Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 1051–1125

1279 questions total · 18pages · All types, answers revealed

Page 14

Page 15 of 18

Page 16
1051
MCQhard

Your organization is planning to deploy Microsoft Defender for Cloud Apps to discover shadow IT. You need to ensure that logs from your network proxy servers are ingested. Which method should you use to connect the logs?

A.Log collector
B.Conditional Access App Control
C.Microsoft Sentinel data connector
D.App connector API
AnswerA

For Microsoft Defender for Cloud Apps to perform Shadow IT discovery, it requires network traffic logs from an organization's firewalls and proxies. A log collector is a lightweight agent deployed on-premises, typically on a dedicated server, that securely ingests these logs, parses them, and then forwards them to Defender for Cloud Apps. This process enables the service to analyze user activity, identify sanctioned and unsanctioned cloud applications, and assess their risk.

Why this answer

Microsoft Defender for Cloud Apps uses log collectors to ingest traffic logs from network proxy servers for shadow IT discovery. The log collector is a dedicated component that parses and uploads proxy logs (e.g., from Squid, Blue Coat, or Zscaler) to Defender for Cloud Apps for analysis. This method is specifically designed for log-based discovery of unsanctioned cloud app usage.

Exam trap

A common mistake on the SC-900 exam is confusing the App connector API (which connects to sanctioned cloud apps via their APIs for activity monitoring) with the Log collector (which ingests proxy logs for shadow IT discovery). Remember: Log collector is for log-based discovery of unsanctioned apps; App connector is for API-based monitoring of already-sanctioned apps.

How to eliminate wrong answers

Option B is wrong because Conditional Access App Control is a session-level policy enforcement feature that controls access to cloud apps in real time, not a method for ingesting proxy logs. Option C is wrong because the Microsoft Sentinel data connector is used to bring Defender for Cloud Apps alerts into Sentinel for SIEM correlation, not to ingest raw proxy logs for shadow IT discovery. Option D is wrong because the App connector API connects directly to cloud app APIs (e.g., Office 365, Salesforce) to pull activity logs, not to ingest network proxy traffic logs.

1052
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to allow external partners to access a specific SharePoint Online site without requiring them to have a Microsoft Entra ID account in your tenant. Which feature should you use?

A.Use Microsoft Entra B2B collaboration to invite partners as guest users.
B.Set up identity protection to allow external access.
C.Configure Microsoft Entra B2C for the partners.
D.Create guest user accounts for each partner.
AnswerA

Microsoft Entra B2B collaboration is the specific feature designed for securely sharing applications and resources with external users from other organizations. It enables partners to use their own corporate or social identities (e.g., Microsoft accounts, Google IDs) to authenticate, rather than requiring them to create new credentials in your tenant. Upon invitation, these partners are represented as guest user objects in your Microsoft Entra ID, allowing for granular access control to specified resources.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it allows you to invite external partners as guest users who can access resources like SharePoint Online using their own identity (e.g., a Microsoft account or a corporate account from another identity provider) without requiring a separate Microsoft Entra ID account in your tenant. This leverages the B2B collaboration protocol, which uses SAML/WS-Federation or OIDC for federation, enabling seamless access while maintaining centralized access control.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C, assuming both are for external users, but B2C is for customer-facing apps with self-service sign-up, while B2B is for granting access to business partners with existing identities.

How to eliminate wrong answers

Option B is wrong because Identity Protection is a security tool for detecting and responding to identity-based risks (e.g., compromised credentials, anomalous sign-ins) and does not provide a mechanism to grant external users access to resources. Option C is wrong because Microsoft Entra B2C is designed for customer-facing applications where users sign up and sign in with social or local accounts, not for granting external business partners access to internal resources like SharePoint Online. Option D is wrong because creating guest user accounts manually for each partner is inefficient and not a feature name; the correct feature is Microsoft Entra B2B collaboration, which automates the invitation and lifecycle management of guest users.

1053
MCQeasy

A user is unable to access a cloud app and receives a message that their sign-in was blocked by a Conditional Access policy. The admin wants to allow the user to self-remediate by meeting policy requirements. What should the admin enable?

A.Self-Service Password Reset
B.Multifactor Authentication registration
C.Identity Protection risk policies
D.Conditional Access policy feedback
AnswerD

Conditional Access policies evaluate various signals, including user, device, location, application, and real-time risk, to make granular access decisions. When a user is blocked from accessing a cloud application due to a Conditional Access policy, the system is designed to provide direct, actionable feedback. This feedback explicitly informs the user *why* access was denied (e.g., 'Your device is not compliant') and often includes clear steps or links to remediate the issue, enabling them to meet the policy requirements and gain access.

Why this answer

Enabling Conditional Access policy feedback allows users to receive guidance on why their sign-in was blocked and how to meet the policy requirements, such as using a compliant device or accessing from a trusted location. This feature provides actionable messages that enable self-remediation without admin intervention, directly addressing the scenario where the user needs to unblock themselves by satisfying the policy conditions.

Exam trap

The trap here is that candidates often confuse 'Conditional Access policy feedback' with other self-service features like SSPR or MFA registration, but the question specifically asks for the mechanism that provides users with actionable guidance on why they were blocked and how to meet the policy requirements, which is unique to policy feedback.

How to eliminate wrong answers

Option A is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords, but it does not address Conditional Access policy blocks that are unrelated to password issues, such as device compliance or location requirements. Option B is wrong because Multifactor Authentication (MFA) registration enables users to set up MFA, but the sign-in was blocked by a Conditional Access policy that may require additional conditions (e.g., compliant device, trusted IP) beyond MFA; enabling MFA registration alone does not guarantee the user can meet all policy requirements. Option C is wrong because Identity Protection risk policies are a separate feature that detects and responds to risky sign-ins (e.g., leaked credentials), but they do not provide the user with specific feedback on why a Conditional Access policy blocked them or how to self-remediate; risk policies automatically block or require MFA based on risk level, not user-driven feedback.

1054
Multi-Selectmedium

Your company uses Microsoft Defender for Endpoint. You need to configure attack surface reduction (ASR) rules. Which TWO of the following are ASR rules?

Select 2 answers
A.Block executable content from email client and webmail
B.Allow only signed executables
C.Block inbound connections from the internet
D.Block untrusted fonts
E.Block Office applications from creating child processes
AnswersA, E

This is a correct answer because "Block executable content from email client and webmail" is a specific Attack Surface Reduction (ASR) rule designed to prevent malware from being launched directly from email applications or webmail services. This rule targets common infection vectors by blocking the execution of files like .exe, .dll, or .js that originate from email clients (e.g., Outlook) or popular web browsers when accessing webmail. It helps mitigate phishing and drive-by download attacks by restricting the initial execution phase.

Why this answer

ASR rules are designed to block common attack vectors by controlling specific behaviors. 'Block executable content from email client and webmail' prevents malicious scripts or executables from running when delivered via email, which is a primary infection vector. Option E is correct because 'Block Office applications from creating child processes' stops attackers from using Office apps (like Word or Excel) to spawn malicious processes (e.g., PowerShell or cmd.exe), a classic technique for code execution.

Exam trap

The trap here is that candidates confuse ASR rules with other Windows security features like AppLocker, Windows Firewall, or Exploit Guard, leading them to select options that are valid security controls but not specifically ASR rules.

1055
MCQmedium

Your company is using Microsoft Entra ID to manage identities. You want to allow users to reset their own passwords without help desk intervention, but only if they have registered for self-service password reset (SSPR). What should you configure?

A.Require all users to register for Microsoft Entra MFA.
B.Configure Microsoft Entra password protection.
C.Implement Privileged Identity Management (PIM).
D.Enable Self-Service Password Reset (SSPR) in Microsoft Entra ID.
AnswerD

Enabling Self-Service Password Reset (SSPR) in Microsoft Entra ID is the direct and correct solution for allowing users to reset their own forgotten passwords without requiring administrator assistance. Once SSPR is configured and users have successfully registered their chosen authentication methods (e.g., mobile app, phone, email), they can independently verify their identity and set a new password, significantly improving user experience and reducing help desk workload.

Why this answer

Enabling Self-Service Password Reset (SSPR) in Microsoft Entra ID allows users to reset their own passwords without help desk intervention, provided they have registered for the feature. This directly meets the requirement of allowing password resets only for registered users, as SSPR requires prior registration to verify identity before a reset is permitted.

Exam trap

The trap here is that candidates often confuse enabling SSPR with requiring MFA registration, but MFA registration alone does not grant password reset capabilities—SSPR must be explicitly enabled and configured.

How to eliminate wrong answers

Option A is wrong because requiring all users to register for Microsoft Entra MFA is a separate security feature that adds multi-factor authentication but does not enable password reset functionality; MFA can be used as part of SSPR registration but is not sufficient alone. Option B is wrong because Microsoft Entra password protection is a feature that blocks weak passwords and common password attacks, but it does not provide self-service password reset capabilities. Option C is wrong because Privileged Identity Management (PIM) is designed for managing, controlling, and monitoring access to privileged roles, not for enabling end-user password self-service.

1056
MCQeasy

You are reviewing a conditional access policy in Microsoft Entra ID. The policy is enabled, applies to all cloud apps, and is configured to include users assigned to the Global Administrator or Exchange Administrator roles. Which users are affected by this policy?

A.All users who are members of any Azure AD administrative role
B.All users who are members of the Global Administrator role only
C.All users who are members of the Global Administrator or Exchange Administrator role
D.All users in the organization
AnswerC

Role inclusion in a conditional access policy targets the directory role assignment, so every user holding Global Administrator or Exchange Administrator membership is in scope. The policy evaluates role membership, not sign-in location or client app, so all such members are affected.

Why this answer

The conditional access policy includes users assigned to the Global Administrator or Exchange Administrator roles. Therefore, only users with those specific roles are affected. It does not include all administrative roles or all users in the organization.

Exam trap

The trap is misreading the role inclusion; candidates might think 'any administrative role' is included, but the policy explicitly lists only two roles, so only those are affected.

How to eliminate wrong answers

Option A is wrong because the policy only includes Global Administrator and Exchange Administrator roles, not all administrative roles. Option B is wrong because it omits Exchange Administrator, which is explicitly included. Option D is wrong because the policy is scoped to specific roles, not all users.

1057
MCQmedium

You are an identity consultant for a mid-sized company with 5,000 employees. They use Microsoft Entra ID P1 and Microsoft Intune for device management. The company wants to implement passwordless authentication for all employees to improve security and user experience. Currently, users sign in with username and password plus MFA via the Microsoft Authenticator app. The company has a mix of Windows 10/11 devices (both domain-joined and Microsoft Entra joined) and iOS/Android mobile devices. They want to support passwordless sign-in on all platforms. The CTO is concerned about cost and wants to minimize additional licensing. Which passwordless method should you recommend?

A.Enable Windows Hello for Business for all devices
B.Deploy FIDO2 security keys to all employees
C.Implement SMS-based one-time passcodes
D.Use the Microsoft Authenticator app for passwordless sign-in
AnswerD

The Microsoft Authenticator app offers a highly effective and cost-efficient solution for passwordless sign-in across a wide range of devices, including iOS, Android, and Windows. It leverages existing smartphone hardware to provide a secure, push-notification-based or number-matching authentication method, eliminating the need for users to type a password. This approach minimizes additional hardware costs, simplifies deployment, and enhances user convenience and security by removing the weakest link in traditional authentication.

Why this answer

The Microsoft Authenticator app supports passwordless sign-in using phone-based authentication, which works on both iOS and Android devices and can be used to sign into Windows 10/11 devices via the 'Sign in with phone' feature. This method leverages existing Microsoft Entra ID P1 licensing without requiring additional costs, as it is included with the current P1 license. It provides a seamless user experience by eliminating the need for hardware tokens or additional infrastructure, aligning with the CTO's cost-minimization goal.

Exam trap

The trap here is that candidates often assume Windows Hello for Business is the only Microsoft passwordless solution for Windows devices, overlooking that the Microsoft Authenticator app can provide passwordless sign-in across all platforms (Windows, iOS, Android) without additional licensing or hardware costs.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business requires either a domain-joined device with on-premises Active Directory or a Microsoft Entra joined device, and it does not support iOS/Android mobile devices, so it cannot cover all platforms as required. Option B is wrong because deploying FIDO2 security keys to 5,000 employees would incur significant hardware procurement and management costs, contradicting the CTO's directive to minimize additional licensing and expenses. Option C is wrong because SMS-based one-time passcodes are not a passwordless method; they still require a password as the primary authentication factor and are considered a form of MFA, not passwordless authentication.

1058
Multi-Selecthard

Which THREE of the following are capabilities of Microsoft Purview eDiscovery? (Choose three.)

Select 3 answers
A.Block sharing of sensitive data via email
B.Export search results to a PST file
C.Place a legal hold on mailboxes and sites
D.Automatically delete emails older than 7 years
E.Search for content across Exchange Online, SharePoint Online, and OneDrive for Business
AnswersB, C, E

Microsoft Purview eDiscovery provides the capability to export identified search results, including emails, documents, and other content, into a portable PST (Personal Storage Table) file format. This export functionality is crucial for transferring collected evidence to legal review platforms, external counsel, or for offline analysis. The PST file preserves the original metadata and folder structure, ensuring the integrity and usability of the collected data.

Why this answer

Option B is correct because Microsoft Purview eDiscovery supports exporting search results, and one of the available export formats is a PST file for mailbox content. Option C is correct because eDiscovery allows administrators to place legal holds (e.g., via Litigation Hold or eDiscovery holds) on Exchange Online mailboxes and SharePoint/OneDrive sites to preserve content. Option E is correct because eDiscovery searches can span Microsoft 365 workloads including Exchange Online, SharePoint Online, OneDrive for Business, and other sources.

Option A is not an eDiscovery capability; blocking sensitive-data sharing via email is handled by Data Loss Prevention (DLP) policies in Microsoft Purview. Option D is not an eDiscovery capability; automatic deletion of emails older than 7 years is achieved through retention policies or retention labels, not eDiscovery.

Exam trap

The trap here is that candidates confuse eDiscovery's search and hold capabilities with retention or DLP features, leading them to select options like automatic deletion or blocking sensitive data, which belong to separate Purview solutions.

1059
MCQeasy

A healthcare organization uses digital signatures on electronic medical records to ensure that the records have not been tampered with during transmission. Which security goal is primarily being addressed by this practice?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerB

Digital signatures let the recipient verify that a record's contents have not been altered in transit, because any modification invalidates the signature check against the signer's key. This directly satisfies the requirement to detect tampering, which is the integrity goal rather than confidentiality or availability.

Why this answer

Digital signatures use asymmetric cryptography (e.g., RSA or ECDSA) to create a hash of the electronic medical record, which is then encrypted with the signer's private key. Any tampering with the record during transmission will cause the hash verification to fail, directly ensuring data integrity. This practice does not primarily address confidentiality (which requires encryption) or availability (which focuses on uptime).

Exam trap

The trap here is that candidates often confuse integrity with non-repudiation, but the question's focus on 'tampered with during transmission' directly points to integrity, not the ability to prove who signed it.

How to eliminate wrong answers

Option A is wrong because confidentiality is about preventing unauthorized access to data, typically achieved through encryption (e.g., AES or TLS), not through digital signatures which do not hide the content. Option C is wrong because availability ensures that systems and data are accessible when needed, often via redundancy or disaster recovery, and digital signatures do not contribute to uptime. Option D is wrong because non-repudiation prevents the signer from denying their action, which is a secondary benefit of digital signatures, but the question specifically asks about tamper detection during transmission, which is the core integrity goal.

1060
Multi-Selectmedium

Which TWO components are part of the 'Zero Trust' security model? (Choose two.)

Select 2 answers
A.Least privilege
B.VPN access
C.Password complexity
D.Verify explicitly
E.Perimeter-based security
AnswersA, D

Least privilege grants users only the access required for their tasks, limiting lateral movement if credentials are compromised. This directly implements Zero Trust's assume-breach principle by constraining each identity's permissions rather than trusting network location.

Why this answer

Option A (Least privilege) is correct because Zero Trust requires granting users and workloads only the minimum access needed for a specific task, typically enforced through just-in-time and just-enough-access policies, which limits lateral movement if an identity is compromised. Option D (Verify explicitly) is correct because Zero Trust mandates authenticating and authorizing every request based on all available signals—identity, device health, location, and data sensitivity—rather than trusting anything implicitly based on network location. Options B (VPN access), C (Password complexity), and E (Perimeter-based security) do not belong: a VPN is a legacy network-centric tunneling control that grants broad internal access once connected, password complexity is a single authentication hygiene rule rather than a Zero Trust principle, and perimeter-based security is the traditional castle-and-moat model that Zero Trust explicitly replaces with 'never trust, always verify.'

Exam trap

SC-900 often tests the misconception that Zero Trust includes traditional perimeter security or VPNs, when in fact it explicitly rejects those models in favor of continuous verification and least privilege.

1061
MCQmedium

A company uses Microsoft Defender for Cloud to secure their multi-cloud environment, which includes Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). They want a unified view of security posture, continuous assessment of resources, and recommendations to improve security across all clouds. Which feature of Defender for Cloud provides this capability?

A.Cloud Security Posture Management (CSPM)
B.Cloud Workload Protection (CWP)
C.Microsoft Secure Score
D.Regulatory Compliance Dashboard
AnswerA

Cloud Security Posture Management continuously assesses Azure, AWS and GCP resources against security benchmarks, surfacing misconfigurations and hardening recommendations in one unified dashboard. This satisfies the multi-cloud visibility and posture-assessment requirement, unlike workload protection plans that focus on runtime threat detection per resource type.

