Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 1126–1200

1279 questions total · 18pages · All types, answers revealed

Page 15

Page 16 of 18

Page 17
1126
MCQmedium

A company needs to retain all customer emails for 7 years for regulatory compliance. After 7 years, they must be permanently deleted. They also need a legal hold for an ongoing investigation. Which Microsoft Purview solution should they use for the retention and deletion requirement?

A.Data Lifecycle Management
B.Records Management
C.Compliance Manager
D.eDiscovery
AnswerA

Data Lifecycle Management (DLM), specifically through Microsoft 365 retention policies, is designed to automatically manage content throughout its lifecycle. These policies can be configured to retain emails for a specified duration, such as seven years, to meet regulatory compliance requirements. After the retention period expires, DLM policies can then automatically initiate the deletion of that content, ensuring compliance with both retention and disposal obligations without manual intervention. This directly addresses the need for automatic retention and subsequent deletion of customer emails.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview is the correct solution because it allows you to define retention policies that automatically retain customer emails for a specified period (7 years) and then permanently delete them. This directly addresses the regulatory compliance requirement for retention and deletion without manual intervention.

Exam trap

The trap here is that candidates often confuse Records Management with Data Lifecycle Management, thinking that 'records' implies retention and deletion, but Records Management is specifically for declaring items as records with immutable preservation, not for automated lifecycle-based retention and deletion.

How to eliminate wrong answers

Option B (Records Management) is wrong because it focuses on declaring records for long-term preservation and disposition, not on automated lifecycle-based retention and deletion for compliance; it is more about managing records as evidence. Option C (Compliance Manager) is wrong because it is a risk assessment and compliance score tool that helps track compliance posture, not a solution for implementing data retention or deletion policies. Option D (eDiscovery) is wrong because it is used for searching and exporting content for legal investigations, not for setting retention or deletion rules; it can place holds but does not manage lifecycle deletion.

1127
MCQmedium

A company must retain all vendor contracts for 10 years to meet regulatory requirements. After 10 years, the contracts must be permanently destroyed with no possibility of recovery. The compliance team wants to automate this lifecycle and ensure that during the retention period, the contracts cannot be edited or deleted by users. Which Microsoft Purview solution should they use?

A.Data Lifecycle Management (DLM)
B.Records Management
C.eDiscovery (Premium)
D.Sensitivity Labels
AnswerB

Microsoft Purview Records Management is specifically designed for regulatory, legal, and business-critical recordkeeping, ensuring content immutability. It utilizes retention labels to classify items as records, which prevents their modification or deletion for a specified period, such as 10 years for vendor contracts. This capability is crucial for meeting strict retention requirements and supporting automated disposition reviews, ensuring compliance with organizational and legal obligations.

Why this answer

Records Management in Microsoft Purview is designed to declare records (regulatory or legal) that must be retained for a specific period and then disposed of in a compliant manner. It enforces immutability during the retention period—users cannot edit or delete records—and supports a disposition review or automatic permanent deletion after the retention period ends, exactly matching the requirement for 10-year retention followed by destruction with no recovery.

Exam trap

Microsoft often tests the distinction between Data Lifecycle Management (which manages non-record content) and Records Management (which enforces immutability and disposition for regulatory records), so the trap here is assuming DLM can provide the required edit/delete prevention and automatic destruction, when only Records Management offers those capabilities.

Why the other options are wrong

A

Data Lifecycle Management (DLM) manages retention and deletion of data but does not enforce immutability or prevent users from editing/deleting records during the retention period. The question requires that contracts cannot be edited or deleted, which is a records management feature.

When would these options actually be correct?

A

A company needs to automatically delete old customer data after 5 years to comply with a data privacy law, but users can edit the data during the retention period. DLM would be the correct solution to set retention and deletion policies without requiring record-level restrictions.

Why candidates pick the wrong answer

A

Candidates may confuse DLM with Records Management because both handle retention and deletion, but DLM lacks the immutability and legal hold capabilities required for records that must be preserved unaltered.

1128
MCQhard

A large enterprise is concerned about insider threats. The compliance team needs to detect and investigate potential data theft scenarios, such as when employees nearing their resignation date suddenly copy large amounts of sensitive data to USB drives or email confidential files to personal accounts. They require a solution that uses machine learning to identify risky activities and create alerts for investigation. Which Microsoft Purview solution should they deploy?

A.Data Lifecycle Management
B.Audit (Premium)
C.Insider Risk Management
D.Compliance Manager
AnswerC

Insider Risk Management applies machine-learning analytics to signals such as mass file downloads, USB copy events and personal-email exfiltration, correlating them with HR data like resignation dates. It generates alerts and investigation cases, matching the compliance team's detection and investigation requirements.

Why this answer

Insider Risk Management is the correct solution because it uses machine learning to correlate signals from user activities (e.g., copying files to USB, emailing to personal accounts) with contextual indicators like resignation dates, enabling detection of potential data theft scenarios. It provides built-in alerting and investigation workflows specifically designed for insider threat use cases, unlike the other options which focus on retention, auditing, or compliance posture.

Exam trap

The trap here is that candidates often confuse Audit (Premium) with a detection solution, but Audit is purely a logging and search tool, not a proactive ML-based risk detection system like Insider Risk Management.

Why the other options are wrong

A

Data Lifecycle Management focuses on governing data retention and deletion policies, not on detecting insider threats or risky user behavior using machine learning.

D

Compliance Manager is a risk assessment tool that helps organizations evaluate their compliance posture against regulations, not a solution for detecting insider threats via machine learning on user activities.

When would these options actually be correct?

A

A question asking which solution to automatically retain or delete data based on regulatory requirements, such as implementing a policy to delete customer records after 7 years, would make Data Lifecycle Management the correct answer.

D

An organization needs to assess and improve its compliance posture against industry standards like GDPR or ISO 27001, and requires a dashboard to track remediation actions and control effectiveness.

Why candidates pick the wrong answer

A

Candidates may confuse data governance with security monitoring, assuming that managing data lifecycles includes preventing data theft, but the two are distinct functions.

D

Candidates may confuse 'compliance' in the name with the compliance team's need, or think Compliance Manager covers all compliance-related detection scenarios.

1129
MCQeasy

A company wants to allow employees to access corporate resources such as email and internal apps using their personal smartphones. The IT team does not want to fully manage or domain-join these devices but needs each device to have a simple identity that links the user's work account to the device. Which Microsoft Entra ID device identity option should they implement?

A.Microsoft Entra ID Registered
B.Microsoft Entra ID Joined
C.Hybrid Microsoft Entra ID Joined
D.Active Directory Joined
AnswerA

This option is specifically designed for Bring Your Own Device (BYOD) scenarios, allowing personal devices to establish a device identity in Microsoft Entra ID. It enables employees to securely access corporate resources, such as email and applications, through conditional access policies without the organization taking full management control of the device. The device is recognized and trusted, but not fully managed, making it ideal for personal devices.

Why this answer

Microsoft Entra ID Registered (formerly Azure AD Registered) provides a device identity for personal (BYOD) devices without requiring organizational domain join or full management. It links the user's work account to the device, enabling access to corporate resources via conditional access and Intune app protection policies. This matches the requirement of a simple identity for personal smartphones without full management.

Exam trap

SC-900 often tests the confusion between device join types; candidates may think 'Registered' means full management, but it is actually the lightest identity option for BYOD, while 'Joined' implies organizational ownership.

Why the other options are wrong

C

Hybrid Microsoft Entra ID Joined requires devices to be domain-joined and managed by on-premises AD with synchronization to Entra ID, which contradicts the requirement to avoid full management or domain-joining of personal smartphones.

D

Active Directory Joined requires devices to be domain-joined to an on-premises Active Directory, which involves full management and does not support personal smartphones that are not domain-joined. The question specifies that devices should not be fully managed or domain-joined.

When would these options actually be correct?

C

A company with on-premises Active Directory wants devices that are both domain-joined and registered in Entra ID for SSO and conditional access, while still being managed via Group Policy. The question would specify that devices are corporate-owned and need hybrid management.

D

A company has on-premises Windows computers that need to authenticate against on-premises Active Directory for access to network resources, and there is no requirement for cloud-based identity or device management.

Why candidates pick the wrong answer

C

Candidates may think 'Hybrid' implies a middle ground between registered and joined, or they may confuse it with the ability to support personal devices, not realizing it still requires domain join and full management.

D

Candidates may confuse Active Directory Joined with Microsoft Entra ID Joined, thinking that any device identity option that links a user account to a device must involve traditional domain joining, especially if they are more familiar with on-premises AD than cloud identity solutions.

1130
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Defender for Cloud Apps alert. Based on the evidence, which action should you take first?

A.Mark the alert as benign
B.Suspend the user account
C.Isolate the device immediately
D.Request file upload for analysis
AnswerD

Requesting a file upload for analysis is the most appropriate immediate next step for an unconfirmed file detection. This action allows security analysts to submit the suspicious file to advanced threat intelligence services, such as Microsoft Defender for Endpoint's cloud-based sandboxing or detonation chambers. These environments perform deep behavioral analysis, static analysis, and reputation checks to definitively determine if the file is malicious, benign, or potentially unwanted, providing crucial context for subsequent response actions.

Why this answer

The alert evidence shows a suspicious file upload activity, which could indicate a potential malware or data exfiltration attempt. Requesting file upload for analysis (Option D) is the correct first action because it allows Defender for Cloud Apps to perform deep content inspection and threat detection before taking any disruptive actions like suspending the user or isolating the device, ensuring that the response is proportionate and evidence-based.

Exam trap

The trap here is that candidates often jump to punitive actions like suspending the user or isolating the device, forgetting that Defender for Cloud Apps is a CASB designed for investigation and policy-based response, where the first step should always be to gather more evidence through file analysis.

How to eliminate wrong answers

Option A is wrong because marking the alert as benign would dismiss the suspicious activity without investigation, potentially allowing a real threat to persist. Option B is wrong because suspending the user account is a severe action that should only be taken after confirming malicious intent through analysis, not as a first step based solely on a file upload alert. Option C is wrong because isolating the device immediately is an extreme containment measure typically reserved for confirmed endpoint compromise, and it bypasses the need to first analyze the file to determine if it is actually malicious.

1131
Multi-Selectmedium

A security analyst is using Microsoft Sentinel to investigate an incident. Which THREE data sources can be ingested into Sentinel?

Select 3 answers
A.Power BI usage metrics
B.Azure Active Directory logs
C.Office 365 logs
D.Windows Security Events
E.Azure DevOps audit logs
AnswersB, C, D

Microsoft Sentinel offers a robust, out-of-the-box data connector for Azure Active Directory, enabling the ingestion of critical identity-related logs such as sign-in logs, audit logs, and provisioning logs. These logs are fundamental for detecting suspicious authentication attempts, privilege escalation, and other identity-based threats across an organization's cloud identity infrastructure. The connector streams these events directly into a Log Analytics workspace for real-time analysis and correlation with other security data.

Why this answer

Microsoft Sentinel natively supports ingesting Azure Active Directory (Azure AD) sign-in and audit logs through the Azure AD data connector, making option B correct for identity-based threat detection. Option C is correct because Office 365 logs (Exchange, SharePoint, Teams, etc.) are ingested via the Office 365 connector using the Office 365 Management Activity API. Option D is correct because Windows Security Events can be collected via the Azure Monitor Agent (AMA) or the Log Analytics agent using the Windows Security Events via AMA connector or the Security Events connector.

Option A is not a supported Sentinel data source, as Power BI usage metrics are not part of Sentinel's built-in connectors. Option E is also not a standard Sentinel connector; Azure DevOps audit logs are not natively ingested into Sentinel without custom workarounds.

Exam trap

The trap here is that candidates may assume any Microsoft service log can be ingested into Sentinel, but only services with dedicated, built-in data connectors (like Azure AD, Office 365, and Windows Security Events) are directly supported, while others like Power BI and Azure DevOps require custom or third-party solutions.

1132
MCQmedium

Your organization uses Microsoft Entra ID and wants to provide a single sign-on (SSO) experience for a third-party SaaS application that supports SAML 2.0. The app must also enforce multifactor authentication (MFA) for external users. What should you configure?

A.Set up SAML-based federation in Microsoft Entra ID and assign a Conditional Access policy requiring MFA
B.Add the app as a Linked Sign-On application
C.Use password-based SSO in Microsoft Entra ID
D.Configure OAuth 2.0 authorization in Microsoft Entra ID
AnswerA

SAML-based federation is the industry standard for enabling Single Sign-On (SSO) between an identity provider like Microsoft Entra ID and external enterprise applications. By configuring SAML, users authenticate once with Microsoft Entra ID and gain seamless access to the application. Subsequently, a Conditional Access policy can be applied to this specific application, mandating multi-factor authentication (MFA) to enhance security before access is granted, ensuring compliance with organizational security postures.

Why this answer

The scenario requires SAML 2.0-based federation for SSO, which Microsoft Entra ID supports natively. By assigning a Conditional Access policy that requires MFA, you enforce multifactor authentication for external users accessing the third-party SaaS application, meeting both SSO and MFA requirements.

Exam trap

The trap here is that candidates often confuse Linked Sign-On (Option B) with true federation, not realizing that Linked Sign-On merely redirects to an external login page without any identity provider integration or MFA enforcement capability.

How to eliminate wrong answers

Option B is wrong because Linked Sign-On (also known as existing SSO) simply creates a deep link to an existing sign-on page and does not provide SAML-based federation or the ability to enforce MFA via Conditional Access. Option C is wrong because password-based SSO uses credential vaulting and form-filling, which does not support SAML 2.0 federation and cannot enforce MFA through Conditional Access policies. Option D is wrong because OAuth 2.0 is an authorization protocol, not an authentication protocol for SSO; while it can be used with OpenID Connect, the question explicitly specifies SAML 2.0, making OAuth 2.0 an incorrect choice.

1133
MCQhard

A company's security operations center wants to detect advanced attacks targeting their on-premises Active Directory, such as Kerberos Golden Ticket attacks, pass-the-hash, and skeleton key malware. They need a solution that monitors domain controller traffic, correlates with entity behavior, and integrates with Microsoft Sentinel for incident response. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Cloud
D.Microsoft Sentinel
AnswerA

Microsoft Defender for Identity (MDI) is specifically designed to protect hybrid identity environments by monitoring on-premises Active Directory domain controllers. It leverages network traffic analysis and security event log inspection to detect sophisticated identity-based attacks, such as pass-the-hash, Golden Ticket, and reconnaissance activities. MDI's behavioral analytics engine establishes baselines for user and entity behavior, enabling it to identify anomalous activities indicative of advanced persistent threats targeting credentials and domain infrastructure. This makes it the ideal solution for a Security Operations Center (SOC) seeking to detect advanced identity-based threats within their on-premises AD.

Why this answer

Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to monitor on-premises Active Directory traffic, including domain controller network traffic, and uses entity behavior analytics to detect advanced attacks like Kerberos Golden Ticket, pass-the-hash, and skeleton key malware. It integrates natively with Microsoft Sentinel to enable automated incident response and investigation.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel as the detection tool itself, when in fact Sentinel is the aggregation and response platform, while Defender for Identity is the dedicated on-premises AD threat detection solution.

Why the other options are wrong

B

Microsoft Defender for Endpoint focuses on endpoint devices (workstations, servers) and does not monitor domain controller traffic or detect Active Directory-specific attacks like Golden Ticket or skeleton key.

C

Microsoft Defender for Cloud is designed for protecting cloud workloads (IaaS, PaaS, and hybrid) and does not monitor on-premises Active Directory traffic or detect Kerberos attacks like Golden Ticket or pass-the-hash.

D

Microsoft Sentinel is a SIEM/SOAR platform that ingests logs and alerts but does not natively monitor domain controller traffic or detect Active Directory attacks like Golden Ticket or skeleton key. It relies on other solutions (e.g., Defender for Identity) for such detections.

When would these options actually be correct?

B

A company needs to detect and respond to advanced malware and fileless attacks on endpoints, such as ransomware or exploit kits, and requires integration with Microsoft Sentinel for incident response.

