

A company needs to enable external partners (e.g., vendors, suppliers) to access internal applications using their own corporate credentials or social accounts. The question would specify 'partner access' rather than 'customer sign-in'.

C

A question asking which Microsoft Entra solution helps detect and block compromised accounts or risky sign-ins for an organization's internal users would make Identity Protection the correct answer.

D

A company wants to enforce multi-factor authentication for all users accessing a sensitive internal application based on sign-in risk level. Conditional Access would be the correct solution to apply such policies.

Why candidates pick the wrong answer

B

Candidates may confuse 'External ID' as a single solution and overlook the B2C vs B2B distinction, or assume social login is only for B2B scenarios.

C

Candidates may confuse identity protection with authentication solutions, thinking it manages external identities, or they may overestimate its role in sign-in processes.

D

Candidates may confuse Conditional Access as a general identity solution, thinking it can handle external identity scenarios, or they may overestimate its scope beyond access control policies.

982
MCQeasy

A user reports that they cannot access a sensitive document in SharePoint. The document has a sensitivity label of 'Highly Confidential' applied. The user is a member of the 'Finance' group, which has the label permission. However, the user is located in a country that is blocked by a conditional access policy. What is the most likely reason the user cannot access the document?

A.The user does not have the required sensitivity label permission
B.The user does not have a Microsoft 365 E5 license
C.A conditional access policy is blocking access based on the user's location
D.The document does not have a sensitivity label applied
AnswerC

Conditional Access policies evaluate various signals, including user location, device compliance, and sign-in risk, to determine if access should be granted or blocked. A policy configured to restrict access to sensitive documents from untrusted or unapproved geographic locations would explicitly override any inherent sensitivity label permissions, directly causing the user's inability to access the document.

Why this answer

The user is a member of the Finance group, which has the necessary sensitivity label permission, so lack of permission is not the issue. The most likely reason is that a conditional access policy is blocking access based on the user's location, as the user is in a blocked country. Conditional access policies in Microsoft Entra ID can restrict access based on location, and this would override other permissions.

Exam trap

SC-900 often tests the difference between permission-based access (sensitivity labels) and policy-based access (conditional access). Candidates might focus on the label permission and overlook the conditional access policy, but the location block is the most likely cause given the user's group membership.

How to eliminate wrong answers

Option A is wrong because the user is a member of the Finance group, which has the label permission, so they do have the required permission. Option B is wrong because the question does not indicate a licensing issue; sensitivity labels require certain licenses, but the user's group membership suggests they have the necessary access. Option D is wrong because the document has a sensitivity label applied ('Highly Confidential'), so it is not missing a label.

983
MCQhard

Your organization uses Microsoft Entra ID. You need to ensure that when a user is terminated, all access to SaaS applications is automatically revoked. What should you configure?

A.Configure a conditional access policy to block access for disabled users.
B.Use Privileged Identity Management to remove role assignments.
C.Schedule an access review for quarterly review of access.
D.Configure Microsoft Entra lifecycle workflows to disable the user and remove group memberships upon termination.
AnswerD

Microsoft Entra lifecycle workflows are specifically designed to automate user lifecycle events, including offboarding. These workflows can be configured to automatically disable a user account, remove them from specified groups, and revoke application access immediately upon a termination event, often triggered by changes synced from an HR system. This ensures timely, consistent, and comprehensive removal of access, directly addressing the requirement for efficient and secure offboarding.

Why this answer

Microsoft Entra lifecycle workflows automate the user offboarding process by disabling the user account and removing group memberships upon termination. This ensures that the user loses access to all SaaS applications that rely on Entra ID for authentication, as group membership removal revokes access tokens and disables sign-in.

Exam trap

The trap here is that candidates often confuse conditional access policies (which control sign-in conditions) with automated lifecycle actions, mistakenly thinking a policy can proactively revoke access upon termination without the underlying user state change.

How to eliminate wrong answers

Option A is wrong because a conditional access policy that blocks access for disabled users is reactive and does not automatically trigger upon termination; it only enforces a block if the user is already disabled, but does not handle the removal of group memberships or provisioning. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments and does not revoke access to SaaS applications for non-privileged users or remove group memberships. Option C is wrong because scheduling an access review for quarterly review only provides periodic auditing and does not automatically revoke access upon termination; it is a manual or scheduled review process, not an immediate revocation mechanism.

984
Multi-Selectmedium

Which THREE of the following are features of Microsoft Purview Data Loss Prevention (DLP)? (Choose three.)

Select 3 answers
A.Provide policy tips to users
B.Detect sensitive data in email messages
C.Apply sensitivity labels automatically
D.Retain data for a specified period
E.Monitor sensitive data on endpoints
AnswersA, B, E

Microsoft Purview Data Loss Prevention (DLP) policies can be configured to display real-time policy tips to users. These tips appear directly within applications like Outlook, SharePoint, OneDrive, and Teams, informing users when they are about to share or transmit sensitive information in violation of organizational policies. This proactive guidance helps educate users and prevents accidental data loss before it occurs.

Why this answer

Option A is correct because Microsoft Purview DLP can display policy tips to users in supported workloads (for example, Outlook and Office apps) to warn them when they are about to share content that matches a DLP rule, helping them make informed decisions before sending or sharing. Option B is correct because DLP is designed to detect sensitive information types (such as credit card numbers, national ID numbers, or custom regex/keyword patterns) in Exchange Online email messages and take policy actions like block, encrypt, or notify. Option E is correct because Purview DLP supports endpoint DLP, which monitors sensitive data activities on onboarded Windows and macOS devices, including copying to USB, printing, and uploading to cloud services.

Option C is not a DLP feature but a capability of Microsoft Purview Information Protection sensitivity labels, which can be auto-applied via label policies or client-side auto-labeling. Option D is not a DLP feature but a retention capability provided by Microsoft Purview Data Lifecycle Management retention policies and retention labels.

Exam trap

The trap here is that candidates confuse DLP's ability to use sensitivity labels as conditions (which is true) with the ability to automatically apply labels (which is a separate Information Protection feature), and they also mistake retention policies for DLP's data lifecycle controls.

985
MCQmedium

An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to ensure that when a user tries to share a document containing a credit card number externally via email, the user sees a policy tip and the email is blocked. Which DLP rule action should they configure?

A.Notify user with policy tip only
B.Block the message and notify the user with a policy tip
C.Block the message only
D.Redirect the message to the compliance admin
AnswerB

This action effectively prevents data loss by blocking the transmission of the message containing sensitive information, ensuring the policy is enforced. Simultaneously, it provides a policy tip to the user, explaining why the message was blocked and offering guidance on how to remediate the issue or comply with organizational policies. This combination both enforces security and educates the user, aligning perfectly with robust data loss prevention objectives.

Why this answer

The requirement is to both block the email and show a policy tip to the user. In Microsoft Purview DLP, the 'Block the message and notify the user with a policy tip' action enforces the block at the transport level while simultaneously displaying a customizable policy tip in Outlook or Outlook on the web, informing the user why the message was blocked. This meets the dual need of prevention and user notification.

Exam trap

The trap here is that candidates often confuse 'Notify user with policy tip only' as sufficient because it provides a warning, but they overlook the explicit requirement to block the message, which requires the combined action of blocking and notifying.

How to eliminate wrong answers

Option A is wrong because 'Notify user with policy tip only' allows the email to be sent after the user acknowledges the tip, which does not block the message as required. Option C is wrong because 'Block the message only' prevents delivery but does not show a policy tip to the user, failing the notification requirement. Option D is wrong because 'Redirect the message to the compliance admin' sends the email to an administrator for review instead of blocking it, which does not prevent the external sharing of sensitive data.

986
MCQmedium

A financial organization needs to automatically detect emails containing the phrase 'Non-Public Material Information' and apply a retention policy that retains those emails for 7 years. They also need to train senders with a policy tip before sending, and if they still send the email, it should be encrypted and blocked from being forwarded outside the organization. Which Microsoft Purview solution should they use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is specifically engineered to identify, monitor, and protect sensitive information across Microsoft 365, including email communications. It leverages sensitive information types, keywords, and trainable classifiers to detect specific content patterns. Upon detection, DLP policies can automatically enforce a range of protective actions, such as blocking email delivery, encrypting messages, applying specific retention labels, or providing policy tips to users, directly addressing the need for automatic detection and enforcement.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it can automatically detect sensitive content (e.g., 'Non-Public Material Information') in emails, apply policy tips to train senders before sending, enforce encryption, and block forwarding outside the organization. DLP policies also integrate with retention labels to retain emails for a specified period, such as 7 years, by applying a retention label automatically when the sensitive content is detected.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management (retention only) with DLP (detection + action), or assume Communication Compliance handles all email content monitoring, but DLP is the only solution that combines real-time content detection, user training via policy tips, and automated enforcement actions like encryption and forwarding blocks.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management focuses solely on retaining and deleting data based on policies, but it cannot detect sensitive content in real-time, apply policy tips, or enforce encryption and forwarding restrictions. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect policy violations (e.g., harassment, insider trading) for review and remediation, not to automatically apply retention, encryption, or forwarding blocks on emails containing specific phrases. Option D is wrong because Microsoft Purview Audit provides logging and investigation of past activities, but it cannot proactively detect content, apply policy tips, encrypt emails, or block forwarding.

987
MCQhard

A company uses Microsoft Defender for Endpoint on all workstations and Microsoft Defender for Office 365 for email protection. The security operations team wants a single console to see all incidents from both products, automatically investigate and respond to threats across endpoints and email, and integrate with Microsoft Sentinel for advanced hunting. Which Microsoft security solution should they use?

A.Microsoft 365 Defender
B.Microsoft Defender for Cloud
C.Microsoft Purview Compliance Portal
D.Microsoft Entra ID Protection
AnswerA

Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies security signals from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. It correlates alerts across these domains into consolidated incidents, providing a comprehensive view of attacks and enabling automated, cross-domain response actions. This integrated approach significantly enhances an organization's ability to detect, investigate, and remediate sophisticated multi-stage threats.

Why this answer

Microsoft 365 Defender is the correct solution because it provides a unified incident queue that aggregates alerts from Microsoft Defender for Endpoint and Microsoft Defender for Office 365, enabling automated investigation and response (AIR) across endpoints and email. It also natively integrates with Microsoft Sentinel for advanced hunting via the Microsoft 365 Defender connector, allowing the security operations team to correlate signals and perform cross-domain threat hunting.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (which protects cloud workloads) with Microsoft 365 Defender (which unifies endpoint, email, and identity security), leading them to select the cloud-focused option instead of the cross-workload unified solution.

Why the other options are wrong

B

Microsoft Defender for Cloud is designed for protecting cloud workloads (e.g., VMs, containers, SQL) across multi-cloud environments, not for unifying endpoint and email incident management or integrating with Microsoft 365 Defender's automated investigation and response.

C

Microsoft Purview Compliance Portal is focused on data governance, compliance, and risk management, not on unified incident management and automated response for endpoint and email threats.

When would these options actually be correct?

B

A company wants to secure its Azure and on-premises servers, containers, and databases, with a focus on cloud security posture management (CSPM) and workload protection, and needs to integrate alerts into Microsoft Sentinel for centralized monitoring.

C

A company needs to manage data retention policies, perform eDiscovery, enforce data loss prevention (DLP) rules, and monitor compliance with regulations like GDPR or HIPAA across Microsoft 365 services.

Why candidates pick the wrong answer

B

Candidates may confuse 'Defender for Cloud' with 'Microsoft 365 Defender' due to similar naming, or assume it covers all Microsoft security products, overlooking its specific cloud workload focus.

C

Candidates may confuse 'compliance' with security operations, or think that a single portal for all Microsoft 365 security-related tasks includes incident response, but Purview is specifically for compliance and data governance.

988
MCQeasy

Your company wants to provide a single sign-on experience for all cloud applications. Which Microsoft Entra ID feature should you implement?

A.B2B collaboration
B.Identity Protection
C.App registration and SSO configuration
D.Conditional Access
AnswerC

App registration in Microsoft Entra ID is the essential process for integrating an application to use Entra ID as its identity provider. By registering an application, administrators define how users authenticate, grant necessary permissions, and configure single sign-on (SSO) protocols like OpenID Connect or SAML. This direct integration enables users to access the registered application seamlessly using their existing Entra ID credentials without re-entering them, thereby providing a unified SSO experience.

Why this answer

App registration and SSO configuration in Microsoft Entra ID enables single sign-on (SSO) by registering each cloud application as an enterprise application and configuring federation protocols such as SAML 2.0, OpenID Connect, or OAuth 2.0. This allows users to authenticate once with their Entra ID credentials and access all configured cloud applications without repeated logins.

Exam trap

The trap here is that candidates often confuse Conditional Access (a policy enforcement tool) with SSO configuration, or they mistakenly think B2B collaboration is needed for internal app SSO, when in fact App registration and SSO configuration is the correct feature for enabling a unified sign-on experience.

How to eliminate wrong answers

Option A is wrong because B2B collaboration is designed for inviting external users (guests) from other organizations, not for providing SSO across cloud applications for internal users. Option B is wrong because Identity Protection is a security feature that detects and remediates identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs), not a mechanism for SSO. Option D is wrong because Conditional Access is a policy engine that enforces access controls (e.g., MFA, device compliance) after authentication, but it does not configure or enable SSO itself.

989
MCQmedium

A company is subject to a legal investigation and must preserve all email communications related to the case for an indefinite period, even if users try to delete them. The compliance officer needs a solution that can place a hold on specific user mailboxes and prevent any permanent deletion of relevant content. Which Microsoft Purview feature should be used?

A.Retention labels
B.Litigation hold
C.Data loss prevention
D.Compliance Manager
AnswerB

Litigation hold is specifically designed to preserve all electronically stored information (ESI) within a user's mailbox, including active items, deleted items, and even items modified after the hold is placed. It places an indefinite hold on content, preventing users from permanently deleting items and ensuring data immutability for legal discovery or investigation purposes. This mechanism is crucial for meeting eDiscovery requirements by ensuring no relevant data is lost.

Why this answer

Litigation hold is the correct feature because it places a hold on an entire mailbox, preserving all content including deleted items and versions, and prevents permanent deletion by users or automated processes. Unlike retention labels or policies, litigation hold applies to the entire mailbox and is designed specifically for legal investigations where indefinite preservation is required.

Exam trap

The trap here is that candidates often confuse retention labels or policies with litigation hold, not realizing that retention labels apply granularly to content while litigation hold applies to the entire mailbox and is specifically designed for legal preservation scenarios.

Why the other options are wrong

A

Retention labels are used to classify and retain data based on policies, but they do not prevent users from deleting items; they only ensure that deleted items are preserved in a recoverable state for a specified period. In this scenario, the requirement is to place a hold that prevents permanent deletion indefinitely, which is a feature of Litigation hold, not retention labels.

C

Data loss prevention (DLP) policies prevent accidental sharing of sensitive data but cannot place a legal hold on mailboxes to preserve content indefinitely against user deletion.

D

Compliance Manager is a risk assessment and compliance score tool, not a feature for placing holds on mailboxes to preserve content. It does not prevent deletion of emails.

When would these options actually be correct?

A

A company needs to automatically apply a retention policy to all emails containing specific keywords (e.g., 'confidential') for a period of 5 years, and users should be able to delete the emails, but the organization must be able to recover them if needed. In this case, a retention label with a retention rule would be the correct answer.

C

A company wants to automatically detect and block emails containing credit card numbers from being sent to external recipients. Which Microsoft Purview feature should be used?

D

A company needs to assess its compliance posture against data protection regulations and track remediation actions. Compliance Manager would be correct for evaluating and improving compliance scores.

Why candidates pick the wrong answer

A

Candidates may confuse retention labels with holds because both involve preserving data, but they don't realize that retention labels do not block deletion by users; they only retain deleted items for a set period, whereas a hold prevents deletion entirely.

C

Candidates may confuse the preservation aspect of DLP (preventing data loss) with the legal preservation requirement of litigation hold, assuming DLP can also prevent deletion.