Why this answer

Cloud Security Posture Management (CSPM) is the correct feature because it provides a unified, multi-cloud view of security posture, continuously assesses resources against security benchmarks (e.g., CIS, NIST), and generates actionable recommendations to harden configurations across Azure, AWS, and GCP. This directly matches the scenario's requirement for a single pane of glass for posture management and improvement across all three clouds.

Exam trap

The trap here is that candidates confuse Cloud Security Posture Management (CSPM) with Cloud Workload Protection (CWP), mistakenly thinking that workload protection includes posture assessment, when in fact CSPM is the dedicated feature for multi-cloud posture visibility and recommendations.

How to eliminate wrong answers

Option B (Cloud Workload Protection, CWP) is wrong because CWP focuses on threat detection and advanced defenses for workloads (e.g., just-in-time VM access, file integrity monitoring), not on providing a unified posture view or continuous assessment of resource configurations. Option C (Microsoft Secure Score) is wrong because Secure Score is a metric that quantifies an organization's security posture based on Defender for Cloud recommendations, but it is not the feature that performs the continuous assessment or generates the recommendations itself. Option D (Regulatory Compliance Dashboard) is wrong because this dashboard tracks compliance against specific standards (e.g., SOC 2, PCI DSS) using built-in assessments, but it does not provide the general, unified posture view and continuous assessment of all resources across multi-cloud environments.

1062
MCQhard

Refer to the exhibit. A user accesses a web app from a device that is Microsoft Entra joined but not Intune compliant. Which condition will be satisfied?

A.Domain joined
B.Neither condition
C.Compliant device
D.Both conditions
AnswerB

This option is incorrect because the device *does* satisfy at least one of the specified conditions. Specifically, the device being Microsoft Entra joined fulfills the 'Domain joined' requirement as interpreted by Conditional Access. Consequently, stating that neither condition is met is a false assessment of the device's state against the policy.

Why this answer

The exhibit shows a Conditional Access policy that requires both 'Domain joined' and 'Compliant device' conditions. The device is Microsoft Entra joined. In Conditional Access, the 'Domain joined' condition specifically refers to devices that are *Hybrid Azure AD joined* (joined to an on-premises Active Directory and registered with Microsoft Entra ID).

A device that is *only* Microsoft Entra joined does not satisfy the 'Domain joined' condition. Additionally, the device is stated as 'not Intune compliant', so it fails the 'Compliant device' condition. Therefore, neither the 'Domain joined' nor the 'Compliant device' condition is satisfied, making option B correct.

Exam trap

Candidates often mistakenly confuse 'Microsoft Entra joined' with 'Domain joined' in Conditional Access. The 'Domain joined' condition specifically requires a *Hybrid Azure AD joined* device (joined to on-premises AD and registered with Microsoft Entra ID), not just a Microsoft Entra joined device. This is a common point of confusion regarding device states in Conditional Access.

How to eliminate wrong answers

Option A is wrong because 'Domain joined' alone is not the condition being evaluated; the device is Entra joined, which is a form of domain join, but the question's context implies both conditions are required, so satisfying only one does not make it the correct answer. Option C is wrong because the device is explicitly stated as 'not Intune compliant,' so the 'Compliant device' condition is not satisfied. Option D is wrong because the device does not satisfy both conditions; it is not Intune compliant, so 'Both conditions' cannot be true.

1063
MCQmedium

A company is migrating its on-premises workloads to Azure. The CISO wants to understand the division of security responsibilities between Microsoft and the customer across cloud service models. For which cloud service model does the customer have the most security responsibility?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.On-premises
AnswerC

Infrastructure as a Service (IaaS) is the correct choice for migrating existing on-premises workloads to Azure because it provides the most control over the underlying operating systems, applications, and data, closely mirroring an on-premises environment. In IaaS, the customer is responsible for securing the operating system, applications, network configuration, and data, while Azure manages the physical infrastructure, virtualization, and networking fabric. This model facilitates a "lift-and-shift" approach, allowing the CISO to maintain significant security responsibility and control over their familiar stack within the cloud.

Why this answer

In the Infrastructure as a Service (IaaS) model, the customer is responsible for securing the operating system, applications, data, and network configurations, while Microsoft only secures the physical datacenter, host servers, and hypervisor. This gives the customer the most security responsibility compared to PaaS or SaaS, where Microsoft manages more of the stack.

Exam trap

The trap here is that candidates often confuse 'most responsibility' with 'most control' and incorrectly pick on-premises (Option D), forgetting that the question explicitly asks about cloud service models, where IaaS gives the customer the greatest security responsibility among the cloud options.

Why the other options are wrong

A

In SaaS, the customer has the least security responsibility because Microsoft manages the entire stack, including applications, data, and infrastructure. The question asks for the model with the most customer responsibility, which is IaaS.

B

In PaaS, the customer manages applications and data, while Microsoft handles the runtime, middleware, OS, and infrastructure. This gives the customer less security responsibility than IaaS, where they manage everything from the OS upward.

When would these options actually be correct?

A

A question asks: 'For which cloud service model does the customer have the least security responsibility?' or 'Which model shifts the most security responsibility to the cloud provider?'

B

A question asks: 'For which cloud service model does the customer have the most control over the application runtime environment without managing the underlying OS?' In that context, PaaS would be correct because it provides a platform for deploying apps while abstracting OS and infrastructure management.

Why candidates pick the wrong answer

A

Candidates may mistakenly think SaaS requires significant customer security effort due to data protection and access control, overlooking that the provider secures the underlying platform and application.

B

Candidates may confuse 'most responsibility' with 'most control over applications,' thinking PaaS gives them more security duties than IaaS because they still manage the app layer, but they overlook that IaaS requires managing the OS, network, and storage as well.

1064
MCQhard

A security analyst runs the above KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.Correlate MFA failures with other security events
B.Identify all users who had an MFA failure anomaly in the last 7 days
C.Identify users who have been blocked due to MFA failures
D.Identify users with more than 5 MFA failure anomalies in the last 7 days
AnswerD

The query correctly filters `SecurityAlert` records generated within the last 7 days for MFA failure anomalies. It then groups these anomalies by user and calculates the total count for each user. The subsequent `where AlertCount > 5` clause precisely isolates and presents only those users whose aggregated count of MFA failure anomalies exceeds five, directly matching the objective described in this option.

Why this answer

The KQL query uses `summarize` with `count()` on MFA failure anomalies, then filters with `where count_ > 5` and `where TimeGenerated > ago(7d)`. This explicitly returns only users whose anomaly count exceeds 5 in the last 7 days, making option D correct. The query does not correlate with other events, list all users with any anomaly, or check block status.

Exam trap

The trap here is that candidates see 'MFA failure anomalies' and 'last 7 days' and assume the query returns all users with any anomaly (option B), missing the critical `where count_ > 5` threshold filter that narrows the result to only high-frequency failures.

How to eliminate wrong answers

Option A is wrong because the query only filters on a single table (presumably `SigninLogs` with MFA failure anomalies) and does not use `join` or `union` to correlate with other security event tables. Option B is wrong because the query includes a `where count_ > 5` filter, so it does not identify all users with any MFA failure anomaly—only those exceeding the threshold. Option C is wrong because the query does not reference any column indicating a blocked status (e.g., `Status` or `Blocked`), nor does it use `where ResultType` values like `500121` (MFA blocked); it only counts anomaly occurrences.

1065
MCQmedium

A security operations center (SOC) team needs a centralized platform to collect logs from firewalls, servers, and cloud applications. They want to analyze these logs to detect threats, create custom alerts, and automate response actions using playbooks. The solution should also provide threat intelligence feeds and allow for advanced hunting with Kusto Query Language (KQL). Which Microsoft security solution should the team implement?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Endpoint
D.Microsoft Purview Compliance Manager
AnswerB

Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests logs from firewalls, servers and cloud applications, provides built-in threat intelligence, KQL-based advanced hunting, custom analytics alerts and Logic Apps playbooks for automated response, satisfying every requirement in the scenario.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It provides a centralized platform for collecting logs from diverse sources (firewalls, servers, cloud apps), enables custom alert creation, automates response via playbooks (Azure Logic Apps), integrates threat intelligence feeds, and supports advanced hunting using Kusto Query Language (KQL).

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) with a full SIEM/SOAR solution, overlooking that Sentinel is the dedicated platform for centralized log collection, custom alerts, playbook automation, and KQL-based hunting.

Why the other options are wrong

A

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP), not a centralized SIEM/SOAR solution. It does not provide native log collection from diverse sources, custom alert creation, playbook automation, or KQL-based advanced hunting.

C

Microsoft Defender for Endpoint focuses on endpoint protection and detection, not centralized log collection from firewalls, servers, and cloud apps, nor does it provide playbook automation or KQL-based advanced hunting across multiple data sources.

D

Microsoft Purview Compliance Manager focuses on compliance posture management and assessment, not on centralized log collection, threat detection, custom alerts, or automated response playbooks.

When would these options actually be correct?

A

A team needs to assess and improve the security posture of their Azure, hybrid, and multi-cloud workloads, with recommendations for hardening and threat protection. They require a unified view of security configurations and compliance across cloud environments.

C

A question asking for a solution to protect endpoints (e.g., detect malware on laptops and servers) with EDR capabilities, and optionally integrate with Microsoft 365 Defender, would make Defender for Endpoint correct.

D

A question asking for a solution to assess compliance against regulatory standards (e.g., ISO 27001, NIST) and manage compliance scores across cloud and on-premises environments would make Purview Compliance Manager the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse Defender for Cloud's security monitoring and alerting capabilities with a full SIEM, or assume it can centralize logs from various sources because it integrates with Azure services.

C

Candidates may confuse Microsoft Sentinel's SIEM capabilities with Defender for Endpoint's security features, or think 'Defender' products all cover centralized log analysis and automation.

D

Candidates may confuse compliance and security monitoring, thinking a compliance tool can also handle threat detection and response, or they may misremember Purview's capabilities as broader than they are.

1066
MCQmedium

Your organization uses Microsoft Copilot for Security. You want to use natural language to generate a KQL query for threat hunting. What should you do?

A.Manually write the KQL query in the advanced hunting page.
B.Use the Copilot prompt bar in the Microsoft Defender portal.
C.Install the Copilot add-in for Sentinel.
D.Subscribe to Microsoft 365 Copilot.
AnswerB

Utilizing the Copilot prompt bar within the Microsoft Defender portal is the correct and intended method for leveraging Microsoft Copilot for Security to generate KQL queries. This integrated interface allows security analysts to input natural language descriptions of their threat hunting or investigation needs. Copilot then processes these prompts, translating them into accurate KQL queries that can be immediately executed in Advanced Hunting, significantly streamlining security operations and enhancing analyst productivity.

Why this answer

Microsoft Copilot for Security is integrated directly into the Microsoft Defender portal, allowing security analysts to use natural language prompts to generate KQL queries for threat hunting. The Copilot prompt bar interprets the natural language input and converts it into the appropriate KQL syntax, eliminating the need for manual query writing.

Exam trap

The trap here is that candidates may confuse Microsoft Copilot for Security with Microsoft 365 Copilot, assuming any 'Copilot' subscription will generate KQL queries, when in fact only the security-specific Copilot integrated into the Defender portal provides this capability.

How to eliminate wrong answers

Option A is wrong because manually writing KQL queries in the advanced hunting page does not leverage Copilot's natural language capabilities; it requires the user to already know KQL syntax. Option C is wrong because there is no 'Copilot add-in for Sentinel' — Microsoft Copilot for Security is a standalone service or integrated into the Defender portal, not an add-in for Azure Sentinel. Option D is wrong because subscribing to Microsoft 365 Copilot provides AI assistance for productivity apps like Word and Excel, not for security-specific tasks like generating KQL queries for threat hunting.

1067
MCQmedium

You work for a law firm that uses Microsoft 365 E5. The firm handles highly confidential client information and must comply with attorney-client privilege. You need to implement a compliance solution that: - Prevents unauthorized sharing of privileged documents via email. - Enables lawyers to easily classify documents as 'Privileged' and automatically encrypt them. - Allows the compliance team to monitor for accidental exposure of privileged information in Teams chats. - Ensures that privileged documents are retained for 7 years after case closure, then automatically deleted. - Provides the ability to search for privileged documents in case of a legal hold. What should you configure?

A.Sensitivity labels with encryption, DLP, Communication Compliance, Data Lifecycle Management, and eDiscovery
B.DLP, Communication Compliance, Data Lifecycle Management, and Audit (Standard)
C.Insider Risk Management, DLP, Data Lifecycle Management, and eDiscovery
D.Sensitivity labels, Information Barriers, Data Lifecycle Management, and eDiscovery
AnswerA

Sensitivity labels apply encryption at classification, satisfying the 'Privileged' tagging requirement. DLP blocks unauthorised email sharing, Communication Compliance monitors Teams chats, Data Lifecycle Management enforces the seven-year retention then deletion, and eDiscovery supports legal hold searches. Together these Microsoft Purview solutions cover every stated constraint.

Why this answer

Sensitivity labels with encryption classify and encrypt privileged documents, DLP prevents unauthorized email sharing, Communication Compliance monitors Teams chats for accidental exposure, Data Lifecycle Management enforces 7-year retention then deletion, and eDiscovery supports legal hold searches. Together these Microsoft Purview solutions meet all five requirements. This combination is the only one that covers classification, encryption, monitoring, retention, and search.

Exam trap

SC-900 often tests the difference between Information Barriers (which restrict or block communication between groups) and Communication Compliance (which monitors communications for policy violations). Option D includes Information Barriers but omits Communication Compliance and DLP, and its sensitivity labels are not specified as encrypting, so it cannot meet the requirements for Teams chat monitoring, preventing unauthorized email sharing, or automatic encryption.

How to eliminate wrong answers

Option B is wrong because it lacks sensitivity labels with encryption, so documents cannot be easily classified and automatically encrypted by lawyers. Option C is wrong because Insider Risk Management does not provide document classification/encryption or the required eDiscovery search capability for legal hold. Option D is wrong because Information Barriers restrict communication between groups but do not monitor Teams chats for accidental exposure or provide the DLP email-sharing prevention required.

1068
MCQmedium

A company uses Microsoft Entra ID. The IT department wants to automatically assign a Microsoft 365 E5 license to all users in the Sales department based on their department attribute. Which Microsoft Entra ID feature should they use?

A.Dynamic Groups
B.Administrative Units
C.Identity Protection
D.Access Reviews
AnswerA

Microsoft Entra ID dynamic groups automatically manage membership based on defined attribute-based rules, such as a user's department or job title. When a user's attributes change, they are automatically added to or removed from the group, ensuring accurate membership. This capability is crucial for automating license assignment through group-based licensing, as licenses are then automatically provisioned or de-provisioned as users join or leave these dynamic groups.

Why this answer

Dynamic Groups in Microsoft Entra ID allow automatic user membership based on user attributes, such as the department attribute. By creating a dynamic group rule like `user.department -eq "Sales"`, the system automatically assigns the group membership and can then apply a Microsoft 365 E5 license via group-based licensing.

Exam trap

The trap here is that candidates may confuse Administrative Units with Dynamic Groups, thinking that delegating admin control over a department also handles license assignment, but Administrative Units only manage administrative boundaries, not automated provisioning.

Why the other options are wrong

B

Administrative Units are used to delegate administrative permissions over subsets of users, groups, or devices, not to automatically assign licenses based on attributes like department.

C

Identity Protection is a feature for detecting and responding to identity-based risks, not for automating license assignments based on user attributes.

D

Access Reviews are used to review and certify user access rights periodically, not to automatically assign licenses based on attributes.

When would these options actually be correct?

B

A question asks: 'You need to delegate management of users in the Sales department to a junior admin, without giving them access to other departments. Which feature should you use?'

C

An organization wants to automatically detect and block sign-ins from anonymous IP addresses or compromised credentials. Identity Protection would be the correct feature to configure risk-based conditional access policies.

D

A company needs to periodically verify that only Sales department users have access to a sensitive application. Access Reviews would be the correct feature to create a review campaign for that group.

Why candidates pick the wrong answer

B

Candidates may confuse Administrative Units with groups, thinking they can be used for license assignment or attribute-based membership, but they are solely for administrative scoping.

C

Candidates may confuse Identity Protection with identity governance features, assuming it can manage user attributes or group memberships, due to the broad term 'identity' in its name.

D

Candidates may confuse the concept of managing access (Access Reviews) with assigning licenses, as both involve user permissions and Entra ID features.

1069
MCQmedium

A company uses Microsoft Defender for Cloud to secure their Azure environment. The security team needs to check whether their resources comply with the CIS (Center for Internet Security) benchmark. How can they view their compliance status against CIS in Defender for Cloud?

A.Use the secure score recommendations and look for CIS-related controls
B.Use the Regulatory Compliance dashboard and add the CIS standard as a compliance initiative
C.Use Azure Policy initiative assignments directly from the Policy service
D.Use the vulnerability assessment solution for machines to check CIS settings
AnswerB

The Regulatory Compliance dashboard in Microsoft Defender for Cloud is specifically designed to assess and report on your organization's adherence to various industry standards and regulatory benchmarks. By adding the CIS standard as a compliance initiative, Defender for Cloud automatically maps relevant security recommendations and assessments to the specific controls within that standard, providing a consolidated view of your compliance posture. This direct integration enables comprehensive tracking and reporting against the chosen benchmark.