C

A company wants to assess the security posture of their Azure and hybrid cloud resources, detect misconfigurations, and protect against cloud-specific threats like compromised storage accounts or vulnerable VMs. They need a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP).

D

A company needs a cloud-native SIEM to centralize security logs from multiple sources (e.g., firewalls, servers, cloud apps) and automate incident response. The question would specify that the goal is log aggregation and orchestration, not direct AD attack detection.

Why candidates pick the wrong answer

B

Candidates may confuse endpoint protection with identity protection, assuming that 'Defender for Endpoint' covers all security scenarios including Active Directory attacks.

C

Candidates may confuse 'Defender for Cloud' with identity protection because the name includes 'Defender' and they think it covers all security, not realizing it focuses on cloud infrastructure rather than on-premises Active Directory.

D

Candidates may confuse Sentinel as the solution because it integrates with many security tools and can ingest identity-related alerts, but they overlook that it does not perform the actual monitoring of domain controller traffic or entity behavior analysis itself.

1134
MCQhard

Refer to the exhibit. A sensitivity label is configured as shown. A user applies the parent label to a document containing credit card numbers. What is the expected behavior?

A.The document gets the parent label's header and the sublabel's encryption and watermark
B.The document gets no protection because credit card numbers are only detected by auto-labeling
C.The document gets the parent label's encryption (ViewOnly) and header, but no watermark
D.The document gets the parent label's encryption and header, and auto-labeling applies the sublabel
AnswerC

When a user manually applies a parent sensitivity label, the document inherits all the protection settings directly configured on that specific parent label. This includes the specified encryption (e.g., ViewOnly) and any content markings like a header. Since the parent label itself does not have a watermark configured, and sublabels are not automatically applied, the document will not receive a watermark, even if a sublabel has one.

Why this answer

When a user manually applies a parent sensitivity label that has sublabels, only the parent label's settings (encryption and header) are applied. The sublabel's watermark is not applied because sublabels are separate entities that must be explicitly selected; they are not automatically inherited or triggered by applying the parent label. The encryption (ViewOnly) and header come from the parent label's configuration, while the watermark belongs to the sublabel and is not applied.

Exam trap

The trap here is that candidates assume applying a parent label automatically cascades its settings to or includes its sublabels, but in reality, sublabels are separate labels that must be explicitly chosen, and no inheritance or automatic application occurs between parent and sublabels.

How to eliminate wrong answers

Option A is wrong because applying the parent label does not automatically apply the sublabel's encryption and watermark; sublabels must be manually selected by the user. Option B is wrong because credit card numbers are detected by auto-labeling, but the question states the user manually applies the parent label, so auto-labeling is not triggered; manual application applies the label's configured protections regardless of content detection. Option D is wrong because auto-labeling does not apply the sublabel when the parent label is manually applied; auto-labeling is a separate process that can apply labels based on sensitive content, but it does not automatically apply sublabels of a manually applied parent label.

1135
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Defender for Cloud Apps? (Choose three.)

Select 3 answers
A.Threat detection to identify malicious behavior in cloud apps
B.Cloud Discovery to identify shadow IT
C.Email scanning and remediation
D.Endpoint detection and response (EDR)
E.Information protection to apply labels to files stored in cloud apps
AnswersA, B, E

Microsoft Defender for Cloud Apps provides robust threat detection by continuously monitoring user and entity behavior across connected cloud applications. It leverages advanced analytics and machine learning to identify anomalous activities, such as impossible travel, unusual data downloads, or suspicious administrative actions, which could indicate a compromised account or insider threat. This capability offers real-time alerts and automated remediation to protect against malicious behavior within the cloud app environment.

Why this answer

Option A is correct because Microsoft Defender for Cloud Apps (MDA) includes anomaly detection and threat detection policies that use Microsoft's threat intelligence and user behavior analytics to identify malicious activity, compromised accounts, and risky user behavior across cloud applications. Option B is correct because Cloud Discovery is a core MDA capability that analyzes traffic logs (from firewalls, proxies, or Defender for Endpoint) against the Cloud App Catalog to detect shadow IT and assess app risk. Option E is correct because MDA integrates with Microsoft Purview Information Protection to classify and apply sensitivity labels to files stored in supported cloud apps, enabling data protection and DLP enforcement.

Option C is not correct because email scanning and remediation is handled by Microsoft Defender for Office 365, not MDA. Option D is not correct because endpoint detection and response is provided by Microsoft Defender for Endpoint, not MDA.

Exam trap

The trap here is that candidates often confuse the overlapping capabilities of Microsoft security products—specifically, they may incorrectly associate email scanning (Defender for Office 365) or endpoint detection (Defender for Endpoint) with Defender for Cloud Apps, which is strictly a CASB focused on cloud app discovery, threat detection, and information protection.

1136
MCQeasy

A company wants to create a sensitivity label called 'Highly Confidential' in Microsoft 365. When applied to a document, the label should automatically encrypt the document and restrict access to employees in the finance department only. Which Microsoft Purview solution should the administrator use to configure this label?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Information Protection
C.Microsoft Purview Compliance Manager
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Information Protection is the correct service for creating and managing sensitivity labels, which classify and protect sensitive data. These labels can be configured to apply encryption, visual markings like headers or footers, and granular access restrictions to content, regardless of where it is stored or shared. This comprehensive approach ensures that sensitive information remains protected throughout its lifecycle, aligning with data governance policies.

Why this answer

Microsoft Purview Information Protection is the correct solution because it provides the ability to create and configure sensitivity labels that enforce protection actions such as encryption and access restrictions. When a 'Highly Confidential' label is applied, it can automatically encrypt the document using Azure Rights Management (Azure RMS) and restrict access to only members of the finance department via a defined permission policy.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection with Data Lifecycle Management, mistakenly thinking retention labels can enforce encryption, when in fact only sensitivity labels can apply protection actions like encryption and access control.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management (formerly Data Lifecycle Management) focuses on retaining, deleting, and managing data based on retention policies and labels, not on applying encryption or access control. Option C is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance scoring tool that helps manage compliance posture, not a tool for configuring sensitivity labels or encryption. Option D is wrong because Microsoft Purview Audit provides auditing and logging of user and admin activities, not the ability to create or apply sensitivity labels with encryption and access restrictions.

1137
MCQmedium

An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for all users accessing sensitive data from outside the corporate network. Which Microsoft Entra capability should they configure?

A.Conditional Access
B.B2B Collaboration
C.Privileged Identity Management
D.Identity Protection
AnswerA

Conditional Access policies evaluate real-time signals such as user location and network IP address, enabling the security team to enforce MFA specifically when access originates from outside the corporate network. This satisfies the stem’s constraint of restricting MFA to external access only, without affecting internal users. Unlike baseline or per-user MFA, Conditional Access provides granular, context-aware control based on the network location condition.

Why this answer

Conditional Access is the correct capability because it allows administrators to define policies that enforce MFA based on specific conditions, such as network location. By configuring a policy that targets all users and applies the 'Require multi-factor authentication' grant control when the location is outside the corporate network, the security team can precisely meet the requirement. This policy evaluates the user's IP address against named locations defined in Entra ID before granting access to sensitive data.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA trigger with the ability to enforce MFA based on a static network location, but Identity Protection only responds to risk events and does not allow direct configuration of location-based conditions.

How to eliminate wrong answers

Option B (B2B Collaboration) is wrong because it is designed for inviting external users (guests) from partner organizations, not for enforcing MFA on internal users based on network location. Option C (Privileged Identity Management) is wrong because it focuses on just-in-time privileged role activation and approval workflows, not on location-based MFA enforcement for all users. Option D (Identity Protection) is wrong because it detects and remediates risks like leaked credentials or sign-ins from anonymous IPs, but it does not directly enforce MFA based on a static network boundary; it can trigger MFA via Conditional Access policies but is not the capability that configures the location condition itself.

1138
MCQeasy

A security analyst at Fabrikam, Inc. is reviewing alerts in the Microsoft 365 Defender portal. The analyst needs to understand the function of the 'Automated investigation and response' (AIR) capability in Microsoft Defender for Office 365. What is the primary purpose of AIR?

A.To automatically block all incoming email messages from external domains.
B.To provide a real-time dashboard of all email traffic in the organization.
C.To enforce data loss prevention policies for email attachments.
D.To automatically investigate alerts and take remediation actions, such as soft-deleting malicious emails.
AnswerD

AIR in Microsoft Defender for Office 365 automatically investigates alerts triggered by suspicious emails, attachments, or links. It can then take remediation actions, such as soft-deleting malicious messages from user mailboxes, blocking malicious senders, and removing malicious attachments. This reduces the burden on security teams and accelerates response to threats.

Why this answer

Automated investigation and response (AIR) in Microsoft Defender for Office 365 automatically investigates alerts and takes remediation actions, such as soft-deleting malicious emails, blocking senders, and removing malicious attachments. It helps security teams respond to threats quickly and consistently without manual intervention for every alert.

Exam trap

The trap here is confusing AIR with email traffic monitoring or DLP enforcement, when AIR is specifically about automated investigation and remediation of threats.

1139
MCQmedium

A company has implemented a security model where every access request is fully authenticated, authorized, and encrypted before granting access, regardless of where the request originates (corporate network or internet). The model assumes that no entity is inherently trustworthy and requires continuous verification. This model is known as:

A.Defense in depth
B.Least privilege
C.Zero Trust
D.Shared responsibility
AnswerC

Zero Trust is a security model fundamentally built on the principle of 'never trust, always verify,' meaning no user, device, or application is implicitly trusted, regardless of its location inside or outside the network perimeter. Every access request is explicitly authenticated, authorized, and continuously validated based on all available data points, including user identity, device health, service, and data classification. This continuous verification ensures that access is granted only when all conditions are met, eliminating implicit trust.

Why this answer

The described model—requiring full authentication, authorization, and encryption for every access request, treating no entity as inherently trustworthy, and demanding continuous verification—is the core definition of Zero Trust. This aligns with the NIST SP 800-207 standard, which explicitly states that Zero Trust assumes no implicit trust and enforces verification for every request, regardless of network location.

Exam trap

The trap here is that candidates often confuse Zero Trust with defense in depth, assuming that multiple security layers inherently imply no trust, but defense in depth does not require per-request authentication, authorization, and encryption from any location.

Why the other options are wrong

A

Defense in depth is a layered security approach using multiple controls, but it does not inherently assume no entity is trustworthy or require continuous verification; it focuses on redundancy, not the zero-trust principle of 'never trust, always verify.'

B

The question describes a model where no entity is trusted by default and continuous verification is required, which is the definition of Zero Trust. Least privilege is a principle of granting only necessary permissions, not a model for continuous verification and encryption of all access requests.

D

The shared responsibility model describes the division of security tasks between a cloud provider and customer, not the principle of never trusting any entity by default and requiring continuous verification.

When would these options actually be correct?

A

Defense in depth would be correct for a question describing a security strategy that implements multiple layers of defense (e.g., firewalls, antivirus, intrusion detection) to protect against a single point of failure, without emphasizing continuous verification or distrust of all entities.

B

A question that asks: 'A company wants to ensure users have only the minimum permissions needed to perform their job functions. Which security principle should they apply?' In that context, least privilege would be the correct answer.

D

In a question like 'Which model outlines that the cloud provider is responsible for security of the cloud, while the customer is responsible for security in the cloud?', shared responsibility would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse defense in depth with zero trust because both involve multiple security controls, but defense in depth lacks the core zero-trust requirement of continuous verification and implicit distrust of all access requests.

B

Candidates may confuse least privilege with Zero Trust because both involve limiting access, but they fail to recognize that Zero Trust is a broader security model encompassing continuous verification, while least privilege is a specific access control principle.

D

Candidates may confuse the broad security concept of Zero Trust with the operational division of duties in cloud environments, especially when the question mentions 'security model' without specifying cloud context.

1140
MCQmedium

Refer to the exhibit. The JSON shows a Microsoft Purview DLP policy. A user sends an email with a credit card number to an external recipient. What will happen?

A.The email is delivered normally because TeamsChatAndChannel is false.
B.The email is delivered but an alert is generated.
C.The email is blocked and the user receives a notification.
D.The email is encrypted before delivery.
AnswerC

This statement is correct. The DLP policy is configured to apply to `Exchange` (where email resides), and its rule specifies `BlockAccess` as the action when sensitive content is detected. Furthermore, the `UserNotification` setting is enabled, ensuring that the sender receives a policy tip or notification explaining why their email was blocked, providing immediate feedback and promoting compliance.

Why this answer

The DLP policy in the exhibit has a condition that detects credit card numbers and an action set to 'BlockMessage' with 'NotifyUser' enabled. Since the policy is configured for Exchange (email) and the action blocks the message, the email is blocked and the user receives a notification. The 'TeamsChatAndChannel' property being false is irrelevant because the policy is applied to Exchange, not Teams.

Exam trap

The trap here is that candidates confuse the 'TeamsChatAndChannel' property with the overall policy applicability, assuming a false value means the entire policy is inactive, when in fact it only controls Teams scope and the Exchange action still applies.

How to eliminate wrong answers

Option A is wrong because 'TeamsChatAndChannel' being false only means the policy does not apply to Teams chat/channel messages; it does not affect Exchange email delivery, and the policy's 'BlockMessage' action overrides normal delivery. Option B is wrong because the policy action is 'BlockMessage', not 'GenerateAlert' alone; while an alert could be generated, the primary action blocks the email, so it is not delivered. Option D is wrong because the policy does not specify encryption as an action; the configured action is 'BlockMessage', not 'EncryptMessage'.

1141
MCQhard

A company is deploying a web application on Azure App Service. The security officer states that according to the shared responsibility model, the customer is responsible for managing access to the application and securing the application code. Which of the following responsibilities does Microsoft retain for Azure App Service?

A.Configuring network firewall rules for the App Service
B.Patching the underlying operating system of the App Service host
C.Managing user authentication and authorization
D.Applying encryption to the application data at rest
AnswerB

As part of the Platform as a Service (PaaS) offering, Microsoft is fully responsible for managing and patching the underlying operating system and virtual machine infrastructure that hosts Azure App Service instances. This includes applying security updates, hotfixes, and service packs to the host OS to maintain platform security and stability, abstracting this operational burden from the customer. This responsibility ensures the foundational environment upon which customer applications run remains secure.

Why this answer

For Azure App Service, Microsoft retains responsibility for patching the underlying operating system of the host infrastructure. This is part of the shared responsibility model where the cloud provider manages the host OS and hypervisor, while the customer manages the application code, data, and access configurations.

Exam trap

The trap here is that candidates often confuse 'patching the underlying OS' with 'patching the application runtime' or 'configuring network security,' mistakenly thinking Microsoft handles all security tasks for PaaS services, when in fact the customer retains significant control over access and data protection.

Why the other options are wrong

A

In Azure App Service, configuring network firewall rules is a customer responsibility, not Microsoft's. The shared responsibility model assigns platform-level security (like OS patching) to Microsoft, but network configuration for the app is managed by the customer.

C

In Azure App Service, managing user authentication and authorization is a customer responsibility, not Microsoft's. The shared responsibility model assigns application-level access control to the customer.

D

In the shared responsibility model for Azure App Service, Microsoft is responsible for the physical infrastructure and platform, but encryption of application data at rest is typically the customer's responsibility because they control the data and can enable encryption features like Azure Storage Service Encryption.

When would these options actually be correct?

A

This option would be correct in a question about Azure infrastructure services (IaaS), such as a virtual machine, where Microsoft manages the physical host and network, but the customer configures firewall rules for the VM. For example: 'Which of the following is a customer responsibility when using an Azure VM?'

C

This option would be correct in a question about Azure Active Directory (Azure AD) as an identity provider, where Microsoft manages the authentication service itself, including user authentication and authorization for cloud resources.

D

This option would be correct in a question about Azure SQL Database or Azure Storage, where Microsoft manages encryption at rest by default (e.g., transparent data encryption). For example: 'Which responsibility does Microsoft retain for Azure SQL Database?'

Why candidates pick the wrong answer

A

Candidates may confuse the shared responsibility model for PaaS (App Service) with IaaS, assuming Microsoft handles all network security. They might also think that because Microsoft manages the platform, it also configures network firewalls for the app.