D

Candidates may confuse Compliance Manager with a feature that enforces legal holds because both relate to compliance and legal requirements, but they serve different purposes.

990
MCQmedium

A company has an on-premises web-based expense report application. The IT team wants to make this application accessible to remote employees over the internet without requiring a VPN. They need to use Microsoft Entra ID for authentication and apply Conditional Access policies such as requiring multi-factor authentication. Which Microsoft Entra ID feature should they implement?

A.Azure AD Application Proxy
B.Self-service password reset (SSPR)
C.Azure AD B2B collaboration
D.Azure AD Domain Services
AnswerA

Azure AD Application Proxy securely publishes on-premises web applications, making them accessible to remote users without requiring a VPN or inbound firewall rules. It leverages a lightweight connector installed within the corporate network, which establishes an outbound-only connection to the Azure AD Application Proxy service. This allows users to pre-authenticate with Entra ID, apply Conditional Access policies, and then access the internal application via a secure proxy URL, providing single sign-on capabilities.

Why this answer

Azure AD Application Proxy allows on-premises web applications to be published for remote access without a VPN. It integrates with Microsoft Entra ID for authentication and supports Conditional Access policies, including multi-factor authentication, by acting as a reverse proxy that forwards authenticated requests to the internal application.

Exam trap

The trap here is that candidates may confuse Azure AD Application Proxy with a VPN solution or think that Azure AD Domain Services is needed for authentication, but the key is that Application Proxy specifically publishes on-premises web apps with Entra ID authentication and Conditional Access support without requiring a VPN.

Why the other options are wrong

C

Azure AD B2B collaboration is designed for sharing apps and resources with external guest users from other organizations, not for publishing internal on-premises apps to remote employees.

D

Azure AD Domain Services provides managed domain services like domain join, group policy, and LDAP, but it does not publish on-premises web applications to the internet or integrate with Conditional Access policies for remote access without VPN.

When would these options actually be correct?

C

A company needs to grant external partners access to a cloud-based application while using their own identities for authentication. The question would specify that the users are from partner organizations, not the company's own employees.

D

A company needs to lift-and-shift legacy on-premises applications that require domain-joined servers and use Kerberos/NTLM authentication to Azure VMs, without managing domain controllers. They want to use Microsoft Entra ID for authentication but the apps require AD domain services.

Why candidates pick the wrong answer

C

Candidates may confuse B2B collaboration with remote access solutions because both involve external-facing authentication, but B2B is specifically for external identities, not internal app publishing.

D

Candidates may confuse Azure AD Domain Services with Azure AD Application Proxy because both involve on-premises resources and Azure AD, but Domain Services is for domain management, not application publishing.

991
MCQmedium

A company uses Microsoft Entra ID and Intune for device management. They want to ensure that only devices marked as compliant (e.g., updated, encrypted) can access the corporate HR portal. Which Conditional Access assignment condition should the administrator configure?

A.Locations
B.Device state
C.Client apps
D.Sign-in risk
AnswerB

Device state condition can be set to require a device to be compliant (as defined in Intune) or hybrid Microsoft Entra ID joined. This is the correct condition to enforce access based on device compliance.

Why this answer

The 'Device state' condition in Conditional Access allows administrators to require that only devices marked as compliant (via Intune compliance policies) can access resources. By configuring this condition, the HR portal will block access from non-compliant devices, enforcing security requirements like encryption and updates before granting access.

Exam trap

The trap here is that candidates may confuse 'Device state' with 'Sign-in risk' or 'Client apps', thinking device compliance is tied to user risk or application type, but Microsoft specifically separates device health from user risk and app context in Conditional Access.

How to eliminate wrong answers

Option A is wrong because 'Locations' controls access based on IP address ranges or geographic regions, not device compliance status. Option C is wrong because 'Client apps' filters access by application type (e.g., browser, mobile app), not device health or compliance. Option D is wrong because 'Sign-in risk' is part of Identity Protection and evaluates user authentication risk (e.g., leaked credentials), not device compliance.

992
MCQhard

A financial services firm must comply with regulatory requirements that mandate supervisory review of communications between advisors and clients. They need to automatically capture emails and Microsoft Teams messages from a specific group of advisors, assign them to a supervisor for review, and flag messages containing potential code words for insider trading. Which Microsoft Purview solution should they use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Information Protection
D.Microsoft Purview Insider Risk Management
AnswerB

Microsoft Purview Communication Compliance is specifically designed to help organizations detect, investigate, and remediate policy violations in communications. It leverages machine learning and customizable dictionaries to identify problematic content, such as potential insider trading code words, across various communication channels. This solution provides a structured workflow for supervisory review, allowing designated personnel to examine flagged messages, assign them for further investigation, and take appropriate action, directly addressing the need for content flagging and review.

Why this answer

Microsoft Purview Communication Compliance is the correct solution because it is specifically designed to capture and review communications (email, Teams messages) for regulatory compliance, such as supervisory oversight of advisor-client interactions. It can automatically flag messages containing sensitive keywords or patterns (e.g., potential code words for insider trading) and route them to designated supervisors for review, meeting the firm's regulatory mandate.

Exam trap

The trap here is that candidates often confuse the 'capture and review communications' requirement with Insider Risk Management (Option D), which focuses on behavioral analytics and risk scoring rather than direct communication capture and keyword-based flagging.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management focuses on retaining, deleting, and managing data based on policies (e.g., retention labels, disposition review), not on capturing and reviewing communications for compliance or flagging specific content. Option C is wrong because Microsoft Purview Information Protection is used for classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not for supervisory review or automated flagging of communications. Option D is wrong because Microsoft Purview Insider Risk Management is designed to detect and investigate risky user activities (e.g., data exfiltration, policy violations) using analytics and behavioral indicators, not to capture and review communications for regulatory compliance or flag specific keywords.

993
MCQmedium

Your organization must ensure that financial reports are protected with encryption and cannot be forwarded. Which two Microsoft Purview features should you combine?

A.Data Lifecycle Management and Data Loss Prevention
B.Retention policies and Records Management
C.Information Barriers and Communication Compliance
D.eDiscovery (Premium) and Audit (Standard)
E.Sensitivity labels with encryption and Data Loss Prevention
AnswerE

Sensitivity labels allow organizations to classify and protect sensitive content by applying persistent encryption, visual markings, and access restrictions directly to documents and emails. This ensures the financial reports are encrypted regardless of where they are stored or shared. Data Loss Prevention (DLP) policies then complement this by detecting sensitive information and actively preventing its unauthorized forwarding or sharing based on predefined rules, thus providing comprehensive protection.

Why this answer

Sensitivity labels with encryption allow you to apply persistent encryption to financial reports, ensuring they remain protected even when shared. Data Loss Prevention (DLP) policies can then block or warn users from forwarding these encrypted reports via email or other channels, providing a combined solution for encryption and forwarding prevention.

Exam trap

The trap here is that candidates often think DLP alone can prevent forwarding, but without encryption (via sensitivity labels), the content remains unprotected if forwarded outside the organization, so both features must be combined.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management governs retention and deletion, not encryption or forwarding prevention, and DLP alone doesn't provide encryption. Option B is wrong because Retention policies and Records Management control data retention and disposition, not encryption or blocking forwarding. Option C is wrong because Information Barriers restrict communication between specific groups, and Communication Compliance monitors for policy violations, neither directly encrypts nor prevents forwarding of financial reports.

Option D is wrong because eDiscovery (Premium) is for legal discovery and Audit (Standard) logs activities, neither provides encryption or forwarding controls.

994
MCQhard

Tailspin Toys is a toy manufacturer with headquarters in the US and subsidiaries in Europe and Asia. You are the compliance administrator. The company must comply with the EU General Data Protection Regulation (GDPR). Requirements: 1) Personal data of EU residents must be retained only for as long as necessary (max 5 years after last interaction). 2) If a user tries to share personal data outside the EU, the action must be blocked. 3) Users must be able to manually mark documents as 'GDPR High Risk' which will encrypt them and add a watermark 'GDPR PROTECTED'. 4) All access to personal data must be audited. You have Microsoft Purview with E5 compliance licenses. What is the most efficient solution?

A.Use a retention policy to delete all content after 5 years; create a DLP policy to block sharing of personal data outside EU; create a sensitivity label for manual application with encryption and watermark; enable audit logging
B.Create an auto-labeling policy to apply a 'Personal Data' sensitivity label; create a retention label 'GDPR Retention' to auto-apply to personal data and retain for 5 years; create a DLP policy to block sharing of labeled personal data outside EU; create a separate sensitivity label 'GDPR High Risk' for manual application with encryption and watermark; enable audit logging
C.Use a retention policy to delete personal data after 5 years; create a DLP policy to block cross-border sharing; use a sensitivity label with auto-labeling for personal data; enable audit logging
D.Create a DLP policy to block sharing of personal data outside EU; use a retention label for 5 years; use a single sensitivity label for both automatic and manual scenarios; enable audit logging
AnswerB

Auto-labeling applies sensitivity label; retention label retains personal data for 5 years; DLP blocks cross-border sharing; manual label provides encryption and watermark; audit logging tracks access.

Why this answer

Option B is correct because it uses the full Microsoft Purview toolset appropriately: an auto-labeling policy applies a 'Personal Data' sensitivity label to identify and classify personal data at scale; a retention label 'GDPR Retention' is auto-applied to that labeled content to enforce the 5-year retention requirement; a DLP policy blocks sharing of labeled personal data outside the EU; a separate sensitivity label 'GDPR High Risk' is manually applied by users to encrypt and watermark documents; and audit logging is enabled. This combination meets all four requirements with minimal manual effort and leverages E5 compliance features like auto-labeling and DLP with sensitivity labels.

Exam trap

SC-900 often tests the difference between retention policies and retention labels, and the distinction between auto-labeling and manual sensitivity labeling, causing candidates to choose a solution that uses a retention policy instead of a retention label or a single label for both automatic and manual scenarios.

How to eliminate wrong answers

Option A is wrong because it uses a retention policy (which applies at the workload level, not per-item) and lacks auto-labeling for personal data, so it cannot automatically identify and retain personal data for 5 years after last interaction; it also does not provide a way to automatically apply retention to specific personal data. Option C is wrong because it uses a retention policy instead of a retention label, which cannot be auto-applied to specific personal data based on classification, and it lacks a separate manual sensitivity label for the 'GDPR High Risk' scenario, so it cannot meet the encryption and watermark requirement for manually marked documents. Option D is wrong because it uses a single sensitivity label for both automatic and manual scenarios, which is not feasible: auto-labeling policies apply labels automatically, while manual labeling requires user action; a single label cannot serve both purposes effectively, and it also uses a retention label without auto-application to personal data, so retention may not be enforced correctly.

995
MCQmedium

A user authenticates with a smart card and is then granted access to a specific database based on their job role in the finance department. Which security concept describes the process of determining what the authenticated user is allowed to do?

A.Authentication
B.Authorization
C.Accounting
D.Encryption
AnswerB

Authorization is the critical security process that determines what an authenticated user is permitted to do or access within a system. After a user successfully authenticates with a smart card, the system consults predefined policies, roles, and permissions to evaluate whether that user has the necessary rights to perform a specific action, such as accessing a particular database. This evaluation directly leads to the decision of whether access is granted or denied.

Why this answer

Authorization is the security concept that determines what an authenticated user is permitted to do. In this scenario, after the user authenticates with a smart card, the system checks their job role in the finance department against access control lists (ACLs) or role-based access control (RBAC) policies to grant access to the specific database. This is distinct from authentication, which only verifies identity.

Exam trap

The trap here is confusing authentication with authorization; candidates often pick 'Authentication' because they focus on the smart card step, but the question explicitly asks about determining what the user is allowed to do, which is authorization.

How to eliminate wrong answers

Option A is wrong because authentication is the process of verifying the user's identity (e.g., via smart card credentials), not determining what they are allowed to do. Option C is wrong because accounting (or auditing) tracks and logs user activities for compliance and monitoring, but does not enforce permissions. Option D is wrong because encryption protects data at rest or in transit by converting it into ciphertext, but does not control access rights after decryption.

996
MCQmedium

Your organization is implementing a Zero Trust security model. Which Microsoft Entra ID feature should you use to verify that users and devices meet specific health requirements before granting access to corporate resources?

A.Privileged Identity Management (PIM)
B.Identity Governance
C.Identity Protection
D.Conditional Access
AnswerD

Conditional Access evaluates signals such as user, device compliance and location, then enforces grant controls before access is allowed. This satisfies the Zero Trust requirement to verify that users and devices meet specific health requirements before granting access to corporate resources.

Why this answer

Conditional Access is the Microsoft Entra ID policy engine that evaluates signals—including user, device compliance state, location, and risk—before granting access to resources. It can require that devices be marked compliant in Intune or hybrid-joined before allowing access, which directly implements the Zero Trust 'verify explicitly' principle. This makes it the correct feature for enforcing device health requirements at access time.

Exam trap

SC-900 often tests the confusion between Conditional Access (the enforcement engine) and Identity Protection (the risk detection engine)—candidates pick Identity Protection because it sounds security-focused, but only Conditional Access applies access controls based on device state.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management governs just-in-time role activation and approval workflows for privileged roles, not device health checks at resource access. Option B is wrong because Identity Governance handles access reviews, entitlement management, and lifecycle workflows—it does not evaluate device compliance during sign-in. Option C is wrong because Identity Protection detects and remediates risky users and sign-ins using risk signals, but it does not itself enforce device health requirements as an access gate.

997
MCQeasy

A company uses Microsoft 365 and several third-party SaaS apps. The security team wants to detect when a user signs in from a remote location that is significantly far from their typical sign-in location within a very short time, indicating possible account compromise. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Identity
C.Microsoft Defender for Office 365
D.Microsoft Defender for Endpoint
AnswerA

Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility and control over both sanctioned and unsanctioned cloud applications, including Microsoft 365 and third-party SaaS. It excels at detecting anomalous user behavior through advanced analytics, such as impossible travel. This capability specifically identifies suspicious sign-ins originating from geographically disparate locations within an unusually short timeframe, directly addressing the need for detecting such anomalies across various cloud services.

Why this answer

Microsoft Defender for Cloud Apps (MDCA) provides the 'impossible travel' detection capability, which analyzes sign-in events across both Microsoft 365 and third-party SaaS apps. It uses machine learning to establish a baseline of a user's typical sign-in locations and then alerts when two sign-ins occur from geographically distant locations within a time frame that makes physical travel impossible, indicating a potential account compromise.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Identity, assuming identity protection covers all sign-in anomalies, but MDCA specifically handles cross-cloud app behavioral analytics like impossible travel, while Defender for Identity is limited to on-premises AD and hybrid identity threats.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Identity focuses on on-premises Active Directory and hybrid identity threats (e.g., Kerberos attacks, DCSync), not cross-SaaS sign-in anomaly detection. Option C is wrong because Microsoft Defender for Office 365 protects email and collaboration workloads (e.g., phishing, malware in attachments), not user sign-in behavior across multiple SaaS apps. Option D is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution for devices (e.g., malware, fileless attacks), not for analyzing cloud app sign-in patterns.

998
MCQeasy

An organization wants to use a cloud-based SIEM to collect security data from multiple sources, including on-premises servers and cloud applications. Which Microsoft solution should they choose?

A.Microsoft Sentinel
B.Microsoft Intune
C.Microsoft 365 Defender
D.Microsoft Defender for Cloud
AnswerA

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It excels at collecting security data from diverse sources across an organization's entire digital estate, including Azure, on-premises, and other clouds, through built-in data connectors. Sentinel then uses AI and machine learning to detect, investigate, and respond to threats efficiently, making it ideal for comprehensive security event collection and analysis.

Why this answer

Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR solution, built on Azure and designed to ingest security data from multiple sources — including on-premises servers via agents, cloud applications via connectors, and Microsoft 365/Azure services. It provides analytics rules, incident management, workbooks, and automation playbooks, making it the correct choice for a cloud-based SIEM.

Exam trap

SC-900 often tests the SIEM vs. XDR vs. CSPM distinction — candidates pick Microsoft 365 Defender or Defender for Cloud for SIEM scenarios because the names sound security-related, missing that Sentinel is the dedicated SIEM/SOAR product.