Why this answer

The Regulatory Compliance dashboard in Microsoft Defender for Cloud allows you to add built-in compliance standards like CIS as an initiative. Once added, the dashboard continuously assesses your Azure resources against the CIS benchmark controls and displays pass/fail status. This is the correct method because Defender for Cloud integrates with Azure Policy to evaluate compliance against regulatory standards.

Exam trap

The trap here is that candidates confuse secure score recommendations with regulatory compliance assessments, assuming that secure score covers all compliance standards, when in fact secure score is a separate metric based on security controls, not specific regulatory frameworks like CIS.

How to eliminate wrong answers

Option A is wrong because secure score recommendations are based on security best practices and built-in controls, not specific regulatory standards like CIS; they do not directly map to CIS benchmarks. Option C is wrong because Azure Policy initiative assignments from the Policy service can define compliance rules, but viewing the compliance status against CIS specifically requires the Regulatory Compliance dashboard in Defender for Cloud, which provides a pre-built view with continuous assessment and reporting. Option D is wrong because the vulnerability assessment solution for machines (e.g., Qualys or Microsoft Defender Vulnerability Management) checks for OS-level vulnerabilities and missing patches, not compliance with CIS benchmark settings across all resource types.

1070
MCQmedium

Your organization is deploying Microsoft Defender XDR to detect and respond to advanced threats. You need to ensure that security alerts from Microsoft Defender for Endpoint are automatically correlated with alerts from Microsoft Defender for Office 365. What should you configure?

A.Ensure that all Microsoft Defender services are onboarded to the same tenant and that the incidents feature is enabled
B.Configure a custom detection rule in Microsoft 365 Defender
C.Create an advanced hunting query to join alerts from different data sources
D.Enable Microsoft Sentinel and configure incident creation rules
AnswerA

Microsoft Defender XDR's core strength lies in its ability to automatically correlate alerts from various Defender services into unified incidents. This powerful cross-domain correlation engine requires all constituent Defender services (e.g., Defender for Endpoint, Office 365, Identity) to be onboarded within the *same* Azure Active Directory tenant. The incidents feature, which drives this correlation, is enabled by default, ensuring a holistic view of attacks and significantly reducing alert fatigue for security operations teams.

Why this answer

Microsoft Defender XDR automatically correlates alerts from different Microsoft Defender services (e.g., Defender for Endpoint and Defender for Office 365) when they are onboarded to the same tenant and the incidents feature is enabled. This built-in correlation uses the Microsoft 365 Defender backend to fuse related alerts into a single incident, providing a unified view of the attack chain without additional configuration.

Exam trap

The trap here is that candidates may think additional tools like Sentinel or custom rules are needed for correlation, but Microsoft Defender XDR provides automatic cross-service correlation by default when all services are in the same tenant and incidents are enabled.

How to eliminate wrong answers

Option B is wrong because custom detection rules in Microsoft 365 Defender are used to create custom alerts based on advanced hunting queries, not to automatically correlate existing alerts from different services. Option C is wrong because advanced hunting queries are for manually searching and analyzing raw data across tables, not for enabling automatic correlation of alerts into incidents. Option D is wrong because Microsoft Sentinel is a separate SIEM solution that requires additional licensing and configuration; it is not required for native correlation within Microsoft Defender XDR, which handles this automatically when services are in the same tenant.

1071
Multi-Selectmedium

A company must implement data classification labels in Microsoft Purview to protect sensitive information. Which TWO actions are required to create and publish a sensitivity label?

Select 2 answers
A.Deploy the label using Microsoft Intune configuration profiles.
B.Define the label scope to include SharePoint and OneDrive.
C.Create the label in the Microsoft Purview compliance portal.
D.Publish the label using a label policy.
E.Configure auto-labeling rules in Microsoft 365 Defender.
AnswersC, D

Creating the sensitivity label in the Microsoft Purview compliance portal is the foundational and indispensable first step for implementing data classification. This action involves defining the label's name, description, visual markings, and associated protection settings like encryption or access restrictions. Without this initial creation, no label exists to be published or applied, making it the absolute prerequisite for any data classification initiative using Microsoft Purview Information Protection.

Why this answer

Option C is correct because every sensitivity label must first be created in the Microsoft Purview compliance portal (Solutions > Information protection > Labels), where you define its name, description, and encryption/content-marking settings. Option D is correct because a label only becomes available to users and services after it is published through a label policy, which defines the users/groups and the locations (workloads) where the label is applied. Options A, B, and E are not required: labels are not deployed via Intune configuration profiles, the label scope (SharePoint/OneDrive, Exchange, etc.) is selected inside the label policy rather than being a separate mandatory action, and auto-labeling rules are configured in Microsoft Purview (not Microsoft 365 Defender) and are optional for creating and publishing a label.

Exam trap

The trap here is that candidates confuse the optional configuration steps (like defining scope or auto-labeling) with the mandatory actions required to create and publish a sensitivity label, leading them to select B or E instead of the correct pair C and D.

1072
MCQeasy

A company wants to allow employees to use their corporate Microsoft Entra ID credentials to sign in to third-party SaaS applications like Salesforce and ServiceNow. Which feature provides this capability?

A.Microsoft Entra federation with SaaS applications
B.Microsoft Entra B2B collaboration
C.Microsoft Entra Identity Protection
D.Microsoft Entra Privileged Identity Management
AnswerA

Microsoft Entra federation with SaaS applications is the correct solution because it enables employees to use their existing corporate Microsoft Entra ID credentials for single sign-on (SSO) to third-party Software as a Service (SaaS) applications. This process involves configuring Microsoft Entra ID as the identity provider, allowing it to authenticate users and securely pass identity assertions (e.g., via SAML or OIDC) to the SaaS application, eliminating the need for separate usernames and passwords. This enhances user experience, improves security posture, and centralizes identity management.

Why this answer

Microsoft Entra federation with SaaS applications (Option A) enables single sign-on (SSO) by establishing a trust relationship between Microsoft Entra ID and third-party SaaS apps like Salesforce and ServiceNow. This allows users to authenticate using their corporate Entra ID credentials via federation protocols such as SAML 2.0 or OpenID Connect, eliminating the need for separate credentials.

Exam trap

The trap here is that candidates often confuse B2B collaboration (external user access) with federation (corporate user SSO to external apps), leading them to select Option B instead of A.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2B collaboration is designed for inviting external users (e.g., partners or vendors) to access your organization's resources, not for enabling corporate users to sign in to third-party SaaS apps. Option C is wrong because Microsoft Entra Identity Protection is a security tool that detects and responds to identity-based risks (e.g., leaked credentials or anomalous sign-ins), not a feature for federated authentication. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles within Azure AD and Azure resources, not for federating with external SaaS applications.

1073
MCQeasy

Your organization uses Microsoft Purview eDiscovery to manage legal holds. A legal hold has been placed on a user’s mailbox, but the user has left the company and their mailbox has been converted to a shared mailbox. You need to ensure that the legal hold remains effective. What should you do?

A.Convert the shared mailbox back to a user mailbox to keep the hold.
B.Create a new legal hold for the shared mailbox.
C.Verify that the legal hold is still listed in the eDiscovery case for the mailbox.
D.Remove the legal hold and reapply it to the shared mailbox.
AnswerC

Converting a mailbox to shared does not remove an eDiscovery hold, but the hold must remain associated with the case. Confirming it is still listed verifies the mailbox is still within scope, satisfying the requirement that the legal hold stays effective.

Why this answer

When a mailbox is converted to a shared mailbox, the legal hold applied via eDiscovery remains in effect and does not need to be recreated. It is important to verify that the hold is still listed in the eDiscovery case. Option A is incorrect because converting back is unnecessary and may lose shared mailbox features.

Option B is incorrect because the hold is still active; creating a new hold is redundant. Option D is incorrect because removing and reapplying the hold is not required.

1074
MCQeasy

You run the PowerShell command shown in the exhibit. What is the purpose of this command?

A.Applies a sensitivity label to a document
B.Encrypts a document using Azure Information Protection
C.Removes a sensitivity label from a document
D.Exports audit logs for labeled documents
AnswerA

The cmdlet applies a sensitivity label to the specified document, tagging it with the organisation's classification so encryption and protection policies follow the file. It does not create, remove or list labels, only assigns one.

Why this answer

The PowerShell command shown in the exhibit is used to apply a sensitivity label to a document. Sensitivity labels in Microsoft 365 are applied using cmdlets like Set-AIPFileLabel or Set-Label, which tag the file with the specified label for classification and protection. This action does not encrypt the document by itself; encryption is a potential outcome of the label's protection settings, but the command's primary purpose is labeling.

Exam trap

The trap is assuming the command directly encrypts the document, when in fact it applies a label that may include encryption as a side effect.

How to eliminate wrong answers

Option B is wrong because while sensitivity labels can enforce encryption, the command itself applies the label, not directly encrypts the document; encryption is a configured action of the label. Option C is wrong because removing a label would use a different cmdlet or parameter, such as Remove-Label or Set-AIPFileLabel with -RemoveLabel. Option D is wrong because exporting audit logs is unrelated to this command and would involve the Search-UnifiedAuditLog or Export-AuditLog cmdlets.

1075
MCQmedium

Your organization uses Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from their CEO asking for a wire transfer. The email passed through the spam filter. What additional protection should be enabled to detect such attacks?

A.Safe Attachments policy
B.Anti-spam policy
C.Safe Links policy
D.Impersonation protection in anti-phishing policy
AnswerD

Impersonation protection within an anti-phishing policy is specifically engineered to identify and mitigate attacks where attackers spoof a known user's display name or email address, or a trusted domain. It analyzes various email attributes, including sender display name, sender address, and domain similarity, against configured protected users and domains to detect and act upon these highly targeted phishing attempts. This direct focus on identity spoofing makes it the correct control for preventing impersonation.

Why this answer

The attack described is a business email compromise (BEC) or CEO fraud, which relies on impersonation rather than malicious links or attachments. Microsoft Defender for Office 365's anti-phishing policy includes impersonation protection that specifically detects and mitigates attempts where a sender spoofs a high-profile user (like the CEO) or domain. Enabling impersonation protection in the anti-phishing policy is the correct additional safeguard because the email passed the spam filter, indicating it was not a bulk or malware-based threat.

Exam trap

The trap here is that candidates confuse the general anti-phishing policy (which includes spoof intelligence) with the specific impersonation protection setting, or they mistakenly think Safe Links or Safe Attachments can detect social engineering attacks that contain no malicious payload.

How to eliminate wrong answers

Option A is wrong because Safe Attachments policy protects against malicious attachments by detonating them in a sandbox, but the reported email does not contain an attachment—it is a social engineering request for a wire transfer. Option B is wrong because Anti-spam policy handles bulk email and spam classification, and the email already passed the spam filter, so adjusting anti-spam settings would not address the impersonation tactic. Option C is wrong because Safe Links policy provides time-of-click protection against malicious URLs, but the email contains no link—it is a direct request for action via reply.

1076
Multi-Selectmedium

Which TWO are principles of the Zero Trust security model?

Select 2 answers
A.Verify explicitly
B.Trust everything inside the network
C.Assume breach
D.Use a VPN for remote access
E.Layer defenses
AnswersA, C

Verify explicitly requires authentication and authorisation decisions using all available signals, including identity, device health and location. It satisfies the Zero Trust principle that every access request is fully authenticated before resource access is granted.

Why this answer

Option A, "Verify explicitly," is a core Zero Trust principle: every access request must be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust based on network location. Option C, "Assume breach," is the other foundational Zero Trust principle: organizations must operate as if an attacker is already present, which drives micro-segmentation, least-privilege access, end-to-end encryption, and continuous monitoring to minimize blast radius and detect threats. Option B, "Trust everything inside the network," is the opposite of Zero Trust, which explicitly rejects the castle-and-moat assumption that internal traffic is inherently trustworthy.

Option D, "Use a VPN for remote access," is a connectivity mechanism, not a Zero Trust principle; Zero Trust instead favors per-request, identity-based access controls over implicit network-level trust. Option E, "Layer defenses," describes defense in depth, a complementary but distinct security strategy, not one of the three canonical Zero Trust principles (verify explicitly, use least-privilege access, assume breach).

Exam trap

SC-900 often tests whether candidates can distinguish the three named Zero Trust principles from related but separate concepts like defense in depth, VPN usage, or network segmentation — candidates pick 'layer defenses' because it sounds security-sound but isn't one of the three principles.

1077
MCQmedium

Your organization uses Microsoft Purview to manage data lifecycle. You need to ensure that after a project ends, all related files are automatically deleted after 3 years. What should you configure?

A.Create a retention label with a retention period of 3 years and a disposition action of deletion
B.Configure a DLP policy to delete files after 3 years
C.Create an eDiscovery case and manually delete the files
D.Apply a sensitivity label marked 'Project' and configure auto-deletion
AnswerA

Retention labels in Microsoft Purview are specifically designed to manage the lifecycle of data, including its eventual deletion. By creating a retention label with a 3-year retention period and a disposition action set to deletion, the organization ensures that content is preserved for the required duration and then automatically removed from its location. This mechanism is central to compliant data lifecycle management, enforcing policy across various Microsoft 365 services to meet regulatory and internal governance requirements.

Why this answer

A retention label in Microsoft Purview allows you to define a retention period and then automatically trigger a disposition action—such as permanent deletion—when that period expires. By creating a label with a 3-year retention period and setting the disposition action to 'Delete', all files tagged with that label will be automatically removed after three years, meeting the requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which handle classification and protection) with retention labels (which handle lifecycle and disposition), leading them to choose Option D even though sensitivity labels lack native auto-deletion capabilities.

How to eliminate wrong answers

Option B is wrong because a Data Loss Prevention (DLP) policy is designed to detect and prevent the unauthorized sharing or leakage of sensitive data, not to enforce time-based retention or deletion of files. Option C is wrong because eDiscovery cases are used for legal holds and manual review/discovery of content, not for automated lifecycle management or scheduled deletion. Option D is wrong because sensitivity labels in Microsoft Purview primarily classify and protect data based on sensitivity (e.g., encryption, markings), and while they can support auto-labeling, they do not natively include a configurable auto-deletion action based on a retention period.

1078
MCQhard

A multinational corporation must comply with several regulatory frameworks, including GDPR, SOX, and HIPAA. The compliance officer wants to continuously assess the organization's compliance posture against these regulations, receive prioritized improvement actions, and track the implementation progress of those actions. Which Microsoft Purview solution should the compliance officer use?

A.Information Protection
B.Compliance Manager
C.Data Lifecycle Management
D.Insider Risk Management
AnswerB

Microsoft Purview Compliance Manager is specifically designed to help organizations manage their compliance posture against various regulatory frameworks. It provides pre-built assessment templates for numerous regulations (e.g., GDPR, HIPAA, ISO 27001), a quantifiable compliance score, and actionable improvement recommendations. This centralized dashboard allows for continuous monitoring, tracking progress on improvement actions, and generating reports to demonstrate adherence to complex global and industry-specific compliance requirements.

Why this answer

Compliance Manager is the correct solution because it provides a centralized dashboard for continuously assessing compliance posture against multiple regulatory frameworks (GDPR, SOX, HIPAA), generates prioritized improvement actions based on built-in assessments, and tracks implementation progress of those actions through a task-based workflow. It uses automated control mapping and continuous monitoring to help organizations meet evolving compliance requirements.

Exam trap

The trap here is that candidates confuse Compliance Manager with Information Protection, thinking that protecting data automatically ensures compliance, but Compliance Manager is the only solution that provides continuous assessment and actionable improvement tracking across multiple regulations.

Why the other options are wrong

A

Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not on assessing compliance posture against multiple regulations or tracking improvement actions.

C

Data Lifecycle Management focuses on governing data retention and deletion policies, not on assessing compliance posture against regulations or tracking improvement actions.

D

Insider Risk Management is designed to detect, investigate, and act on risky user activities (e.g., data theft, policy violations), not to assess compliance posture against regulations or track improvement actions.

When would these options actually be correct?

A

A question asking which Microsoft Purview solution to use for automatically classifying and protecting sensitive data (e.g., credit card numbers, health records) with sensitivity labels and encryption would make Information Protection the correct answer.

C

A question asking which solution manages retention and deletion of data to meet regulatory requirements, such as automatically archiving or deleting emails after a specified period for GDPR compliance.

D

A question asks: 'Which Microsoft Purview solution helps detect and investigate potential data security incidents caused by malicious or inadvertent insider activities, such as unauthorized data exfiltration?'

Why candidates pick the wrong answer

A

Candidates may confuse 'compliance' with 'protecting information' because both involve regulatory requirements, but Information Protection is about data security controls, not continuous compliance assessment and action tracking.

C

Candidates may mistakenly think that managing data lifecycle is sufficient for compliance, overlooking the need for continuous assessment and action tracking provided by Compliance Manager.

D

Candidates may confuse 'compliance' broadly with 'risk management' and assume Insider Risk Management covers regulatory compliance assessments, not realizing it focuses on user behavior risks rather than framework-based compliance scoring.

1079
Multi-Selecthard

Which THREE of the following are included in Microsoft Defender XDR (Extended Detection and Response)? (Choose three.)

Select 3 answers
A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Azure Information Protection
D.Microsoft Defender for Office 365
E.Microsoft Defender for Cloud
AnswersA, B, D

This solution provides comprehensive protection for hybrid identity environments by monitoring Active Directory and Azure Active Directory signals. It detects advanced threats, compromised identities, and malicious insider actions using behavioral analytics and machine learning. As a core component of Microsoft Defender XDR, it correlates identity-related incidents with signals from endpoints, email, and cloud apps to provide a unified view of an attack.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that bundles several Defender workloads under a single portal and correlation engine. Option A, Microsoft Defender for Identity, is correct because it is one of the core Defender XDR components, monitoring on-premises Active Directory signals (via sensors on domain controllers) for identity-based attacks. Option B, Microsoft Defender for Endpoint, is correct because it is the endpoint detection and response workload included in Defender XDR, providing device telemetry, threat detection, and automated investigation/response.