C

Candidates may confuse the platform's built-in authentication features (which are configurable by the customer) with Microsoft-managed responsibilities, assuming that because Azure offers authentication modules, Microsoft handles all aspects of it.

D

Candidates may assume that because Azure offers encryption features, Microsoft handles all encryption responsibilities, overlooking that customers must configure and manage encryption for their application data.

1142
MCQmedium

A company runs a web application in Azure that is publicly accessible. They want to protect it against large-scale distributed denial-of-service (DDoS) attacks from multiple sources. Which Azure service is specifically designed for this purpose?

A.Azure Firewall
B.Azure DDoS Protection
C.Microsoft Defender for Cloud
D.Azure Application Gateway with Web Application Firewall (WAF)
AnswerB

Azure DDoS Protection provides always-on traffic monitoring and automatic mitigation capabilities specifically designed to protect Azure resources from volumetric, protocol, and resource-layer DDoS attacks. It leverages Azure's global network scale to absorb and scrub malicious traffic at the network edge before it reaches the target application, ensuring legitimate traffic flow. This service is essential for publicly accessible applications in Azure, offering comprehensive protection against sophisticated denial-of-service threats.

Why this answer

Azure DDoS Protection is specifically designed to safeguard Azure resources against large-scale distributed denial-of-service (DDoS) attacks. It leverages the global scale of Microsoft's network to absorb and mitigate multi-gigabit attacks, providing always-on traffic monitoring and adaptive tuning. This service is the only option among the choices that is purpose-built for DDoS mitigation at the network and transport layers (L3/L4), and it also offers application-layer (L7) protection when combined with Application Gateway WAF.

Exam trap

The trap here is that candidates often confuse Azure Firewall or Application Gateway WAF as DDoS solutions, but those services handle different layers of defense—Azure Firewall for network filtering and WAF for application-layer attacks—whereas only Azure DDoS Protection is designed to absorb and mitigate large-scale volumetric attacks from multiple sources.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a stateful network firewall that filters traffic based on rules (e.g., IP addresses, ports, protocols) but does not provide dedicated DDoS mitigation; it cannot absorb volumetric attacks. Option C is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that provides threat detection and security recommendations, not a DDoS mitigation service. Option D is wrong because Azure Application Gateway with WAF protects against application-layer attacks (e.g., SQL injection, cross-site scripting) but does not mitigate large-scale volumetric DDoS attacks at the network layer; it can be used in conjunction with Azure DDoS Protection but is not a standalone DDoS solution.

1143
MCQmedium

A company must retain all customer contracts for 10 years to comply with industry regulations. After 10 years, the contracts must be permanently deleted. Which Microsoft Purview solution should be used to automate this process?

A.Data Loss Prevention (DLP)
B.Data Lifecycle Management
C.eDiscovery
D.Information Protection
AnswerB

Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels and policies to govern the entire lifecycle of data, from creation to deletion. It enables organizations to define specific retention periods, such as 10 years for customer contracts, ensuring compliance with legal or regulatory obligations. After the retention period expires, DLM policies can automatically dispose of the data, streamlining information governance and reducing risk.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview is the correct solution because it allows you to define retention labels and policies that automatically retain contracts for a specified period (10 years) and then trigger a permanent deletion disposition review or direct deletion. This aligns directly with the regulatory requirement to retain data for a fixed duration and then dispose of it securely.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management with Data Loss Prevention, mistakenly thinking DLP can delete data after a period, when DLP only blocks or alerts on data exfiltration, not manage retention schedules.

Why the other options are wrong

A

Data Loss Prevention (DLP) is designed to prevent accidental sharing or leakage of sensitive data, not to automate retention and deletion of records based on a fixed time period.

D

Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not on automated retention and deletion schedules. The requirement to retain and then delete contracts after 10 years is a lifecycle management task, not a protection task.

When would these options actually be correct?

A

A company wants to automatically detect and block emails containing credit card numbers from being sent to external recipients. DLP policies would be the correct solution to enforce this rule.

D

A company needs to automatically apply encryption and access restrictions to all customer contracts containing personally identifiable information (PII) to prevent unauthorized sharing. Information Protection with sensitivity labels would be the correct solution.

Why candidates pick the wrong answer

A

Candidates may confuse DLP with retention policies because both involve data governance, but DLP focuses on preventing data loss, not lifecycle management.

D

Candidates may confuse 'protecting' data with 'managing its lifecycle,' assuming that retention and deletion are part of protection. The term 'Information Protection' sounds broad enough to include retention policies, but in Microsoft Purview it specifically covers classification and protection controls.

1144
MCQmedium

A company has an on-premises Active Directory and wants to synchronize user accounts to Microsoft Entra ID. They also need to enable password hash synchronization so users can sign in to cloud resources with the same password. Which Microsoft tool should they use?

A.Microsoft Entra Connect
B.Microsoft Entra ID Application Proxy
C.Microsoft Identity Manager
D.Microsoft Entra Domain Services
AnswerA

Microsoft Entra Connect is the essential Microsoft tool designed to achieve hybrid identity goals by synchronizing users, groups, and contacts from an on-premises Active Directory to Microsoft Entra ID. It facilitates various synchronization features, including password hash synchronization (PHS), pass-through authentication (PTA), and federation with Active Directory Federation Services (AD FS). PHS, enabled by default, securely synchronizes a hash of the user's password hash, allowing users to sign in to cloud services with their on-premises credentials.

Why this answer

Microsoft Entra Connect is the correct tool because it is specifically designed to synchronize on-premises Active Directory user accounts to Microsoft Entra ID and supports password hash synchronization (PHS). PHS enables users to sign in to cloud resources using the same password as their on-premises environment by synchronizing a hash of the password hash to Entra ID.

Exam trap

The trap here is that candidates may confuse Microsoft Entra Connect with Microsoft Identity Manager (MIM), but MIM is a legacy tool for on-premises identity management and does not natively support password hash synchronization to Microsoft Entra ID.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Application Proxy provides secure remote access to on-premises web applications, not directory synchronization or password hash sync. Option C is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution for managing identities across heterogeneous directories, but it is not the primary tool for synchronizing to Microsoft Entra ID and does not natively enable password hash synchronization to Entra ID. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., Kerberos, LDAP) for cloud VMs, not user account synchronization or password hash sync from on-premises Active Directory.

1145
MCQeasy

What is the primary purpose of Microsoft Defender for Cloud Apps?

A.Monitor network traffic
B.Manage mobile devices
C.Protect on-premises servers
D.Secure cloud applications and data
AnswerD

Microsoft Defender for Cloud's primary purpose is to provide comprehensive security posture management and threat protection across cloud environments, including Azure, AWS, and GCP. This encompasses securing cloud applications, data, virtual machines, containers, databases, and other services by identifying misconfigurations, recommending security improvements, and detecting and responding to threats. It acts as a Cloud Workload Protection Platform (CWPP) and Cloud Security Posture Management (CSPM) solution, ensuring the overall security of cloud-native assets.

Why this answer

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, data controls, and threat protection for cloud applications and data. Its primary purpose is to secure cloud apps (like Microsoft 365, Salesforce, or Dropbox) by enforcing policies, detecting anomalous behavior, and preventing data exfiltration, not to manage network traffic, mobile devices, or on-premises servers.

Exam trap

The trap here is that candidates may confuse Defender for Cloud Apps with a general-purpose security tool, mistakenly thinking it monitors network traffic (Option A) or protects on-premises servers (Option C), when its focus is exclusively on cloud application security and data protection.

How to eliminate wrong answers

Option A is wrong because monitoring network traffic is the primary function of network security tools like Microsoft Defender for Network or Azure Firewall, not Defender for Cloud Apps. Option B is wrong because managing mobile devices is the domain of Microsoft Intune (a Mobile Device Management/MDM solution), not a CASB. Option C is wrong because protecting on-premises servers is the role of Microsoft Defender for Servers (part of Defender for Cloud) or System Center, not a cloud app security broker.

1146
MCQmedium

A company needs to grant IT administrators temporary and time-limited access to privileged roles in Microsoft Entra ID (Azure AD). The access must require approval from a manager and be automatically revoked after the task is completed. Which Microsoft Entra ID feature should be used?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Entitlement Management
AnswerC

Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft services. It enables just-in-time (JIT) access, allowing administrators to activate privileged roles only when needed, for a specific, time-limited duration. This includes features like multi-factor authentication (MFA) enforcement during activation, approval workflows, and comprehensive audit logs, directly fulfilling the requirement for temporary and time-limited administrative access.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access by allowing administrators to activate eligible role assignments for a limited duration. It supports approval workflows (e.g., manager approval) and automatically deactivates the role when the activation time expires or the task is completed, meeting the requirement for temporary, time-limited, approved, and auto-revoked access.

Exam trap

The trap here is confusing Entitlement Management (which manages access packages for non-privileged resources) with PIM (which specifically handles time-limited privileged role activation with approval), leading candidates to choose D because they see 'approval' and 'temporary access' without recognizing the privileged role context.

Why the other options are wrong

A

Conditional Access enforces access policies based on signals like user location or device state, but it does not provide time-limited, approval-based activation of privileged roles or automatic revocation.

B

Identity Protection is designed to detect and respond to identity-based risks, such as compromised credentials or suspicious sign-ins, not to manage time-limited privileged role assignments with approval workflows.

D

Entitlement Management manages access packages and resource access requests, but it does not provide time-limited, automatically revoked privileged role assignments with manager approval; PIM handles just-in-time privileged role activation.

When would these options actually be correct?

A

A company needs to require multi-factor authentication or block access from untrusted locations when administrators sign in to the Azure portal. Conditional Access would be the correct feature to enforce such policies.

B

A company wants to automatically detect and block sign-ins from anonymous IP addresses or enforce multi-factor authentication based on risk level. Which Microsoft Entra ID feature should be used?

D

A company needs to allow employees to request access to a set of applications and groups for a specific project, with approval from their manager and automatic expiration after 30 days. Entitlement Management would be the correct feature to create access packages for this scenario.

Why candidates pick the wrong answer

A

Candidates may confuse Conditional Access with access control for privileged roles, not realizing it governs sign-in conditions rather than role activation and approval workflows.

B

Candidates may confuse Identity Protection with Privileged Identity Management because both involve security and identity, but Identity Protection focuses on risk detection rather than role activation and approval workflows.

D

Candidates may confuse Entitlement Management's approval and expiration features with PIM's privileged role activation, not realizing that Entitlement Management is for general resource access, not privileged role management.

1147
MCQhard

You are the identity administrator for Contoso Ltd., a global company with over 10,000 employees. The company uses Microsoft Entra ID P2 and Microsoft Intune. Employees use both company-owned and personal devices. The security team requires that all access to corporate applications be protected with multifactor authentication (MFA). However, to minimize user friction, they want to exempt MFA for users who are on the corporate network and using compliant devices. Additionally, for users with privileged roles (e.g., Global Administrator), MFA must always be required regardless of location or device. You need to configure a Conditional Access policy to meet these requirements. Which of the following approaches should you take?

A.Create two Conditional Access policies: Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions.
B.Create one Conditional Access policy that targets all users and requires MFA. Create a second policy that targets privileged roles and excludes trusted locations.
C.Create one Conditional Access policy that targets all users, requires MFA, and excludes trusted locations and compliant devices. Do not create any additional policies.
D.Create one Conditional Access policy that targets all users and requires MFA. Use Microsoft Intune compliance policies to exempt compliant devices from MFA.
AnswerA

This solution correctly implements a layered security approach using two distinct Conditional Access policies. Policy 1 ensures that standard users require Multi-Factor Authentication (MFA) but allows for usability by excluding trusted locations and compliant devices. Policy 2 specifically targets privileged roles, enforcing MFA without any exclusions, thereby guaranteeing that these high-impact accounts always face the strongest authentication challenge, regardless of their location or device compliance status. This design effectively balances security for privileged identities with user experience for general users.

Why this answer

It uses two separate Conditional Access policies to handle the two distinct user groups. Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices, which satisfies the requirement to minimize friction for users on the corporate network with compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions, ensuring that Global Administrators and other privileged role members always must perform MFA regardless of location or device compliance.

Exam trap

The trap here is that candidates often think a single policy with exclusions can handle all users, forgetting that privileged roles require unconditional MFA, which necessitates a separate policy with no exclusions to override the more permissive exclusions applied to regular users.

How to eliminate wrong answers

Option B is wrong because it creates a second policy that targets privileged roles and excludes trusted locations, which would exempt privileged role users from MFA when they are on the corporate network, violating the requirement that MFA must always be required for privileged roles. Option C is wrong because it creates only one policy targeting all users with exclusions for trusted locations and compliant devices, which would incorrectly exempt privileged role users from MFA when they meet those conditions. Option D is wrong because Intune compliance policies cannot be used to exempt devices from MFA in a Conditional Access policy; MFA enforcement is controlled by Conditional Access policies, not by compliance policies.

1148
MCQmedium

An organization needs to grant its IT administrators temporary access to the Global Administrator role. The access should require a separate approval from a designated manager before activation, and the permissions should automatically expire after 4 hours. Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Access Reviews
AnswerC

Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within an organization. It enables just-in-time (JIT) access, allowing administrators to activate privileged roles only when needed and for a limited duration. This process often includes an approval workflow, multi-factor authentication, and automatic deactivation of the role after the specified time, directly addressing the requirement for temporary, controlled access.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access, allowing IT administrators to activate the Global Administrator role for a limited time (e.g., 4 hours) only after receiving approval from a designated manager. This directly meets the requirement for temporary, approval-based, and auto-expiring permissions.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Conditional Access, mistakenly thinking that Conditional Access can enforce time-limited role activation, when in fact PIM is the only feature that provides just-in-time privileged access with approval and automatic expiration.

Why the other options are wrong

A

Conditional Access enforces access policies based on signals like user location or device state, but it does not provide just-in-time role activation with approval and automatic expiry.

D

Access Reviews are used to audit and confirm the ongoing need for group memberships or role assignments, not to grant temporary, approval-based activation of privileged roles with automatic expiration.

When would these options actually be correct?

A

An organization needs to require multi-factor authentication for all users accessing a sensitive application from outside the corporate network. Conditional Access would be the correct feature to configure such a policy.

D

An organization needs to periodically verify that all users with Global Administrator access still require that role, and remove those who no longer need it. Access Reviews would be the correct feature to configure.

Why candidates pick the wrong answer

A

Candidates may confuse Conditional Access with access control for privileged roles, not realizing it governs user access to resources rather than role activation workflows.

D

Candidates may confuse Access Reviews with PIM because both involve privileged roles and oversight, but Access Reviews focus on periodic attestation rather than just-in-time activation with approval.

1149
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. A security analyst notices anomalous file downloads from a SharePoint site by a user flagged as high risk. What should the analyst configure to automatically block such activity?

A.Configure a file policy
B.Configure an access policy
C.Configure an app permission policy
D.Configure a session policy
AnswerD

Configuring a session policy is the correct approach because these policies leverage Microsoft Defender for Cloud Apps' Conditional Access App Control to act as a reverse proxy, intercepting and inspecting user sessions in real-time. This allows administrators to apply granular, context-aware controls over user activities within cloud applications, such as blocking downloads, preventing uploads of sensitive files, or restricting copy-paste actions. Session policies are specifically designed for real-time monitoring and control of ongoing user interactions.

Why this answer

Session policies in Microsoft Defender for Cloud Apps allow real-time monitoring and control of user activities based on risk level. When a user is flagged as high risk, a session policy can be configured to automatically block anomalous file downloads from SharePoint by intercepting the session and applying actions such as block, allow, or restrict. This is the correct choice because it directly addresses the need to prevent the specific activity in real time.

Exam trap

The trap here is that candidates often confuse session policies with access policies, but access policies control entry (authentication/authorization) while session policies control behavior during an active session, which is required to block specific file downloads in real time.