How to eliminate wrong answers

Option B is wrong because Microsoft Intune is a mobile device management (MDM) and endpoint management solution, not a SIEM — it manages device configuration and compliance, not security event correlation. Option C is wrong because Microsoft 365 Defender is an extended detection and response (XDR) suite for Microsoft 365 workloads (email, identity, endpoints, cloud apps), not a general-purpose SIEM for ingesting arbitrary on-prem and multi-cloud telemetry. Option D is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform for Azure/multicloud resources, not a SIEM.

999
MCQeasy

Your organization wants to ensure that all external emails are automatically tagged with a disclaimer at the top of the email body. Which Microsoft Exchange Online feature should you configure?

A.Journal rule
B.Data loss prevention (DLP) policy
C.Safe Links policy
D.Mail flow rule (transport rule)
AnswerD

Mail flow rules, also known as transport rules in Exchange Online, are powerful tools that allow administrators to inspect, modify, or route email messages based on specific conditions. These rules operate at the transport layer, enabling actions such as adding disclaimers, blocking messages, encrypting content, or redirecting mail before it reaches the recipient's inbox. Applying a standardized disclaimer to all external emails is a classic and direct application of a mail flow rule's capabilities.

Why this answer

Mail flow rules (also known as transport rules) in Exchange Online allow you to inspect messages and take actions such as adding a disclaimer to the top of the email body. This rule can be scoped to apply only to external emails by using the condition 'The sender is located outside the organization'. The action 'Prepend a disclaimer' inserts the text at the beginning of the message body, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse mail flow rules with DLP policies because both can apply conditions and actions to emails, but DLP policies cannot modify the email body with a disclaimer—they only detect and protect data.

How to eliminate wrong answers

Option A is wrong because a journal rule captures and records email communications for compliance or archival purposes, not for modifying message content like adding disclaimers. Option B is wrong because a Data Loss Prevention (DLP) policy is designed to detect and protect sensitive data (e.g., credit card numbers) and can trigger notifications or block messages, but it cannot prepend a disclaimer to the email body. Option C is wrong because a Safe Links policy protects users from malicious URLs by scanning and rewriting links in messages, not by adding disclaimers to the message body.

1000
Multi-Selecthard

Which THREE of the following are features of Microsoft Purview Insider Risk Management?

Select 3 answers
A.Phishing simulation campaigns
B.Vulnerability scanning of network endpoints
C.Detection of repeated security policy violations by a user
D.Detection of unauthorized data exfiltration via email
E.Forensic evidence capturing user actions on devices
AnswersC, D, E

Microsoft Purview's Insider Risk Management solution is specifically designed to detect and manage cumulative policy violations by users. It leverages signals from various sources, including Microsoft 365 services, Windows endpoints, and third-party platforms, to identify patterns of risky behavior, such as repeated attempts to access sensitive data or consistent non-compliance with data handling policies. This capability helps organizations proactively identify and mitigate potential insider threats before they escalate into significant incidents.

Why this answer

Insider Risk Management (IRM) in Microsoft Purview is designed to detect, investigate, and act on risky user activity, so option C is correct because IRM policies can surface indicators of repeated security policy violations (e.g., repeated DLP rule matches or unusual downloads) as risk signals. Option D is correct because IRM correlates signals such as email events and DLP alerts to detect unauthorized data exfiltration via email, including sending sensitive content to personal or external recipients. Option E is correct because IRM includes forensic evidence capabilities, such as the forensic evidence add-on that captures user actions on onboarded devices (e.g., file copies, uploads, and keystrokes) for investigation.

Option A is not part of IRM; phishing simulation campaigns are delivered by Microsoft Defender for Office 365 Attack simulation training. Option B is not part of IRM; vulnerability scanning of endpoints is handled by Microsoft Defender Vulnerability Management, not Insider Risk Management.

Exam trap

The trap here is that candidates may confuse Insider Risk Management with broader security solutions like Defender for Office 365 or Defender for Endpoint, leading them to select phishing simulation or vulnerability scanning as features of Insider Risk Management.

1001
Multi-Selecteasy

Which TWO of the following are capabilities of Microsoft Entra ID?

Select 2 answers
A.Email filtering and anti-malware protection.
B.Identity and access management for cloud applications.
C.Single sign-on to SaaS applications.
D.Encryption of data at rest in Azure Storage.
E.Network firewall management.
AnswersB, C

Microsoft Entra ID is a comprehensive identity and access management (IAM) solution designed to manage user identities and control their access to various cloud-based applications. It enables organizations to provision users, enforce authentication policies like multi-factor authentication, and authorize access based on roles and groups. This capability is central to securing access to a vast ecosystem of SaaS and custom-developed cloud applications.

Why this answer

Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management (IAM) service. It provides authentication and authorization for cloud applications, including support for single sign-on (SSO) to thousands of pre-integrated SaaS applications like Salesforce, Office 365, and Workday. These are core IAM capabilities, not security functions like email filtering or network firewall management.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID's identity management role with broader security services like email protection or network security, leading them to select options that belong to other Azure or Microsoft 365 security products.

1002
MCQmedium

An organization uses Microsoft Defender for Cloud to secure its Azure workloads. They want to receive recommendations for improving the security posture of their virtual machines. What should they enable?

A.Microsoft Defender for Cloud Apps
B.Microsoft Sentinel
C.Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM)
D.Azure Policy
AnswerC

Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) continuously assesses cloud resources for misconfigurations and vulnerabilities across multi-cloud environments. It provides actionable security recommendations, prioritized by potential impact, to improve the organization's overall security posture. CSPM also includes compliance monitoring against regulatory standards and industry benchmarks, offering a unified view of security health.

Why this answer

Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) provides continuous assessment of Azure workloads, including virtual machines, against security baselines and best practices. It generates actionable recommendations to improve the security posture, such as applying missing system updates or enabling encryption. This is the correct feature for receiving VM-specific security recommendations.

Exam trap

The trap here is that candidates confuse Azure Policy (which enforces rules) with CSPM (which assesses and recommends), or they think Microsoft Sentinel (a SIEM) is needed for security recommendations, when CSPM is the dedicated posture management service.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on shadow IT discovery and data protection across SaaS applications, not on providing security recommendations for Azure VMs. Option B is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) and Security Orchestration Automation and Response (SOAR) solution for threat detection and incident response, not a posture management tool that generates VM security recommendations. Option D is wrong because Azure Policy enforces organizational rules and compliance by applying policies (e.g., requiring a specific VM SKU), but it does not generate security posture recommendations; CSPM is the service that provides those recommendations.

1003
MCQmedium

An organization wants to protect against business email compromise (BEC) attacks where attackers impersonate the CEO to trick employees into transferring funds. Which Microsoft Defender for Office 365 capability should they configure to detect such impersonation?

A.Safe Attachments
B.Safe Links
C.Impersonation protection
D.Spoof intelligence
AnswerC

Impersonation protection is a critical feature within anti-phishing policies in Microsoft Defender for Office 365 specifically designed to combat Business Email Compromise (BEC) attacks. It allows administrators to define specific high-value users (e.g., executives, financial personnel) and trusted domains to monitor for impersonation attempts. The system analyzes various email headers and content attributes, such as display name, reply-to address, and sender address, to detect subtle variations that indicate an attempt to spoof a protected identity. When an impersonation is detected, the email can be quarantined, moved to junk, or have a safety tip added, directly mitigating BEC threats.

Why this answer

Impersonation protection in Defender for Office 365 is specifically designed to detect and block business email compromise (BEC) attacks where an attacker spoofs a trusted sender, such as a CEO or CFO. It uses machine learning and sender intelligence to analyze email patterns and flag messages that impersonate internal or external high-value targets, making it the correct capability for this scenario.

Exam trap

The trap here is that candidates often confuse impersonation protection (user-level) with spoof intelligence (domain-level), assuming both handle the same type of attack, but impersonation protection is the only one that detects CEO fraud by analyzing sender identity rather than just domain authentication.

How to eliminate wrong answers

Option A is wrong because Safe Attachments protects against malware by detonating attachments in a sandbox, not against impersonation-based BEC attacks. Option B is wrong because Safe Links protects users from malicious URLs in emails and Office documents by checking links at click-time, not from sender impersonation. Option D is wrong because Spoof intelligence handles domain-level spoofing (e.g., forged From addresses using similar domains) but does not cover user-level impersonation of specific individuals like a CEO.

1004
MCQhard

Your company uses Microsoft Purview Information Protection to classify sensitive data. A user reports that when they try to share a document containing a credit card number via email, the email is blocked. Which Purview feature is most likely causing this behavior?

A.Data Loss Prevention (DLP) policy
B.Audit log
C.Sensitivity label
D.Retention label
AnswerA

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations, including email. They utilize sensitive information types (SITs) to detect specific data patterns, such as credit card numbers, and can enforce actions like blocking email transmission, notifying users, or encrypting content to prevent unauthorized sharing. This capability directly addresses the requirement to detect sensitive data and block its sharing via email.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is specifically designed to detect and block sensitive data—such as credit card numbers—from being shared via email. When a user attempts to send a document containing a credit card number, the DLP policy scans the email content and attachments, matches the credit card pattern (e.g., using the predefined Sensitive Info Type for credit card numbers), and enforces an action like blocking the message. This is the most likely cause of the email being blocked.

Exam trap

The trap here is that candidates often confuse Sensitivity labels with DLP policies, thinking labels alone can block emails, but labels only apply classification and protection—they require a DLP policy to enforce blocking actions based on content detection.

How to eliminate wrong answers

Option B is wrong because the Audit log records user and admin activities for compliance and forensic analysis but does not actively block or prevent data sharing—it is a passive logging feature. Option C is wrong because Sensitivity labels apply classification and protection (e.g., encryption or visual markings) to documents and emails, but they do not inherently block email transmission based on content patterns like credit card numbers; they require a DLP policy to enforce actions on labeled content. Option D is wrong because Retention labels manage how long data is kept or when it should be deleted, and they do not scan or block email content for sensitive data like credit card numbers.

1005
MCQeasy

A company uses Microsoft Entra ID and wants to enable employees to reset their own passwords without needing to contact the help desk. They want to enforce multifactor authentication when the employee performs the reset. Which Microsoft Entra feature should they enable?

A.Microsoft Entra Self-Service Password Reset (SSPR)
B.Microsoft Entra ID Federation
C.Microsoft Entra Identity Protection
D.Microsoft Entra Privileged Identity Management (PIM)
AnswerA

Microsoft Entra Self-Service Password Reset (SSPR) is a Microsoft Entra ID feature that empowers users to reset their forgotten or locked passwords without requiring administrator assistance. It significantly reduces helpdesk calls by allowing users to verify their identity through pre-registered authentication methods, such as a mobile app notification, text message, or email to an alternate address. This self-service capability enhances user productivity and can be configured to enforce multi-factor authentication during the reset process for heightened security.

Why this answer

Microsoft Entra Self-Service Password Reset (SSPR) is the correct feature because it allows users to reset their own passwords without help desk intervention, and it can be configured to require multifactor authentication (MFA) during the reset process. This aligns directly with the scenario of enabling self-service password changes while enforcing MFA for security.

Exam trap

The trap here is that candidates often confuse Identity Protection (which detects risky password changes) with SSPR (which enables the actual password reset), leading them to select Option C instead of A.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Federation is used to establish trust between an on-premises identity provider (e.g., AD FS) and Entra ID for single sign-on, not for self-service password reset with MFA enforcement. Option C is wrong because Microsoft Entra Identity Protection is a risk-based security tool that detects and responds to identity threats (e.g., risky sign-ins or leaked credentials), but it does not provide a self-service password reset capability. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged role activation and access reviews, not end-user password reset functionality.

1006
Multi-Selectmedium

Which TWO of the following are benefits of using Microsoft Entra ID for identity management?

Select 2 answers
A.Single sign-on (SSO) to cloud applications
B.Password hash synchronization
C.Multi-factor authentication (MFA)
D.Automated security incident detection
E.Replacement of on-premises Active Directory
AnswersA, C

Single sign-on (SSO) to cloud applications is a core benefit of Microsoft Entra ID, enabling users to authenticate once with their Entra ID credentials and gain seamless access to thousands of integrated Software-as-a-Service (SaaS) applications. This capability significantly enhances user productivity by eliminating the need to remember multiple passwords and repeatedly log in, while also improving security by centralizing identity management. Entra ID acts as the central identity provider, issuing secure tokens after initial authentication.

Why this answer

Option A is correct because Microsoft Entra ID provides single sign-on (SSO), allowing users to authenticate once and access many cloud applications (e.g., Microsoft 365, Salesforce) via protocols like SAML 2.0, WS-Federation, or OpenID Connect, which is a core identity-management benefit. Option C is correct because Entra ID natively supports multi-factor authentication (MFA), adding a second verification factor (such as the Microsoft Authenticator app, SMS, or FIDO2 key) to strengthen sign-in security, which is a primary benefit of the service. Option B is not a benefit of Entra ID itself but rather a specific hybrid identity synchronization method (via Microsoft Entra Connect) used to sync on-premises password hashes to the cloud.

Option D is incorrect because automated security incident detection is a capability of Microsoft Defender/Sentinel, not a core identity-management benefit of Entra ID. Option E is incorrect because Entra ID is a cloud identity provider and does not replace on-premises Active Directory Domain Services; the two are typically used together in hybrid scenarios.

Exam trap

SC-900 often tests whether candidates confuse Entra ID features (like password hash sync) with benefits, or mistakenly believe Entra ID replaces on-premises Active Directory.

1007
MCQhard

A company wants to allow external customers to sign in to their custom web application using their own social identities, such as Google or Facebook. They also need to support self-service registration and custom branding for the sign-in pages. Which Microsoft Entra External ID solution should they use?

A.Microsoft Entra ID B2B collaboration
B.Microsoft Entra ID B2C
C.Microsoft Entra ID guest accounts
D.Managed identities
AnswerB

Microsoft Entra ID B2C is specifically engineered for customer identity and access management (CIAM), enabling external customers to sign up and sign in to your custom web and mobile applications. It supports a wide array of identity providers, including social accounts like Google and Facebook, as well as local accounts. B2C provides a highly customizable, branded experience for customer registration, sign-in, and profile management, making it ideal for this scenario.

Why this answer

Microsoft Entra ID B2C (Business-to-Consumer) is the correct solution because it is specifically designed for external customer identity and access management, supporting social identity providers (Google, Facebook, etc.) via OAuth 2.0 and OpenID Connect, self-service registration, and full customization of sign-in pages (branding, HTML, CSS). This aligns exactly with the requirements for a customer-facing web application with social sign-in and custom branding.

Exam trap

The trap here is that candidates often confuse B2B collaboration (for external partners) with B2C (for external customers), mistakenly thinking B2B can handle social identities and self-service registration, but B2B lacks those capabilities and is designed for federated business accounts.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID B2B collaboration is intended for business-to-business scenarios, allowing external partners to sign in with their own work or school accounts, not social identities like Google or Facebook, and it does not support self-service registration or custom branding for sign-in pages. Option C is wrong because Microsoft Entra ID guest accounts are a feature of B2B collaboration, used for inviting external users (typically with work/school accounts) to access resources in the tenant, lacking social identity provider support and self-service registration. Option D is wrong because managed identities are an Azure resource authentication mechanism for Azure services to authenticate to other Azure services without storing credentials, not a solution for external customer sign-in or identity management.

1008
MCQhard

A company runs containerized applications on Azure Kubernetes Service (AKS) and stores container images in Azure Container Registry. The security team wants to automatically scan container images for vulnerabilities every time a new image is pushed to the registry and receive recommendations for remediation. Which Microsoft security solution should they enable?