Option D, Microsoft Defender for Office 365, is correct because it is the email and collaboration protection workload included in Defender XDR, covering Exchange Online, Teams, and SharePoint/OneDrive against phishing and malware. Option C, Microsoft Azure Information Protection, is not part of Defender XDR; it is a separate information-protection/classification service (now largely folded into Microsoft Purview Information Protection). Option E, Microsoft Defender for Cloud, is not part of Defender XDR; it is a cloud security posture management and workload protection (CSPM/CWPP) service that lives in the Azure portal and is distinct from the Defender XDR suite.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) as part of Defender XDR, but it is not included; instead, the XDR suite focuses on endpoint, identity, email, and cloud app security, while Defender for Cloud remains a separate security management service.

1080
Multi-Selectmedium

Which TWO are capabilities of Microsoft Defender for Cloud Apps? (Choose two.)

Select 2 answers
A.Endpoint detection and response (EDR)
B.Identity protection for user accounts
C.Data classification of on-premises files
D.Session control to monitor user activity in cloud apps
E.Cloud Discovery to identify shadow IT
AnswersD, E

Conditional Access App Control proxies sessions through Defender for Cloud Apps, letting administrators monitor and block user activity within cloud apps in real time. This satisfies the requirement to control actions inside sanctioned apps, which API-based connectors alone cannot enforce.

Why this answer

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides Cloud Discovery to identify shadow IT by analyzing traffic logs from firewalls and proxies, making option E correct. It also delivers Conditional Access App Control, which uses reverse-proxy session control to monitor and restrict user activity in cloud apps in real time, making option D correct. Option A is wrong because endpoint detection and response is provided by Microsoft Defender for Endpoint, not Defender for Cloud Apps.

Option B is wrong because identity protection for user accounts is handled by Microsoft Entra ID Protection. Option C is wrong because data classification of on-premises files is performed by Microsoft Purview Information Protection, not by this CASB service.

Exam trap

The trap here is that candidates confuse the broad 'security solutions' umbrella and attribute endpoint or identity features to Defender for Cloud Apps, when in fact each Microsoft security product (Defender for Endpoint, Entra ID Protection, Purview) has a distinct scope and integration point.

1081
MCQeasy

A company wants to allow users to sign in to Microsoft 365 services using their existing on-premises Active Directory credentials without maintaining a separate password in the cloud. The company requires that authentication be validated directly against on-premises domain controllers. Which Microsoft Entra authentication method should they implement?

A.Certificate-based authentication
B.Password hash synchronization
C.Pass-through authentication
D.Federation with Active Directory Federation Services (AD FS)
AnswerC

Pass-through authentication (PTA) uses a lightweight agent on-premises to validate user credentials directly against Active Directory. When users sign in, their passwords are encrypted and sent to the agent, which verifies them with domain controllers. This meets the requirement of direct validation without storing passwords in the cloud. It provides a seamless experience and is ideal when organizations want to enforce on-premises password policies in real time.

Why this answer

Pass-through authentication validates user credentials directly against on-premises Active Directory, ensuring that password policies and account status are enforced in real time. It requires a lightweight agent and does not store password hashes in the cloud. This method is ideal when organizations want to maintain full control over authentication without complex federation infrastructure.

Exam trap

The trap here is confusing pass-through authentication with password hash synchronization, but only pass-through authentication validates credentials on-premises in real time.

1082
MCQmedium

Your company is implementing a hybrid identity solution with Microsoft Entra ID. You need to ensure that password changes on-premises are synchronized to the cloud within minutes. Which feature should you enable?

A.Password Hash Synchronization
B.Pass-through Authentication
C.Seamless Single Sign-On
D.Password Writeback
AnswerA

Password Hash Synchronization continuously replicates on-premises password hashes to Microsoft Entra ID, so any password change made in Active Directory is reflected in the cloud within minutes. This directly satisfies the stem's requirement for near-immediate synchronisation of on-premises password changes, without requiring users to authenticate against on-premises infrastructure.

Why this answer

Password Hash Synchronization (A) synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID in near real-time, ensuring that password changes made on-premises are reflected in the cloud within minutes. Password Writeback (D) performs the reverse: it writes password changes from the cloud back to on-premises, not from on-premises to the cloud. Pass-through Authentication (B) validates passwords against on-premises AD directly without syncing hashes, and Seamless SSO (C) provides automatic sign-in but does not handle password synchronization.

Exam trap

The trap is that candidates often think Password Writeback is for on-premises-to-cloud sync when it actually does the opposite (cloud-to-on-premises). Password Hash Synchronization is the correct feature for synchronizing on-premises password changes to the cloud.

How to eliminate wrong answers

Option A is wrong because Password Hash Synchronization (PHS) syncs password hashes from on-premises to the cloud but does not write back changes made on-premises; it is a one-way sync that occurs every few minutes by default, not triggered by individual password changes. Option B is wrong because Pass-through Authentication (PTA) validates passwords against on-premises Active Directory without storing password hashes in the cloud, so it does not synchronize password changes to the cloud. Option C is wrong because Seamless Single Sign-On (SSO) provides automatic sign-in for domain-joined devices but does not handle password synchronization or writeback.

1083
MCQeasy

A company uses Microsoft 365. The compliance department requires that all financial documents be retained for 10 years and then automatically deleted, while marketing documents must be retained for 3 years and then deleted. Additionally, they want to apply a default retention policy to all SharePoint Online sites. Which Microsoft Purview solution should the company use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview eDiscovery
C.Microsoft Purview Compliance Manager
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerA

Microsoft Purview Data Lifecycle Management (DLM), formerly known as Microsoft 365 Records Management, is the primary service within Microsoft Purview for managing the entire lifecycle of an organization's data. It enables the creation and application of retention labels and policies to define how long content should be kept, whether for regulatory compliance, legal hold, or business requirements, and when it should be permanently deleted. This ensures that data is retained for the necessary period and then defensibly disposed of according to established policies, directly addressing compliance department requirements for data retention and deletion.

Why this answer

Microsoft Purview Data Lifecycle Management (formerly Microsoft 365 Retention) is the correct solution because it allows organizations to define retention and deletion policies based on content type and location. In this scenario, the company needs to apply different retention periods (10 years for financial documents, 3 years for marketing documents) and a default retention policy for all SharePoint Online sites, which is exactly what Data Lifecycle Management's retention policies and labels provide.

Exam trap

The trap here is that candidates often confuse eDiscovery (which holds content for legal reasons) with Data Lifecycle Management (which automates retention and deletion based on time), leading them to select eDiscovery when the question clearly asks for automated retention and deletion schedules.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview eDiscovery is used for legal discovery and litigation hold, not for automated retention and deletion based on time periods. Option C is wrong because Compliance Manager is a risk assessment and compliance score tool that helps track regulatory compliance posture, not a solution for applying retention or deletion policies. Option D is wrong because Data Loss Prevention (DLP) is designed to prevent unauthorized sharing or leakage of sensitive data through policies, not to manage retention schedules or automatic deletion.

1084
MCQmedium

A company uses Microsoft 365 and Azure. They want a unified security solution that provides threat protection across email, endpoints, identities, and cloud apps, with automated investigation and response capabilities. Which Microsoft solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft 365 Defender
C.Microsoft Sentinel
D.Microsoft Entra ID Protection
AnswerB

Microsoft 365 Defender is the correct solution as it provides a unified Extended Detection and Response (XDR) experience specifically tailored for the Microsoft 365 ecosystem. It automatically collects, correlates, and analyzes security signals from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This integrated approach enables cross-domain threat protection, automated investigation, and remediation across email, endpoints, identities, and cloud applications, offering a holistic view of an organization's security posture within Microsoft 365.

Why this answer

Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that coordinates detection, prevention, investigation, and response across email, endpoints, identities, and cloud apps. It provides automated investigation and response (AIR) capabilities through its integrated components (e.g., Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps), making it the correct choice for the described requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool for cloud workloads) with Microsoft 365 Defender (a unified XDR solution for the Microsoft 365 ecosystem), or they mistakenly think Microsoft Sentinel (a SIEM) provides the same built-in, cross-domain automated investigation and response as Microsoft 365 Defender.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) focused on securing Azure, on-premises, and multi-cloud workloads, not a unified solution for email, endpoints, identities, and cloud apps with automated investigation and response. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution that ingests logs and alerts from multiple sources for threat detection and response, but it is not a unified security solution that natively provides threat protection across email, endpoints, identities, and cloud apps with built-in automated investigation and response like Microsoft 365 Defender. Option D is wrong because Microsoft Entra ID Protection is an identity protection service that detects and remediates identity-based risks (e.g., leaked credentials, anomalous sign-ins), but it does not provide threat protection across email, endpoints, or cloud apps, nor does it offer automated investigation and response across those domains.

1085
MCQmedium

A company is required by a compliance regulation to retain all user and admin activity audit logs for 2 years. They also need the ability to perform faster, historical searches on this audit data. Which Microsoft Purview solution should they use?

A.Microsoft Purview Audit (Standard)
B.Microsoft Purview Audit (Premium)
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview eDiscovery (Premium)
AnswerB

Microsoft Purview Audit (Premium) is the appropriate solution for retaining audit logs for two years, as it offers a default retention of one year, which can be extended to up to 10 years for specific activities. This service provides advanced auditing capabilities, including higher-fidelity logging, faster access to audit data, and increased API bandwidth, making it suitable for meeting stringent regulatory compliance requirements for long-term audit log retention.

Why this answer

Microsoft Purview Audit (Premium) provides a 2-year retention capability for audit logs, which meets the compliance regulation requirement. Additionally, it offers faster, historical searches through features like high-bandwidth access to the Audit Log Search API and intelligent insights, enabling efficient querying of large volumes of audit data. Standard Audit only retains logs for 90 days by default and lacks the performance optimizations for historical searches.

Exam trap

The trap here is that candidates confuse the 90-day default retention of Audit (Standard) with the 2-year requirement, or mistakenly think Data Lifecycle Management or eDiscovery can fulfill audit log retention and search needs, when only Audit (Premium) combines long-term retention with high-performance historical search capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Audit (Standard) retains audit logs for only 90 days by default (extendable to 1 year with manual configuration), not the required 2 years, and does not provide the enhanced search performance for historical data. Option C is wrong because Microsoft Purview Data Lifecycle Management focuses on retention and deletion policies for content (e.g., documents, emails) based on labels, not on auditing user and admin activity logs or enabling faster historical searches. Option D is wrong because Microsoft Purview eDiscovery (Premium) is designed for legal investigations and content search across Exchange, SharePoint, and Teams, not for long-term retention and high-performance querying of audit logs.

1086
MCQmedium

A healthcare organization must comply with HIPAA regulations. They need to automatically detect and classify sensitive health information such as medical record numbers stored in SharePoint Online and OneDrive. When detected, the solution should apply encryption and restrict access to only authorized personnel. Which Microsoft Purview solution should they configure?

A.Information Protection
B.Data Lifecycle Management
C.Audit
D.eDiscovery
AnswerA

Microsoft Purview Information Protection (MIP) is the correct solution because it enables organizations to discover, classify, label, and protect sensitive data, including Protected Health Information (PHI) relevant to HIPAA. Sensitivity labels can be applied manually or automatically based on content inspection (e.g., detecting medical record numbers or other sensitive info types), enforcing encryption, visual markings, and access restrictions. This ensures that data is protected at rest and in transit, aligning directly with HIPAA's security rule requirements for safeguarding electronic PHI.

Why this answer

Microsoft Purview Information Protection (specifically sensitivity labels and auto-labeling policies) can automatically detect sensitive health information like medical record numbers using built-in sensitive information types (e.g., U.S. HIPAA-defined types). When detected, it can apply encryption via Rights Management and restrict access to authorized personnel, meeting HIPAA compliance requirements.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management (retention/deletion) with Information Protection (classification/encryption), or assume Audit/eDiscovery can enforce access controls, when they only provide logging or search capabilities.

Why the other options are wrong

B

Data Lifecycle Management focuses on retaining or deleting data based on policies (e.g., retention labels), not on detecting, classifying, or protecting sensitive health information like medical record numbers.

C

Audit logs user and admin activities but does not detect, classify, or protect sensitive data like medical records. The question requires automatic detection, classification, encryption, and access restriction, which are capabilities of Information Protection, not Audit.

D

eDiscovery is used for searching and exporting content for legal or investigative purposes, not for automatically detecting, classifying, and protecting sensitive data like medical records.

When would these options actually be correct?

B

A question asking which Microsoft Purview solution to use for automatically retaining healthcare records for a specific period (e.g., 6 years) to meet HIPAA retention requirements, then deleting them afterward.

C

A company needs to track who accessed sensitive documents in SharePoint and OneDrive for compliance reporting. They want to see a history of actions like viewing, editing, or sharing files. In this scenario, Audit would be the correct solution.

D

An organization needs to search for and export content related to a legal case or regulatory investigation, such as finding all emails and documents mentioning a specific patient's medical record number across Exchange Online and SharePoint.

Why candidates pick the wrong answer

B

Candidates may confuse lifecycle management with protection because both involve labels, and they might think managing data includes security controls like encryption.

C

Candidates may think Audit is needed to monitor compliance with HIPAA, but they overlook that the primary requirement is proactive data protection (detection, classification, encryption) rather than just logging activities.

D

Candidates may confuse eDiscovery's search capabilities with the detection and classification features of Information Protection, assuming that searching for sensitive data implies automatic protection.

1087
MCQmedium

A company uses a hybrid environment with Azure virtual machines (IaaS) and on-premises Windows servers. The security team needs a single solution that continuously assesses the security posture of these workloads, provides a regulatory compliance dashboard with actionable recommendations, and enables threat detection. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Cloud
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Cloud is the correct solution as it provides comprehensive Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across Azure, on-premises, and multi-cloud environments. It continuously assesses security posture, offers a secure score, monitors regulatory compliance against various benchmarks, and delivers integrated threat detection and protection for Azure Virtual Machines and hybrid servers via Azure Arc.

Why this answer

Microsoft Defender for Cloud is the correct answer because it provides a unified security management platform that continuously assesses the security posture of both Azure VMs (IaaS) and on-premises Windows servers via Azure Arc. It offers a regulatory compliance dashboard with actionable recommendations based on built-in standards like CIS, NIST, and Azure Security Benchmark, and integrates with Microsoft Defender for Cloud's workload protection plans to enable threat detection for these hybrid workloads.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a posture management and threat protection platform) with Microsoft Sentinel (a SIEM), but the question specifically asks for a single solution that includes a compliance dashboard and continuous assessment, which is a core feature of Defender for Cloud, not Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on shadow IT discovery and data protection for SaaS applications, not on assessing the security posture or providing a compliance dashboard for IaaS VMs and on-premises servers. Option B is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution that focuses on device-level threat detection and response, but it does not provide a regulatory compliance dashboard or continuous security posture assessment across hybrid workloads. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests logs and alerts for threat detection and incident response, but it is not primarily designed for continuous security posture assessment or out-of-the-box regulatory compliance dashboards; it requires custom workbooks and analytics rules for compliance reporting.

1088
MCQmedium

Your company uses Microsoft Entra ID and wants to allow external partners to sign in using their own Google or Facebook accounts. Which feature should you enable?

A.Azure Active Directory Domain Services
B.Microsoft Entra B2C
C.Microsoft Entra B2B collaboration
D.External Identities (social identity providers)
AnswerD

External Identities is the overarching capability within Microsoft Entra ID that enables secure interaction with external users. Specifically, the social identity providers feature allows external users to sign in to your Microsoft Entra ID-protected applications using their existing credentials from popular social accounts like Google, Facebook, LinkedIn, or Amazon. This eliminates the need for external users to create a new account or have an existing Microsoft Entra ID or Microsoft account, streamlining access for a broad range of external collaborators.

Why this answer

External Identities (social identity providers) in Microsoft Entra ID allows you to configure Google and Facebook as identity providers for external users. This enables partners to sign in using their existing social accounts without needing a separate Microsoft account, leveraging OAuth 2.0 and OpenID Connect protocols for authentication.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration (which handles external organizational accounts) with External Identities (which includes social identity providers), leading them to incorrectly select B2B when the question explicitly mentions Google or Facebook accounts.

How to eliminate wrong answers

Option A is wrong because Azure Active Directory Domain Services (Azure AD DS) provides managed domain services like LDAP and Kerberos for legacy applications, not social identity federation. Option B is wrong because Microsoft Entra B2C is designed for customer-facing applications with extensive customization of sign-up and sign-in flows, not for simple partner access using existing social accounts. Option C is wrong because Microsoft Entra B2B collaboration enables external users to sign in with their own organizational accounts (e.g., Azure AD, Microsoft account) but does not natively support social identity providers like Google or Facebook without additional configuration through External Identities.

1089
MCQeasy

Your company needs to detect and prevent employees from sharing confidential product plans via email with external parties. Which Microsoft Purview solution should you configure?

A.Sensitivity labels
B.Communication compliance
C.Data Loss Prevention (DLP)
D.Retention policies
AnswerC

Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and automatically protect sensitive information across various locations, including endpoints, cloud apps, and services like Exchange, SharePoint, and OneDrive. By detecting specific sensitive information types or content, DLP can actively block sharing, encrypt data, or notify users and administrators in real-time. This direct enforcement capability is crucial for preventing unauthorized data exfiltration or sharing.