How to eliminate wrong answers

Option A is wrong because file policies are designed to detect and govern data at rest or in transit using content inspection and metadata, but they do not provide real-time session-level blocking based on user risk; they typically trigger alerts or apply governance actions after the fact. Option B is wrong because access policies control authentication and authorization at the point of sign-in (e.g., requiring MFA or blocking access from untrusted locations), but they do not monitor or block specific activities like file downloads during an active session. Option C is wrong because app permission policies manage the permissions granted to third-party apps (e.g., OAuth apps) to access organizational data, not the real-time behavior of individual user sessions.

1150
MCQeasy

A company wants to provide secure external access to a partner application without creating user accounts manually. They need to allow partners to authenticate using their existing corporate identities (e.g., from other organizations) and configure policies for access. Which Microsoft Entra feature should they use?

A.Microsoft Entra Identity Protection
B.Microsoft Entra External ID (B2B collaboration)
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra Domain Services
AnswerB

Microsoft Entra External ID (B2B collaboration) is the correct solution as it specifically enables organizations to invite external users, such as partners, to access their applications and resources using their own existing identities. This feature integrates partner users into the inviting organization's Microsoft Entra tenant as guest users, allowing for the application of robust access policies and secure management of their access to partner applications.

Why this answer

Microsoft Entra External ID (B2B collaboration) allows organizations to securely share applications and resources with external partners by letting them authenticate using their own corporate identities (e.g., from other Azure AD tenants, Microsoft accounts, or social identity providers). It eliminates the need to manually create and manage user accounts for partners, while enabling you to apply conditional access policies for granular control over external access.

Exam trap

The trap here is that candidates often confuse B2B collaboration (External ID) with B2C (External Identities for customer-facing apps) or think that Privileged Identity Management is needed for external access, but the question specifically asks about allowing partners to use their existing corporate identities without manual account creation, which is the core purpose of B2B collaboration.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Identity Protection is a risk-based security tool that detects and responds to identity threats (e.g., leaked credentials, sign-in anomalies) for users within your tenant, not a feature for inviting external partners or federating with their existing identities. Option C is wrong because Microsoft Entra Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles within your own directory (e.g., just-in-time admin access), not for enabling external partner authentication or collaboration. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., LDAP, Kerberos, NTLM) for legacy on-premises applications in the cloud, not for external identity federation or B2B guest access.

1151
MCQmedium

Your company uses Microsoft Entra ID. Security policy requires that all external guest users must be reviewed and their access approved by their sponsor every 90 days. If not approved, access should be automatically removed. Which feature should you use?

A.Microsoft Entra Conditional Access
B.Microsoft Entra B2B collaboration settings
C.Microsoft Entra entitlement management
D.Microsoft Entra access reviews
AnswerD

Microsoft Entra access reviews are specifically designed to enable organizations to efficiently manage group memberships, access to enterprise applications, and role assignments by scheduling periodic reviews. These reviews allow designated reviewers to confirm continued access necessity, and critically, they can be configured to automatically remove access for users who are not approved or whose review is not completed, directly addressing the requirement for periodic validation and automated revocation.

Why this answer

Microsoft Entra access reviews (Option D) allow you to configure recurring reviews of guest users' access, with automatic removal of access if not approved. This directly meets the requirement for a 90-day review cycle with automatic enforcement, as access reviews can be scoped to guest users and integrated with entitlement management or groups.

Exam trap

The trap here is that candidates confuse entitlement management (which creates access packages) with the actual review and removal mechanism, but access reviews are the specific feature that enforces periodic attestation and automatic cleanup.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access controls access based on conditions like location or device state, but it does not provide periodic review or automatic removal of access based on approval. Option B is wrong because Microsoft Entra B2B collaboration settings manage invitation policies and external user properties, but they lack the recurring review and auto-removal workflow. Option C is wrong because Microsoft Entra entitlement management manages access packages and catalogs, but the actual review and removal process is implemented through access reviews, not entitlement management alone.

1152
MCQhard

A company runs critical Windows virtual machines on Azure. To reduce the attack surface, the security team wants to block all inbound RDP (port 3389) traffic from the internet by default. When a security engineer needs to connect via RDP for troubleshooting, they must request access through a portal, and the RDP port will be opened for a limited time (e.g., 4 hours) only to their source IP address. Which Microsoft security solution should they use to implement this control?

A.Microsoft Defender for Cloud's Just-in-time (JIT) VM access
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Azure Network Security Groups (NSGs) with application security groups
AnswerA

Microsoft Defender for Cloud's Just-in-time (JIT) VM access is a crucial security feature designed to reduce the attack surface of Azure virtual machines. It achieves this by locking down inbound management ports, only opening them for specific, approved source IP addresses for a limited duration. This temporary, on-demand access significantly minimizes exposure to potential threats, aligning with zero-trust principles and enhancing overall VM security posture.

Why this answer

Microsoft Defender for Cloud's Just-in-time (JIT) VM access is the correct solution because it specifically provides time-limited, request-based opening of inbound ports (such as RDP port 3389) to approved source IP addresses, reducing the attack surface by keeping ports closed by default. This aligns directly with the requirement to block all inbound RDP from the internet by default and allow temporary access only through a portal request.

Exam trap

The trap here is that candidates may confuse network-level controls (NSGs) with a managed security service that automates temporary access, leading them to choose Option D without realizing NSGs lack the time-limited, request-based workflow that JIT provides.

How to eliminate wrong answers

Option B (Microsoft Defender for Cloud Apps) is wrong because it is a cloud access security broker (CASB) focused on controlling and monitoring user access to SaaS applications, not on managing inbound network ports to Azure VMs. Option C (Microsoft Defender for Endpoint) is wrong because it is an endpoint detection and response (EDR) solution for securing devices against malware and threats, not a network-level port management tool. Option D (Azure Network Security Groups with application security groups) is wrong because while NSGs can block or allow traffic, they do not provide time-limited, request-based just-in-time access; they require manual rule changes and do not integrate with a portal-based approval workflow.

1153
MCQmedium

A company uses Microsoft Entra ID and wants to enforce multifactor authentication (MFA) for all users accessing a sensitive customer relationship management (CRM) application, but only when the access request originates from outside the corporate network. Which component of a Conditional Access policy should the administrator configure to specify this location-based requirement?

A.Assignments
B.Conditions
C.Grant controls
D.Session controls
AnswerB

Conditions are the "if" part of a Conditional Access policy, evaluating specific attributes of a sign-in attempt to determine if the policy applies. This includes critical contextual factors such as the user's sign-in risk level, the device platform being used, the client application, and crucially, the network location from which the access request originates. The location condition specifically allows administrators to define trusted or untrusted IP ranges, enabling enforcement based on geographic or network-specific access points.

Why this answer

The 'Conditions' section of a Conditional Access policy allows administrators to define the circumstances under which the policy is applied, including the location from which an access request originates. By configuring a location condition, you can specify that MFA is enforced only when users access the CRM application from outside the corporate network, using named locations or IP ranges. This is the correct component to enforce the location-based requirement.

Exam trap

The trap here is that candidates often confuse 'Assignments' (who/what) with 'Conditions' (when/where), mistakenly selecting Assignments because they think location is part of the user or app assignment, whereas Conditions specifically handle environmental factors like location, device state, and risk.

How to eliminate wrong answers

Option A is wrong because 'Assignments' define which users, groups, or applications the policy applies to, not the conditions under which it is triggered. Option C is wrong because 'Grant controls' specify what actions to take (e.g., require MFA, require compliant device) after the policy conditions are met, not the location condition itself. Option D is wrong because 'Session controls' manage session-level behaviors like app-enforced restrictions or sign-in frequency, not the location-based trigger for MFA enforcement.

1154
MCQeasy

A compliance administrator creates the above custom sensitive information type for detecting social security numbers (SSNs). What is required for a document to be classified as containing an SSN?

A.The document must contain either the SSN regex or a keyword
B.The document must contain the SSN regex with high confidence level
C.The document must contain a pattern matching the SSN regex and at least two keywords
D.The document must contain a pattern matching the SSN regex and at least one keyword
AnswerD

This option accurately describes the conditions for a match. The custom sensitive information type (SIT) rule is configured with a logical AND operator, requiring both the detection of a pattern matching the Social Security Number (SSN) regular expression and the presence of associated keywords. Specifically, the `minMatches=1` setting for the keyword component means that at least one keyword must be found in proximity to the SSN pattern to trigger a successful detection.

Why this answer

A custom sensitive information type in Microsoft Purview uses a primary element (the SSN regex pattern) and requires at least one supporting element (a keyword) to trigger a match. This ensures that the document is not falsely classified by the regex alone, which could match random number sequences. The compliance administrator configured the type with a minimum count of one keyword as a proximity requirement, so the document must contain both the regex pattern and at least one keyword.

Exam trap

The trap here is that candidates confuse the confidence level (which is a calculated percentage) with the required matching criteria (regex plus keywords), leading them to select Option B, which incorrectly implies that high confidence alone is sufficient without the keyword requirement.

How to eliminate wrong answers

Option A is wrong because requiring either the SSN regex or a keyword would allow classification based solely on a keyword without any number pattern, which defeats the purpose of detecting SSNs. Option B is wrong because 'high confidence level' is a separate confidence setting (e.g., 85% or higher) that can be configured, but the question asks what is required for classification—not the confidence threshold; the requirement is the regex plus keywords, not just the regex with high confidence. Option C is wrong because the custom sensitive information type was created with a minimum count of one keyword, not two; requiring at least two keywords would be an incorrect interpretation of the proximity and count settings.

1155
MCQhard

A multinational corporation wants to implement a Zero Trust security model. They plan to verify every access request explicitly, use least privilege access, and assume breach. Which Microsoft security solution should they use to enforce conditional access policies based on user, device, location, and risk?

A.Microsoft Sentinel
B.Microsoft Intune
C.Microsoft Entra Conditional Access
D.Microsoft Defender for Cloud Apps
AnswerC

Microsoft Entra Conditional Access evaluates signals including user identity, device compliance, location and sign-in risk, then enforces grant or block decisions per policy. This directly implements the explicit verification and least privilege requirements of the Zero Trust model described.

Why this answer

Microsoft Entra Conditional Access is the correct solution for enforcing conditional access policies based on signals like user, device, location, and risk. Option A (Microsoft Sentinel) is a SIEM/SOAR solution for security analytics, not access control. Option B (Microsoft Intune) manages devices but does not enforce access policies on its own.

Option D (Microsoft Defender for Cloud Apps) provides cloud app security but is not the primary conditional access engine.

1156
MCQmedium

A company uses Microsoft Entra ID. They need to provide temporary access to a set of external auditors so they can review financial documents stored in SharePoint Online. The auditors must use their own email addresses to receive an access code. Which Microsoft Entra feature should the company configure?

A.Microsoft Entra Privileged Identity Management (PIM)
B.Microsoft Entra Conditional Access
C.Microsoft Entra B2C
D.Microsoft Entra B2B collaboration with email one-time passcode
AnswerD

Microsoft Entra B2B collaboration allows you to invite external users as guest users. With email one-time passcode, the invited users can authenticate using a code sent to their email, without needing a Microsoft account or Azure AD account. This meets the requirement for auditors to use their own email addresses and receive a code. It is the appropriate feature for temporary external access.

Why this answer

Microsoft Entra B2B collaboration enables you to invite external users as guests and allows them to authenticate using email one-time passcode. This is ideal for temporary access scenarios like audits, where external users can use their own email addresses without creating Microsoft accounts. It simplifies management and ensures secure access to resources like SharePoint Online.

Exam trap

The trap here is confusing B2B collaboration with B2C, but B2B is for business partners while B2C is for customers, and only B2B supports email one-time passcode for guests.

1157
MCQeasy

You are a security administrator for a company that uses Microsoft 365. The compliance team needs to automatically classify and protect sensitive data such as credit card numbers in emails and documents. Which Microsoft Purview solution should you recommend?

A.Microsoft Purview Information Protection
B.Microsoft Purview Records Management
C.Microsoft Purview Insider Risk Management
D.Microsoft Purview Data Loss Prevention
AnswerA

Microsoft Purview Information Protection applies sensitivity labels with automatic classification, detecting credit card numbers in emails and documents and enforcing encryption or protection automatically. This satisfies the compliance team's need to classify and protect sensitive data across Microsoft 365 workloads.

Why this answer

A is correct because Microsoft Purview Information Protection (formerly Azure Information Protection) provides automatic classification of sensitive data, such as credit card numbers, by applying sensitivity labels based on rules and patterns. It also offers protection through encryption or access restrictions. This solution directly addresses the compliance team's requirement for both automatic classification and protection.

Data Loss Prevention (DLP) enforces protective actions after classification but does not perform the classification itself.

Exam trap

The trap is that candidates may confuse Microsoft Purview Data Loss Prevention (DLP) with Information Protection. DLP enforces policies to prevent data loss but does not automatically classify data; Information Protection handles the actual labeling and classification. The question explicitly requires both classification and protection, making Information Protection the correct choice.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on manually or automatically applying sensitivity labels to classify and protect data, but it does not natively enforce real-time data loss prevention actions like blocking emails containing credit card numbers; DLP handles that enforcement. Option B is wrong because Microsoft Purview Records Management is designed for managing retention and disposition of records based on regulatory requirements, not for real-time detection and protection of sensitive data in transit or at rest. Option C is wrong because Microsoft Purview Insider Risk Management identifies and investigates risky user activities (e.g., data theft by insiders), but it does not automatically classify or protect sensitive data like credit card numbers in emails and documents; it focuses on user behavior analytics, not content-based protection.

1158
MCQeasy

A company uses Microsoft Entra ID. Employees often forget their passwords and contact the IT helpdesk to reset them. The company wants to reduce helpdesk costs by allowing users to reset their own passwords using a verified mobile phone number or email address. Which Microsoft Entra ID feature should the administrator enable?

A.Microsoft Entra ID Identity Protection
B.Self-Service Password Reset (SSPR)
C.Privileged Identity Management (PIM)
D.Conditional Access
AnswerB

Self-Service Password Reset (SSPR) is a crucial Microsoft Entra ID feature that empowers users to reset their forgotten passwords without requiring assistance from IT helpdesk staff. Users must pre-register at least two authentication methods, such as a mobile phone number or an alternate email address, which are then used to verify their identity during the reset process. This capability significantly reduces helpdesk call volumes and improves user productivity by enabling immediate password recovery.

Why this answer

Self-Service Password Reset (SSPR) is the correct feature because it allows users to reset their own passwords without helpdesk intervention, using a verified mobile phone number or email address as authentication methods. This directly reduces helpdesk costs by shifting password reset responsibility to the user, while maintaining security through verification of registered contact methods.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with self-service password reset, because both involve 'management' of identities, but PIM is strictly for privileged role activation, not end-user password changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection is a risk-based security tool that detects potential identity vulnerabilities and automated remediation, but it does not provide self-service password reset capabilities. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and access reviews, not end-user password resets. Option D is wrong because Conditional Access enforces access policies based on signals like user location or device state, but it does not enable users to reset their own passwords.

1159
MCQhard

Your organization uses Microsoft Purview for data governance. You need to ensure that when a user marks an email as 'Confidential' using a sensitivity label, the email is automatically encrypted and cannot be forwarded. What configuration is required?

A.Configure the sensitivity label with encryption and a rights management template that prohibits forwarding
B.Create a DLP policy that detects the 'Confidential' label and applies encryption
C.Use the Azure Information Protection unified labeling scanner
D.Apply a retention label that triggers encryption
AnswerA

Sensitivity labels are designed to classify and protect data directly at the point of creation or modification. By configuring a sensitivity label with encryption, it applies Azure Rights Management (Azure RMS) protection to the content. This protection can include specific usage rights, such as "Do Not Forward," which prevents recipients from forwarding, printing, or copying the protected email or document, ensuring the data remains within its intended scope. This method directly embeds the protection into the content, making it persistent wherever the data travels.

Why this answer

Microsoft Purview sensitivity labels can be configured with encryption settings that use Azure Rights Management (Azure RMS) to enforce usage restrictions. By selecting the 'Do Not Forward' template, the email is automatically encrypted and the recipient cannot forward, copy, or print the message, meeting the requirement.

Exam trap

The trap here is that candidates often confuse the role of DLP policies with sensitivity labels, assuming DLP can enforce encryption, when in fact encryption is a native capability of sensitivity labels using Azure RMS templates.