A.A. Microsoft Defender for Endpoint
B.B. Microsoft Defender for Identity
C.C. Microsoft Defender for Cloud
D.D. Microsoft Defender for Office 365
AnswerC

Microsoft Defender for Cloud is the correct solution as it provides comprehensive cloud security posture management (CSPM) and cloud workload protection (CWP). Specifically, its Defender for Containers plan integrates with Azure Container Registry (ACR) and Azure Kubernetes Service (AKS) to automatically scan container images for known vulnerabilities upon push, during import, or on a recurring basis. It identifies security misconfigurations and provides actionable remediation recommendations, crucial for securing containerized applications running on Azure Kubernetes.

Why this answer

Microsoft Defender for Cloud provides integrated vulnerability assessment for container images stored in Azure Container Registry. When enabled, it automatically scans each new image pushed to the registry, identifies known vulnerabilities (using the Qualys scanner or Microsoft's own threat intelligence), and generates actionable remediation recommendations. This directly meets the security team's requirement for automated scanning and remediation guidance.

Exam trap

The trap here is that candidates confuse 'Defender for Cloud' (which covers workload protection including containers) with 'Defender for Endpoint' (which is device-focused), leading them to incorrectly select A because they think container scanning is an endpoint function.

Why the other options are wrong

A

Microsoft Defender for Endpoint focuses on endpoint devices (workstations, servers, mobile devices) and does not scan container images in Azure Container Registry for vulnerabilities.

B

Microsoft Defender for Identity focuses on detecting identity-based threats in on-premises Active Directory, not on scanning container images for vulnerabilities in Azure Container Registry.

D

Microsoft Defender for Office 365 protects against threats in email, Office apps, and collaboration tools, not container image vulnerability scanning in Azure Container Registry.

When would these options actually be correct?

A

If the question asked for a solution to protect endpoints (e.g., detect and respond to threats on servers or client devices) and included scenarios like malware detection or attack surface reduction, Defender for Endpoint would be correct.

B

A question asks: 'Which Microsoft security solution monitors and alerts on suspicious user activities and potential identity compromise in an on-premises Active Directory environment?'

D

An exam question asking which Microsoft security solution protects against malicious links and attachments in email messages or SharePoint files, or provides anti-phishing policies for Exchange Online.

Why candidates pick the wrong answer

A

Candidates may confuse 'container security' with 'endpoint security' because containers run on hosts, and Defender for Endpoint can protect the underlying host OS, but it does not scan container images in a registry.

B

Candidates may confuse 'Defender for Identity' with a general security solution for Azure, or mistakenly think it covers container security due to the broad 'Defender' branding.

D

Candidates may confuse the 'Defender' branding and assume all Defender products offer similar vulnerability scanning capabilities, overlooking that Defender for Office 365 focuses on productivity suite security.

1009
MCQeasy

A security administrator is using Microsoft Defender for Cloud to improve the security posture of Azure resources. The administrator wants to view a consolidated assessment of compliance with industry standards such as CIS and NIST. Which feature should be used?

A.Regulatory compliance dashboard
B.Secure Score
C.Azure Policy
D.Microsoft Sentinel
AnswerA

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a centralized view of an organization's compliance posture against various industry standards and regulatory benchmarks, such as CIS, NIST, and PCI DSS. It continuously assesses the environment, mapping security controls to specific requirements within these frameworks and clearly indicating which controls pass or fail. This dashboard is specifically designed to help organizations understand and improve their adherence to external regulations by offering actionable recommendations and detailed compliance reports.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a consolidated view of compliance with industry standards like CIS and NIST. It continuously assesses Azure resources against built-in compliance frameworks and displays the results in a dashboard, showing which controls are passing or failing. This directly meets the administrator's need to view a consolidated assessment of compliance with those specific standards.

Exam trap

The trap here is that candidates often confuse Secure Score (which shows overall security posture) with the Regulatory compliance dashboard (which specifically maps to industry standards), leading them to pick Secure Score when the question explicitly asks for compliance with CIS and NIST.

Why the other options are wrong

B

Secure Score provides a numerical rating of security posture based on security controls, but it does not offer a consolidated assessment of compliance with specific industry standards like CIS or NIST.

C

Azure Policy is used to enforce organizational standards and assess compliance at a resource level, but it does not provide a consolidated view of compliance with industry standards like CIS and NIST. The Regulatory compliance dashboard in Defender for Cloud is specifically designed for that purpose.

D

Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not for viewing compliance assessments against industry standards like CIS and NIST.

When would these options actually be correct?

B

A security administrator wants to quickly assess the overall security posture of Azure resources and identify recommendations to improve it, without needing compliance details for specific standards.

C

An administrator needs to enforce specific security configurations (e.g., require encryption on storage accounts) across all Azure resources. In this scenario, Azure Policy would be the correct answer because it allows creating and assigning policies to audit or enforce compliance rules.

D

A security team needs to centralize security logs and alerts from multiple sources, detect threats, and automate incident response across the enterprise environment.

Why candidates pick the wrong answer

B

Candidates may confuse Secure Score with compliance assessment because both are security posture features in Defender for Cloud, and Secure Score is prominently displayed.

C

Candidates may confuse Azure Policy's compliance assessment capabilities with the broader compliance dashboard, thinking that policy definitions can aggregate industry standard compliance, but they lack the pre-built mappings and consolidated view.

D

Candidates may confuse Sentinel's security monitoring capabilities with compliance assessment features, as both involve security posture management.

1010
Multi-Selecthard

A company uses Microsoft Entra ID. The IT team wants to provide external partners with access to internal applications. The partners will use their own email addresses to sign in, and the company wants to minimize administrative overhead by not creating guest accounts manually. The company also wants to allow partners to use their existing social identities, such as Google or Facebook, to access resources. Which TWO Microsoft Entra features should the company implement? (Choose two.)

Select 2 answers
A.External Identities cross-tenant access settings
B.Configure Google and Facebook as identity providers in Microsoft Entra ID
C.Microsoft Entra Connect Sync
D.B2B collaboration with self-service sign-up
E.B2C tenant
AnswersB, D

Configuring Google and Facebook as identity providers in Microsoft Entra ID allows external users to sign in with their existing social accounts. This works with B2B collaboration to enable partners to use social identities for access. It reduces the need for partners to create new credentials and supports the requirement for social identity sign-in.

Why this answer

B2B collaboration with self-service sign-up lets external partners sign up using their own email addresses, reducing administrative overhead. Configuring Google and Facebook as identity providers in Microsoft Entra ID enables partners to use their existing social identities. Together, these features meet the requirements for partner access without manual guest account creation and with social identity support.

Exam trap

The trap here is confusing B2C tenants, which are for consumer apps, with B2B collaboration and social identity providers, which are for partner access to internal resources.

1011
MCQmedium

An organization needs to detect and address potential policy violations in Microsoft Teams chat messages and channel conversations. They want to configure a policy that automatically scans for keywords related to confidential information and for sensitive data patterns like credit card numbers. When a violation is found, the policy should notify the user and their manager, and optionally escalate to a designated reviewer. Which Microsoft Purview solution should they configure?

A.Communication Compliance
B.Data Lifecycle Management
C.eDiscovery
D.Audit
AnswerA

Communication Compliance is the correct solution as it proactively identifies and addresses potential policy violations within an organization's communications, such as Microsoft Teams chats, Exchange emails, and Yammer posts. It leverages machine learning and predefined or custom policies to detect issues like harassment, threats, or the sharing of sensitive information. When a policy is triggered, it generates alerts for designated reviewers, enabling them to investigate, remediate, and escalate findings through a structured workflow.

Why this answer

Communication Compliance is the correct solution because it is specifically designed to detect policy violations in Microsoft Teams messages and other communication channels by scanning for keywords and sensitive data patterns (e.g., credit card numbers). It can automatically notify the user and their manager, and optionally escalate violations to a designated reviewer for remediation, directly matching the organization's requirements.

Exam trap

The trap here is that candidates may confuse Communication Compliance with Data Loss Prevention (DLP) or eDiscovery, but DLP focuses on preventing data leaks (e.g., blocking sharing) rather than detecting and escalating policy violations with user/manager notifications, while eDiscovery is reactive and not designed for automated detection and notification workflows.

Why the other options are wrong

B

Data Lifecycle Management focuses on retaining or deleting data based on policies, not on scanning messages for policy violations or notifying users and managers.

C

eDiscovery is used for searching and exporting content for legal or investigative purposes, not for real-time policy violation detection and user notification in Teams messages.

D

Audit logs user and admin activity but does not scan Teams messages for policy violations or sensitive data patterns like credit card numbers.

When would these options actually be correct?

B

An organization needs to automatically retain Teams chat messages for 7 years to meet regulatory requirements and then delete them. Data Lifecycle Management would be the correct solution to configure retention and deletion policies.

C

An organization needs to search for and export specific Teams chat messages and channel conversations as part of a legal investigation or litigation hold. They want to place a hold on relevant data to preserve it for eDiscovery purposes.

D

An organization needs to investigate a specific incident by reviewing historical user activity logs, such as who accessed a sensitive file or changed a retention policy. Audit would be the correct solution for tracking such events.

Why candidates pick the wrong answer

B

Candidates may confuse data management policies (retention/deletion) with compliance policies that monitor content, as both involve managing data in Microsoft 365.

C

Candidates may confuse eDiscovery's ability to search and analyze content with the proactive detection and remediation features of Communication Compliance, especially since both involve scanning communications.

D

Candidates may confuse auditing (reviewing past actions) with proactive monitoring of communications, or think that detecting policy violations requires enabling audit logging first.

1012
MCQhard

A company wants to prevent users from sharing files containing personally identifiable information (PII) with external recipients. They also need to notify users if they attempt to share such files. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Sensitivity Labels
B.Microsoft Purview Communication Compliance
C.Microsoft Purview eDiscovery
D.Microsoft Purview Data Loss Prevention
AnswerD

DLP policies inspect content for sensitive information types such as PII, then block sharing with external recipients and surface user notifications or policy tips. This directly satisfies both the prevention and notification requirements, unlike labels or retention, which govern classification and lifecycle rather than real-time sharing control.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, prevent, and notify users about the sharing of sensitive data, such as personally identifiable information (PII), with external recipients. DLP policies can be configured to automatically block the sharing of files containing PII and display a policy tip notification to the user when they attempt to share such content.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels with DLP, but Sensitivity Labels only classify and protect data without enforcing sharing restrictions or user notifications, whereas DLP is the solution that actively monitors and blocks the external sharing of sensitive data.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Sensitivity Labels are used to classify and protect data by applying encryption or visual markings, but they do not inherently block sharing or provide user notifications when a user attempts to share PII externally. Option B is wrong because Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) within an organization, not to prevent the sharing of files containing PII with external recipients. Option C is wrong because Microsoft Purview eDiscovery is used for searching, preserving, and exporting content for legal or investigative purposes, not for real-time prevention or notification of data sharing violations.

1013
MCQmedium

A company uses Microsoft 365 and wants to protect users from malicious attachments in email. The security team wants a solution that detonates attachments in a sandbox environment before delivery, and only allows the email through if the attachment is deemed safe. Which Microsoft security solution should they use?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Cloud Apps
D.Azure Firewall
AnswerA

Microsoft Defender for Office 365 is the correct solution as it provides advanced threat protection specifically for email and collaboration services within Microsoft 365. Its Safe Attachments feature proactively detonates email attachments in a secure, isolated sandbox environment before they reach user inboxes, effectively identifying and blocking malicious content, including zero-day malware. Additionally, Safe Links rewrites URLs to scan them at the time of click, further protecting users from phishing and malicious websites.

Why this answer

Microsoft Defender for Office 365 includes Safe Attachments, a feature that detonates email attachments in a virtual sandbox environment before delivery. It analyzes the attachment's behavior for malicious activity and only releases the email to the recipient's mailbox if the attachment is deemed safe, directly meeting the requirement for pre-delivery sandboxing.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (which handles email security) with Microsoft Defender for Endpoint (which handles device security), leading them to select the wrong solution for email-specific threats.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not email attachment sandboxing. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) for controlling shadow IT and data protection across SaaS apps, not for email attachment detonation. Option D is wrong because Azure Firewall is a network-layer firewall that filters traffic based on IP/port rules, not capable of detonating email attachments in a sandbox.

1014
MCQhard

Your organization is using Microsoft Entra Permissions Management (CIEM). You need to identify overprivileged identities in AWS. Which capability should you use?

A.Audit trail
B.Permissions Analytics Report
C.Identity governance
D.Activity trail
AnswerB

The Permissions Analytics Report within Microsoft Entra Permissions Management is specifically designed to identify overprivileged identities by analyzing granted permissions against actual usage data over a defined period. This report leverages machine learning to compare an identity's assigned permissions with the specific actions they have performed, highlighting unused, high-risk, or excessive permissions. It provides actionable insights to right-size permissions and enforce the principle of least privilege effectively.

Why this answer

Permissions Analytics Report is the correct capability because it specifically analyzes permissions across AWS, Azure, and GCP to identify overprivileged identities, unused permissions, and risky actions. It generates a detailed report that highlights identities with excessive permissions, enabling remediation to enforce least privilege. This aligns directly with the CIEM (Cloud Infrastructure Entitlement Management) goal of reducing privilege risks.

Exam trap

The trap here is that candidates confuse 'Permissions Analytics Report' with generic auditing features like Audit trail or Activity trail, assuming any logging tool can identify overprivileged identities, but only the report performs the specific analysis of permissions versus usage.

How to eliminate wrong answers

Option A is wrong because Audit trail in Microsoft Entra Permissions Management records historical changes to permissions and configurations, but it does not analyze or identify overprivileged identities; it is a logging feature. Option C is wrong because Identity governance in Microsoft Entra ID focuses on access reviews, entitlement management, and lifecycle workflows for users and groups, not on analyzing cloud infrastructure permissions across AWS. Option D is wrong because Activity trail tracks user actions and API calls in real-time or historically, but it does not assess permission levels or detect overprivileged identities; it is an auditing feature.

1015
MCQmedium

A company uses Microsoft Defender for Cloud to secure its Azure resources. The security team wants to receive a single recommendation for all resources that are missing just-in-time (JIT) VM access. Which Microsoft Defender for Cloud feature should they use?

A.Regulatory compliance dashboard
B.Security recommendations
C.Inventory
D.Security alerts
AnswerB

Microsoft Defender for Cloud's security recommendations are actionable suggestions generated by continuously analyzing the security state of your Azure resources against Microsoft's security benchmarks and best practices. These recommendations, such as enabling Just-In-Time (JIT) VM access or applying adaptive application controls, directly guide users on specific steps to mitigate vulnerabilities and enhance their overall security posture. They are designed to improve the secure score and provide a prioritized list of tasks for remediation.

Why this answer

Microsoft Defender for Cloud's security recommendations feature provides a centralized list of actionable steps to improve your security posture, including a specific recommendation to enable just-in-time (JIT) VM access on all eligible virtual machines. This recommendation aggregates all resources missing JIT configuration into a single entry, allowing the security team to remediate them collectively. The other options do not aggregate missing JIT configurations into a single recommendation.

Exam trap

The trap here is that candidates confuse 'security recommendations' (proactive posture improvements) with 'security alerts' (reactive threat detections), leading them to select D because they think missing JIT is a security incident rather than a configuration gap.

How to eliminate wrong answers

Option A is wrong because the Regulatory compliance dashboard maps your Azure environment to compliance standards (e.g., SOC 2, ISO 27001) and does not provide operational recommendations like enabling JIT VM access. Option C is wrong because Inventory is a resource browser that lists all your Azure resources but does not generate or aggregate security recommendations for missing configurations. Option D is wrong because Security alerts are triggered by active threats or suspicious activities, not by the absence of a security control like JIT VM access.

1016
MCQhard

A company uses Microsoft Entra ID with a custom line-of-business application that only supports SAML 2.0. They want to enable single sign-on for users. What should they configure in Microsoft Entra ID?

A.Kerberos delegation
B.OpenID Connect authentication
C.SCIM-based user provisioning
D.SAML-based single sign-on
AnswerD

SAML (Security Assertion Markup Language) 2.0 is an XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). Microsoft Entra ID acts as a robust IdP, enabling users to sign in once and gain access to multiple enterprise applications (SPs) without re-entering credentials. This protocol is widely adopted for federated single sign-on with custom line-of-business applications and many SaaS applications, making it a secure, mature, and common solution for integrating enterprise applications with Microsoft Entra ID.