Why this answer

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and prevent the unauthorized sharing of sensitive information, such as confidential product plans, via email and other channels. DLP policies can inspect email content and attachments for sensitive data types (e.g., custom keywords or patterns) and automatically block or quarantine the message if it is sent to external recipients. This aligns directly with the requirement to prevent employees from sharing confidential plans externally.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which apply protection at rest) with DLP (which enforces actions in transit), leading them to select sensitivity labels when the question explicitly requires detection and prevention of sharing via email.

How to eliminate wrong answers

Option A is wrong because sensitivity labels classify and protect data by applying encryption or visual markings, but they do not actively monitor or block the transmission of data in transit like email. Option B is wrong because communication compliance focuses on detecting policy violations (e.g., harassment or insider trading) in communications, not on preventing the sharing of specific confidential data via DLP rules. Option D is wrong because retention policies manage how long data is kept or deleted, not how it is shared or blocked from external transmission.

1090
MCQeasy

A company implements a security measure to ensure that only authorized employees can view sensitive customer records. Which principle of the CIA triad does this measure primarily protect?

A.Confidentiality
B.Integrity
C.Availability
D.Accountability
AnswerA

Confidentiality, a cornerstone of the CIA triad, ensures that information is accessible only to those authorized to view it. This principle directly addresses the company's security measure to limit access to specific employees, preventing unauthorized disclosure of sensitive data. Implementing strong access controls, encryption, and data classification are typical methods to uphold confidentiality, aligning perfectly with the goal of restricting information access.

Why this answer

Confidentiality ensures that sensitive information is accessible only to authorized individuals. By restricting access to customer records to authorized employees, the company directly prevents unauthorized disclosure, which is the core goal of confidentiality in the CIA triad.

Exam trap

The trap here is that candidates often confuse confidentiality with integrity, thinking that preventing unauthorized changes is the same as preventing unauthorized viewing, but confidentiality is about secrecy, not data accuracy.

Why the other options are wrong

B

Integrity ensures data accuracy and prevents unauthorized modification, not restriction of access. The question focuses on limiting who can view records, which is confidentiality.

C

The question specifies that the measure ensures only authorized employees can view records, which directly protects confidentiality (preventing unauthorized access), not availability (ensuring access when needed).

D

Accountability is not a principle of the CIA triad; the CIA triad consists of Confidentiality, Integrity, and Availability. This question specifically asks about the CIA triad, so Accountability is not a valid option.

When would these options actually be correct?

B

A question asking which CIA principle is primarily protected by a measure that uses hashing to verify that customer records have not been altered during transmission.

C

A question stating: 'A company implements redundant servers and backup power to ensure customer records are always accessible. Which CIA principle does this protect?' would make availability correct.

D

A question asks: 'Which security principle ensures that actions can be traced back to a specific user?' In that context, Accountability would be the correct answer because it involves auditing and non-repudiation.

Why candidates pick the wrong answer

B

Candidates may confuse 'authorized employees' with data accuracy, thinking integrity involves ensuring only authorized changes, but the core here is viewing, not modifying.

C

Candidates may confuse 'access control' with 'availability' because both involve access, but availability focuses on uptime and reliability, not authorization.

D

Candidates may confuse Accountability with Confidentiality because both involve controlling access to data, but Accountability focuses on tracking who did what, not on preventing unauthorized viewing.

1091
Multi-Selectmedium

Which THREE capabilities are provided by Microsoft Defender XDR? (Choose THREE.)

Select 3 answers
A.Cloud security posture management
B.Advanced hunting
C.Automated investigation and response
D.Incident management
E.Vulnerability management
AnswersB, C, D

Advanced hunting is a powerful, proactive threat-hunting tool within Microsoft Defender XDR that allows security analysts to explore raw event data using Kusto Query Language (KQL). It provides access to up to 30 days of historical data from endpoints, identities, cloud apps, and email, enabling the discovery of unknown or advanced threats that automated detections might miss. This capability is crucial for deep investigations and creating custom detection rules.

Why this answer

Microsoft Defender XDR provides advanced hunting (B), a Kusto Query Language (KQL)-based tool that lets security teams proactively search across up to 30 days of raw endpoint, email, identity, and cloud app telemetry to hunt for threats. It also delivers automated investigation and response (C), using automated investigation playbooks and self-healing actions to triage and remediate alerts across the Defender workloads. Incident management (D) is a core capability, correlating related alerts from multiple Defender products into a single incident with a unified timeline and remediation workflow in the Microsoft 365 Defender portal.

Cloud security posture management (A) is a Microsoft Defender for Cloud capability, not Defender XDR, and vulnerability management (E) is provided by Microsoft Defender Vulnerability Management (or Defender for Endpoint), so neither belongs to the Defender XDR feature set.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR's core capabilities (incident management, advanced hunting, automated investigation and response) with adjacent services like Defender for Cloud's CSPM or Defender Vulnerability Management, which are separate offerings that integrate with but are not core to Defender XDR.

1092
MCQhard

Refer to the exhibit. You are a compliance administrator managing a DLP policy in Microsoft Purview. The policy is set to 'enforce' mode but you notice that internal users can still share credit card numbers via email to external recipients. What is the most likely cause?

A.The policy is in test mode, not enforce mode
B.The policy is not applied to the user's mailbox
C.The condition requires a minimum count of 5
D.The action only blocks access to the content from external users, not sharing by internal users
AnswerD

The action "blockOnlyExternal" specifically prevents external users from accessing content that contains sensitive information, but it does not prevent internal users from initially sharing or sending that content to external recipients. While external access to the shared content might be blocked, the internal user successfully initiated the sharing action. This distinction is crucial because the policy allows the internal user to perform the outbound sharing, even if the external recipient cannot ultimately view the sensitive data within the shared item.

Why this answer

A DLP policy in 'enforce' mode can still allow internal users to share sensitive data if the policy action is configured to 'block access to content from external users' rather than 'block sharing by internal users'. In Microsoft Purview, the 'block access' action restricts external recipients from viewing the content but does not prevent the internal sender from transmitting the email. To stop internal users from sending, the policy must use the 'block sending' action, which prevents the message from being delivered.

Exam trap

The trap here is that candidates assume 'enforce' mode means all sharing is blocked, but they overlook that the action type (block access vs. block sending) determines whether internal users can still send the data externally.

How to eliminate wrong answers

Option A is wrong because the question explicitly states the policy is set to 'enforce' mode, not test mode, so test mode is not the cause. Option B is wrong because DLP policies in Microsoft Purview are applied at the scope of the policy (e.g., Exchange, SharePoint, OneDrive) and do not require individual mailbox assignment; if the policy is scoped to Exchange, it applies to all mailboxes in the organization by default. Option C is wrong because a minimum count condition (e.g., 5 credit card numbers) would only reduce false positives by requiring a threshold to trigger the policy; if the user shares fewer than 5 numbers, the policy would not act, but the question implies sharing is occurring and the policy is not blocking it, so the issue is the action type, not the condition threshold.

1093
MCQeasy

A company wants to automatically prevent users from sharing files containing personal data (e.g., passport numbers) via email. Which Microsoft Purview solution should they configure?

A.Communication Compliance
B.Data Loss Prevention (DLP)
C.Sensitivity labels
D.eDiscovery
AnswerB

Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations, including cloud services, endpoints, and on-premises. DLP can detect specific sensitive data types, such as credit card numbers or personally identifiable information (PII), and enforce rules to prevent sharing, copying, or transferring this data outside defined organizational boundaries. It directly fulfills the requirement to automatically block sharing actions based on content.

Why this answer

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and automatically block the sharing of sensitive information, such as passport numbers, via email. DLP policies use deep content analysis (e.g., regular expressions, keyword matching, and data classification) to inspect email attachments and body text in transit, and can enforce actions like blocking the message or sending a policy tip to the user. This aligns directly with the requirement to prevent users from sharing files containing personal data through email.

Exam trap

The trap here is that candidates often confuse Communication Compliance with DLP because both involve monitoring communications, but Communication Compliance is for auditing and review, not for automatic blocking of sensitive data in transit.

How to eliminate wrong answers

Option A is wrong because Communication Compliance is focused on monitoring and reviewing internal and external communications for policy violations (e.g., harassment, insider trading), not on automatically blocking data sharing based on content patterns like passport numbers. Option C is wrong because Sensitivity labels are classification and protection tools that apply markings and encryption to documents and emails, but they do not automatically inspect and block content in transit; they rely on users or automated labeling policies to apply labels, and blocking requires integration with DLP. Option D is wrong because eDiscovery is used for identifying, preserving, and exporting electronic data for legal or investigative purposes, not for real-time prevention of data sharing via email.

1094
MCQmedium

Your organization uses Microsoft Defender XDR. You need to investigate a potential lateral movement attack where a compromised user account is used to access multiple workstations. Which feature should you use to visualize the attack path?

A.Attack graph
B.Microsoft Sentinel workbooks
C.Threat analytics in Microsoft 365 Defender
D.Incident queue
AnswerA

The Attack graph in Microsoft Defender XDR specifically visualizes the full scope of an attack, including how an attacker moved laterally, which assets were impacted, and the relationships between entities. It provides a rich, interactive representation of the attack chain, making it ideal for understanding lateral movement paths and identifying potential pivot points. This feature is crucial for incident responders to trace the progression of sophisticated threats.

Why this answer

Attack graph in Microsoft Defender XDR is the correct feature because it automatically maps and visualizes the potential paths an attacker could take to move laterally across devices using compromised credentials. It correlates alerts and incidents to show the sequence of events, such as a user account authenticating to multiple workstations, enabling security teams to identify the scope and entry point of the attack.

Exam trap

The trap here is that candidates often confuse the attack graph with the incident queue or threat analytics, assuming any security dashboard can visualize attack paths, but only the attack graph provides the automated, graph-based lateral movement visualization specific to Defender XDR.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel workbooks are customizable dashboards for querying and visualizing security data from multiple sources, but they do not automatically generate attack path visualizations specific to lateral movement within Defender XDR. Option C is wrong because Threat analytics in Microsoft 365 Defender provides intelligence reports on active threats and vulnerabilities, not a real-time graph of attack paths. Option D is wrong because the Incident queue lists all security incidents in a tabular view for triage and management, but it does not offer a visual representation of lateral movement steps.

1095
MCQmedium

A company uses Microsoft Entra ID. The security team needs to ensure that when users sign in to a critical financial application from an untrusted network, they must first complete multi-factor authentication (MFA). Additionally, the team wants to block the sign-in if the device is not marked as compliant by Microsoft Intune. Which conditional access grant control should they configure to meet both requirements?

A.Require multi-factor authentication AND Require device to be marked as compliant
B.Require multi-factor authentication only
C.Require one of the selected controls
D.Require device to be marked as compliant only
AnswerA

Combining both grant controls within one conditional access policy enforces MFA and blocks non-compliant devices at sign-in, matching the untrusted-network and Intune compliance conditions. Both requirements must be satisfied before access is granted, so AND logic is required.

Why this answer

Conditional Access grant controls allow you to require multiple conditions to be met simultaneously. By selecting 'Require multi-factor authentication' AND 'Require device to be marked as compliant', the policy ensures that both MFA and device compliance are enforced for the sign-in, meeting the security team's requirements.

Exam trap

The trap here is that candidates often confuse 'AND' (all controls required) with 'OR' (one of the selected controls), leading them to choose Option C, which would not enforce both MFA and device compliance simultaneously.

Why the other options are wrong

B

This option only enforces MFA, but the question explicitly requires both MFA and device compliance. It fails to block sign-ins from non-compliant devices, so it does not meet the full requirement.

C

The question requires both MFA and device compliance to be enforced simultaneously. Option C, 'Require one of the selected controls,' would allow sign-in if either MFA or device compliance is met, not both, failing to meet the requirement.

When would these options actually be correct?

B

This option would be correct if the question asked only to require MFA when signing in from an untrusted network, without any device compliance requirement. For example: 'Ensure users complete MFA when accessing a financial app from an untrusted network.'

C

In a scenario where the security team wants to allow access if the user either completes MFA OR uses a compliant device (e.g., for a less critical app where flexibility is acceptable), selecting 'Require one of the selected controls' would be correct.

Why candidates pick the wrong answer

B

Candidates may think MFA alone is sufficient for security, overlooking the additional device compliance requirement. They might also assume that MFA implicitly covers device health, which is incorrect.

C

Candidates may misinterpret 'one of the selected controls' as meaning both controls are required, or they may think it provides a flexible way to enforce either condition without understanding that it grants access if only one condition is satisfied.

1096
MCQhard

Refer to the exhibit. A Microsoft Purview DLP policy is configured in Test mode. An administrator notices that a user is still able to share a document containing a credit card number. What is the most likely reason?

A.The credit card number is not detected because low confidence threshold
B.The BlockAccess action is not supported for SharePoint Online
C.The policy is in Test mode, so actions are not enforced
D.The policy requires an administrator to approve the action
AnswerC

When a Microsoft Purview DLP policy is configured in "Test mode," it is designed to evaluate policy matches and generate incident reports without enforcing any configured actions, such as blocking access or notifying users. This mode allows administrators to assess the policy's impact and fine-tune its rules before full deployment. Consequently, any specified actions, like blocking access to a credit card number, will not be enforced while the policy remains in test mode.

Why this answer

When a Microsoft Purview DLP policy is configured in Test mode, it logs policy matches and generates alerts but does not enforce any restrictive actions such as blocking access or sharing. The administrator observed that the user could still share the document because Test mode explicitly disables action enforcement, allowing the organization to evaluate the policy's impact before moving to Enforce mode.

Exam trap

The trap here is that candidates may assume Test mode still enforces some actions (like blocking) because they confuse it with 'Test mode with policy tips' or think DLP policies always block sharing by default, but Test mode explicitly disables all enforcement actions.

How to eliminate wrong answers

Option A is wrong because the credit card number detection uses a predefined Sensitive Information Type (SIT) with a default confidence level; if the policy matched, the number was detected, and a low confidence threshold would not prevent detection—it would simply require a higher match accuracy. Option B is wrong because the BlockAccess action is fully supported for SharePoint Online in Purview DLP policies; it can block sharing or restrict access to documents containing sensitive data. Option D is wrong because the policy does not require administrator approval for actions in Test mode; administrator approval is a separate feature (e.g., using Power Automate or custom workflows) and is not a default behavior of DLP Test mode.

1097
MCQeasy

Your organization wants to centrally manage security policies for all devices (Windows, iOS, Android) and ensure they meet compliance requirements before accessing corporate resources. Which Microsoft solution should you use?

A.Microsoft Purview Compliance Manager
B.Microsoft Defender for Endpoint
C.Microsoft Intune
D.Microsoft Entra ID
AnswerC

Microsoft Intune is a cloud-based Unified Endpoint Management (UEM) solution specifically designed to manage and secure devices, including mobile phones, tablets, and laptops, across various operating systems. It enables organizations to centrally deploy and enforce security policies, manage application lifecycles, and configure compliance settings, ensuring all managed devices meet organizational security and operational standards. This direct device configuration and policy enforcement capability is precisely what the question asks for.

Why this answer

Microsoft Intune is the correct solution because it is a cloud-based mobile device management (MDM) and mobile application management (MAM) service that centrally manages security policies across Windows, iOS, and Android devices. It enforces compliance requirements—such as encryption, OS version, and jailbreak detection—before granting access to corporate resources, integrating with Conditional Access in Microsoft Entra ID.

Exam trap

The trap here is that candidates confuse Microsoft Entra ID's identity-based Conditional Access with the device-level policy management that Intune provides, assuming Entra ID alone can enforce device compliance without Intune.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a risk-assessment and compliance-scoring tool for regulatory frameworks (e.g., GDPR, ISO 27001), not a device management or policy enforcement solution. Option B is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) and vulnerability management tool focused on threat detection and remediation, not on centrally managing device compliance policies or controlling resource access. Option D is wrong because Microsoft Entra ID is an identity and access management (IAM) service that provides authentication and authorization, but it does not directly manage device security policies or enforce device compliance; it relies on Intune for device-level controls.

1098
Multi-Selectmedium

Which TWO of the following are features of Microsoft Defender for Cloud? (Choose two.)

Select 2 answers
A.Data classification and labeling
B.Security Information and Event Management (SIEM)
C.Cloud Workload Protection Platform (CWPP)
D.Mobile Threat Defense (MTD)
E.Cloud Security Posture Management (CSPM)
AnswersC, E

Cloud Workload Protection Platform (CWPP) is a key feature of Microsoft Defender for Cloud. This capability provides comprehensive protection for diverse cloud workloads, including virtual machines, containers, databases, and storage, across multi-cloud and hybrid environments. Defender for Cloud offers vulnerability assessments, just-in-time access, adaptive application controls, and file integrity monitoring to secure these critical compute resources against threats.

Why this answer

Microsoft Defender for Cloud is a Cloud Workload Protection Platform (CWPP) that provides unified security management and advanced threat protection for workloads running in Azure, on-premises, and other clouds. It also includes Cloud Security Posture Management (CSPM) capabilities, which continuously assess your environment against security benchmarks (e.g., CIS, NIST) and provide actionable recommendations to improve your security posture.

Exam trap

The trap here is that candidates often confuse the SIEM and SOAR capabilities of Microsoft Sentinel with the CWPP and CSPM functions of Defender for Cloud, or they mistakenly associate data classification (Purview) with Defender for Cloud's security recommendations.