How to eliminate wrong answers

Option B is wrong because a Data Loss Prevention (DLP) policy can detect sensitivity labels and trigger actions like blocking or warning, but it cannot directly apply encryption to emails; encryption is a property of the sensitivity label itself, not a DLP action. Option C is wrong because the Azure Information Protection unified labeling scanner is used for discovering, classifying, and labeling files on-premises, not for configuring encryption on emails sent from Exchange Online. Option D is wrong because retention labels are designed to manage data lifecycle and retention, not to apply encryption or rights protection; they do not enforce 'Do Not Forward' restrictions.

1160
MCQhard

A company's security team needs to detect and investigate potential data theft by employees who have legitimate access to sensitive data. They want a solution that uses heuristics and behavioral analytics to identify risky user actions such as data exfiltration to personal cloud storage. Which Microsoft Purview solution should they use?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Audit (Standard)
D.Microsoft Purview Information Barriers
AnswerB

Microsoft Purview Insider Risk Management is the correct solution as it specifically leverages built-in risk indicators, machine learning, and behavioral analytics to identify and investigate potential insider risks, including data theft. It correlates various user activities across Microsoft 365 services to detect unusual patterns, enabling security teams to proactively identify, analyze, and respond to incidents.

Why this answer

Microsoft Purview Insider Risk Management is the correct solution because it is specifically designed to detect, investigate, and act on risky user activities that may lead to data theft, using heuristics and behavioral analytics. It correlates signals from Microsoft 365 and Azure services to identify patterns like data exfiltration to personal cloud storage, which aligns directly with the scenario's requirements.

Exam trap

The trap here is that candidates often confuse the reactive, policy-based enforcement of Data Loss Prevention (DLP) with the proactive, behavioral detection of Insider Risk Management, assuming DLP can detect risky user actions when it actually only blocks or alerts on content matching static rules.

Why the other options are wrong

A

Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data by enforcing policies, but it does not use heuristics and behavioral analytics to detect risky user actions like data exfiltration by insiders.

D

Information Barriers are designed to prevent communication and collaboration between specific groups to avoid conflicts of interest, not to detect or investigate data theft by employees with legitimate access.

When would these options actually be correct?

A

A company wants to automatically block employees from emailing credit card numbers to external recipients or uploading them to a public SharePoint site. DLP would be the correct solution to enforce policies that prevent data loss.

D

A company needs to restrict communication between two departments (e.g., traders and analysts) to prevent insider trading. Which Microsoft Purview solution should they use?

Why candidates pick the wrong answer

A

Candidates may confuse DLP's data protection capabilities with insider risk detection, assuming that any solution involving sensitive data and prevention also covers behavioral analytics.

D

Candidates may confuse 'barriers' with 'preventing data theft' and think Information Barriers can block data exfiltration, but they focus on communication restrictions, not behavioral analytics.

1161
MCQmedium

A security team wants to discover all cloud apps being used by employees, including unsanctioned personal apps like unauthorized file-sharing services. They plan to analyze firewall logs to identify traffic patterns and assess each app's risk score. Which feature of Microsoft Defender for Cloud Apps should they enable?

A.Cloud Discovery
B.App Governance
C.Information Protection
D.Conditional Access App Control
AnswerA

Cloud Discovery, a core capability within Microsoft Defender for Cloud Apps, is precisely designed to identify all cloud applications accessed by users within an organization. It achieves this by analyzing traffic logs from firewalls and proxies, providing comprehensive visibility into both sanctioned and unsanctioned "shadow IT" applications. This process generates detailed risk assessments for each discovered app, enabling security teams to understand potential vulnerabilities, compliance gaps, and usage patterns. Its primary function is comprehensive app discovery and risk assessment.

Why this answer

Cloud Discovery is the correct feature because it analyzes traffic logs (e.g., from firewalls or proxies) to identify all cloud apps in use, including unsanctioned personal apps like unauthorized file-sharing services. It then assesses each app's risk score based on over 80 risk factors, such as encryption standards and data residency, enabling the security team to discover and evaluate shadow IT.

Exam trap

The trap here is that candidates often confuse Cloud Discovery with Conditional Access App Control, mistakenly thinking that real-time session policies can also discover unsanctioned apps, but discovery requires log analysis, not policy enforcement.

How to eliminate wrong answers

Option B (App Governance) is wrong because it focuses on monitoring and managing OAuth-enabled apps that have been granted access to Microsoft 365 data, not on discovering unsanctioned cloud apps from firewall logs. Option C (Information Protection) is wrong because it deals with classifying, labeling, and protecting sensitive data (e.g., via sensitivity labels and DLP), not with discovering cloud app usage or analyzing traffic patterns. Option D (Conditional Access App Control) is wrong because it enforces real-time access policies (e.g., session controls) on sanctioned apps, but it does not perform discovery or risk assessment of unsanctioned apps from firewall logs.

1162
MCQmedium

A company requires all employees to provide a one-time passcode generated by an authenticator app in addition to their password when accessing the corporate VPN. This practice is an example of which security concept?

A.A. Authorization
B.B. Auditing
C.C. Authentication
D.D. Accounting
AnswerC

Authentication is the foundational security process of verifying an entity's identity, confirming they are who they claim to be. In this scenario, requiring a one-time passcode (OTP) alongside another factor, like a password, establishes multi-factor authentication (MFA). This robust method significantly enhances security by requiring multiple proofs of identity before granting access to a system or resource, directly addressing the company's need to confirm employee identity.

Why this answer

The requirement for a one-time passcode (OTP) from an authenticator app in addition to a password is a classic implementation of multi-factor authentication (MFA). Authentication is the process of verifying the identity of a user, device, or service, and this scenario uses two distinct factors: something you know (password) and something you have (the OTP generated by the app). This directly aligns with the security concept of authentication, not authorization, auditing, or accounting.

Exam trap

The trap here is that candidates often confuse authentication (proving identity) with authorization (granting permissions), especially when the question describes a 'gate' like VPN access, leading them to incorrectly select authorization.

Why the other options are wrong

A

Authorization determines what resources a user can access after authentication, but the scenario describes verifying identity via a one-time passcode, which is an authentication process, not authorization.

B

Auditing refers to the process of reviewing and analyzing logs or records to ensure compliance or detect anomalies, not to verifying identity. The question describes verifying identity via password and passcode, which is authentication, not auditing.

When would these options actually be correct?

A

A question that asks: 'After a user authenticates, the system checks if they have permission to access a specific file. This is an example of which security concept?' — then authorization would be correct.

B

A company requires all VPN access attempts to be logged and reviewed monthly for unauthorized access attempts. This practice is an example of auditing.

Why candidates pick the wrong answer

A

Candidates may confuse the terms 'authentication' and 'authorization' because both involve access control, and the use of a passcode might be mistakenly thought to grant access rights rather than verify identity.

B

Candidates may confuse auditing with authentication because both involve security controls, and auditing often includes reviewing authentication logs, leading them to think the passcode step is part of an audit process.

1163
MCQmedium

Your company uses Microsoft Purview Data Lifecycle Management. You need to ensure that emails in users' mailboxes are retained for 7 years for compliance, but users should be able to delete emails they no longer need before that period. Which configuration achieves this?

A.Configure a Data Loss Prevention policy
B.Place a litigation hold on the mailboxes
C.Apply a retention label with record locking
D.Apply a retention policy without a preservation lock
AnswerD

Applying a retention policy without a preservation lock allows users to delete items from their primary view within applications like Outlook or SharePoint. However, the retention policy ensures that a copy of the deleted item is moved to a secure, hidden location (e.g., the Recoverable Items folder for Exchange, or the Preservation Hold library for SharePoint/OneDrive) and retained for the policy's duration. This mechanism precisely meets the requirement of allowing user deletion while guaranteeing the item remains discoverable and recoverable by administrators.

Why this answer

A retention policy without a preservation lock (Option D) allows you to define a retention period (7 years) for emails while still permitting users to delete items before that period ends. When a user deletes an email, it is moved to the Recoverable Items folder and retained for the remainder of the 7-year period, after which it is permanently deleted. This meets the compliance requirement without preventing user deletion.

Exam trap

The trap here is that candidates often confuse retention policies with holds or labels, assuming that any retention mechanism must block user deletion, but a retention policy without a preservation lock allows deletion while still retaining the data in the background.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy is designed to prevent sensitive data from being shared or leaked, not to retain emails for a fixed period. Option B is wrong because a litigation hold preserves all mailbox content indefinitely (or until the hold is removed) and does not allow users to delete emails before the retention period expires. Option C is wrong because a retention label with record locking marks items as records, preventing users from deleting or modifying them, which contradicts the requirement that users should be able to delete emails they no longer need.

1164
MCQeasy

A company wants to enforce conditional access policies that require multifactor authentication (MFA) for all users accessing financial apps from outside the corporate network. Which Microsoft Entra ID license is minimally required to create conditional access policies?

A.Microsoft 365 Business Basic
B.Microsoft Entra ID P2
C.Microsoft Entra ID Free
D.Microsoft Entra ID P1
AnswerD

Microsoft Entra ID P1 is the correct and minimal license required to enforce Conditional Access policies. This license tier enables organizations to define and apply robust access controls, such as requiring multi-factor authentication (MFA) for specific applications, blocking access from untrusted locations, or enforcing device compliance. It provides the essential framework for implementing a strong, adaptive access management strategy.

Why this answer

Microsoft Entra ID P1 (formerly Azure AD Premium P1) is the minimum license required to create and enforce conditional access policies. Conditional access is a premium feature that is not available in Free or Microsoft 365 Business Basic tiers, and while P2 includes additional capabilities like Identity Protection, it is not necessary for basic MFA enforcement based on location.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID P2 as the minimum because they associate it with advanced security features, but the exam specifically tests that P1 is sufficient for creating conditional access policies without the need for P2's Identity Protection or PIM capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic does not include Microsoft Entra ID P1; it only provides the Free tier of Entra ID, which lacks conditional access policy creation. Option B is wrong because Microsoft Entra ID P2 includes all P1 features plus Identity Protection and Privileged Identity Management, but it is not the minimum required for basic conditional access policies. Option C is wrong because Microsoft Entra ID Free does not support conditional access policies; it only supports basic security defaults, not customizable policies.

1165
MCQmedium

A company uses Microsoft Defender for Cloud Apps to protect its SaaS apps. The security team needs to detect when a user downloads more than 100 files from SharePoint Online within 10 minutes. Which policy type should they create?

A.Anomaly detection policy
B.Activity policy
C.Threat detection policy
D.Compliance policy
AnswerA

Anomaly detection policies in Microsoft Defender for Cloud Apps leverage advanced machine learning algorithms to establish a baseline of normal user and entity behavior within your cloud environment. These policies continuously monitor for significant deviations from this established baseline, such as impossible travel, unusual administrative activities, or mass downloads to an unmanaged device. By identifying these statistical anomalies, they proactively detect potential threats like compromised accounts, insider threats, or data exfiltration attempts that might otherwise go unnoticed.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish a baseline of normal user behavior and then trigger alerts when deviations occur, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This specific scenario—unusually high download volume in a short time—is a classic example of a behavioral anomaly that an anomaly detection policy is designed to catch, as it may indicate a data exfiltration attempt.

Exam trap

The trap here is that candidates often confuse 'activity policy' with 'anomaly detection policy,' assuming any user action-based alert is an activity policy, but activity policies require explicit, static conditions (e.g., 'download from SharePoint') and cannot dynamically detect unusual volume or frequency without additional logic.

How to eliminate wrong answers

Option B (Activity policy) is wrong because activity policies are rule-based and match specific, predefined activities (e.g., 'download file from SharePoint') but cannot natively detect anomalous volume thresholds like 'more than 100 files in 10 minutes' without custom scripting or repeated log aggregation. Option C (Threat detection policy) is wrong because threat detection policies in Defender for Cloud Apps focus on identifying known threat actors, malware, or compromised accounts using threat intelligence feeds, not on behavioral anomalies based on volume or frequency. Option D (Compliance policy) is wrong because compliance policies are used to enforce data handling standards (e.g., DLP, data classification) and do not monitor user activity patterns for anomalous behavior.

1166
MCQhard

A Microsoft Purview retention policy is configured to retain emails for 365 days and then delete them. What will happen to emails after 365 days?

A.Emails will be deleted immediately
B.Emails will be retained for 365 days and then deleted
C.Emails will be retained and then reviewed for deletion
D.Emails will be kept indefinitely
AnswerB

The Microsoft Purview retention policy is configured with a 'Keep and then delete' action, specifically set for a duration of 365 days. This means that emails covered by this policy will be preserved and immutable for the entire 365-day period from their creation or last modification date. Upon the expiration of this retention period, the policy will automatically trigger the permanent deletion of these emails from their respective locations.

Why this answer

The retention policy is configured to retain emails for 365 days and then delete them. In Microsoft Purview, when a retention policy specifies a retention period followed by a deletion action, content is preserved for the entire duration and then permanently removed at the end of the period. Therefore, after 365 days, the emails will be deleted automatically.

Exam trap

The trap here is that candidates often confuse a retention policy with a litigation hold or eDiscovery hold, which preserve content indefinitely until manually released, whereas a retention policy with a deletion action automatically removes content after the specified period.

How to eliminate wrong answers

Option A is wrong because the policy does not specify immediate deletion; it includes a retention period of 365 days before deletion occurs. Option C is wrong because Microsoft Purview retention policies do not include a manual review step before deletion; deletion is automatic based on the configured action. Option D is wrong because the policy explicitly sets a retention period of 365 days with a deletion action, so emails will not be kept indefinitely.

1167
MCQmedium

A company uses Microsoft Entra ID to manage identities. They want to enforce access policies based on user location, device compliance, and application sensitivity. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra ID Protection
B.Conditional Access
C.Privileged Identity Management (PIM)
D.Microsoft Entra Connect Sync
AnswerB

Conditional Access is the precise solution for defining and enforcing granular access policies based on a wide array of conditions. Administrators can configure policies that evaluate user attributes, device state (e.g., compliant vs. non-compliant), location, application being accessed, and sign-in risk. This allows for dynamic access control, enabling actions like requiring multi-factor authentication, blocking access, or allowing access only from managed devices, directly addressing the need for policy enforcement based on specific criteria.

Why this answer

Conditional Access is the correct capability because it allows administrators to create policies that enforce access controls based on conditions such as user location, device compliance, and application sensitivity. These policies evaluate signals at sign-in time and can require multi-factor authentication, block access, or grant limited access based on the defined conditions.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Protection (which deals with risk detection) with Conditional Access (which enforces policies based on conditions like location and device compliance), but ID Protection does not directly enforce location- or device-based access rules.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, anonymous IP addresses) and does not directly enforce policies based on device compliance or application sensitivity. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and role activation workflows, not location- or device-based access policies. Option D is wrong because Microsoft Entra Connect Sync is a tool for synchronizing on-premises directory objects to Entra ID and has no role in enforcing access policies.

1168
MCQeasy

Refer to the exhibit. You have a Data Loss Prevention (DLP) policy in Microsoft Purview. What will happen when a user tries to share a document containing a credit card number via email?

A.The email is blocked only if the recipient is external
B.The email is sent with a warning to the recipient
C.The email is sent but the user is not notified
D.The email is blocked and the user receives a notification
AnswerD

This option accurately describes the combined effect of a typical DLP policy configured for strict enforcement. When sensitive information is detected within the email, the policy's 'Block access' action prevents the email from being delivered to its intended recipients, ensuring data protection. Concurrently, the policy's notification setting ensures that the sender is immediately informed about the policy violation and the reason for the email's blocking, allowing them to understand and rectify the issue.

Why this answer

When a DLP policy in Microsoft Purview is configured to block content containing sensitive information types like credit card numbers, the email is prevented from being sent and the user receives a policy tip notification explaining the violation. This is the standard 'Block' action behavior in a DLP rule, which stops the email at send time and surfaces a non-compliance notification to the sender.

Exam trap

SC-900 often tests the misconception that DLP only applies to external recipients — in reality, DLP rules can block internal sharing too, and the 'block' action always includes a user notification.