Why this answer

D is correct because the custom line-of-business application explicitly supports SAML 2.0, and Microsoft Entra ID can be configured as an identity provider (IdP) to enable SAML-based single sign-on. This allows users to authenticate once in Entra ID and then access the application without re-entering credentials, using SAML assertions to pass authentication and authorization data.

Exam trap

The trap here is that candidates may confuse SCIM provisioning (Option C) with SSO, or assume OpenID Connect (Option B) is universally compatible, but the question explicitly states the application only supports SAML 2.0, making SAML-based SSO the only correct choice.

How to eliminate wrong answers

Option A is wrong because Kerberos delegation is used for Windows-integrated authentication (e.g., on-premises Active Directory) and requires Kerberos protocol support, which is not compatible with a SAML 2.0-only application. Option B is wrong because OpenID Connect (OIDC) is built on OAuth 2.0 and uses JSON Web Tokens (JWTs), not SAML 2.0; the application only supports SAML 2.0, so OIDC cannot be used. Option C is wrong because SCIM (System for Cross-domain Identity Management) is a provisioning protocol for automating user and group lifecycle management, not an authentication or SSO protocol; it does not enable single sign-on.

1017
MCQhard

A company uses Azure SQL Database for a critical line-of-business application. The security team wants to enable threat protection that specifically detects and alerts on SQL injection attempts and anomalous database access patterns. Which workload protection plan should they enable within Microsoft Defender for Cloud?

A.Azure Defender for Servers
B.Azure Defender for SQL
C.Azure Defender for App Service
D.Azure Defender for Storage
AnswerB

Azure Defender for SQL is the dedicated security solution tailored for Azure SQL Database, Azure SQL Managed Instance, and SQL servers on Azure VMs or hybrid environments. It offers comprehensive vulnerability assessments to identify misconfigurations and provides advanced threat protection to detect anomalous activities, including SQL injection attacks, brute-force attempts, and suspicious access patterns. This specialized plan ensures robust security for the database layer, safeguarding sensitive data.

Why this answer

Azure Defender for SQL is the correct workload protection plan because it is specifically designed to detect and alert on SQL injection attempts and anomalous database access patterns for Azure SQL Database. It uses Microsoft's threat intelligence and machine learning to monitor database activity, providing targeted alerts for SQL-specific threats, unlike other Defender plans that focus on different resource types.

Exam trap

The trap here is that candidates may confuse Azure Defender for SQL with Azure Defender for App Service, mistakenly thinking SQL injection is a web application attack, but SQL injection targets the database layer, which is protected by the SQL-specific plan, not the App Service plan.

How to eliminate wrong answers

Option A is wrong because Azure Defender for Servers protects virtual machines and their operating systems, not Azure SQL Database, and it does not specialize in SQL injection detection. Option C is wrong because Azure Defender for App Service secures web applications and APIs, focusing on threats like DDoS or web app vulnerabilities, not database-level SQL injection. Option D is wrong because Azure Defender for Storage monitors storage accounts for anomalies like unusual access patterns or malware uploads, but it does not cover SQL databases or SQL injection attempts.

1018
MCQeasy

Your organization uses Microsoft Purview to classify documents containing health information. You need to ensure that only users with explicit permission can access these documents. Which Microsoft Purview capability should you use?

A.Audit logs
B.Retention policies
C.Data Loss Prevention
D.Sensitivity labels with encryption
AnswerD

Sensitivity labels in Microsoft Purview allow organizations to classify and protect their sensitive data throughout its lifecycle, regardless of where it's stored or shared. When configured with encryption, these labels apply persistent, rights-management protection directly to the document content. This ensures that only authorized users, as defined by the label's policy, can open, view, or modify the document, even if it leaves the organization's controlled environment, thereby enforcing access controls.

Why this answer

Sensitivity labels with encryption are the correct choice because they allow you to classify documents containing health information and apply encryption to restrict access to only users with explicit permissions. This ensures that even if the document is shared or moved, only authorized users can decrypt and read it, meeting the requirement for access control.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with access control, but DLP only monitors and blocks data exfiltration, not who can view or edit documents after they are stored.

How to eliminate wrong answers

Option A is wrong because Audit logs record user activities and access events but do not enforce access restrictions; they are for monitoring, not controlling access. Option B is wrong because Retention policies manage how long data is kept or when it is deleted, not who can access it; they do not provide permission-based access control. Option C is wrong because Data Loss Prevention (DLP) policies detect and prevent unauthorized sharing of sensitive data but do not enforce encryption or granular user permissions; DLP can trigger actions like blocking sharing but cannot restrict access to documents already stored.

1019
MCQeasy

Which Microsoft cloud service provides a unified data governance solution that helps you manage and protect data across your entire data estate, including multi-cloud and on-premises?

A.Microsoft Defender for Cloud
B.Microsoft Intune
C.Microsoft Sentinel
D.Microsoft Purview
AnswerD

Microsoft Purview is the unified data governance service spanning multi-cloud and on-premises sources, satisfying the stem's cross-estate constraint. Its Data Map catalogues and classifies assets, while sensitivity labels and policies enforce protection, capabilities that Microsoft Entra ID and Defender for Cloud do not provide.

Why this answer

Microsoft Purview is the correct answer because it is a unified data governance service that provides visibility into data assets across on-premises, multi-cloud, and SaaS environments. It enables data classification, sensitive data discovery, and policy-based access control to manage and protect the entire data estate, aligning with the question's requirement for a comprehensive governance solution.

Exam trap

The trap here is that candidates often confuse Microsoft Purview with Microsoft Defender for Cloud or Microsoft Sentinel, because all three involve 'protection' or 'security,' but Purview is specifically a data governance and compliance solution, not a security monitoring or posture management tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform, not a data governance solution; it focuses on securing cloud infrastructure and detecting threats, not on managing and protecting data across the data estate. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for endpoint management and compliance, not a unified data governance tool for multi-cloud and on-premises data. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution for security analytics and threat detection, not a data governance service for managing and protecting data assets.

1020
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to ensure that when a user's on-premises account is disabled, their cloud account is automatically disabled within 5 minutes. Which configuration should you use?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Entra Conditional Access with session controls
C.Microsoft Entra Connect with directory sync configured for 5-minute sync interval
D.Microsoft Entra Connect Health
AnswerC

Microsoft Entra Connect is the foundational tool for synchronizing identities between an on-premises Active Directory and Microsoft Entra ID, including critical user account attributes like 'disabled' status. By default, the synchronization cycle runs every 30 minutes, but administrators can configure the Microsoft Entra Connect sync scheduler to run more frequently. This allows for a minimum 5-minute interval, ensuring that time-sensitive changes, such as account disablement, are reflected in the cloud promptly.

Why this answer

Microsoft Entra Connect with directory synchronization configured for a 5-minute sync interval ensures that changes made to on-premises Active Directory (such as disabling a user account) are replicated to Microsoft Entra ID within that interval. This meets the requirement of automatically disabling the cloud account within 5 minutes of the on-premises change.

Exam trap

The trap here is confusing identity synchronization (Entra Connect) with identity governance or access control tools like PIM or Conditional Access, which do not handle the propagation of on-premises account status changes to the cloud.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time access and role activation, not the synchronization of user account status changes. Option B is wrong because Microsoft Entra Conditional Access with session controls enforces access policies based on conditions like location or device state, but it does not synchronize account disabled status from on-premises to the cloud. Option D is wrong because Microsoft Entra Connect Health monitors the health and performance of the sync infrastructure but does not control the sync interval or propagate account status changes.

1021
Multi-Selecthard

A healthcare organization subject to HIPAA regulations stores patient health information (PHI) in SharePoint Online and OneDrive. The compliance team needs to automatically detect and classify medical record numbers and other PHI when documents are uploaded. Detected sensitive content must be protected by encryption and restricted to authorized users only. Additionally, the team wants to prevent users from sharing such documents externally. Which TWO Microsoft Purview solutions should they combine to achieve these requirements? (Choose two.)

Select 2 answers
A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Information Protection
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Data Lifecycle Management
AnswersA, B

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across various locations within Microsoft 365, including Exchange Online, SharePoint Online, OneDrive, and Teams. It leverages sensitive information types, trainable classifiers, and exact data match to detect HIPAA-regulated data, such as Protected Health Information (PHI). Upon detection, DLP can enforce actions like blocking sharing, notifying users and administrators, or automatically applying sensitivity labels to prevent unauthorized disclosure, directly addressing detection and prevention requirements.

Why this answer

Microsoft Purview Information Protection (B) enables automatic classification and labeling of sensitive data like medical record numbers and PHI based on sensitive info types or trainable classifiers. Microsoft Purview Data Loss Prevention (A) then enforces policies to apply encryption, restrict access to authorized users, and block external sharing of labeled documents. Together, they meet the requirements for detection, protection, and sharing prevention.

Exam trap

The trap here is that candidates may confuse Communication Compliance (which monitors communications) with DLP or Information Protection, or assume Data Lifecycle Management handles classification, but it only manages retention and deletion.

Why the other options are wrong

C

Communication Compliance focuses on detecting policy violations in communications (e.g., inappropriate language, insider trading) rather than automatically detecting and protecting PHI in documents. It does not provide encryption or access restrictions for sensitive content.

D

Data Lifecycle Management manages retention and deletion of data based on policies, but does not detect, classify, or protect sensitive content like PHI, nor does it prevent external sharing.

When would these options actually be correct?

C

An organization needs to monitor employee communications (e.g., email, Teams) for policy violations such as harassment, confidential information leaks, or regulatory compliance breaches (e.g., FINRA). In that scenario, Communication Compliance would be the correct solution.

D

A question requiring automatic retention or deletion of documents after a specified period (e.g., retaining medical records for 6 years per HIPAA) would make Data Lifecycle Management the correct answer.

Why candidates pick the wrong answer

C

Candidates may confuse 'compliance' with data protection, assuming Communication Compliance handles all compliance-related tasks, including detecting sensitive data in documents, due to its name and general compliance focus.

D

Candidates may confuse data lifecycle management with data protection, assuming that managing data over time includes security controls, but DLM focuses on retention and disposal, not classification or encryption.

1022
Multi-Selectmedium

A financial services company is adopting a Zero Trust security model. The security team must implement controls that align with the principle of least privilege. Which two practices should they implement? (Choose two.)

Select 2 answers
A.Disable multifactor authentication to streamline the user experience.
B.Grant all employees permanent administrator rights to simplify IT support.
C.Allow all users to access all company data to foster collaboration.
D.Assign users the minimum permissions required to perform their job duties.
E.Use just-in-time (JIT) access for privileged roles, granting permissions only when needed.
AnswersD, E

Assigning minimum permissions is a core implementation of least privilege. It ensures users can only access resources essential for their roles, reducing the potential impact of compromised accounts. In a Zero Trust model, this limits lateral movement and enforces strict access control. This practice directly supports the principle of least privilege and is a recommended security control.

Why this answer

Least privilege requires that users have only the minimum access necessary to perform their tasks. Assigning minimum permissions and using just-in-time access for privileged roles both enforce this principle. The other options either grant excessive access or weaken authentication, which are contrary to Zero Trust and least privilege.

These two practices help limit the blast radius of a potential compromise.

Exam trap

The trap here is assuming that least privilege means giving everyone admin rights for convenience or disabling security controls to improve usability, when it actually requires minimizing access.

1023
MCQhard

A security operations center (SOC) wants to enrich their detection capabilities by automatically correlating internal network logs with external threat intelligence feeds containing known malicious IP addresses and domains. They need to ingest, normalize, and prioritize these indicators and generate alerts when matches are found. Which Microsoft security solution provides built-in capabilities for this purpose?

A.Microsoft Sentinel
B.Microsoft Defender for Cloud
C.Microsoft Defender for Endpoint
D.Microsoft 365 Defender
AnswerA

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution specifically engineered for comprehensive security operations. It offers robust capabilities for ingesting vast amounts of log data from diverse sources and natively supports integrating various external threat intelligence feeds through dedicated data connectors (e.g., TAXII, STIX, custom APIs). SOCs leverage Sentinel's analytics rules to automatically correlate these incoming threat indicators with collected log data, thereby enriching detections and enabling proactive threat hunting and response.

Why this answer

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that provides built-in capabilities to ingest logs from internal network sources, normalize them using common data models, and automatically correlate them with external threat intelligence feeds (e.g., STIX/TAXII). It can prioritize indicators based on severity and generate real-time alerts when matches are found, making it the correct choice for this SOC requirement.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft 365 Defender (an XDR), assuming that XDR covers all security operations needs, but XDR lacks the broad log ingestion and custom threat intelligence feed integration that a SIEM provides.

How to eliminate wrong answers

Option B (Microsoft Defender for Cloud) is wrong because it is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) focused on securing cloud resources, not a SIEM for ingesting and correlating internal network logs with external threat intelligence feeds. Option C (Microsoft Defender for Endpoint) is wrong because it is an endpoint detection and response (EDR) solution that protects individual devices, not a centralized platform for ingesting diverse network logs and threat intelligence. Option D (Microsoft 365 Defender) is wrong because it is an extended detection and response (XDR) solution that correlates signals across Microsoft 365 products (e.g., email, endpoints, identities), but it lacks the broad log ingestion and custom threat intelligence feed integration capabilities of a dedicated SIEM like Sentinel.

1024
MCQeasy

Your company is deploying Microsoft Defender for Office 365. The security team wants to automatically remove malicious attachments from emails before they reach user inboxes. Which protection feature should be configured?

A.Anti-spam policies
B.Safe Attachments policies
C.Anti-phishing policies
D.Safe Links policies
AnswerB

Safe Attachments policies are specifically designed to protect against zero-day malware and advanced threats embedded in email attachments. This feature utilizes a cloud-based sandbox environment to detonate and analyze attachments in real-time, isolating them from the user's environment. If an attachment is deemed malicious, it is either blocked or quarantined before it can reach the recipient's inbox, preventing the execution of harmful code.

Why this answer

Safe Attachments policies in Microsoft Defender for Office 365 are specifically designed to detect and neutralize malicious attachments in email messages before they reach user inboxes. This feature uses a detonation environment to open attachments in a sandbox, analyzing their behavior for threats, and then automatically removes or replaces the attachment if it is found to be malicious.

Exam trap

The trap here is that candidates often confuse Safe Attachments with Safe Links, thinking both handle attachments, but Safe Links only protects against malicious URLs, not file attachments, while Safe Attachments is the dedicated feature for attachment-based malware protection.

How to eliminate wrong answers

Option A is wrong because anti-spam policies focus on filtering unsolicited bulk email (spam) based on sender reputation, content filters, and bulk mail thresholds, not on scanning attachments for malware. Option C is wrong because anti-phishing policies protect against deceptive messages that attempt to steal credentials or personal information, using impersonation detection and spoof intelligence, but they do not perform attachment-level malware analysis. Option D is wrong because Safe Links policies protect users from clicking on malicious URLs within emails or Office documents by checking links at time of click, not by scanning or removing attachments.

1025
MCQhard

A data analyst is planning to leave the company in two weeks and has access to a large volume of sensitive customer data. The compliance team wants to detect if the analyst starts downloading large amounts of files to a personal USB drive or sending sensitive content to an external email address. They need to set up a policy that alerts on such anomalous data exfiltration activities without blocking operations until a thorough investigation is completed. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Insider Risk Management
B.Microsoft Purview Data Lifecycle Management
C.Microsoft Purview Communication Compliance
D.Microsoft Purview eDiscovery (Standard)
AnswerA

Microsoft Purview Insider Risk Management is the correct solution as it proactively identifies and mitigates potential data exfiltration risks from within the organization. It leverages machine learning to detect anomalous user behaviors, such as unusual download volumes, email forwarding, or cloud uploads, especially when correlated with HR signals like an employee's impending departure. The service provides configurable policies, alerts security teams to suspicious activities, and offers case management tools for investigation and remediation, directly addressing the scenario of a departing data analyst.