1099
MCQmedium

A multinational organization uses Microsoft 365 and must demonstrate compliance with both GDPR and ISO 27001. The compliance team needs a centralized tool to assess their current compliance posture against these frameworks, receive prioritized improvement actions, and track the implementation of those actions over time. Which Microsoft Purview solution should they use?

A.Compliance Manager
B.Data Lifecycle Management
C.Audit
D.eDiscovery
AnswerA

Compliance Manager provides framework-specific assessments against GDPR and ISO 27001, with a compliance score, prioritised improvement actions, and tracking of implementation progress. It satisfies the requirement for a single centralised tool covering posture assessment and ongoing action tracking.

Why this answer

Compliance Manager is the correct solution because it provides a centralized dashboard that assesses an organization's compliance posture against frameworks like GDPR and ISO 27001. It offers prioritized improvement actions based on built-in assessments and tracks the implementation of those actions over time, directly meeting the requirements for a unified compliance management tool.

Exam trap

The trap here is that candidates may confuse Audit or Data Lifecycle Management as compliance tools, but they lack the centralized assessment and action tracking capabilities that Compliance Manager uniquely provides for framework-specific compliance management.

Why the other options are wrong

B

Data Lifecycle Management focuses on governing data retention and deletion policies, not on assessing compliance posture against frameworks like GDPR and ISO 27001 or tracking improvement actions.

C

Audit is used for investigating specific security or compliance events by searching the unified audit log, not for assessing compliance posture against frameworks like GDPR and ISO 27001 or tracking improvement actions.

D

eDiscovery is used for identifying and preserving electronic content for legal cases, not for assessing compliance posture against frameworks like GDPR and ISO 27001 or tracking improvement actions.

When would these options actually be correct?

B

A question asking which Microsoft Purview solution to use for automatically retaining or deleting data based on regulatory requirements (e.g., GDPR data retention) would make Data Lifecycle Management the correct answer.

C

A question asking which Microsoft Purview solution allows an organization to search and export user and admin activity logs to investigate a security incident or perform forensic analysis would have Audit as the correct answer.

D

A legal team needs to identify and preserve all emails and documents related to a pending lawsuit across Microsoft 365. They require a tool to search, hold, and export relevant data for litigation purposes.

Why candidates pick the wrong answer

B

Candidates may confuse managing data lifecycle with managing compliance, as both involve regulatory requirements, but Data Lifecycle Management does not provide assessment or action tracking.

C

Candidates may confuse Audit with Compliance Manager because both are compliance-related, and they might think auditing is sufficient for compliance assessment without understanding the distinct capabilities of each solution.

D

Candidates may confuse eDiscovery with compliance because both involve data management and regulatory requirements, but eDiscovery focuses on litigation, not continuous compliance assessment.

1100
MCQhard

A healthcare organization runs a mix of workloads on Azure (Azure VMs, SQL Database) and on-premises (Windows Servers). They must continuously assess their compliance against the HIPAA and HITRUST regulatory frameworks. They want a unified dashboard that shows their compliance score against these standards and provides step-by-step recommendations to remediate violations. Which Microsoft Defender for Cloud capability should they use?

A.Regulatory compliance dashboard
B.Secure score
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Servers
AnswerA

The Regulatory compliance dashboard, a core feature of Microsoft Defender for Cloud, provides a centralized view to manage and track an organization's compliance posture against various regulatory standards. It allows users to add built-in standards like HIPAA and HITRUST, crucial for healthcare organizations, and continuously monitors the environment, mapping security recommendations to specific controls within these frameworks. This dashboard presents a compliance score and actionable recommendations, enabling organizations to efficiently demonstrate adherence to industry-specific regulations.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a unified view of an organization's compliance posture against specific regulatory standards like HIPAA and HITRUST. It displays a compliance score for each selected framework and offers step-by-step remediation recommendations for identified violations, directly meeting the requirement for continuous assessment and guided remediation.

Exam trap

The trap here is that candidates often confuse the Secure score (which measures general security hygiene) with the Regulatory compliance dashboard (which measures adherence to specific regulatory frameworks), leading them to select Secure score when the question explicitly asks for compliance against HIPAA and HITRUST.

How to eliminate wrong answers

Option B (Secure score) is wrong because it measures the overall security posture based on security controls and recommendations, not compliance against specific regulatory frameworks like HIPAA or HITRUST. Option C (Microsoft Defender for Cloud Apps) is wrong because it is a Cloud Access Security Broker (CASB) focused on shadow IT discovery, data protection, and threat detection across SaaS applications, not on assessing compliance against healthcare regulatory standards. Option D (Microsoft Defender for Servers) is wrong because it provides threat detection and advanced protections for server workloads, but does not include a dashboard for regulatory compliance scoring or step-by-step remediation against HIPAA or HITRUST.

1101
MCQhard

Contoso uses Microsoft Sentinel. They want to automate response to a high-severity incident by blocking the source IP in Azure Firewall and sending a notification to the SOC team via email. Which feature should they use?

A.Create a hunting query.
B.Create an automation rule.
C.Enable Fusion.
D.Create a workbook.
AnswerB

An automation rule in Microsoft Sentinel is the primary mechanism for orchestrating automated responses to incidents or alerts. These rules allow administrators to define conditions based on incident or alert properties, and then automatically perform actions such as suppressing false positives, assigning incidents, or, most importantly, triggering a playbook (Azure Logic App) to execute complex response workflows. This direct linkage to playbooks is precisely how Contoso can automate its incident response processes.

Why this answer

Microsoft Sentinel automation rules allow you to define triggers and actions based on incident creation or updates. They can automatically run playbooks (Logic Apps) to perform response actions like blocking an IP in Azure Firewall and sending email notifications. Automation rules are designed for orchestration and response, making them the correct choice for automating incident response.

Exam trap

The trap is confusing automation rules with other Sentinel features like Fusion or hunting queries. Candidates might think Fusion handles automation, but it's for incident correlation. The key is that automation rules are specifically for orchestrating responses.

How to eliminate wrong answers

Option A is wrong because hunting queries are used for proactive threat hunting, not automated response. Option C is wrong because Fusion is a feature that uses machine learning to correlate alerts into incidents, but it does not perform automated response actions. Option D is wrong because workbooks are for visualization and reporting, not automation.

1102
MCQmedium

A multinational corporation must comply with several regulations including GDPR, ISO 27001, and NIST. They need a single solution that provides a compliance score, tracks their progress, and recommends specific improvement actions that can be assigned to different departments. Which Microsoft Purview solution meets these requirements?

A.A
B.B
C.C
D.D
AnswerA

Microsoft Purview Compliance Manager is the correct solution as it provides a comprehensive dashboard to assess and manage an organization's compliance posture against various regulatory standards and industry benchmarks. It offers a real-time compliance score, recommended improvement actions, and the ability to assign and track tasks to address identified gaps. This tool is specifically designed to help multinational corporations navigate complex regulatory landscapes by simplifying compliance management and demonstrating adherence.

Why this answer

Microsoft Purview Compliance Manager provides a unified compliance score, tracks progress over time, and offers recommended improvement actions that can be assigned to specific departments. It supports multiple regulations like GDPR, ISO 27001, and NIST by mapping controls to these frameworks, making it the correct solution for the multinational corporation's needs.

Exam trap

The trap here is that candidates may confuse Compliance Manager with other Purview solutions like Audit or eDiscovery, which address different compliance needs (logging vs. scoring), but only Compliance Manager provides a centralized score and assignable improvement actions.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit (Standard or Premium) is focused on logging and investigating user and admin activity, not on providing a compliance score or tracking improvement actions. Option C is wrong because Microsoft Purview eDiscovery is designed for identifying, collecting, and exporting content for legal or investigative purposes, not for compliance scoring or action assignment. Option D is wrong because Microsoft Purview Data Lifecycle Management (formerly Records Management) handles retention and deletion policies, not compliance scoring or improvement recommendations.

1103
Multi-Selecteasy

Your company wants to protect sensitive data in Microsoft Teams. Which two Microsoft Purview features can help prevent accidental sharing of confidential information? (Choose two.)

Select 2 answers
A.Data Loss Prevention (DLP) policies for Teams
B.Audit log search for Teams
C.eDiscovery for Teams
D.Retention policies for Teams messages
E.Sensitivity labels for Teams sites and content
AnswersA, E

DLP policies for Teams proactively identify and prevent the sharing of sensitive information, such as credit card numbers or health records, within Teams chats, channels, and files. These policies leverage sensitive information types and trainable classifiers to detect data and can automatically block sharing, notify users, or require justification before allowing the action, directly protecting against data exfiltration.

Why this answer

Data Loss Prevention (DLP) policies for Teams can detect and block sharing of sensitive information (e.g., credit card numbers, social security numbers) in Teams messages and channels, preventing accidental exposure. Sensitivity labels allow you to classify and protect Teams sites and content by applying encryption, visual markings, and access restrictions, ensuring confidential data is not shared with unauthorized users.

Exam trap

The trap here is that candidates often confuse detective controls (like audit logs and eDiscovery) with preventive controls (like DLP and sensitivity labels), leading them to select options that only record or search for data after it has been shared rather than stopping the sharing in the first place.

1104
MCQeasy

A company's security policy requires that customer data must only be accessible by authorized sales representatives. Which security principle does this requirement directly enforce?

A.Integrity
B.Availability
C.Confidentiality
D.Non-repudiation
AnswerC

Confidentiality is the fundamental security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. It directly addresses the requirement of limiting access to customer data only to those who are explicitly authorized, typically through mechanisms like encryption, access control lists (ACLs), and the principle of least privilege. This principle is paramount for protecting sensitive information from unauthorized viewing or exposure, aligning perfectly with the stated security policy.

Why this answer

Confidentiality ensures that data is accessible only to authorized individuals, which directly matches the requirement that customer data must only be accessible by authorized sales representatives. This principle is typically enforced through access controls, encryption, and authentication mechanisms. Integrity focuses on data accuracy, availability on uptime, and non-repudiation on proving an action occurred.

Thus, the requirement is a classic example of enforcing confidentiality.

Exam trap

SC-900 often tests the CIA triad by presenting a scenario that sounds like integrity or availability but actually hinges on access restriction, so candidates must distinguish between 'only authorized access' (confidentiality) and 'data is accurate' (integrity) or 'data is accessible' (availability).

Why the other options are wrong

A

The requirement to restrict access to customer data to authorized sales representatives directly enforces confidentiality, not integrity. Integrity ensures data is not tampered with or modified by unauthorized parties, but the primary goal here is preventing unauthorized access.

D

Non-repudiation ensures that a party cannot deny having performed an action (e.g., signing a document), but the requirement to restrict access to customer data is about preventing unauthorized disclosure, which is confidentiality.

When would these options actually be correct?

A

A question that asks: 'A company wants to ensure that customer data has not been altered during transmission. Which security principle does this enforce?' In that context, integrity would be correct because it focuses on protecting data from unauthorized modification.

D

A question where the security policy requires that sales representatives cannot deny having accessed or modified customer data, such as 'The company needs to prove that a sales representative viewed a customer record; which principle is enforced?'

Why candidates pick the wrong answer

A

Candidates may confuse confidentiality with integrity because both involve protecting data. They might think that restricting access also ensures data remains unchanged, but integrity specifically addresses unauthorized modification, not access control.

D

Candidates may confuse non-repudiation with access control because both involve authorization and accountability, but non-repudiation specifically addresses denial of actions, not access restriction.

1105
MCQhard

A healthcare organization must comply with HIPAA. They need to automatically detect protected health information (PHI) in emails sent from Exchange Online, prevent users from sharing these emails with unauthorized external recipients, and apply a retention label that retains PHI emails for six years. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Information Protection and Data Loss Prevention
B.Microsoft Purview eDiscovery
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Insider Risk Management
AnswerA

Microsoft Purview Information Protection enables organizations to discover, classify, and protect sensitive data like Protected Health Information (PHI) through sensitivity labels, which can automatically apply encryption or visual markings. Concurrently, Microsoft Purview Data Loss Prevention (DLP) policies leverage these classifications to detect and prevent unauthorized sharing or transfer of PHI across various locations, including email, SharePoint, and Teams. This combined approach ensures data is appropriately handled, retained, and safeguarded against exfiltration, directly addressing HIPAA's privacy and security requirements.

Why this answer

Microsoft Purview Information Protection and Data Loss Prevention (DLP) is the correct solution because it combines sensitive data classification (to detect PHI via built-in HIPAA data classifiers) with policy-based enforcement (to block sharing with unauthorized external recipients) and can automatically apply a retention label (via auto-labeling policies) to retain PHI emails for six years. This directly addresses all three requirements: detection, prevention, and retention.

Exam trap

The trap here is that candidates may confuse Communication Compliance (which monitors for policy violations) with DLP (which enforces data protection actions), or assume eDiscovery handles retention and blocking, when in fact DLP is the only solution that combines detection, prevention, and retention label application in a single policy.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for real-time detection or prevention of data sharing. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect policy violations in communications (e.g., harassment, insider trading) and does not natively enforce DLP actions like blocking external sharing or applying retention labels. Option D is wrong because Microsoft Purview Insider Risk Management focuses on identifying risky user activities (e.g., data theft, sabotage) through behavioral analytics, not on automatically detecting PHI in emails or preventing external sharing.

1106
MCQeasy

A company wants to provide employees with single sign-on access to both Microsoft 365 and a third-party SaaS application. Which feature of Microsoft Entra ID should they use?

A.Identity Protection
B.Conditional Access
C.Federation
D.Privileged Identity Management
AnswerC

Federation establishes a trust relationship between an identity provider (IdP) and one or more service providers (SPs), enabling users to authenticate once with the IdP and gain access to multiple SPs without re-entering credentials. This mechanism, often leveraging protocols like SAML or OpenID Connect, allows the IdP to assert a user's identity to various applications. It is the core technology that facilitates single sign-on (SSO) across different applications and organizational boundaries.

Why this answer

Federation (Option C) is correct because it establishes a trust relationship between Microsoft Entra ID and the third-party SaaS application's identity provider using standards like SAML 2.0 or WS-Federation. This allows users to authenticate once with their corporate credentials and gain access to both Microsoft 365 and the third-party app without separate logins, enabling true single sign-on (SSO).

Exam trap

The trap here is that candidates confuse Conditional Access (a policy engine) with the underlying federation trust required for SSO, mistakenly thinking that policy enforcement alone enables single sign-on.

How to eliminate wrong answers

Option A is wrong because Identity Protection is a risk-based detection and remediation tool that identifies compromised identities or suspicious sign-ins, not a mechanism for enabling SSO. Option B is wrong because Conditional Access enforces policies (e.g., requiring MFA or blocking sign-ins from certain locations) after authentication, but it does not establish the trust relationship needed for SSO. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time access and approval workflows for privileged roles, not the federation trust required for SSO.

1107
MCQeasy

A user downloads a software update from a company's internal website. The update file is hashed, and the hash value is published on a separate secure page. After downloading, the user computes the hash of the downloaded file and compares it to the published hash. The two values match. Which security concept is primarily demonstrated by this comparison?

A.Confidentiality
B.Integrity
C.Availability
D.Authentication
AnswerB

Integrity ensures data has not been tampered with or corrupted during transit or storage. When a user downloads a software update, comparing its cryptographic hash (e.g., SHA256) with a known, trusted hash value provided by the company directly verifies that the file's contents are exactly as intended. This process specifically confirms the data's integrity, ensuring the downloaded software is free from unauthorized modifications or accidental damage.

Why this answer

Hashing is a one-way cryptographic function that produces a fixed-size digest from input data. By comparing the computed hash of the downloaded file to the published hash, the user verifies that the file has not been altered during transit or storage. This directly demonstrates the security concept of integrity, which ensures data has not been tampered with or corrupted.

Exam trap

The trap here is that candidates often confuse integrity with authentication, mistakenly thinking that verifying a hash proves the file's origin (authentication) rather than its unaltered state (integrity).

Why the other options are wrong

A

The scenario involves verifying that the file has not been altered, which is a matter of data integrity, not confidentiality. Confidentiality is about preventing unauthorized access, not ensuring data remains unchanged.

C

Availability ensures that resources are accessible when needed, but comparing hashes verifies that the file has not been altered, which is a matter of integrity, not availability.

D

Authentication verifies the identity of a user or system, not the integrity of data. Comparing hashes ensures the file hasn't been altered, which is integrity, not authentication.

When would these options actually be correct?

A

A user downloads a sensitive document from a company's internal website that is encrypted using HTTPS. The user verifies that the document was not intercepted by checking the TLS certificate. This demonstrates confidentiality because encryption protects the data from being read during transmission.

C

A question describing a scenario where a company implements redundant servers and load balancing to ensure users can always download updates, even during high traffic or server failures, would demonstrate availability.

D

A user logs in using a password and biometric scan. Which security concept is demonstrated? The answer would be authentication, as it verifies the user's identity.

Why candidates pick the wrong answer

A

Candidates may confuse hashing with encryption or think that protecting data from tampering also keeps it secret, but hashing does not conceal the content.

C

Candidates may confuse availability with the ability to access and verify the file, thinking that the hash comparison confirms the file is 'available' in its original form, rather than recognizing it as an integrity check.

D

Candidates may confuse authentication with integrity because both involve verification processes, but authentication verifies identity, while integrity verifies data unchanged.

1108
MCQmedium

A company uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) only for external guest users, while allowing internal employees to sign in without MFA. Which Conditional Access setting should be configured?

A.Require MFA for all users
B.Exclude internal users by group
C.Target the 'Guest or external users' identity type
D.Use Identity Protection's user risk policy
AnswerC

Conditional Access policies in Microsoft Entra ID provide the precise control needed to enforce requirements based on identity types. By configuring a policy to include the 'Guest or external users' identity type, administrators can specifically mandate multi-factor authentication (MFA) solely for B2B collaboration guests and other external identities. This direct targeting ensures that internal users are not affected, thereby accurately meeting the requirement to enforce MFA exclusively for external users.