How to eliminate wrong answers

Option A is wrong because DLP policies apply based on the rule's conditions (location, sensitive info type, user/group scope), not solely on whether the recipient is external — internal emails can also be blocked if the policy covers them. Option B is wrong because a 'warning to the recipient' implies the email was delivered, which contradicts the 'block' action; warnings are a separate DLP action (Override or Warn) that allows sending with justification. Option C is wrong because DLP always notifies the user via policy tips when a rule matches — silent blocking without notification is not standard behavior.

1169
MCQhard

You are analyzing a PIM activation request. The roleDefinitionId corresponds to the Global Administrator role. What is the duration of the activation?

A.4 hours
B.8 hours
C.8 minutes
D.8 days
AnswerA

The ISO 8601 duration string "PT8H" explicitly defines an eight-hour period for role activation. Therefore, interpreting this as 4 hours is an incorrect reading of the specified duration. Azure AD PIM relies on precise time definitions to enforce Just-In-Time access, and any deviation from the configured "PT8H" value would contradict the role's maximum activation setting.

Why this answer

By default, the activation duration for a PIM role is 4 hours. While the maximum allowed activation duration for any role, including Global Administrator, is 8 hours, the system's default setting is 4 hours if no custom configuration is applied. Highly privileged roles like Global Administrator are often configured with an 8-hour maximum by organizations, but the system default is 4 hours.

Exam trap

The trap here is that candidates confuse the *default* activation duration for PIM roles (4 hours) with the *maximum allowed* duration (8 hours), or the 8-minute activation window for temporary access passes, leading them to select the wrong option. For highly privileged roles like Global Administrator, while 8 hours is the maximum and often configured, the system default is 4 hours.

How to eliminate wrong answers

Option A is wrong because 4 hours is not the default maximum activation duration for Global Administrator; it is a possible custom duration but not the default. Option C is wrong because 8 minutes is far too short for a Global Administrator activation; PIM allows durations in hours, not minutes, for such roles. Option D is wrong because 8 days would violate the principle of just-in-time access; PIM enforces a maximum of 8 hours for Global Administrator to prevent persistent elevation.

1170
MCQhard

A multinational company uses a hybrid infrastructure with on-premises Active Directory and Azure resources. They have deployed Microsoft Defender for Cloud to protect their Azure workloads. They now want to extend threat detection to their on-premises Active Directory by collecting security events from domain controllers to detect attacks like Golden Ticket, DCSync, and malicious Kerberos activity. The solution should integrate with Microsoft Sentinel for automated response. Which security solution should they deploy on the on-premises domain controllers?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Identity is purpose-built to detect advanced threats targeting on-premises Active Directory environments by analyzing network traffic and Windows events from domain controllers. It deploys lightweight sensors directly on domain controllers or uses port mirroring to gain deep visibility into authentication protocols like Kerberos and NTLM. This specialized analysis allows it to identify suspicious user behavior, privilege escalation attempts, and specific attack patterns, such as Golden Ticket, Pass-the-Hash, and DCShadow, providing crucial security alerts for AD compromise. Its focus is precisely on the unique attack surface presented by Active Directory.

Why this answer

Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to monitor on-premises Active Directory signals, including security events from domain controllers, to detect advanced identity-based attacks such as Golden Ticket, DCSync, and malicious Kerberos activity. MDI integrates natively with Microsoft Sentinel to enable automated response workflows, fulfilling the requirement for extending threat detection to on-premises AD.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) with Microsoft Defender for Identity (an AD-focused identity threat detection tool), because both names include 'Defender' and both can integrate with Sentinel, but only MDI monitors on-premises Active Directory authentication events.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) focused on securing Azure, hybrid, and multi-cloud resources, not on-premises Active Directory domain controllers. Option B is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution for devices like servers and workstations, not for monitoring Active Directory authentication protocols or Kerberos attacks. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR platform that ingests logs and triggers responses, but it does not deploy agents on domain controllers to collect security events; it relies on data connectors from other sources like MDI.

1171
Multi-Selecteasy

Which TWO of the following are types of retention actions available in Microsoft Purview? (Choose two.)

Select 2 answers
A.Retain data for a specified period
B.Encrypt data at rest
C.Classify data as confidential
D.Delete data after a specified period
E.Search for data using eDiscovery
AnswersA, D

This is a fundamental retention action within Microsoft Purview, designed to prevent the permanent deletion of content for a specified duration. It ensures that data, such as emails, documents, or Teams messages, remains discoverable and accessible, even if users attempt to delete it from their applications. This action is crucial for meeting regulatory compliance, legal discovery requirements, or internal organizational policies by placing an immutable hold on the data.

Why this answer

Option A (Retain data for a specified period) is correct because Microsoft Purview retention policies and retention labels support a retain action that keeps content for a defined duration, such as 7 years, before any further action occurs. Option D (Delete data after a specified period) is correct because Purview retention settings also provide a delete action that removes content once the specified retention period expires, either alone or combined with retention. These two actions—retain and delete—are the fundamental retention actions configurable in Purview retention policies and labels.

Option B is incorrect because encryption at rest is handled by services such as BitLocker, Azure Storage Service Encryption, or Microsoft 365 encryption features, not by retention actions. Option C is incorrect because classifying data as confidential is a sensitivity labeling or classification function, not a retention action. Option E is incorrect because searching for data using eDiscovery is an investigation and discovery capability, not a retention action.

Exam trap

The trap here is that candidates confuse retention actions (which only involve keeping or deleting data over time) with other Purview capabilities like encryption, classification, or search, leading them to select options that describe security or discovery features rather than actual retention behaviors.

1172
MCQmedium

A financial organization implements a security control that logs every access attempt to sensitive financial records, including who accessed the data, when it was accessed, and from which device. The logs are regularly reviewed by the security team. This control primarily addresses which security concept?

A.Confidentiality
B.Integrity
C.Availability
D.Accountability
AnswerD

Accountability is the ability to trace actions and events back to a specific entity, whether a user, process, or system. By meticulously recording access, modifications, and system events, logging creates an indispensable audit trail. This trail enables forensic analysis, compliance verification, and the attribution of responsibility, making it a foundational component for holding individuals and systems accountable for their actions within an organization.

Why this answer

Accountability ensures that actions affecting sensitive data can be traced uniquely to an individual. By logging who accessed the data, when, and from which device, the organization creates an audit trail that holds users responsible for their actions. This directly supports non-repudiation and forensic analysis, which are the core goals of accountability.

Exam trap

The trap here is that candidates confuse logging with confidentiality, thinking that tracking access prevents unauthorized viewing, when in fact logging only records the event and does not block the access itself.

How to eliminate wrong answers

Option A is wrong because confidentiality focuses on preventing unauthorized access to data (e.g., through encryption or access controls), not on logging who accessed it. Option B is wrong because integrity ensures data has not been altered or tampered with (e.g., via hashing or checksums), whereas logging does not protect against modification. Option C is wrong because availability ensures systems and data are accessible when needed (e.g., through redundancy or failover), and logging does not directly contribute to uptime or resilience.

1173
MCQmedium

A company is involved in a legal dispute and must preserve all emails and documents related to the case. The legal team needs to identify specific custodians (employees) and place a hold on their Exchange Online mailboxes and SharePoint sites to prevent any deletion or alteration of relevant content. Additionally, they need to collect the preserved data for review and analysis. Which Microsoft Purview solution should they use?

A.Microsoft Purview eDiscovery (Premium)
B.Microsoft Purview Audit
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Communication Compliance
AnswerA

eDiscovery (Premium) supports custodian identification, placing holds on Exchange Online mailboxes and SharePoint sites, and collecting preserved content into review sets. Standard eDiscovery lacks custodian management and advanced review, so Premium satisfies both the hold and collection requirements.

Why this answer

Microsoft Purview eDiscovery (Premium) is the correct solution because it provides end-to-end workflow for legal investigations: identifying and placing custodians on hold (via litigation hold on Exchange Online mailboxes and SharePoint sites), preserving content from deletion or alteration, and then collecting, reviewing, and analyzing the preserved data. This directly matches the scenario's requirements for legal hold and data collection for review.

Exam trap

The trap here is confusing the logging/auditing capability (Audit) with the preservation and collection workflow (eDiscovery), or assuming that retention policies (Data Lifecycle Management) can serve as a legal hold, when in fact they are designed for lifecycle management and do not support custodian-based holds or case-specific collection.

How to eliminate wrong answers

Option B (Microsoft Purview Audit) is wrong because it only logs and records user and admin activities (e.g., who accessed or deleted content) but does not place holds on data or allow collection for review. Option C (Microsoft Purview Data Lifecycle Management) is wrong because it focuses on retention and deletion policies based on data lifecycle (e.g., automatically deleting old emails), not on preserving data for a specific legal case or identifying custodians. Option D (Microsoft Purview Communication Compliance) is wrong because it is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) by analyzing messages, not for legal hold or eDiscovery collection.

1174
MCQeasy

A company wants to grant temporary, time-limited access to a critical Azure resource for an external consultant. Which Microsoft Entra feature should they use?

A.Entra Verified ID
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerB

Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) capabilities. It allows administrators to grant temporary, time-limited access to privileged roles, which can be activated on demand for a specified duration. This ensures that users only have elevated permissions when absolutely necessary, significantly reducing the attack surface.

Why this answer

Privileged Identity Management (PIM) is the correct choice because it provides just-in-time (JIT) privileged access to Azure resources, allowing administrators to grant time-bound, temporary access that automatically expires. This aligns directly with the requirement for temporary, time-limited access for an external consultant, as PIM supports activation windows, approval workflows, and audit logging for such scenarios.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Conditional Access, thinking that Conditional Access can enforce time-limited access, but Conditional Access only controls sign-in conditions, not the duration of privileged role assignments.

How to eliminate wrong answers

Option A is wrong because Entra Verified ID is a decentralized identity verification solution using verifiable credentials (based on W3C standards) and does not provide time-limited access management to Azure resources. Option C is wrong because Identity Protection is a risk-detection and remediation service that identifies compromised identities or risky sign-ins, not a tool for granting or managing temporary access. Option D is wrong because Conditional Access enforces policies based on conditions like location or device state at sign-in time, but it does not grant or schedule time-limited privileged access to specific resources.

1175
MCQeasy

A user receives an encrypted email from their bank. They use their private key to decrypt the message. After reading it, they verify that the message content has not been altered during transit. Which security principle is primarily demonstrated by the verification that the content was not altered?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerB

Integrity ensures that data remains unaltered and complete during transmission or storage. When a user verifies that the content of an encrypted email from their bank has not been changed, they are confirming its integrity. This is typically achieved through cryptographic mechanisms like hashing or digital signatures, which detect any unauthorized modification, ensuring the message received is exactly what was sent.

Why this answer

The verification that the message content has not been altered during transit directly demonstrates the principle of integrity. Integrity ensures that data remains unchanged from its source to its destination, typically enforced through cryptographic hashing or digital signatures. In this scenario, the user's ability to confirm that the email content was not tampered with relies on a hash or signature verification mechanism, which is the core function of integrity protection.

Exam trap

The trap here is that candidates often confuse integrity with non-repudiation, but non-repudiation proves the origin of the message (who sent it), whereas integrity proves the message was not altered—two distinct security goals.

Why the other options are wrong

A

The question asks about verifying that content was not altered, which is integrity. Confidentiality protects data from unauthorized access, not from modification.

C

The question asks about verifying that message content was not altered, which is the definition of integrity. Availability concerns ensuring data is accessible when needed, not verifying content integrity.

D

Non-repudiation ensures that the sender cannot deny having sent the message, but the question focuses on verifying that the content was not altered, which is integrity.

When would these options actually be correct?

A

A question: 'Which security principle ensures that an encrypted email cannot be read by unauthorized parties?' would make confidentiality correct.

C

A scenario where a user cannot access their encrypted email due to a server outage or denial-of-service attack would test availability. The question would ask: 'Which security principle is compromised when users cannot retrieve their emails?'

D

A user receives a digitally signed email from their bank. After verifying the signature, they can prove to a third party that the bank indeed sent the email. Which security principle does this proof demonstrate?

Why candidates pick the wrong answer

A

Candidates may confuse encryption (which provides confidentiality) with integrity verification, thinking that because the email was encrypted, the verification step also relates to confidentiality.

C

Candidates may confuse availability with integrity because both are part of the CIA triad, and they might think that verifying content is about ensuring the message is 'available' in its original form.

D

Candidates may confuse integrity (content unchanged) with non-repudiation (undeniable origin), as both involve cryptographic verification and are often discussed together in security contexts.

1176
Multi-Selectmedium

A user logs into a company's financial application using their Microsoft Entra ID credentials. After successful sign-in, the application displays a dashboard with data for only the regions the user is authorized to manage. Which two security concepts are demonstrated in this scenario? (Select all that apply.)

Select 2 answers
A.Authentication
B.Authorization
C.Accounting
D.Non-repudiation
AnswersA, B

When a user enters credentials to access a financial application, the system performs authentication. This crucial initial step verifies the user's claimed identity by comparing the provided username and password against stored records. Successful authentication confirms 'who' the user is, granting them entry to the system.

Why this answer

Authentication is demonstrated because the user proves their identity by logging in with Microsoft Entra ID credentials, confirming they are who they claim to be. Authorization is demonstrated because after authentication, the application restricts the dashboard to show only data for regions the user is permitted to manage, enforcing access control based on assigned permissions.

Exam trap

The trap here is that candidates confuse authentication (verifying identity) with authorization (granting permissions), and may incorrectly select accounting or non-repudiation because they associate logging in with tracking or non-denial, but the scenario explicitly describes identity verification and access restriction, not logging or signature-based proof.

Why the other options are wrong

C

Accounting refers to tracking user activities for auditing or billing purposes, but the scenario only describes logging in and viewing authorized data, not recording or reviewing actions.

D

Non-repudiation ensures that a user cannot deny having performed an action, typically through digital signatures or audit logs. This scenario only involves logging in and viewing data, with no action that requires proof of origin or integrity.

When would these options actually be correct?

C

A question that asks: 'An organization needs to track which users accessed sensitive data and when. Which security concept ensures this tracking?' would make Accounting correct.

D

A user submits a purchase order using a digital signature. Later, the user claims they never submitted it. Non-repudiation would be the correct answer if the question asked which security concept prevents the user from denying the submission.

Why candidates pick the wrong answer

C

Candidates may confuse 'accounting' with 'account' (as in user account) or think that logging in implies some form of activity tracking, but accounting specifically involves logging and reviewing actions, not just authentication or authorization.

D

Candidates may confuse non-repudiation with authentication or authorization because all involve identity and access, but non-repudiation specifically deals with undeniable proof of actions, not just verifying identity or permissions.

1177
MCQmedium

A security team needs to continuously assess the security posture of Azure resources, including virtual machines, storage accounts, and SQL databases. They also want to identify vulnerabilities in both Windows and Linux servers running in Azure and on-premises, and receive prioritized recommendations for remediation. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Endpoint
C.Microsoft Sentinel
D.Microsoft Purview
AnswerA

Microsoft Defender for Cloud is the correct choice because it provides comprehensive Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities. It continuously assesses the security posture of Azure, on-premises, and multi-cloud environments by identifying misconfigurations, vulnerabilities, and compliance deviations. This service offers actionable security recommendations and a secure score to proactively enhance an organization's overall security.

Why this answer

Microsoft Defender for Cloud is the correct solution because it provides continuous assessment of Azure resources (VMs, storage accounts, SQL databases) and hybrid workloads, including vulnerability scanning for Windows and Linux servers both in Azure and on-premises. It delivers prioritized remediation recommendations based on the secure score and integrated vulnerability assessment tools like Qualys or Microsoft Defender Vulnerability Management.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM and workload protection solution) with Microsoft Defender for Endpoint (an EDR solution), but the question's focus on assessing security posture of Azure resources and hybrid servers points specifically to Defender for Cloud's CSPM capabilities.

Why the other options are wrong

B

Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on assessing the security posture of Azure resources like VMs, storage accounts, and SQL databases, nor does it provide prioritized remediation recommendations for cloud infrastructure.