Why this answer

Microsoft Purview Insider Risk Management is designed to detect, investigate, and act on risky user activities, including data exfiltration by departing employees. It uses predefined indicators such as downloading files to USB drives or sending emails to external addresses, and can generate alerts without automatically blocking operations, allowing for a thorough investigation first.

Exam trap

The trap here is that candidates often confuse Insider Risk Management with Communication Compliance, but Communication Compliance focuses on communication content (e.g., offensive language) rather than behavioral data exfiltration patterns like USB downloads or bulk external emails.

Why the other options are wrong

B

Microsoft Purview Data Lifecycle Management focuses on retaining and deleting data based on policies, not on detecting anomalous user behavior like data exfiltration to USB drives or external emails.

C

Microsoft Purview Communication Compliance monitors communications for policy violations like inappropriate language or sharing sensitive info, but it does not detect anomalous data exfiltration activities such as bulk file downloads to USB drives.

D

Microsoft Purview eDiscovery (Standard) is used for searching and exporting content for legal or investigative purposes, not for real-time detection and alerting on anomalous data exfiltration activities. It does not provide proactive alerts on user behavior like downloading files to USB drives or sending sensitive emails.

When would these options actually be correct?

B

An organization needs to automatically retain customer data for 7 years to meet regulatory requirements and then securely delete it. They should configure Microsoft Purview Data Lifecycle Management to apply retention labels and deletion policies.

C

An organization wants to detect and prevent employees from sharing confidential information via email or Microsoft Teams messages, such as sending customer data to external recipients. They need a policy that scans communications for sensitive content and can enforce actions like blocking the message.

D

A legal team needs to identify and preserve all emails and documents related to a specific litigation case from a departing employee's mailbox and OneDrive. They require a solution to search, hold, and export relevant data for eDiscovery purposes.

Why candidates pick the wrong answer

B

Candidates may confuse data lifecycle management with data security controls, thinking that managing data retention also covers monitoring data movement, but it does not include behavioral detection.

C

Candidates may confuse Communication Compliance with Insider Risk Management because both deal with insider threats and data leakage, but Communication Compliance focuses on communications rather than behavioral patterns like file downloads.

D

Candidates may confuse eDiscovery's ability to search and export data with the detection of data exfiltration, assuming that monitoring for large downloads falls under the same umbrella of data investigation.

1026
Multi-Selecteasy

Which TWO Microsoft security solutions can be used to centrally manage security policies across hybrid environments including on-premises and cloud? (Choose TWO.)

Select 2 answers
A.Microsoft Sentinel
B.Microsoft Defender for Cloud
C.Microsoft Defender for Office 365
D.Microsoft Intune
E.Microsoft Defender for Cloud Apps
AnswersA, B

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It ingests security data from diverse sources, including Azure, other cloud providers, and on-premises infrastructure, enabling centralized threat detection, investigation, and automated response. This comprehensive capability makes it a primary tool for centralized security management across hybrid and multicloud environments.

Why this answer

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that provides centralized security analytics and threat intelligence across the entire enterprise, including on-premises and multi-cloud environments. It collects data from various sources via connectors (e.g., Azure Monitor Agent, Syslog, Windows Security Events) and allows security teams to manage policies, detect threats, and respond from a single pane of glass. This makes it a correct answer for centrally managing security policies across hybrid environments.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP solution) with Microsoft Defender for Cloud Apps (a CASB), or mistakenly think Microsoft Defender for Office 365 covers hybrid infrastructure policies, when it only protects Microsoft 365 workloads.

1027
MCQeasy

A company uses a cloud-based email service. The service provider ensures that the physical data centers are secure and that the email platform is patched and available. The company is responsible for managing user accounts and ensuring that employees use strong passwords. This division of responsibilities is an example of which concept?

A.Defense in depth
B.Shared responsibility model
C.Zero Trust
D.Principle of least privilege
AnswerB

The Shared Responsibility Model is a fundamental framework in cloud computing that explicitly delineates security obligations between the cloud service provider (CSP) and the customer. The CSP is responsible for the security *of* the cloud, encompassing the underlying infrastructure, physical facilities, and host operating systems. Conversely, the customer is accountable for security *in* the cloud, which includes their data, applications, network configurations, and identity and access management. This model ensures clarity on who manages what aspects of security, varying based on the service model adopted.

Why this answer

The scenario describes a clear division of security responsibilities between the cloud service provider (securing physical data centers, patching the platform) and the customer (managing user accounts, enforcing strong passwords). This is the core definition of the shared responsibility model, which is a foundational concept in cloud computing (as defined by NIST SP 800-145 and adopted by major providers like Microsoft 365). The model explicitly delineates that the provider is responsible for 'security of the cloud' (physical hosts, network, hypervisor) while the customer is responsible for 'security in the cloud' (user identities, data, client endpoints).

Exam trap

The trap here is that candidates confuse the shared responsibility model with defense in depth because both involve multiple security layers, but the question specifically tests the contractual and operational division of security tasks between cloud provider and customer, not the stacking of controls.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered security strategy using multiple controls (e.g., firewalls, antivirus, encryption) to protect assets, not a division of responsibilities between two parties. Option C is wrong because Zero Trust is a security model based on 'never trust, always verify'—it assumes no implicit trust and requires continuous authentication for every access request, not a contractual split of duties. Option D is wrong because the principle of least privilege is an access control concept that grants users only the minimum permissions needed to perform their tasks, not a framework for dividing security obligations between a provider and a customer.

1028
Multi-Selectmedium

You are a security administrator for a company that uses Microsoft Defender for Cloud Apps. The security team wants to detect and respond to risky user activities and unsanctioned cloud app usage. Which two capabilities does Defender for Cloud Apps provide? (Choose two.)

Select 2 answers
A.Just-in-time virtual machine access in Azure.
B.Attack path analysis for multicloud resources.
C.Anomaly detection policies to identify risky user behavior.
D.Cloud Discovery to identify shadow IT and unsanctioned apps.
E.Endpoint detection and response for Windows devices.
AnswersC, D

Defender for Cloud Apps includes anomaly detection policies that use Microsoft threat intelligence and behavior analytics to identify risky activities such as impossible travel, mass downloads, or suspicious inbox rules. These policies generate alerts that security teams can investigate and respond to. This meets the requirement to detect and respond to risky user activities.

Why this answer

Defender for Cloud Apps provides Cloud Discovery to find shadow IT and unsanctioned apps, and anomaly detection policies to surface risky user behavior. These two capabilities directly match the team's goals. Endpoint EDR, just-in-time VM access, and attack path analysis belong to other Defender services and do not address cloud app discovery or user activity monitoring.

Exam trap

The trap here is mixing capabilities from Microsoft Defender for Cloud and Defender for Endpoint into Defender for Cloud Apps, which actually focuses on cloud app discovery and user activity analytics.

1029
MCQmedium

You are a security administrator for Contoso Ltd. The company uses Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Entra ID. Recently, several users reported receiving phishing emails that bypassed the existing anti-phishing policies. The security team suspects that attackers are using sophisticated techniques to evade detection. You need to enhance the email security posture by implementing a solution that uses AI and machine learning to detect advanced phishing attempts, including those using social engineering and impersonation. Which Microsoft solution should you use?

A.Microsoft Sentinel
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Office 365 is specifically designed to protect email, collaboration, and productivity services from advanced threats like phishing, business email compromise (BEC), and malware. It employs machine learning models and detonation chambers to analyze email content, attachments, and links in real-time, identifying and blocking sophisticated phishing attempts, impersonation attacks, and zero-day exploits before they reach user inboxes. This comprehensive suite includes anti-phishing policies, Safe Attachments, and Safe Links to proactively safeguard users.

Why this answer

Microsoft Defender for Office 365 includes advanced anti-phishing capabilities with AI and machine learning, such as impersonation protection and spoof intelligence. Microsoft Sentinel is a SIEM/SOAR, not an email security solution. Defender for Cloud Apps is a CASB.

Defender for Identity identifies threats via on-premises AD signals. Microsoft Purview focuses on compliance and data governance.

1030
MCQmedium

A company uses Microsoft Entra ID. The compliance team requires that membership in highly privileged roles, such as Global Administrator, is reviewed quarterly. The review must be automated: role owners are sent an email notification with a list of current members to approve or deny. If a member does not respond within 30 days, their access should be automatically revoked. Which Microsoft Entra ID feature should the team use to set up this periodic review and automatic removal?

A.Access Reviews
B.Privileged Identity Management (PIM)
C.Conditional Access
D.Identity Protection
AnswerA

Microsoft Entra Access Reviews are specifically designed to manage and automate the periodic review of user access to resources, applications, and roles within Microsoft Entra ID. This feature allows organizations to schedule recurring campaigns where designated reviewers, such as resource owners or managers, certify whether users still require their current permissions. Crucially, Access Reviews can automatically revoke access for users whose permissions are not approved or who fail to respond, directly addressing the compliance requirement for regular access validation and removal of stale assignments.

Why this answer

Access Reviews in Microsoft Entra ID is the correct feature because it is specifically designed for periodic, automated attestation of group or role memberships. It sends email notifications to designated reviewers, tracks responses, and can automatically remove users who do not respond within a defined period (e.g., 30 days). This directly meets the compliance requirement for quarterly reviews of Global Administrator membership with automatic revocation.

Exam trap

The trap here is confusing Privileged Identity Management (PIM) with Access Reviews, as both involve role management, but PIM handles activation and approval while Access Reviews handle periodic attestation and automatic removal.

Why the other options are wrong

B

PIM provides just-in-time role activation and time-bound assignments, but it does not include built-in automated periodic review workflows with email notifications and automatic removal after 30 days of non-response. That functionality is specific to Access Reviews.

D

Identity Protection is designed to detect and respond to identity-based risks (e.g., compromised accounts, sign-in anomalies), not to manage periodic access reviews or automatic removal of role members.

When would these options actually be correct?

B

A question asks: 'The security team needs to grant temporary, time-limited access to the Global Administrator role for specific tasks, with approval required before activation.' In that scenario, PIM is the correct answer because it enables just-in-time privileged role activation with approval workflows.

D

A company wants to automatically detect and block sign-ins from risky IP addresses or users with leaked credentials, and require multi-factor authentication for high-risk sessions. Identity Protection would be the correct feature to configure risk-based Conditional Access policies.

Why candidates pick the wrong answer

B

Candidates confuse PIM's role management capabilities with Access Reviews, assuming PIM includes review workflows because both deal with privileged roles. They overlook that Access Reviews is the dedicated feature for periodic attestation and automated removal.

D

Candidates may confuse Identity Protection's automated risk remediation (e.g., blocking access) with the automated removal of role members, or assume it handles all identity-related automation including reviews.

1031
MCQmedium

A user receives a sensitivity label that automatically marks the email as 'Confidential' and prevents forwarding. The label was applied without user intervention. Which mechanism most likely applied the label?

A.Azure Information Protection file policy
B.Auto-classification via DLP policy
C.Default label configured in Microsoft 365
D.Manual labeling by the user
AnswerB

Auto-classification via a Data Loss Prevention (DLP) policy is the correct mechanism for this scenario. Microsoft Purview DLP policies can be configured to detect specific sensitive information types (SITs) or trainable classifiers within content, such as emails, documents, or Teams messages. Upon detection, the DLP policy can automatically apply a pre-defined sensitivity label to the item, ensuring consistent protection based on the content's sensitivity without requiring any manual user action.

Why this answer

Auto-classification via DLP policy can automatically apply sensitivity labels based on sensitive content, such as credit card numbers, enabling the label to be applied without user intervention. Option A is incorrect because the Azure Information Protection file policy applies to files in Windows File Explorer, not emails. Option C is incorrect because a default label applies to all unlabeled emails but does not use content detection.

Option D is incorrect because manual labeling requires the user to select the label.

1032
Multi-Selectmedium

Which THREE are capabilities of Microsoft Purview Data Loss Prevention (DLP)? (Choose three.)

Select 3 answers
A.Automatically classify and label data
B.Detect sensitive information in documents and emails
C.Block sharing of sensitive data with external users
D.Manage encryption keys for data at rest
E.Provide policy tips to users when they attempt to share sensitive data
AnswersB, C, E

Detecting sensitive information in documents and emails is a fundamental capability of Microsoft Purview Data Loss Prevention. DLP policies are meticulously configured to identify specific sensitive information types (SITs), such as credit card numbers, national ID numbers, or custom patterns, within content across various locations like Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. This precise detection mechanism forms the essential prerequisite for any subsequent enforcement actions, ensuring that policies target the correct data.

Why this answer

Microsoft Purview DLP is designed to detect sensitive information (e.g., credit card numbers, PII) in documents and emails by using built-in or custom sensitive information types. When a match is found, DLP can enforce policies to block sharing with external users and display policy tips to inform users of the violation, making options B, C, and E correct capabilities.

Exam trap

The trap here is that candidates confuse the automatic classification and labeling capabilities of Microsoft Purview Information Protection with the detection and enforcement actions of DLP, leading them to incorrectly select Option A as a DLP capability.

1033
MCQhard

A security operations center (SOC) team needs to ingest security logs from on-premises servers, Azure virtual machines, and SaaS applications like Salesforce. They want a cloud-native solution that uses machine learning to detect threats, provides a unified query language for hunting, and supports automated incident response through playbooks. Which Microsoft solution should they deploy?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft 365 Defender
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is specifically designed for a Security Operations Center (SOC) team to ingest security logs from a vast array of sources, including Microsoft services, third-party applications, on-premises infrastructure, and other cloud providers. Sentinel centralizes this data for advanced threat detection using machine learning, behavioral analytics, and threat intelligence, enabling comprehensive security monitoring, hunting, and automated response playbooks.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) solution that ingests logs from on-premises servers, Azure VMs, and SaaS applications like Salesforce. It uses built-in machine learning to detect threats, offers the Kusto Query Language (KQL) for unified hunting, and supports automated incident response via playbooks built on Azure Logic Apps.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM tool) with a SIEM, or assume Microsoft 365 Defender can ingest third-party SaaS logs, but only Microsoft Sentinel provides a cloud-native SIEM with unified log ingestion, ML threat detection, and automated playbook response.

Why the other options are wrong

A

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform, not a SIEM/SOAR solution. It lacks a unified query language (KQL) for hunting across diverse data sources and does not natively support automated incident response playbooks like Sentinel.

C

Microsoft 365 Defender is designed to protect Microsoft 365 workloads (e.g., email, endpoints, identities) and does not natively ingest logs from on-premises servers, Azure VMs, or third-party SaaS like Salesforce, nor does it provide a unified query language (KQL) or playbook-based automated incident response.

D

Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on ingesting logs from diverse sources like on-premises servers, Azure VMs, and SaaS apps, nor does it provide a unified query language (KQL) for hunting across those sources or support automated incident response playbooks.

When would these options actually be correct?

A

A question asking for a solution to assess and improve the security posture of Azure and hybrid workloads, detect misconfigurations, and provide just-in-time VM access. For example: 'Which Microsoft service provides continuous assessment of security configurations and recommendations for Azure resources?'

C

A question asking for a solution to detect, investigate, and respond to threats across Microsoft 365 services (Exchange, SharePoint, Teams) and endpoints, with integrated threat signals from Microsoft Defender products, and requiring automated response capabilities within the Microsoft 365 ecosystem.

D

A question that asks for a solution to protect endpoints (e.g., Windows, macOS, Linux devices) from advanced threats, with capabilities for endpoint detection and response, automated investigation, and threat hunting specifically on devices, and where the environment does not require multi-source log ingestion or SIEM functionality.

Why candidates pick the wrong answer

A

Candidates may confuse Defender for Cloud's threat detection capabilities (e.g., Azure Defender) with a full SIEM, or assume its integration with Azure covers all log sources, overlooking the need for a unified query language and playbook automation.

C

Candidates may confuse Microsoft 365 Defender as a comprehensive security solution for all environments, overlooking its focus on Microsoft 365 workloads and lack of support for third-party SaaS and on-premises log ingestion.