Why this answer

Conditional Access allows targeting the 'Guest or external users' identity type, which enables MFA enforcement exclusively for external guest users without affecting internal employees. This setting leverages the user type attribute in Microsoft Entra ID to differentiate between internal and external identities, providing granular control over authentication requirements.

Exam trap

The trap here is that candidates often confuse exclusion-based approaches (like excluding internal users by group) with direct targeting of guest identity types, leading them to choose Option B instead of the more precise and scalable Option C.

Why the other options are wrong

A

This option applies MFA to all users, including internal employees, which contradicts the requirement to enforce MFA only for external guest users.

B

Excluding internal users by group does not specifically target external guest users; it would still require MFA for all other users, including guests, but the question asks for MFA only for external guests, not all users.

D

Identity Protection's user risk policy requires Azure AD Premium P2 and evaluates sign-in risk, not user type. It cannot target only external guest users for MFA enforcement.

When would these options actually be correct?

A

In a scenario where the company requires MFA for all users regardless of identity type, such as a security policy mandating MFA for every sign-in to protect against credential theft.

B

If the requirement were to enforce MFA for all users except a specific group of internal employees (e.g., IT admins), then excluding that group by group membership would be correct.

D

A question asks: 'A company wants to block sign-ins for users with compromised credentials detected by Microsoft. Which policy should be configured?' Then Identity Protection's user risk policy would be correct.

Why candidates pick the wrong answer

A

Candidates may think requiring MFA for all users is simpler and still covers external users, overlooking the need to exclude internal employees as specified.

B

Candidates may think that excluding internal users by group is a straightforward way to exempt them, but they overlook that the policy would still apply to all other users, including guests, which is not the desired outcome.

D

Candidates may confuse risk-based policies with identity-based targeting, assuming user risk policy can be scoped to guest users only.

1109
MCQeasy

A company uses Azure virtual machines for a production database. The security team wants to minimize the attack surface by blocking all inbound RDP (port 3389) traffic. However, administrators occasionally need to connect for maintenance. The team needs a solution that allows administrators to request temporary access to the RDP port, which is automatically revoked after a specified time. Which Microsoft Defender for Cloud feature should they use?

A.Adaptive application controls
B.Just-in-time (JIT) VM access
C.File Integrity Monitoring (FIM)
D.Security alerts
AnswerB

Just-in-time (JIT) VM access is a crucial security feature in Azure Defender for Cloud that significantly reduces the attack surface of virtual machines. It achieves this by locking down inbound network traffic to VMs, typically via Network Security Groups (NSGs), allowing only authorized users to request temporary, time-limited access to specific ports. This access is automatically revoked after a configurable duration, ensuring that ports are only open precisely when needed, thereby minimizing exposure for production database VMs.

Why this answer

Just-in-time (JIT) VM access is the correct feature because it specifically addresses the need to block inbound RDP (port 3389) traffic by default while allowing administrators to request temporary, time-bound access. When a request is approved, JIT dynamically modifies the network security group (NSG) to open the port for a specified duration, then automatically reverts the rule to deny all inbound traffic after the time expires. This directly minimizes the attack surface by eliminating persistent open management ports.

Exam trap

The trap here is that candidates may confuse 'just-in-time VM access' with 'adaptive application controls' because both are Defender for Cloud features that involve 'control' and 'access,' but JIT specifically manages network port access while adaptive controls manage application execution.

How to eliminate wrong answers

Option A is wrong because Adaptive application controls are used to create allowlists for applications running on Azure VMs, controlling which executables can run, not for managing network port access. Option C is wrong because File Integrity Monitoring (FIM) monitors changes to critical files, registries, and system configurations, not network traffic or port access. Option D is wrong because Security alerts are notifications generated by Defender for Cloud when threats are detected, not a mechanism to grant or revoke temporary network access.

1110
MCQeasy

A security administrator is explaining the shared responsibility model to a new team member. The company uses a Software-as-a-Service (SaaS) application such as Microsoft 365. For which of the following items is the customer primarily responsible under this model?

A.Physical security of the data center hosting the SaaS application
B.Patching the hypervisor that runs the SaaS infrastructure
C.Managing user access and classifying data stored in the service
D.Applying security updates to the SaaS application itself
AnswerC

Managing user access and classifying data stored within the SaaS application are critical customer responsibilities. The customer defines who can access their organizational data, what permissions they have, and how sensitive that data is, directly impacting data governance and compliance. This ensures that customer-specific information remains secure and properly handled according to internal policies and regulatory mandates.

Why this answer

In the shared responsibility model for SaaS like Microsoft 365, the customer is responsible for managing user access (e.g., configuring Azure AD roles, conditional access policies, and multi-factor authentication) and classifying data stored in the service (e.g., applying sensitivity labels via Microsoft Purview Information Protection). The provider manages the underlying infrastructure, including physical security, hypervisor patching, and application updates.

Exam trap

The trap here is that candidates often confuse operational tasks like patching or physical security with customer responsibilities, failing to recognize that in SaaS the provider handles all infrastructure and application maintenance, leaving only identity and data governance to the customer.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is the sole responsibility of the cloud provider (Microsoft) in the SaaS model; the customer has no physical access or control. Option B is wrong because patching the hypervisor is an infrastructure-layer task managed entirely by the provider, as the customer only interacts with the application layer. Option D is wrong because applying security updates to the SaaS application itself is performed by the provider; the customer is only responsible for configuring application-level settings and managing their own data.

1111
MCQmedium

A company wants to protect its employees from phishing attacks delivered via email. The solution must analyze all URLs embedded in incoming emails in real-time. If a URL points to a known malicious site, the link should be blocked at the time of click. Additionally, the solution should sandbox URLs in attachments and provide time-of-click verification. Which Microsoft security solution should they implement?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Cloud App Security
AnswerB

Microsoft Defender for Office 365 provides Safe Links, which rewrites and scans URLs at time of click, blocking known malicious destinations in real time. It also detonates URLs within attachments in a sandbox before delivery, satisfying the stem's requirement for both time-of-click verification and attachment sandboxing.

Why this answer

Microsoft Defender for Office 365 (MDO) is the correct solution because it provides Safe Links, which performs real-time URL scanning and time-of-click verification for URLs embedded in email messages and attachments. It also includes Safe Attachments, which detonates attachments in a sandbox environment to analyze embedded URLs. These capabilities directly address the requirement to block malicious links at click time and sandbox URLs in attachments.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud Apps (a CASB) with Defender for Office 365, because both have 'Defender' in the name and offer cloud security, but only Defender for Office 365 includes the specific Safe Links and Safe Attachments features required for email phishing protection.

Why the other options are wrong

A

Microsoft Defender for Cloud Apps focuses on shadow IT discovery and cloud app governance, not on email-level URL analysis or time-of-click verification for phishing protection.

C

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., PCs, servers) and does not provide real-time URL analysis or sandboxing for email attachments. The question specifically requires email protection and time-of-click verification, which is outside Defender for Endpoint's scope.

D

Microsoft Cloud App Security (now part of Defender for Cloud Apps) is a CASB for controlling cloud app access and data, not for real-time URL analysis and sandboxing of email attachments. The question specifically requires email protection features like time-of-click verification and attachment sandboxing, which are provided by Defender for Office 365.

When would these options actually be correct?

A

A company wants to discover and control the use of unsanctioned cloud apps, enforce data loss prevention policies across cloud services, and protect against malicious OAuth apps. In that scenario, Microsoft Defender for Cloud Apps would be the correct answer.

C

A company needs to protect its endpoints from malware and advanced threats. The solution must provide antivirus, endpoint detection and response (EDR), and automated investigation on devices. In this scenario, Microsoft Defender for Endpoint would be the correct answer.

D

This option would be correct if the question asked about discovering and controlling the use of third-party cloud apps, enforcing data loss prevention policies for cloud storage, or detecting anomalous behavior in cloud applications (e.g., unusual file downloads from Salesforce).

Why candidates pick the wrong answer

A

Candidates may confuse 'cloud apps' with email protection, or assume that any security solution from Microsoft can handle phishing, overlooking the specific email-focused capabilities of Defender for Office 365.

C

Candidates may confuse the broad 'Defender' branding, assuming all Defender products offer similar email protection, or they may think endpoint security includes email scanning because email clients run on endpoints.

D

Candidates may confuse Cloud App Security with email security because both involve threat protection, or they might think 'cloud' includes email (Exchange Online) and assume it covers phishing, not realizing Defender for Office 365 is the dedicated email security solution.

1112
MCQeasy

A healthcare organization stores sensitive patient records in a cloud database. The database is encrypted at rest using AES-256. If an attacker gains access to the physical storage media, they cannot read the data. Which security concept does this encryption primarily provide?

A.Confidentiality
B.Integrity
C.Availability
D.Authorization
AnswerA

Encryption is a primary control for ensuring confidentiality by transforming data into an unreadable format, known as ciphertext. This process prevents unauthorized individuals from accessing or understanding the sensitive patient records, even if they manage to intercept or steal the encrypted data. Only authorized parties possessing the correct decryption key can revert the data to its original, readable form, thereby protecting against unauthorized disclosure.

Why this answer

Encryption at rest using AES-256 ensures that data stored on physical media is unreadable without the decryption key. If an attacker gains physical access to the storage media, the ciphertext cannot be deciphered, directly protecting the secrecy of the data. This aligns with the security goal of confidentiality, which prevents unauthorized disclosure of information.

Exam trap

The trap here is that candidates confuse encryption at rest with integrity controls, mistakenly thinking encryption prevents modification, when in fact encryption only ensures confidentiality and does not provide tamper detection.

Why the other options are wrong

B

Encryption at rest protects data from being read, which is a confidentiality concern, not integrity. Integrity ensures data is not tampered with, but encryption alone does not prevent modification.

C

Encryption at rest protects data from being read, which is a confidentiality concern, not availability. Availability ensures data is accessible when needed, which encryption does not directly address.

D

Authorization controls who can access the data, but encryption at rest protects data from being read even if physical access is gained. The question asks about reading data from physical media, which is a confidentiality issue, not authorization.

When would these options actually be correct?

B

A question asking which security concept is provided by hashing or digital signatures to ensure data has not been altered during transmission or storage would make integrity the correct answer.

C

In a question about ensuring that a cloud database remains accessible during a DDoS attack, the correct answer would be availability, as it focuses on uptime and access despite disruptions.

D

A question like 'Which security concept is enforced by requiring a user to authenticate before accessing a database?' would make Authorization correct, as it involves granting or denying access based on identity.

Why candidates pick the wrong answer

B

Candidates may confuse encryption with integrity because both involve cryptographic techniques, but encryption primarily protects confidentiality, while integrity is about detecting unauthorized changes.

C

Candidates may confuse encryption with overall security, thinking it contributes to availability by preventing data loss from theft, but encryption primarily protects confidentiality, not system uptime.

D

Candidates may confuse encryption with access control, thinking that encryption 'authorizes' only certain users to read data, but encryption primarily ensures confidentiality, not authorization.

1113
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Purview DLP policy configuration for a compliance team. What is the effect of this policy?

A.The policy blocks access but allows users to override with a justification
B.The policy automatically applies encryption to the content
C.The policy sends a notification but does not block access
D.The policy automatically blocks access without user override
AnswerA

This policy action, often referred to as 'Block with override' in Microsoft Purview Data Loss Prevention (DLP) configurations, is designed to prevent sensitive data from being shared inappropriately. However, it provides a crucial flexibility: users are prompted to provide a business justification if they believe their action is legitimate, allowing them to bypass the block. This approach balances stringent data protection with operational continuity, empowering users to make informed decisions when necessary.

Why this answer

The policy includes a BlockAccess action with behavior set to BlockWithOverride, meaning the action is blocked by default but the user can override with a business justification. Additionally, the NotifyUser action sends a custom notification to the user. This matches Option A.

Option B is incorrect because there is no encryption action configured. Option C is incorrect because the policy does block access (with override), not just send a notification. Option D is incorrect because the policy allows user override, so it does not automatically block without override.

1114
MCQmedium

A company wants to discover which cloud applications are being used by employees, assess the risk of those apps, and control data sharing in sanctioned apps like Box or Dropbox. Which Microsoft security solution should they implement?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Office 365
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Cloud Apps provides Cloud Discovery to identify shadow IT apps, risk scoring, and app governance controls including session and data-sharing policies for sanctioned services like Box and Dropbox, matching the discovery, assessment, and control requirements.

Why this answer

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility into shadow IT by discovering cloud app usage, assessing risk based on over 80 risk factors, and enforcing data loss prevention (DLP) policies to control data sharing in sanctioned apps like Box or Dropbox. It integrates with cloud providers via API connectors to monitor and govern data in real time.

Exam trap

The trap here is confusing the CASB functionality of Defender for Cloud Apps with the endpoint-focused or email-specific protections of other Defender products, leading candidates to pick Defender for Office 365 because it also controls data sharing, but only within Microsoft 365, not third-party apps like Box or Dropbox.

Why the other options are wrong

A

Microsoft Defender for Endpoint focuses on endpoint device protection (antivirus, threat detection, and response), not on discovering cloud app usage, assessing app risk, or controlling data sharing in sanctioned cloud apps like Box or Dropbox.

C

Microsoft Defender for Office 365 focuses on protecting email and collaboration tools like Exchange, SharePoint, and Teams from threats such as phishing and malware, not on discovering and controlling cloud app usage or assessing app risk.

D

Microsoft Defender for Identity focuses on detecting and investigating advanced attacks on on-premises Active Directory, not on discovering or controlling cloud app usage or data sharing in sanctioned apps like Box or Dropbox.

When would these options actually be correct?

A

A company wants to protect its endpoints (e.g., laptops, servers) from malware, detect advanced threats, and provide incident response capabilities. Which Microsoft solution should they implement?

C

This option would be correct if the question asked about protecting against email-based threats, such as phishing attacks, malware in attachments, or malicious links in Office 365, or securing SharePoint and OneDrive from malicious content.

D

This option would be correct in a scenario where the company needs to protect on-premises identities from advanced threats like Pass-the-Hash, Kerberos Golden Ticket attacks, or suspicious lateral movement, especially in a hybrid environment with Active Directory.

Why candidates pick the wrong answer

A

Candidates may confuse 'Defender' branding and assume all Defender products cover cloud app security, or they may think endpoint protection includes monitoring cloud app usage on devices.

C

Candidates may confuse the cloud app discovery and data control capabilities of Defender for Cloud Apps with the Office 365 security features, assuming that Office 365 security covers all cloud app usage since Office 365 is a cloud suite.

D

Candidates may confuse identity protection with cloud app security, assuming that securing identities automatically controls cloud app usage, or they may think Defender for Identity covers all Microsoft security solutions broadly.

1115
MCQmedium

A company's security operations team needs to centralize security log collection from multiple sources including on-premises firewalls, AWS CloudTrail, and Azure Active Directory sign-in logs. They want to use built-in analytics to detect threats across all data sources and create automated response playbooks, such as isolating a compromised user account when a specific attack pattern is detected. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft 365 Defender
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is explicitly designed for centralizing security data from virtually any source, including Microsoft services, on-premises infrastructure, and other cloud providers. This enables comprehensive threat detection through AI and machine learning, alongside automated responses to security incidents across the entire enterprise.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) solution that ingests logs from diverse sources (on-premises firewalls via Syslog, AWS CloudTrail via REST API, and Azure AD via diagnostic settings) and provides built-in analytics rules to detect threats across all data. It also integrates with Azure Logic Apps to create automated playbooks (e.g., isolating a compromised user account) triggered by detected attack patterns, fulfilling the requirement for centralized log collection and automated response.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM for multi-source log ingestion and automated response) with Microsoft 365 Defender (an XDR for Microsoft ecosystem threats), failing to recognize that only Sentinel can ingest third-party logs like on-premises firewalls and AWS CloudTrail for centralized threat detection and playbook automation.

Why the other options are wrong

A

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that focuses on securing cloud resources, not on centralizing security logs from multiple sources (including on-premises) with built-in SIEM analytics and automated response playbooks.

C

Microsoft 365 Defender is designed to protect Microsoft 365 workloads (e.g., email, endpoints, identities) and does not natively ingest third-party logs like AWS CloudTrail or on-premises firewalls, nor does it provide centralized SIEM capabilities for multi-source log collection and custom automated playbooks.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on shadow IT discovery and controlling access to cloud apps, not a centralized SIEM/SOAR for multi-source log collection and automated threat response.

When would these options actually be correct?

A

A company wants to assess and improve the security posture of their Azure, AWS, and GCP workloads, get recommendations for hardening, and protect against cloud-specific threats like misconfigurations and vulnerabilities. They need a solution that provides unified visibility and threat protection across cloud environments.

C

A company wants to unify detection and response across Microsoft 365 services (Exchange, SharePoint, Teams, endpoints) and use built-in automated investigation and remediation for threats like phishing or malware, without needing to ingest non-Microsoft logs or create custom playbooks.

D

A company wants to discover and control the use of unsanctioned cloud apps (shadow IT), enforce data loss prevention policies for cloud applications, and get visibility into user activities across SaaS apps like Office 365, Salesforce, or AWS.

Why candidates pick the wrong answer

A

Candidates may confuse Defender for Cloud's multi-cloud support and threat detection capabilities with the centralized log collection and SIEM/SOAR features of Sentinel, especially since both involve security monitoring and analytics.