C

Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response across the enterprise, not a tool for continuously assessing security posture and identifying vulnerabilities in Azure resources and servers.

D

Microsoft Purview focuses on data governance, classification, and compliance (e.g., data loss prevention, information protection), not on assessing security posture or identifying vulnerabilities in Azure resources and servers.

When would these options actually be correct?

B

A question asking for a solution to protect endpoints (Windows/Linux servers, workstations) from advanced threats, with capabilities for antivirus, EDR, and vulnerability management on those devices, would make Defender for Endpoint the correct answer.

C

A question asking for a cloud-native SIEM that ingests security data from multiple sources (e.g., Azure, on-premises, other clouds) to detect, investigate, and respond to threats, and that provides advanced analytics and automation for incident response.

D

A question asks: 'Which Microsoft solution should an organization use to classify sensitive data across Azure, on-premises, and multi-cloud environments, and enforce data protection policies?'

Why candidates pick the wrong answer

B

Candidates may confuse Defender for Endpoint's vulnerability management features for servers with the broader cloud security posture management (CSPM) capabilities of Defender for Cloud, especially since both can assess server vulnerabilities.

C

Candidates may confuse Sentinel's security monitoring capabilities with the posture assessment and vulnerability management features of Defender for Cloud, especially since both involve security analysis.

D

Candidates may confuse Purview's data security capabilities (like data classification and labeling) with general security posture assessment, or they might think 'Purview' covers all security due to its broad name.

1178
MCQmedium

Your company is deploying Microsoft Defender for Cloud Apps. You need to detect and block the use of unsanctioned cloud apps that exhibit risky behavior. Which feature should you configure?

A.Azure Information Protection labels
B.Conditional Access policies
C.Cloud Discovery
D.Data Loss Prevention (DLP) policies
AnswerC

Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps, analyzes traffic logs from firewalls and proxy servers to identify all cloud applications accessed by users within an organization. It provides crucial visibility into 'shadow IT' by assessing the risk of discovered apps and can integrate with network security appliances to block access to unsanctioned or high-risk applications. This capability is fundamental for enforcing cloud app governance and reducing organizational risk.

Why this answer

Cloud Discovery is the correct feature because it analyzes traffic logs to identify unsanctioned cloud apps and assess their risk based on behavioral factors such as data upload volume, user count, and security posture. Once identified, Defender for Cloud Apps can automatically block these apps using the built-in app governance controls, enforcing policies to prevent risky app usage.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control access to known apps) with Cloud Discovery (which identifies and blocks unknown or unsanctioned apps), missing the core requirement of detecting risky behavior in previously unrecognized cloud services.

How to eliminate wrong answers

Option A is wrong because Azure Information Protection labels classify and protect documents and emails based on sensitivity, not detect or block unsanctioned cloud apps. Option B is wrong because Conditional Access policies control access to sanctioned apps based on user, device, or location conditions, but they do not discover or block unsanctioned cloud apps. Option D is wrong because Data Loss Prevention (DLP) policies monitor and prevent unauthorized sharing of sensitive data within sanctioned apps, not detect or block unsanctioned cloud apps.

1179
MCQhard

Your organization uses Microsoft Entra ID Governance. You need to ensure that access to a critical application is reviewed every 90 days by the application owner. If the review is not completed, access should be revoked automatically. Which feature should you configure?

A.Terms of use
B.Access reviews
C.Privileged Identity Management
D.Entitlement management
AnswerB

Microsoft Entra ID Access Reviews are specifically designed to manage the lifecycle of access to resources, groups, and applications by enabling regular, scheduled reviews. Administrators can configure these reviews to recur periodically, assign reviewers, and set up automatic actions, such as revoking access for users who are not approved or whose review is not completed within a specified timeframe. This functionality directly addresses the requirement for recurring access validation and automated revocation.

Why this answer

Access reviews in Microsoft Entra ID Governance allow you to create recurring reviews of group memberships or application assignments, with automatic revocation of access if the review is not completed. By configuring a review every 90 days and setting the 'Auto apply' action to 'Remove access', you ensure that the application owner must certify access or it is automatically revoked.

Exam trap

The trap here is that candidates confuse Entitlement management (which handles access packages and lifecycle) with Access reviews (which specifically handle recurring attestation and automatic revocation), leading them to pick D instead of B.

How to eliminate wrong answers

Option A is wrong because Terms of use are used to present legal or policy documents that users must accept before accessing applications, not to schedule recurring access reviews with automatic revocation. Option C is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and approval workflows, not for recurring attestation of access to a critical application. Option D is wrong because Entitlement management handles access packages and automated provisioning/deprovisioning based on policies, but it does not provide the recurring review cycle with automatic revocation if the review is not completed; that is the specific function of Access reviews.

1180
MCQmedium

Refer to the exhibit. You run the Azure PowerShell command for a storage account. What is the current network access configuration?

A.The storage account is accessible only from specific virtual networks.
B.The storage account is accessible from all networks.
C.The storage account is not accessible from any network.
D.The storage account is accessible only from specific IP addresses.
AnswerC

With the DefaultAction set to Deny and both the IpRules and VirtualNetworkRules arrays being empty, there are no explicit rules configured to override the default denial. This combination ensures that all incoming network traffic, regardless of its origin (public internet or Azure virtual networks), is blocked. Therefore, the storage account is effectively inaccessible from any network.

Why this answer

The Azure PowerShell command `Update-AzStorageAccountNetworkRuleSet -ResourceGroupName 'RG1' -StorageAccountName 'stgacc1' -DefaultAction Deny` sets the default network access rule to Deny. When the default action is Deny, no traffic is allowed unless explicitly permitted by a network rule (e.g., from a specific virtual network or IP address). Since no such rules are shown in the exhibit, the storage account is effectively not accessible from any network.

Exam trap

Students often mistakenly think that setting `DefaultAction Deny` alone makes the storage account accessible from specific networks or IPs, but they must remember that explicit rules must also be configured for any access to be allowed.

How to eliminate wrong answers

Option A is wrong because while a default action of Deny can be overridden by virtual network rules, the exhibit does not show any virtual network rules being configured, so the storage account is not accessible from specific virtual networks. Option B is wrong because the command explicitly sets `-DefaultAction Deny`, which blocks all network traffic by default, making the storage account inaccessible from all networks. Option D is wrong because although IP rules could permit access from specific IP addresses, no IP rules are shown in the exhibit, so the storage account is not accessible from specific IP addresses.

1181
MCQhard

A multinational company uses Microsoft Entra ID. They want to ensure that users from a specific country only access a sensitive application from compliant devices. Additionally, they want to block access if the sign-in risk is medium or high. Which combination of policies should they create?

A.A Conditional Access session policy to enforce sign-in frequency
B.A device compliance policy in Microsoft Intune
C.A Conditional Access policy requiring MFA from that country
D.A Conditional Access policy with conditions for location, device compliance, and sign-in risk
AnswerD

This Conditional Access policy effectively combines multiple critical signals to provide robust, risk-adaptive access control. By including conditions for location, device compliance, and sign-in risk (from Microsoft Entra ID Protection), it allows the system to evaluate the user's context comprehensively. This enables granular decisions, such as blocking access or requiring stronger authentication, specifically when a sign-in attempt is identified as risky based on these combined factors, directly addressing the company's security requirements.

Why this answer

A single Conditional Access policy can combine multiple conditions—such as location (country), device compliance (via integration with Intune), and sign-in risk—to enforce granular access controls. This allows the company to require compliant devices and block access when sign-in risk is medium or high, all within one policy.

Exam trap

The trap here is that candidates think they need separate policies for each condition (location, device compliance, risk), but Microsoft Entra ID allows combining all three conditions into a single Conditional Access policy, which is more efficient and aligns with the scenario's requirements.

How to eliminate wrong answers

Option A is wrong because sign-in frequency is a session control that re-prompts for authentication after a set time, not a condition to restrict access by location, device compliance, or risk. Option B is wrong because a device compliance policy in Intune defines compliance rules (e.g., encryption, OS version) but does not enforce access decisions or block based on sign-in risk; it only marks devices as compliant or non-compliant. Option C is wrong because requiring MFA from that country does not address device compliance or sign-in risk; it only adds an authentication step, not a block for medium/high risk or non-compliant devices.

1182
MCQhard

Refer to the exhibit. You are creating a custom analytics rule in Microsoft Sentinel. What does this rule detect?

A.Sign-ins with high sign-in risk from any location
B.Sign-ins with medium or high risk from the US
C.Sign-ins from users with high user risk outside the US
D.Sign-ins with medium or high risk from outside the US
AnswerD

This option accurately describes the criteria for the custom analytics rule. The rule targets sign-in attempts that Azure AD Identity Protection has classified with either a medium or high sign-in risk level. Additionally, it specifically filters these risky sign-ins to only include those originating from locations outside the United States, indicating a focus on external or geographically unusual threats.

Why this answer

The rule is configured with 'Risk level: Medium, High' and 'Location: Outside US'. This means it triggers only when both conditions are met: the sign-in risk is medium or high, and the location is outside the US. Option D correctly matches this combination, detecting sign-ins with medium or high risk from outside the US.

Exam trap

The trap here is confusing 'User risk' with 'Sign-in risk' — the rule explicitly uses sign-in risk, and candidates often misread the risk type or overlook the location filter, leading them to choose options that mix up these conditions.

How to eliminate wrong answers

Option A is wrong because the rule includes a location filter ('Outside US'), so it does not detect sign-ins from any location. Option B is wrong because the rule specifies 'Outside US' as the location, not 'from the US'. Option C is wrong because the rule uses 'Sign-in risk' (not 'User risk') as the risk type, and the location filter is 'Outside US', not 'outside the US' for user risk.

1183
MCQmedium

A company wants to gain visibility into which cloud applications are being used by employees (shadow IT) and assess the risk level of each app. They use Microsoft Defender for Cloud Apps. Which feature should they enable to discover and analyze these apps?

A.App Governance
B.Cloud Discovery
C.Conditional Access App Control
D.OAuth app policies
AnswerB

Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps, analyzes traffic logs from firewalls and proxy servers to identify all cloud applications accessed by users within an organization. It provides comprehensive visibility into both sanctioned and unsanctioned cloud services, often referred to as "shadow IT." This process helps security teams assess the risk associated with each discovered application and gain a complete understanding of cloud usage patterns.

Why this answer

Cloud Discovery is the correct feature because it analyzes traffic logs against the Microsoft Defender for Cloud Apps catalog of over 31,000 cloud apps to identify shadow IT usage. It provides risk scores based on factors like security certifications, data encryption, and compliance standards, enabling the company to assess each app's risk level.

Exam trap

The trap here is that candidates confuse Cloud Discovery (which finds unknown apps via traffic analysis) with Conditional Access App Control (which controls access to known apps), leading them to pick Option C for a discovery question.

How to eliminate wrong answers

Option A is wrong because App Governance is a policy and monitoring feature for managing OAuth-enabled apps (e.g., permissions and consent), not for discovering unknown cloud apps via traffic analysis. Option C is wrong because Conditional Access App Control is a reverse-proxy feature that enforces session policies on known apps in real time, not a discovery mechanism for shadow IT. Option D is wrong because OAuth app policies are used to control permissions for third-party OAuth apps connected to Microsoft 365, not to discover or analyze cloud applications in use.

1184
Multi-Selecteasy

Which TWO of the following are features of Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Identity governance and administration
B.Security information and event management (SIEM)
C.Security orchestration, automation, and response (SOAR)
D.Endpoint detection and response (EDR)
E.Data classification and labeling
AnswersB, C

Microsoft Sentinel's SIEM capabilities involve collecting security data at scale from diverse sources across an organization's entire digital estate. It then uses built-in analytics, machine learning, and threat intelligence to detect, investigate, and prioritize security threats. This centralized log management and threat detection are fundamental to its role as a modern cloud-native SIEM.

Why this answer

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that collects security data from across an organization, providing threat detection, investigation, and response. It also includes SOAR (Security Orchestration, Automation, and Response) capabilities through playbooks and automation rules, enabling automated incident response. These two features are core to Sentinel's functionality.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel's SIEM and SOAR capabilities with other Microsoft security products like Microsoft Defender for Endpoint (EDR) or Microsoft Purview (data classification), leading them to select options D or E instead of the correct SIEM and SOAR features.

1185
Multi-Selecteasy

Which TWO of the following are included in Microsoft Entra ID Protection?

Select 2 answers
A.Data loss prevention (DLP)
B.Privileged Identity Management (PIM)
C.Risk-based Conditional Access policies
D.Sign-in risk detections (e.g., anonymous IP address)
E.Passwordless authentication support
AnswersC, D

Microsoft Entra ID Protection directly integrates with Conditional Access policies to enable risk-based access decisions. When ID Protection detects a sign-in or user risk, such as an unfamiliar sign-in property or leaked credentials, it can feed this risk information into Conditional Access. These policies can then automatically enforce actions like requiring multi-factor authentication, password changes, or blocking access entirely, thereby protecting resources dynamically.

Why this answer

Option C (Risk-based Conditional Access policies) is correct because Microsoft Entra ID Protection surfaces user and sign-in risk levels that can be consumed directly by Conditional Access as conditions, allowing policies to block access or require MFA/password change when risk is detected. Option D (Sign-in risk detections such as anonymous IP address) is correct because ID Protection natively detects and reports sign-in risks like anonymous IP, atypical travel, malware-linked IP, and unfamiliar sign-in properties, and these detections feed the risk evaluations used by the service. Options A, B, and E are not part of ID Protection: DLP is a Microsoft Purview/Defender for Cloud Apps capability, PIM is a separate Microsoft Entra ID Governance/Privileged Identity Management service for just-in-time role activation, and passwordless authentication (FIDO2, Windows Hello, Authenticator) is a Microsoft Entra authentication method feature rather than an ID Protection component.

Exam trap

The trap here is that candidates often confuse the broader Microsoft Entra suite with the specific scope of Entra ID Protection, mistakenly selecting features like PIM or passwordless authentication that are part of Entra but not within ID Protection's risk-detection and remediation capabilities.

1186
MCQeasy

A company uses Microsoft 365 and Microsoft Azure. The security team wants a single portal that provides a unified view of alerts and incidents from their endpoints, email, and cloud applications to accelerate threat investigation and response. Which Microsoft security solution should they use?

A.Microsoft 365 Defender portal
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Microsoft Purview Compliance Manager
AnswerA

The Microsoft 365 Defender portal is the unified security operations center for Microsoft 365 services. It consolidates alerts, incidents, and automated investigation and response capabilities from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender for Cloud Apps. This centralized experience provides a comprehensive view of threats across the entire Microsoft 365 ecosystem, enabling security teams to efficiently investigate and remediate multi-stage attacks.

Why this answer

Microsoft 365 Defender portal (now part of the Microsoft 365 Defender unified security operations platform) is designed to aggregate alerts and incidents from endpoints (Microsoft Defender for Endpoint), email (Microsoft Defender for Office 365), and cloud applications (Microsoft Defender for Cloud Apps) into a single queue. This unified view enables security teams to triage and investigate threats across these domains without switching between separate consoles, directly accelerating response times.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Defender portal (a unified incident view for Microsoft 365 security products) with Microsoft Sentinel (a SIEM), not realizing that Sentinel requires additional setup and is not the out-of-the-box single portal for Microsoft's own security alerts.

How to eliminate wrong answers

Option B (Microsoft Defender for Cloud) is wrong because it focuses on securing cloud infrastructure (VMs, containers, PaaS) and provides alerts for those resources, not for endpoints, email, or cloud apps in a unified incident view. Option C (Microsoft Sentinel) is wrong because it is a cloud-native SIEM/SOAR that ingests logs from many sources, but it requires custom configuration and data connectors to unify alerts; it is not a pre-built single portal for Microsoft 365-native alerts and incidents. Option D (Microsoft Purview Compliance Manager) is wrong because it is a compliance management solution for assessing and managing regulatory compliance, not a security incident and alert aggregation tool.