D

Candidates may confuse Defender for Endpoint's threat detection and automated response features with Sentinel's broader SIEM capabilities, or assume that 'Defender' products all provide similar log ingestion and hunting across multiple sources.

1034
MCQmedium

A company uses Microsoft Entra ID. They frequently collaborate with an external partner organization. The IT team wants to allow the partner's users to access the company's internal SharePoint site using their existing corporate credentials from their own Microsoft Entra tenant. The partner users should not have to create separate guest accounts or remember another password. Which Microsoft Entra feature should the IT team configure?

A.Microsoft Entra B2C
B.Microsoft Entra B2B collaboration
C.Microsoft Entra Domain Services
D.Microsoft Entra Application Proxy
AnswerB

Microsoft Entra B2B collaboration is the correct solution for enabling secure and seamless collaboration with external partners. It allows organizations to invite guest users from other Microsoft Entra tenants, social identity providers, or email-verified accounts to access applications and resources within their own Microsoft Entra ID. This feature facilitates cross-organizational projects by letting external users utilize their existing credentials without creating new accounts in the host directory, ensuring efficient and governed access.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it enables external users from a partner organization to access the company's internal SharePoint site using their own corporate credentials from their Microsoft Entra tenant. B2B collaboration creates a guest user object in the resource tenant without requiring separate guest accounts or additional passwords, leveraging cross-tenant trust and SAML/WS-Federation for authentication.

Exam trap

The trap here is that candidates often confuse B2B collaboration with B2C, thinking both are for external users, but B2C is for consumers with self-service sign-up, while B2B is for business partners using their existing corporate identities.

Why the other options are wrong

A

Microsoft Entra B2C is designed for customer-facing applications where external users sign up and manage their own identities, not for enabling existing corporate credentials from another Entra tenant to access internal resources like SharePoint.

C

Microsoft Entra Domain Services provides managed domain services like domain join and group policy, not external user access to SharePoint. It does not enable cross-tenant collaboration or federated authentication for partner users.

D

Microsoft Entra Application Proxy is used to publish on-premises web applications externally, not to enable cross-tenant collaboration with external partners using their existing credentials.

When would these options actually be correct?

A

A company wants to allow external customers to sign up and log in to a consumer-facing web application using their own social accounts (e.g., Google, Facebook) or email/password, without requiring an existing corporate identity. The IT team would configure Microsoft Entra B2C to manage customer identities and authentication.

C

A company needs to lift-and-shift on-premises applications that require LDAP, Kerberos, or NTLM authentication to Azure without managing domain controllers. Entra Domain Services would be the correct feature to provide managed domain services for those legacy apps.

D

A company needs to provide remote access to an internal web application hosted on-premises for external users without requiring a VPN. The IT team wants to secure access with pre-authentication and conditional access policies.

Why candidates pick the wrong answer

A

The 'B2C' label suggests business-to-consumer, which might be confused with business-to-business (B2B). Candidates may think any external user scenario falls under B2C, overlooking that B2C is for consumer identity management, not for partner collaboration with existing corporate credentials.

C

Candidates may confuse 'Domain Services' with identity management for external access, or think it provides a broader identity solution that includes collaboration features, not realizing its focus is on legacy authentication and domain join scenarios.

D

Candidates may confuse Application Proxy with a solution for external access, thinking it can handle partner authentication, but it is designed for publishing on-prem apps, not for B2B collaboration scenarios.

1035
MCQmedium

Your organization wants to use Microsoft Entra ID to provide single sign-on (SSO) for a third-party SaaS application. What must you configure in Microsoft Entra ID?

A.Identity Protection policy
B.Conditional Access policy
C.Enterprise application registration
D.Self-service password reset
AnswerC

Registering the SaaS application as an enterprise application in Microsoft Entra ID creates the service principal and trust configuration needed for SAML or OIDC federation. This enables single sign-on and lets you assign users and configure claims for the third-party service.

Why this answer

To provide SSO for a third-party SaaS application using Microsoft Entra ID, you must configure an enterprise application registration, which represents the application in your tenant and enables SAML or OIDC-based SSO. This registration includes the necessary configuration for single sign-on, such as the reply URL and claims.

Exam trap

SC-900 often tests the confusion between Conditional Access and enterprise application registration; candidates may think Conditional Access alone enables SSO, but it only enforces access policies after SSO is configured.

How to eliminate wrong answers

Option A is wrong because Identity Protection policies are used to detect and remediate identity risks, not to configure SSO for applications. Option B is wrong because Conditional Access policies control access based on conditions but do not themselves provide SSO; they are used in conjunction with SSO. Option D is wrong because self-service password reset allows users to reset their passwords, not to enable SSO for SaaS applications.

1036
MCQmedium

A multinational corporation must retain all financial records for 7 years and then permanently delete them. The compliance officer wants to ensure that even a global administrator cannot modify or delete the retention policy. Which Microsoft Purview solution and configuration should they use?

A.eDiscovery (Standard)
B.Compliance Manager
C.Data Lifecycle Management with a preservation lock
D.Information Protection with sensitivity labels
AnswerC

Data Lifecycle Management (DLM), specifically through Microsoft 365 retention policies, allows organizations to define how long content is retained or deleted. For financial records requiring mandatory retention, a retention policy can be configured to preserve content for a specified period. Applying a preservation lock to this policy makes it immutable, preventing anyone, including administrators, from turning off the policy, deleting it, or making it less restrictive, thus ensuring compliance with stringent regulatory requirements for long-term record retention.

Why this answer

C is correct because Data Lifecycle Management with a preservation lock allows an organization to apply a retention policy that cannot be modified, deleted, or turned off by any administrator, including a global administrator. This ensures financial records are retained for exactly 7 years and then permanently deleted, meeting the compliance officer's requirement for immutable retention.

Exam trap

The trap here is that candidates often confuse retention policies with sensitivity labels or eDiscovery, not realizing that only a preservation lock provides the immutable, administrator-proof retention enforcement required for regulatory compliance.

Why the other options are wrong

A

eDiscovery (Standard) is used for searching and exporting content for legal or investigative purposes, not for enforcing immutable retention policies. It cannot prevent administrators from modifying or deleting retention settings.

B

Compliance Manager is a risk assessment and compliance score tool, not a data retention solution. It cannot enforce retention policies or prevent modification/deletion of retention settings.

When would these options actually be correct?

A

A legal team needs to place a hold on all email communications related to an ongoing lawsuit to prevent deletion or alteration. eDiscovery (Standard) would be the correct solution to create a litigation hold and search for relevant content.

B

An organization needs to assess its compliance posture against regulatory standards (e.g., GDPR, ISO 27001) and track improvement actions. The compliance officer wants a dashboard showing compliance score and recommended actions.

Why candidates pick the wrong answer

A

Candidates may confuse eDiscovery's hold capabilities with retention policies, assuming it can enforce long-term retention and deletion, but eDiscovery holds are temporary and not designed for compliance-based lifecycle management.

B

Candidates may confuse 'compliance' in the name with the ability to enforce retention policies, or think Compliance Manager handles data lifecycle requirements.

1037
MCQeasy

Your organization uses Microsoft Entra ID to manage identities for employees and external partners. You need to ensure that external partners can access only specific applications and that their access expires automatically after 60 days. Which Microsoft Entra feature should you use?

A.Microsoft Entra B2B collaboration.
B.Conditional Access policies.
C.Microsoft Entra Identity Protection.
D.Microsoft Entra entitlement management.
AnswerD

Microsoft Entra entitlement management is a robust identity governance feature specifically designed to manage the identity and access lifecycle for both internal and external users. It enables organizations to create access packages, which bundle resources like groups, applications, and SharePoint sites, and define policies that include mandatory access reviews and automatic expiration dates for assigned access. This capability directly addresses the requirement for assigning access and enforcing its automatic expiration.

Why this answer

Microsoft Entra entitlement management allows you to create access packages that govern external partner access to specific applications, groups, and sites, with built-in time-limited access that automatically expires after a defined period (e.g., 60 days). This feature directly addresses the requirement to scope access to only specific applications and enforce automatic expiration, which is not natively handled by other Entra ID features.

Exam trap

The trap here is that candidates often confuse the invitation and authentication capabilities of B2B collaboration (Option A) with the full lifecycle and access governance provided by entitlement management, assuming B2B alone can enforce time-bound application access.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2B collaboration enables external user invitation and authentication but does not provide granular control over which specific applications they can access or enforce automatic time-bound expiration policies on its own. Option B is wrong because Conditional Access policies enforce access controls based on conditions (e.g., location, device state) but cannot automatically expire access after a fixed duration like 60 days; they are real-time evaluation rules, not time-limited access management. Option C is wrong because Microsoft Entra Identity Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, suspicious sign-ins) and does not manage application-specific access or automatic expiration schedules.

1038
MCQeasy

You are the compliance administrator for a retail company that uses Microsoft 365 Business Premium. The company needs to: - Block customers' credit card numbers from being sent via email. - Retain all sales invoices for 3 years as per financial regulations. - Allow managers to search and export employee emails for HR investigations. - Ensure that only HR can access employee salary information. Which Microsoft Purview solutions should you use?

A.DLP, Information Barriers, eDiscovery, and sensitivity labels
B.DLP, Data Lifecycle Management, eDiscovery, and sensitivity labels
C.Insider Risk Management, Data Lifecycle Management, eDiscovery, and sensitivity labels
D.Communication Compliance, Data Lifecycle Management, eDiscovery, and sensitivity labels
AnswerB

This combination correctly addresses all implied compliance requirements. Data Loss Prevention (DLP) is essential for blocking the sharing of sensitive information like credit card numbers. Data Lifecycle Management (DLM) provides the necessary capabilities for defining and enforcing retention and disposition policies, ensuring data is kept for the required duration and then appropriately deleted. eDiscovery enables the organization to efficiently search, preserve, and produce electronic information for legal or investigative purposes, while sensitivity labels allow for data classification and protection, applying encryption or access restrictions based on content.

Why this answer

DLP (Data Loss Prevention) blocks credit card numbers from being sent via email, Data Lifecycle Management retains sales invoices for 3 years, eDiscovery allows managers to search and export employee emails for HR investigations, and sensitivity labels restrict access to salary information to HR only. Each requirement maps directly to a specific Purview solution: DLP for sensitive data protection, retention policies for compliance, eDiscovery for legal/HR investigations, and sensitivity labels for access control.

Exam trap

The trap here is that candidates confuse Information Barriers (which restrict communication between groups) with DLP (which blocks sensitive data patterns), or assume Insider Risk Management or Communication Compliance can replace DLP for proactive blocking of credit card numbers in email.

How to eliminate wrong answers

Option A is wrong because Information Barriers are designed to prevent communication between specific groups (e.g., to avoid conflicts of interest), not to block sensitive data like credit card numbers or to retain data for a fixed period; DLP handles the blocking, and retention requires Data Lifecycle Management, not Information Barriers. Option C is wrong because Insider Risk Management focuses on detecting risky user activities (e.g., data exfiltration) rather than proactively blocking credit card numbers via email; DLP is the correct solution for that requirement. Option D is wrong because Communication Compliance is used to monitor communications for policy violations (e.g., harassment), not to block specific sensitive data patterns like credit card numbers; DLP is required for that blocking action.

1039
MCQeasy

Refer to the exhibit. You are configuring a Microsoft Entra ID group. What does the exhibit represent?

A.A dynamic security group based on department attribute.
B.A Microsoft 365 group with dynamic membership.
C.A dynamic group based on user location.
D.A static security group with assigned members.
AnswerA

The JSON clearly indicates a dynamic security group through `groupTypes` containing "Security" and "DynamicMembership". The `membershipRule` property, specifically `(user.department -eq "Sales")`, defines the criteria for automatic membership based on the user's 'department' attribute. This configuration ensures that any user whose department is "Sales" is automatically added to or removed from the group, providing efficient and attribute-driven management.

Why this answer

The exhibit shows a rule syntax of `(user.department -eq "Sales")`, which is the expression used to dynamically add or remove members based on the department attribute. This is the defining characteristic of a dynamic security group in Microsoft Entra ID, where membership is evaluated automatically when user attributes change.

Exam trap

The trap here is that candidates confuse dynamic security groups with Microsoft 365 groups, but the key differentiator is the group type (Security vs. Microsoft 365) shown in the exhibit, not the rule syntax itself.

How to eliminate wrong answers

Option B is wrong because a Microsoft 365 group with dynamic membership uses the same rule syntax but the group type is 'Microsoft 365', not 'Security'. Option C is wrong because the rule explicitly checks the `department` attribute, not `user.location` or any location-related attribute. Option D is wrong because a static security group requires manual assignment of members and does not use a membership rule expression.

1040
MCQmedium

Refer to the exhibit. A company has configured the above Conditional Access policy in Microsoft Entra ID. A user attempts to access Exchange Online from an untrusted location. What happens?

A.The user is granted access without MFA because the policy does not apply.
B.Access is blocked because the condition is not met.
C.The user is prompted for MFA because the policy applies to all users.
D.The user is blocked because the grant requires MFA.
AnswerA

The Conditional Access policy is specifically configured to apply *only* when a user is accessing from a "trusted location." Since the user is accessing from an *untrusted* location, the conditions of this particular policy are not met. Consequently, the policy is not enforced, and its grant controls, including the MFA requirement, are not triggered. The user is thus granted access based on default security settings or other applicable policies, without being prompted for MFA by *this* specific policy.

Why this answer

The Conditional Access policy shown in the exhibit is configured with 'Include: All users' and 'Exclude: All users'. When both include and exclude are set to 'All users', the exclusion takes precedence, effectively making the policy apply to no users. Therefore, when a user attempts to access Exchange Online from an untrusted location, the policy does not apply, and the user is granted access without MFA.

Exam trap

The trap here is that candidates assume 'Include: All users' means the policy applies to everyone, overlooking that 'Exclude: All users' negates the inclusion, making the policy effectively inactive.

How to eliminate wrong answers

Option B is wrong because the condition (untrusted location) is met, but the policy does not apply due to the exclusion overriding the inclusion, so access is not blocked. Option C is wrong because the policy does not apply to all users; the 'Exclude: All users' setting removes all users from policy enforcement, so no MFA prompt occurs. Option D is wrong because the grant control requiring MFA is never evaluated, as the policy does not apply to the user.

1041
MCQmedium

Your organization uses Microsoft Purview to manage compliance. You need to ensure that financial documents are automatically labeled as 'Financial' and retained for 7 years. Additionally, if a user tries to share a financial document externally, they must see a policy tip warning them and be blocked if they proceed. You also need to audit all access to financial documents. Which configuration should you implement?

A.Create a DLP policy to detect financial data and block external sharing; use default audit logging
B.Create a manual labeling policy for users to apply 'Financial' label; create a retention label for 7 years; create a DLP policy to warn on external sharing
C.Create a retention label 'Financial' with auto-apply based on sensitive info type; create a DLP policy to block external sharing
D.Create an auto-labeling policy to apply a sensitivity label 'Financial' with encryption; create a retention policy to retain all labeled content for 7 years; create a DLP policy to block external sharing of 'Financial' labeled content with a policy tip; enable audit logging
AnswerD

Auto-labeling applies label automatically; retention policy retains; DLP blocks sharing; audit logging tracks access.

Why this answer

It combines auto-labeling to automatically apply the 'Financial' sensitivity label with encryption, a retention policy to retain labeled content for 7 years, a DLP policy to block external sharing with a policy tip, and audit logging (enabled by default) to track access. Option A lacks labeling and retention. Option B uses manual labeling, which is not automatic, and the DLP only warns, not blocks.

Option C uses a retention label instead of a sensitivity label, so it does not provide encryption or protection, and the DLP policy does not include a policy tip.

1042
MCQmedium

Your organization uses Microsoft 365 and needs to identify internal users who are sending confidential data to external domains repeatedly. Which Microsoft Purview solution should you use?

A.Data Loss Prevention
B.Insider Risk Management
C.Audit (Premium)
D.Communication Compliance
AnswerB

Microsoft Purview Insider Risk Management is specifically engineered to identify, analyze, and act on potential insider risks by correlating diverse signals from Microsoft 365 and other sources. It leverages machine learning and advanced analytics to detect subtle, cumulative patterns of user activity, such as unusual data exfiltration, unauthorized access attempts, or policy violations, that collectively indicate malicious or inadvertent insider threats over time. This capability directly addresses the need to identify evolving patterns of risky behavior.