C

Candidates may confuse Microsoft 365 Defender's security analytics and automation features with Sentinel's SIEM capabilities, or assume that 'Defender' products cover all security needs, overlooking the requirement for multi-source log ingestion and custom playbooks.

D

Candidates may confuse Defender for Cloud Apps with a general security analytics tool because its name includes 'Defender' and it deals with cloud logs, but it lacks the centralized SIEM and SOAR capabilities of Sentinel.

1116
Matchingmedium

Match each Microsoft identity service to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cloud-based identity and access management

Directory service for Windows domain networks

Collaboration with external partners

Customer identity and access management for apps

Integration of on-premises AD with Azure AD

Why these pairings

Microsoft identity services include Azure AD (cloud IAM), Azure AD DS (managed domain services), and Azure AD B2C (customer IAM). Common confusions involve swapping descriptions of Azure AD with on-premises AD and Azure AD DS with Azure AD B2B.

1117
MCQeasy

A company has a SharePoint Online site that stores project documents. Due to legal requirements, all documents in this site must be retained for exactly 5 years from the date they were created, and then automatically deleted. No user should be able to permanently delete a document before the retention period ends. Which Microsoft Purview solution should the administrator configure?

A.Retention policy
B.Sensitivity label
C.Data loss prevention (DLP) policy
D.Audit policy
AnswerA

A retention policy in Microsoft Purview allows administrators to set a retention period (e.g., 5 years) and an action (such as automatic deletion) for content in SharePoint sites. Users cannot permanently delete the content until the retention period expires.

Why this answer

A retention policy in Microsoft Purview can be configured to retain documents for exactly 5 years from creation and then automatically delete them. This policy enforces a mandatory retention period that prevents users from permanently deleting documents before the period ends, meeting the legal requirement.

Exam trap

The trap here is that candidates may confuse a retention policy with a sensitivity label or DLP policy, mistakenly thinking those can enforce time-based retention and deletion, when only a retention policy provides the necessary preservation lock and automatic deletion capabilities.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption, markings), but they do not enforce time-based retention or automatic deletion. Option C is wrong because a Data Loss Prevention (DLP) policy detects and prevents accidental sharing of sensitive data, but it cannot enforce a fixed retention period or block permanent deletion. Option D is wrong because an audit policy logs user activities (e.g., deletions) for investigation, but it does not prevent deletion or enforce retention.

1118
MCQeasy

A user is locked out of their account due to multiple failed sign-in attempts. Which Microsoft Entra ID feature can automatically block suspicious sign-in attempts based on risk?

A.Self-Service Password Reset (SSPR)
B.Microsoft Entra ID Governance
C.Microsoft Entra ID Protection
D.Conditional Access
AnswerC

Microsoft Entra ID Protection is specifically designed to detect, report, and automatically remediate identity-based risks, such as unusual sign-in locations, impossible travel, and multiple failed sign-in attempts. It leverages machine learning to identify suspicious activities and can configure policies to automatically block access or enforce multi-factor authentication (MFA) when a user's risk level is deemed high. This capability directly addresses the scenario of an account lockout due to multiple failed sign-ins by identifying and responding to the underlying risk.

Why this answer

Microsoft Entra ID Protection uses machine learning and heuristic algorithms to detect and automatically block suspicious sign-in attempts based on risk signals such as anonymous IP addresses, atypical travel, or leaked credentials. When a user is locked out due to multiple failed attempts, Entra ID Protection can evaluate the sign-in risk and enforce a block or require multi-factor authentication before allowing access.

Exam trap

The trap here is that candidates often confuse Conditional Access with risk-based blocking, but Conditional Access is the policy engine that enforces the block, while Entra ID Protection is the service that actually detects and assesses the risk to trigger the automatic block.

How to eliminate wrong answers

Option A is wrong because Self-Service Password Reset (SSPR) allows users to unlock their accounts or reset passwords after being locked out, but it does not proactively block suspicious sign-in attempts based on risk. Option B is wrong because Microsoft Entra ID Governance focuses on managing identity lifecycles, access reviews, and entitlement management, not on detecting or blocking risky sign-in events. Option D is wrong because Conditional Access enforces policies based on conditions like location or device compliance after a sign-in attempt is made, but it does not inherently analyze risk signals to automatically block suspicious attempts; it typically relies on risk assessments from Entra ID Protection.

1119
MCQeasy

A company hosts a mission-critical customer portal on Azure virtual machines. To ensure continuous availability, they deploy the application across two separate Azure regions. If one region experiences a failure, traffic is automatically routed to the other region with minimal disruption. Which security goal is primarily being addressed by this architecture?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerC

Deploying a mission-critical customer portal across multiple Azure regions with automatic failover directly addresses the 'A' in the CIA triad: Availability. This strategy ensures that the portal remains continuously accessible and operational for authorized users, even if an entire geographic region experiences a catastrophic outage. The primary objective is to minimize downtime and provide uninterrupted service, which is paramount for mission-critical systems.

Why this answer

Deploying a mission-critical application across two Azure regions with automatic traffic routing directly addresses the security goal of availability. This architecture ensures that if one region fails, the application remains accessible from the other region, minimizing downtime. Azure Traffic Manager or Azure Front Door can be used to route traffic based on priority or latency, providing high availability and disaster recovery.

Exam trap

The trap here is that candidates may confuse high availability (availability goal) with disaster recovery or think that multi-region deployment primarily protects data confidentiality or integrity, when in fact it is designed to ensure continuous service uptime.

Why the other options are wrong

A

Confidentiality ensures data is accessible only to authorized users, but the described architecture focuses on maintaining service uptime across regions, which is a core availability concern.

B

Integrity ensures data is not tampered with, but the scenario describes deploying across regions for automatic failover, which directly addresses availability, not integrity.

D

Non-repudiation ensures that actions or transactions cannot be denied by the parties involved, typically through digital signatures or audit logs. The scenario describes a multi-region deployment for failover, which directly addresses availability, not non-repudiation.

When would these options actually be correct?

A

A question describing encryption of customer data at rest and in transit, or implementing access controls to prevent unauthorized disclosure, would make confidentiality the correct answer.

B

Integrity would be correct if the question described a scenario where the company uses Azure SQL Database with transparent data encryption (TDE) or Azure Storage with immutable blobs to prevent unauthorized modification of customer data.

D

An exam question might ask: 'A company needs to ensure that customers cannot deny having placed orders on an e-commerce site. Which security goal is primarily addressed by implementing digital signatures on order confirmations?' In that context, non-repudiation would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse high-availability architectures with security measures, mistakenly thinking that ensuring continuous access also protects data secrecy.

B

Candidates may confuse high availability with data protection, thinking that replicating data across regions also ensures its integrity, but integrity is about preventing unauthorized changes, not uptime.

D

Candidates may confuse non-repudiation with high availability or disaster recovery, thinking that ensuring service continuity also prevents denial of actions, but non-repudiation is about accountability and proof, not uptime.

1120
MCQhard

You are investigating an alert in Microsoft 365 Defender. The KQL query in the exhibit retrieves evidence for alert-5678. What type of entities does this query filter for?

A.Registry entities
B.Process entities
C.Network entities
D.File entities
AnswerD

This option is correct because the KQL query explicitly includes the condition `EntityType == 'File'`, which is designed to retrieve data specifically related to file system events. This filter ensures that the investigation focuses on activities such as file creation, modification, deletion, or access attempts on endpoints. Therefore, the alert evidence being examined directly corresponds to file entities within the Microsoft 365 Defender data schema, making this the appropriate choice.

Why this answer

The KQL query filters for evidence related to alert-5678 by specifying a hash value (SHA256) of a file. In Microsoft 365 Defender, file entities are uniquely identified by their hash values, such as SHA256, SHA1, or MD5. The query uses the `where` clause to match the specific file hash, confirming that the filtered entities are file entities.

Exam trap

The trap here is that candidates may confuse file hash filtering with process or network entity identification, but Microsoft 365 Defender uses distinct identifiers (SHA256 for files, PID for processes, IP/URL for network) that are explicitly tied to the entity type in the schema.

How to eliminate wrong answers

Option A is wrong because registry entities are identified by registry key paths and values, not by file hashes like SHA256. Option B is wrong because process entities are identified by process IDs (PIDs) or process names, not by file hashes. Option C is wrong because network entities are identified by IP addresses, URLs, or domain names, not by file hashes.

1121
MCQeasy

Your organization uses Microsoft Entra ID. You need to enforce multi-factor authentication (MFA) for all users accessing the company's financial application. Which security feature should you use?

A.Security defaults
B.Privileged Identity Management
C.Identity Protection
D.Conditional Access
AnswerD

Microsoft Entra Conditional Access is a powerful policy engine that allows organizations to enforce specific access requirements based on various conditions, including user identity, device state, location, and application being accessed. By configuring a Conditional Access policy, administrators can precisely target individual cloud applications and mandate multi-factor authentication as a grant control for access, thereby meeting the requirement to enforce MFA per application. This granular control ensures security without unnecessarily impacting all users or applications.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA specifically for the financial application by targeting the application in the policy. This provides granular control over authentication requirements based on conditions such as user, location, device state, and application, which is exactly what is needed to secure a specific app.

Exam trap

The trap here is that candidates confuse Identity Protection's risk-based policies with direct MFA enforcement, but Identity Protection only provides risk signals and requires Conditional Access to act on them.

How to eliminate wrong answers

Option A is wrong because Security defaults enforce MFA for all users across all applications, not just the financial application, and cannot be scoped to a single app. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time access for privileged roles, not MFA enforcement for application access. Option C is wrong because Identity Protection detects risks and can trigger MFA via Conditional Access, but it does not directly enforce MFA; it provides risk signals that Conditional Access policies use.

1122
MCQmedium

A company needs to ensure that employees cannot share sensitive financial reports with external parties via email. They want to automatically detect and block emails that contain the phrase 'Confidential-Financial' in the subject line or body, regardless of the recipient's domain. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP)
B.Information Protection (sensitivity labels)
C.Data Lifecycle Management (retention policies)
D.Audit
AnswerA

Data Loss Prevention in Microsoft Purview inspects email content and can detect the phrase 'Confidential-Financial' in the subject or body, then block or restrict the message regardless of recipient domain. This satisfies the requirement to stop external sharing automatically.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and automatically block sensitive content—such as the phrase 'Confidential-Financial'—in emails, regardless of the recipient's domain. DLP policies can inspect subject lines and body text, then enforce actions like blocking delivery or notifying the user, making it ideal for preventing unauthorized external sharing of financial reports.

Exam trap

The trap here is that candidates confuse Information Protection (sensitivity labels) with DLP, thinking labels alone can block emails, but labels only classify and encrypt—blocking requires a DLP policy to enforce actions based on label conditions or content matches.

How to eliminate wrong answers

Option B (Information Protection/sensitivity labels) is wrong because sensitivity labels classify and protect data by applying encryption or visual markings, but they do not automatically detect and block emails based on content patterns like a specific phrase; they require manual or automated labeling and rely on DLP to enforce blocking actions. Option C (Data Lifecycle Management/retention policies) is wrong because retention policies govern how long data is kept or when it is deleted, not real-time detection and blocking of sensitive content in transit. Option D (Audit) is wrong because auditing logs user activities for review but does not actively detect or block emails; it is a detective control, not a preventive one.

1123
MCQeasy

A company uses Microsoft 365. The compliance team needs to create a policy that automatically blocks outgoing emails that contain personally identifiable information (PII) such as social security numbers. However, they want to allow users to override the block with a business justification if necessary. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP)
B.Communication Compliance
C.Records Management
D.Audit
AnswerA

Data Loss Prevention (DLP) in Microsoft 365 is specifically designed to identify, monitor, and protect sensitive information across various locations, including email, SharePoint, and OneDrive. It uses sensitive information types (SITs) to detect data like credit card numbers or PII, allowing organizations to define policies that block sharing, encrypt content, or notify users and administrators. This capability directly addresses the need to prevent accidental or malicious sharing of sensitive data, often providing user override options for legitimate business cases.

Why this answer

Data Loss Prevention (DLP) in Microsoft Purview is designed to detect and protect sensitive information, such as social security numbers, by automatically blocking outgoing emails that contain PII. DLP policies support user override with a business justification through policy tips and allow overrides, enabling compliance teams to balance security with business needs.

Exam trap

The trap here is that candidates confuse Communication Compliance with DLP because both involve monitoring communications, but Communication Compliance is for policy violations and insider risk, not for automated blocking of sensitive data with user overrides.

Why the other options are wrong

B

Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, insider trading), not to automatically block outgoing emails containing PII with user override capabilities.

C

Records Management focuses on managing retention, disposition, and classification of records, not on preventing data leakage via email. It does not provide the ability to block outgoing emails containing PII or allow user overrides.

D

Audit in Microsoft Purview is used for logging and reviewing user and admin activities, not for creating policies that block or allow emails based on content like PII.

When would these options actually be correct?

B

A company needs to monitor employee communications for policy violations (e.g., offensive language or sharing confidential information) and allow managers to review and take action. The question would specify detecting and remediating communication risks rather than blocking data exfiltration.

C

A company needs to automatically apply retention labels to emails containing specific keywords and ensure they are retained for a regulatory period. Records Management would be the correct solution for defining retention policies and labels.

D

An organization needs to investigate a specific data breach by reviewing detailed logs of who accessed sensitive files and when. Audit would be the correct solution to enable and search the audit log for relevant events.

Why candidates pick the wrong answer

B

Candidates may confuse Communication Compliance with DLP because both deal with email content and compliance, but Communication Compliance focuses on human behavior monitoring rather than automated data protection.

C

Candidates may confuse Records Management with data governance or mistakenly think it includes data loss prevention capabilities, especially since both involve policies and sensitive data classification.

D

Candidates may confuse Audit with monitoring or compliance solutions, thinking that auditing can enforce policies, but it only provides visibility after the fact, not real-time control.

1124
MCQeasy

Your company wants to allow partners to use their own corporate credentials to access a specific SharePoint site. Which Microsoft Entra ID feature supports this?

A.App Registrations
B.B2C collaboration
C.Device Registration
D.B2B collaboration
AnswerD

Microsoft Entra B2B collaboration is the correct solution, enabling organizations to securely share applications and resources with external users from partner companies. It allows these invited guest users to sign in using their existing corporate credentials from their home directory (e.g., another Microsoft Entra tenant, a federated identity provider, or even social identities), eliminating the need for partners to create new accounts in the inviting tenant. This streamlines access while maintaining security and partner identity management.

Why this answer

Microsoft Entra ID B2B (business-to-business) collaboration allows you to invite external users from partner organizations to access your company's resources, such as SharePoint sites, using their own corporate credentials. This feature supports identity federation with the partner's Azure AD or other identity providers, enabling seamless single sign-on (SSO) without requiring the partner users to create new accounts in your tenant.

Exam trap

The trap here is that candidates often confuse B2B collaboration (for partner organizations with existing corporate identities) with B2C collaboration (for consumers using social or local accounts), leading them to select the wrong option when the question specifies 'partners' and 'corporate credentials'.

How to eliminate wrong answers

Option A is wrong because App Registrations are used to register and configure applications that integrate with Microsoft Entra ID for authentication and authorization, not to grant external users access to resources like SharePoint. Option B is wrong because B2C collaboration (Azure AD B2C) is designed for customer-facing applications where users sign up with social or local identities, not for partner organizations using their corporate credentials. Option C is wrong because Device Registration is used to register devices (e.g., Windows, iOS, Android) for management and conditional access policies, not to enable external user access to SharePoint.

1125
MCQmedium

A company uses Microsoft Entra ID and Intune to manage devices. They want to enforce a policy that allows access to financial data from SharePoint Online only when the user's device is compliant (e.g., encrypted, patched) AND the user authenticates from a trusted IP address range. Additionally, if the sign-in risk is assessed as medium or high by Identity Protection, the user must also perform multifactor authentication (MFA). Which Conditional Access components should the administrator configure?

A.Configure conditions for sign-in risk and locations, and use Grant controls to require MFA and device compliance.
B.Configure a session control to require device compliance and an assignment for sign-in risk to trigger MFA.
C.Use Microsoft Entra ID Protection to automatically enforce MFA and device compliance for all users regardless of location.
D.Configure a compliance policy in Intune and link it directly to SharePoint Online to block non-compliant devices.
AnswerA

This correctly identifies that conditions (sign-in risk and locations) are used to define when the policy applies, and Grant controls enforce the requirements. The Grant control 'Require all the selected controls' can combine device compliance and MFA.

Why this answer

Conditional Access in Microsoft Entra ID allows combining multiple conditions (sign-in risk, locations) with grant controls (require MFA, require device compliance) to enforce the described policy. The administrator configures conditions for sign-in risk (medium/high) and locations (trusted IP range), then uses Grant controls to require MFA and device compliance, ensuring access is allowed only when all requirements are met.

Exam trap

The trap here is confusing session controls with grant controls, leading candidates to incorrectly select Option B, which misassigns device compliance as a session control instead of a grant control.

How to eliminate wrong answers

Option B is wrong because session controls (e.g., app enforced restrictions) cannot require device compliance; device compliance is a grant control, not a session control, and sign-in risk is a condition, not an assignment. Option C is wrong because Microsoft Entra ID Protection does not automatically enforce MFA and device compliance for all users regardless of location; it provides risk detection but relies on Conditional Access policies to apply controls. Option D is wrong because Intune compliance policies cannot be linked directly to SharePoint Online to block non-compliant devices; they require Conditional Access to enforce access restrictions based on compliance status.

Page 14

Page 15 of 18

Page 16