Why this answer

Insider Risk Management (IRM) is the correct solution because it is specifically designed to detect, investigate, and act on risky user activities that violate organizational policies, such as repeatedly sending confidential data to external domains. IRM uses predefined or custom policies to correlate signals from Microsoft 365 logs (e.g., email, SharePoint, Teams) and user behavior analytics to identify patterns of data exfiltration by internal users. Unlike other solutions, IRM focuses on user-centric risk scenarios and can trigger automated responses like escalation or case creation.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with user behavior analysis, assuming DLP's alerting on individual sensitive data sends is sufficient to identify repeat offenders, but DLP lacks the cross-event correlation and user-centric risk scoring that Insider Risk Management provides.

How to eliminate wrong answers

Option A (Data Loss Prevention) is wrong because DLP is primarily a content-aware policy engine that blocks or alerts on sensitive data in transit or at rest based on rules (e.g., credit card numbers), but it does not natively analyze repeated user behavior patterns over time or correlate multiple incidents to identify a user as a repeat offender. Option C (Audit (Premium)) is wrong because Audit (Premium) provides detailed logging and forensic investigation capabilities but is a passive recording tool; it does not proactively detect or alert on repeated data exfiltration patterns without additional custom queries or manual analysis. Option D (Communication Compliance) is wrong because Communication Compliance is designed to monitor and review communications (e.g., email, Teams) for offensive language, harassment, or regulatory compliance (e.g., FINRA), not for detecting repeated data exfiltration of confidential data to external domains.

1043
MCQmedium

A financial services organization needs to prevent communication between its research analysts and investment bankers to comply with regulatory requirements. Which Microsoft Purview solution should the compliance team implement?

A.Data Loss Prevention (DLP)
B.Information Barriers
C.Data Lifecycle Management
D.Microsoft Purview eDiscovery
AnswerB

Information Barriers, a feature within Microsoft Purview, are designed to prevent specific groups of users from communicating or collaborating with each other. This is crucial for organizations like financial services firms to establish 'ethical walls' between departments, such as analysts and bankers, ensuring regulatory compliance and preventing conflicts of interest. These policies restrict communication channels like Microsoft Teams chats, calls, and SharePoint site access, directly addressing the need to prevent communication.

Why this answer

Information Barriers (IB) in Microsoft Purview is specifically designed to prevent communication and collaboration between certain user groups to comply with regulatory requirements, such as those in financial services that require separation between research analysts and investment bankers. IB policies enforce restrictions on Microsoft Teams, SharePoint, and OneDrive to block unauthorized communication and file sharing, directly addressing the need to avoid conflicts of interest.

Exam trap

Microsoft often tests the distinction between DLP and Information Barriers, where candidates mistakenly choose DLP because they think preventing communication is about protecting data, but DLP does not restrict person-to-person communication—it only restricts data sharing based on content classification.

Why the other options are wrong

A

Data Loss Prevention (DLP) is designed to prevent unauthorized sharing of sensitive data, not to block communication between specific groups of users. The requirement is to prevent communication between research analysts and investment bankers, which is a classic information barrier scenario, not a data protection issue.

C

Data Lifecycle Management governs retention and deletion of data based on policies, but it does not restrict communication between users or groups. The question requires preventing communication between analysts and bankers, which is a real-time access control need, not a data retention policy.

D

eDiscovery is used for identifying, preserving, and exporting electronic content for legal or investigative purposes, not for preventing communication between groups. It does not enforce real-time communication restrictions.

When would these options actually be correct?

A

DLP would be correct if the question asked about preventing sensitive financial data (e.g., insider trading tips) from being shared via email or chat between these groups. For example: 'The compliance team needs to block emails containing confidential client data from being sent between departments.'

C

A question asks: 'A healthcare organization needs to automatically delete patient records after 7 years to comply with HIPAA retention requirements. Which Microsoft Purview solution should they use?' In that scenario, Data Lifecycle Management would be correct.

D

A law firm needs to search for and export all emails related to a specific client matter for a legal hold. The compliance team should implement Microsoft Purview eDiscovery to identify and preserve relevant data across Exchange, SharePoint, and Teams.

Why candidates pick the wrong answer

A

Candidates may confuse preventing communication with preventing data leaks, assuming DLP can block all forms of information flow between groups. They might think DLP policies can restrict communication channels, but DLP focuses on content inspection, not user-to-user communication blocking.

C

Candidates may confuse 'managing data over its lifecycle' with 'controlling data access or flow,' assuming that lifecycle policies can also restrict communication, or they may think DLM includes broader security controls.

D

Candidates may confuse eDiscovery with compliance solutions that restrict communication, or assume that any regulatory compliance need involves legal discovery processes.

1044
MCQmedium

A company uses Microsoft Entra ID and wants to automate the lifecycle of guest users. When a contractor's project ends, the guest account should be automatically blocked and then removed after 30 days. Which Microsoft Entra capability should they configure to manage this process?

A.Conditional Access
B.Entitlement Management
C.Privileged Identity Management
D.Identity Governance
AnswerB

Entitlement Management, a core component of Microsoft Entra Identity Governance, is specifically designed to automate the lifecycle of access for both internal and external users. It allows organizations to define access packages that bundle resources and specify access policies, including start and end dates. When an access package expires, Entitlement Management automatically revokes access and can remove guest accounts from the directory, directly addressing the requirement for automated guest account creation and removal tied to project timelines.

Why this answer

Entitlement Management in Microsoft Entra ID Governance allows organizations to automate the lifecycle of external identities, including guest users. By configuring an access package with a specific expiration policy (e.g., 30 days after project end), the system can automatically block and then remove the guest account when the entitlement expires, without manual intervention.

Exam trap

The trap here is that candidates confuse the broad category 'Identity Governance' (Option D) with the specific feature 'Entitlement Management' (Option B), but the question asks for the capability that directly configures the automated lifecycle, which is Entitlement Management.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces access controls based on signals like location or device compliance, but it does not automate the lifecycle or removal of guest accounts. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments and approvals, not the lifecycle of guest users or their automatic removal. Option D is wrong because Identity Governance is the overarching category that includes Entitlement Management, but it is not the specific capability that directly configures automated guest lifecycle policies; Entitlement Management is the precise tool within Identity Governance for this task.

1045
MCQhard

A security operations center (SOC) receives a high volume of low-fidelity alerts from various security tools. They need a solution that can automatically correlate alerts into incidents, use built-in machine learning to reduce false positives, and provide a unified console for investigation and response across Azure, on-premises, and Microsoft 365. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is specifically designed to ingest security data from virtually any source, including users, devices, applications, and infrastructure, across on-premises and multi-cloud environments. Sentinel leverages machine learning and AI to correlate high volumes of low-fidelity alerts into actionable incidents, significantly reducing noise and enabling efficient investigation and automated response within a unified platform.

Why this answer

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that ingests high-volume, low-fidelity alerts from multiple sources, correlates them into incidents using built-in analytics and machine learning, and provides a unified console for investigation and response across Azure, on-premises, and Microsoft 365. Its fusion and anomaly detection rules specifically reduce false positives by learning normal behavior patterns, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud (a CSPM/CWPP) with a SIEM, or assume Defender for Endpoint can handle cross-environment correlation, when only Microsoft Sentinel provides the SIEM capabilities of alert aggregation, ML-based false-positive reduction, and a unified investigation console across Azure, on-premises, and Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) focused on securing cloud resources and workloads, not a SIEM that correlates alerts into incidents or provides a unified SOC console across hybrid environments. Option C is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution that protects devices and investigates endpoint-specific threats, but it does not aggregate alerts from multiple security tools or provide cross-domain incident correlation for Azure, on-premises, and Microsoft 365. Option D is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that focuses on shadow IT discovery and data protection for SaaS applications, not a SIEM that performs high-volume alert correlation and false-positive reduction via built-in machine learning.

1046
MCQhard

Your organization uses Microsoft Purview Insider Risk Management. You need to create a policy that detects users exfiltrating sensitive data via email to external recipients. Which policy type should you configure?

A.Offensive language
B.Data leaks
C.Data theft
D.Security policy violations
AnswerB

Microsoft Purview Insider Risk Management is specifically engineered to identify and mitigate risks related to the unauthorized disclosure or exfiltration of sensitive organizational data, whether intentional or accidental. Policies configured within this solution directly target behaviors indicative of data leaving the organization, such as emailing sensitive files to personal accounts, uploading to unsanctioned cloud storage, or copying to removable media, making "data leaks" the most accurate description of its core function.

Why this answer

Data leaks policy type in Microsoft Purview Insider Risk Management is specifically designed to detect and alert on the unauthorized transmission of sensitive data to external recipients, including via email. This policy type analyzes email headers, attachments, and body content against defined sensitive information types (e.g., credit card numbers, PII) and triggers when data is sent outside the organization, matching the scenario described.

Exam trap

The trap here is that candidates often confuse 'Data theft' (which implies physical or logical removal of data) with 'Data leaks' (which specifically covers unauthorized external sharing via communication channels like email), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because Offensive language policy type is designed to detect and manage workplace harassment or inappropriate communication patterns (e.g., bullying, threats), not the exfiltration of sensitive data via email. Option C is wrong because Data theft policy type focuses on unauthorized removal or copying of data by users (e.g., downloading to USB, printing), but it does not specifically target email-based exfiltration to external recipients; it covers broader theft scenarios. Option D is wrong because Security policy violations policy type is intended to detect users bypassing security controls (e.g., disabling antivirus, tampering with logs), not the direct exfiltration of sensitive data via email.

1047
MCQeasy

A company wants to classify and label data in Microsoft SharePoint Online automatically based on content containing passport numbers. Which Microsoft Purview feature should they use?

A.Audit log
B.Data classification dashboard
C.Data loss prevention (DLP) policy
D.Auto-labeling policy
AnswerD

Auto-labeling policies, configured within Microsoft Purview, automatically apply sensitivity labels to content at rest (e.g., in SharePoint, OneDrive) or in transit (e.g., Exchange email) based on specific conditions. These conditions often include the presence of sensitive information types (SITs), keywords, or trainable classifiers, ensuring consistent and scalable data classification without requiring manual user intervention. This directly addresses the need to classify and label data automatically.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on sensitive information types, such as passport numbers. This enables automatic classification and labeling without manual intervention, meeting the requirement to label data based on content.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP policies focus on protecting data through actions like blocking or alerting, not on automatically applying classification labels.

How to eliminate wrong answers

Option A is wrong because Audit log records user and admin activities but does not classify or label data based on content. Option B is wrong because the Data classification dashboard provides visibility into classified data but does not automatically apply labels. Option C is wrong because Data loss prevention (DLP) policies detect and protect sensitive data but do not automatically apply labels; they enforce actions like blocking or alerting.

1048
MCQmedium

A company's security team has adopted a strategy that assumes a breach has already occurred. They implement network segmentation, apply strict least privilege access, continuously verify all access requests, and never trust users or devices solely because they are inside the network perimeter. This approach best describes which security model?

A.Zero Trust
B.Shared responsibility model
C.Defense in depth
D.Identity and Access Management (IAM)
AnswerA

Zero Trust is a strategic security model predicated on the principle of "never trust, always verify." It fundamentally assumes that a breach is inevitable or has already occurred, requiring explicit verification for every access request, regardless of origin or prior authorization. This model mandates continuous validation of identity, device health, and service context, while enforcing least privilege access to minimize potential damage from successful intrusions.

Why this answer

The scenario explicitly describes the core tenets of the Zero Trust model: assume breach, enforce least privilege, segment networks, and never trust any user or device based solely on network location. Zero Trust, as defined by NIST SP 800-207, mandates continuous verification of every access request, treating every request as if it originates from an untrusted network, which directly matches the company's strategy.

Exam trap

The trap here is that candidates confuse 'Defense in depth' with Zero Trust because both involve multiple security controls, but Defense in depth does not require the 'assume breach' mindset or the elimination of implicit trust based on network perimeter, which is the defining characteristic of Zero Trust.

How to eliminate wrong answers

Option B (Shared responsibility model) is wrong because it describes the division of security responsibilities between a cloud provider and a customer (e.g., AWS or Azure), not a security architecture that assumes breach and verifies every request. Option C (Defense in depth) is wrong because it relies on multiple layers of security controls (e.g., firewalls, IDS/IPS) but does not inherently require the 'never trust, always verify' principle or the assumption of an existing breach; it is a layered approach, not a trust model. Option D (Identity and Access Management - IAM) is wrong because IAM is a subset of security controls focused on managing identities and access policies (e.g., Azure AD, RBAC), not a comprehensive security model that dictates network segmentation and continuous verification of all access requests.

1049
MCQmedium

An organization has Microsoft Sentinel and Microsoft Defender XDR. They want to automatically block a user's sign-in if a high-risk alert is triggered. Which Microsoft Entra feature integrates with these products to enforce access controls?

A.Conditional Access with Identity Protection integration
B.Microsoft Entra Access Reviews
C.Microsoft Entra Identity Protection
D.Microsoft Entra Privileged Identity Management
AnswerA

Conditional Access policies, when integrated with Microsoft Entra Identity Protection, can evaluate real-time sign-in risk levels detected by Identity Protection. These policies can then enforce automated actions, such as blocking access, requiring multifactor authentication, or forcing a password change, based on the configured risk thresholds. This provides a robust, automated mechanism to prevent unauthorized access attempts from risky sign-ins.

Why this answer

Conditional Access with Identity Protection integration allows organizations to create policies that automatically block sign-ins when Microsoft Sentinel or Microsoft Defender XDR triggers a high-risk alert. This integration leverages risk signals from Identity Protection to enforce real-time access controls, such as blocking authentication, without manual intervention.

Exam trap

The trap here is that candidates confuse Microsoft Entra Identity Protection (which only detects and reports risk) with Conditional Access (which enforces the actual block), leading them to select Identity Protection alone instead of the integrated Conditional Access solution.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Access Reviews are used for periodic attestation of group memberships, application access, and role assignments, not for real-time automated blocking based on risk alerts. Option C is wrong because Microsoft Entra Identity Protection alone detects and reports risk signals (e.g., leaked credentials, anonymous IP addresses) but does not enforce access controls; it requires integration with Conditional Access to take blocking actions. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not automated sign-in blocking based on security alerts.

1050
MCQmedium

A healthcare organization must comply with HIPAA regulations. They use Microsoft Purview to classify and label patient data. Which Microsoft Purview capability helps them enforce data protection policies automatically?

A.eDiscovery
B.Audit logs
C.Sensitivity labels
D.Data loss prevention (DLP) policies
AnswerD

DLP policies in Microsoft Purview detect sensitive information types and sensitivity labels, then automatically block sharing, restrict access, or warn users. This enforces HIPAA protection without manual review, satisfying the requirement to apply safeguards automatically across workloads.

Why this answer

Data loss prevention (DLP) policies in Microsoft Purview are designed to automatically detect sensitive information (such as HIPAA-regulated data) and enforce protection actions like blocking sharing or applying encryption. DLP uses sensitivity labels and sensitive information types to identify content and then applies policy actions automatically across Exchange, SharePoint, OneDrive, and Teams. This directly enforces data protection policies without manual intervention.

Exam trap

SC-900 often tests the distinction between classification (sensitivity labels) and enforcement (DLP policies)—candidates pick sensitivity labels because they sound like the protection mechanism, but the question asks for automatic enforcement of policies, which is DLP.

How to eliminate wrong answers

Option A is wrong because eDiscovery is used for identifying and collecting content for legal cases, not for automatically enforcing protection policies. Option B is wrong because audit logs record user and admin activities for compliance and investigation, but they do not enforce any protection actions. Option C is wrong because sensitivity labels classify and protect content, but they require user or admin application; DLP policies are what automatically enforce actions based on those labels or sensitive info types.

Page 13

Page 14 of 18

Page 15