1187
MCQmedium

A security operations team uses Microsoft Defender for Cloud and has connected their AWS and GCP accounts. They want to continuously assess the security posture of AWS EC2 instances against the CIS AWS Foundations Benchmark and receive prioritized recommendations. Which feature of Defender for Cloud should they use?

A.Cloud Security Posture Management (CSPM)
B.Microsoft Defender for Servers
C.Security Alerts
D.Workload protections
AnswerA

Cloud Security Posture Management (CSPM) is the core capability within Microsoft Defender for Cloud that continuously assesses cloud resources against security benchmarks and regulatory standards. It provides a secure score, identifies misconfigurations, and offers actionable recommendations to improve an organization's security posture across multi-cloud environments like Azure, AWS, and GCP. This proactive approach is essential for a security operations team focused on maintaining compliance and reducing attack surface.

Why this answer

Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud is specifically designed to continuously assess the security posture of multi-cloud resources (including AWS EC2 instances) against industry benchmarks like the CIS AWS Foundations Benchmark. CSPM provides a compliance dashboard, prioritized recommendations, and automated remediation guidance, directly addressing the team's need for ongoing assessment and prioritized recommendations.

Exam trap

The trap here is that candidates often confuse CSPM with workload protections (Option D) or Microsoft Defender for Servers (Option B), mistakenly thinking that threat detection or server-specific plans automatically include compliance assessment, when in fact CSPM is the dedicated feature for multi-cloud posture management and benchmark compliance.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Servers is a workload protection plan that provides advanced threat detection, just-in-time VM access, and file integrity monitoring for servers, but it does not natively assess compliance against the CIS AWS Foundations Benchmark or provide continuous posture assessment for AWS EC2 instances. Option C is wrong because Security Alerts are generated from threat detection signals (e.g., suspicious activities or attacks) and are not designed to continuously assess security posture against a compliance benchmark like CIS AWS Foundations. Option D is wrong because Workload protections refer to the suite of threat detection and prevention capabilities (e.g., for servers, databases, containers) within Defender for Cloud, but they do not include the compliance assessment and posture scoring features that CSPM provides.

1188
Multi-Selecthard

Which THREE of the following are features of Microsoft Purview Compliance Manager?

Select 3 answers
A.Data Loss Prevention policies
B.Improvement actions with assigned owners
C.Audit log search
D.Compliance score
E.Pre-built assessments for regulations like GDPR
AnswersB, D, E

Improvement actions with assigned owners are a core feature within Microsoft Purview Compliance Manager, representing specific tasks recommended to enhance an organization's compliance posture against various regulations and standards. These actions can be assigned to individual users or teams, ensuring clear accountability and enabling systematic tracking of progress as an organization works towards implementing necessary controls and demonstrating adherence to compliance requirements.

Why this answer

Compliance Manager is a Microsoft Purview solution that helps organizations assess and improve their compliance posture. Option B is correct because Compliance Manager provides improvement actions that can be assigned to owners, with implementation status and testing tracked per action. Option D is correct because Compliance Manager calculates a compliance score that quantifies progress toward completing improvement actions and assessments.

Option E is correct because Compliance Manager includes pre-built assessments and templates for regulations and standards such as GDPR, ISO 27001, and NIST. Option A is not part of Compliance Manager; Data Loss Prevention policies are configured in Microsoft Purview Data Loss Prevention. Option C is not part of Compliance Manager; Audit log search is provided by Microsoft Purview Audit.

Exam trap

The trap here is that candidates confuse the broad capabilities of Microsoft Purview (like DLP and audit) with the specific features of Compliance Manager, which is solely focused on compliance assessment, scoring, and improvement tracking.

1189
MCQeasy

Your company uses Microsoft Defender for Cloud Apps. You want to discover which cloud apps are being used in your organization and assess their risk levels. What should you use?

A.Cloud App Security Catalog
B.Cloud Discovery
C.Microsoft Purview Data Map
D.Microsoft Intune app inventory
AnswerB

Cloud Discovery is the precise capability within Microsoft Defender for Cloud Apps designed to identify and analyze all cloud applications accessed by users across an organization's network. It functions by ingesting and analyzing traffic logs from various sources, including firewalls, proxies, and endpoint agents, to detect accessed URLs, IP addresses, and user agents. This process effectively uncovers shadow IT, assesses the inherent risk of discovered applications, and provides comprehensive insights into their usage patterns.

Why this answer

Cloud Discovery is the feature within Microsoft Defender for Cloud Apps that analyzes traffic logs to identify which cloud apps are being used in your organization and assesses their risk based on the Cloud App Security Catalog. It provides visibility into Shadow IT by discovering unsanctioned app usage and assigning a risk score to each app.

Exam trap

The trap here is confusing the Cloud App Security Catalog (a static risk database) with Cloud Discovery (the active monitoring and log analysis feature), leading candidates to pick A when they need the tool that actually discovers in-use apps.

How to eliminate wrong answers

Option A is wrong because the Cloud App Security Catalog is a database of over 31,000 cloud apps with risk scores, but it does not discover which apps are actually being used in your organization—it only provides risk assessment for known apps. Option C is wrong because Microsoft Purview Data Map is used for data governance, classification, and lineage tracking across on-premises and cloud data sources, not for discovering cloud app usage. Option D is wrong because Microsoft Intune app inventory focuses on managing and reporting on apps deployed through mobile device management (MDM) or mobile application management (MAM), not on discovering unsanctioned cloud apps via traffic analysis.

1190
MCQeasy

A compliance officer needs to search for emails containing trade secrets across all mailboxes in the organization. Which Microsoft Purview solution should they use?

A.eDiscovery (Premium)
B.Communication Compliance
C.Data Loss Prevention
D.Audit (Standard)
AnswerA

eDiscovery (Premium) is the appropriate solution for a compliance officer who needs to search for specific email content across an organization's data. This service in Microsoft Purview enables robust content searches, legal holds, and the collection of electronically stored information (ESI) from various sources like Exchange mailboxes, SharePoint sites, and OneDrive accounts. It is specifically designed for investigative purposes, allowing for advanced querying, review, and export of relevant content.

Why this answer

eDiscovery (Premium) is the correct solution because it is specifically designed for legal and investigative searches across all mailboxes, including the ability to search for specific content like trade secrets using keyword queries and advanced features like predictive coding and review sets. It supports searching across Exchange Online mailboxes, SharePoint sites, and OneDrive for Business, making it ideal for a compliance officer conducting a broad, targeted search for sensitive information.

Exam trap

The trap here is that candidates often confuse Communication Compliance (which monitors for policy violations) with eDiscovery (which performs content searches), leading them to choose B because they think 'compliance' implies searching for trade secrets, but Communication Compliance is reactive and policy-based, not a search tool.

How to eliminate wrong answers

Option B (Communication Compliance) is wrong because it focuses on monitoring and detecting policy violations in communications (e.g., harassment, insider trading) based on configurable policies, not on performing ad-hoc searches for specific content like trade secrets across all mailboxes. Option C (Data Loss Prevention) is wrong because it is designed to prevent accidental or unauthorized sharing of sensitive data through policies that block or warn users in real-time, not to retrospectively search for existing emails containing specific content. Option D (Audit (Standard)) is wrong because it provides logging of user and admin activities (e.g., who accessed a mailbox or deleted an email) but does not allow searching the actual content of emails for specific keywords or phrases.

1191
MCQhard

You are investigating an alert in Microsoft Sentinel. The exhibit shows the JSON output of an alert that was generated from a sign-in log. The alert is linked to an active incident. Which action should you take to prioritize the incident for investigation?

A.Change the incident severity to critical
B.Close the incident as a false positive
C.Delete the alert from the incident
D.Reassign the incident to another analyst
AnswerA

In Microsoft Sentinel, changing an incident's severity to "Critical" directly impacts its prioritization within the security operations center (SOC) workflow. This action signals to analysts that the incident requires immediate attention and resources, often triggering specific escalation procedures or service level agreements (SLAs) to ensure rapid investigation and remediation. It effectively moves the incident to the top of the queue, ensuring it receives the necessary focus.

Why this answer

Changing the incident severity to critical in Microsoft Sentinel directly influences the prioritization and triage workflow. By elevating the severity, the incident is flagged for immediate attention, ensuring it appears at the top of the queue for investigation. This action aligns with the incident management best practice of using severity levels to indicate business impact and urgency.

Exam trap

The trap here is that candidates may confuse 'reassigning' with 'prioritizing,' but reassignment only changes the owner, not the incident's severity or position in the queue, while severity directly controls triage order in Sentinel.

How to eliminate wrong answers

Option B is wrong because closing the incident as a false positive would dismiss the alert without investigation, which is inappropriate since the alert is linked to an active incident and requires analysis. Option C is wrong because deleting the alert from the incident would remove evidence and break the linkage, potentially losing context needed for investigation; alerts are meant to be retained for forensic purposes. Option D is wrong because reassigning the incident to another analyst does not prioritize it; it merely changes ownership without affecting its urgency or visibility in the queue.

1192
MCQeasy

Your company uses Microsoft Defender for Cloud to secure Azure resources. You need to assess compliance with the CIS benchmark. What should you enable?

A.Azure Policy
B.Regulatory compliance standards in Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure Firewall
AnswerB

Microsoft Defender for Cloud's regulatory compliance dashboard is specifically designed to provide a centralized view of an organization's compliance posture against various industry standards and regulatory benchmarks, including the CIS Benchmarks. It continuously assesses Azure resources, identifies security misconfigurations, and maps these findings to specific controls within selected standards. This feature directly enables organizations to track, manage, and improve their compliance with frameworks like CIS by offering actionable recommendations.

Why this answer

To assess compliance with the CIS benchmark in Microsoft Defender for Cloud, you must enable the appropriate regulatory compliance standard. Defender for Cloud includes built-in support for industry standards like CIS, and by adding the CIS benchmark as a regulatory compliance standard, the service continuously assesses your Azure resources against the CIS controls and displays compliance status in the dashboard.

Exam trap

The trap here is that candidates confuse Azure Policy (the mechanism) with the regulatory compliance standards feature (the pre-built benchmark mapping), leading them to select Azure Policy instead of the correct option that activates the CIS benchmark assessment in Defender for Cloud.

How to eliminate wrong answers

Option A is wrong because Azure Policy is the underlying engine that enforces rules and evaluates resources, but it does not itself provide the CIS benchmark assessment; you must enable the specific regulatory compliance standard within Defender for Cloud to map CIS controls to Azure Policy initiatives. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and incident response, not a compliance assessment tool for benchmarks like CIS. Option D is wrong because Azure Firewall is a network security service that filters traffic, and it has no role in evaluating resource configurations against the CIS benchmark.

1193
MCQeasy

A user logs into a company's application using their username and password. After logging in, the application checks whether the user belongs to the 'Admin' role before granting access to the user management page. Which security concept is primarily illustrated by the role check?

A.Authentication
B.Authorization
C.Accounting
D.Non-repudiation
AnswerB

Authorization is the process of granting or denying access to resources based on the authenticated user's permissions. The role check determines if the user is authorized to access the user management page, making this the correct answer.

Why this answer

The role check after login determines what actions the authenticated user is allowed to perform, specifically whether they can access the user management page. This is the essence of authorization, which controls access to resources based on identity and assigned permissions. In Microsoft identity and access management, authorization is enforced via role-based access control (RBAC), where the application verifies the user's role claim (e.g., 'Admin') in the access token.

Exam trap

Microsoft often tests the distinction between authentication and authorization by presenting a scenario where a user is already logged in and then a permission check occurs, leading candidates to mistakenly select 'authentication' because they focus on the login step rather than the subsequent access control decision.

Why the other options are wrong

A

The role check occurs after the user has already logged in, meaning authentication (verifying identity via username/password) is complete. The check determines what the user is allowed to do, which is authorization, not authentication.

C

Accounting refers to tracking user activities and resource usage (auditing), not to checking permissions after authentication. The role check determines access rights, which is authorization.

D

Non-repudiation ensures that a user cannot deny having performed an action, typically through digital signatures or audit logs. The role check in this question determines access rights based on identity, not proof of action.

When would these options actually be correct?

A

A question that asks: 'A user provides their username and password to access a system. Which security concept does this step represent?' In that context, the correct answer would be authentication, as it verifies the user's identity.

C

A question asks: 'An organization needs to track which users accessed sensitive data and when. Which security concept is primarily involved?' Here, accounting (auditing) would be correct as it logs user actions for review.

D

A question that asks: 'After a user performs a financial transaction, the system logs the transaction with a digital signature to prevent the user from denying they made it. Which security concept is this?' would have non-repudiation as the correct answer.

Why candidates pick the wrong answer

A

Candidates often confuse authentication and authorization because both involve user identity and access control, and the role check happens after login, making it seem like part of the authentication process.

C

Candidates may confuse 'accounting' with 'authorization' because both involve user identity and access, but accounting is about logging and monitoring, not permission checks.

D

Candidates may confuse non-repudiation with authorization because both involve verifying user identity, but non-repudiation focuses on accountability for actions rather than access control.

1194
Multi-Selecteasy

A company uses Microsoft Defender for Cloud to secure its environment. Which TWO plans are available?

Select 2 answers
A.Cloud Security Posture Management (CSPM)
B.Defender for Servers
C.Microsoft Intune
D.Microsoft Sentinel
E.Microsoft Defender for Identity
AnswersA, B

Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) is a foundational capability that continuously assesses the security posture of your cloud resources across Azure, AWS, and GCP. It provides visibility into misconfigurations, offers actionable security recommendations, and helps ensure compliance with industry benchmarks and regulatory standards. This core functionality is essential for identifying and remediating potential vulnerabilities in your cloud environment.

Why this answer

Option A, Cloud Security Posture Management (CSPM), is correct because it is one of the Defender for Cloud plans, providing continuous assessment of misconfigurations and security posture across Azure, AWS, and GCP resources. Option B, Defender for Servers, is correct because it is a Defender for Cloud workload protection plan (offered in P1 and P2 tiers) that delivers threat detection, vulnerability assessment, and file integrity monitoring for Windows and Linux VMs. Option C, Microsoft Intune, is incorrect because it is a separate cloud-based endpoint management/MDM service for device and app management, not a Defender for Cloud plan.

Option D, Microsoft Sentinel, is incorrect because it is a standalone cloud-native SIEM/SOAR solution that integrates with Defender for Cloud but is not itself one of its plans. Option E, Microsoft Defender for Identity, is incorrect because it is a distinct service for monitoring on-premises Active Directory signals to detect identity-based attacks, not a Defender for Cloud plan.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel and Microsoft Defender for Identity as being 'plans' within Defender for Cloud because they are part of the broader Microsoft security ecosystem and integrate with Defender for Cloud, but they are separate services with their own licensing and management interfaces.

1195
MCQmedium

A company wants to detect and respond to advanced attacks targeting their on-premises Active Directory infrastructure, such as Kerberos Golden Ticket attacks, pass-the-hash, and brute-force attempts. The solution should integrate with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Identity
C.Microsoft Defender for Office 365
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Defender for Identity is purpose-built to monitor on-premises Active Directory (AD) and hybrid environments for advanced threats. It deploys sensors directly on domain controllers and AD FS servers to analyze network traffic and Windows events, detecting suspicious user and entity behavior, reconnaissance activities, lateral movement paths, and privilege escalation techniques like Pass-the-Hash or Golden Ticket attacks. This specialized focus on identity-based threats within the AD infrastructure makes it the ideal solution for protecting against attacks targeting an organization's core directory services.

Why this answer

Microsoft Defender for Identity (MDI) is specifically designed to protect on-premises Active Directory by monitoring for advanced attacks like Kerberos Golden Ticket, pass-the-hash, and brute-force attempts. It integrates natively with Microsoft Sentinel and Microsoft 365 Defender to enable cross-domain investigations, correlating identity signals with endpoint and cloud data.

Exam trap

The trap here is that candidates often confuse Defender for Identity with Defender for Endpoint, assuming endpoint protection covers identity attacks, but MDI is the only solution that directly monitors Active Directory authentication protocols and domain controller traffic for advanced on-premises identity threats.

Why the other options are wrong

A

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., workstations, servers) and does not specifically monitor or protect on-premises Active Directory infrastructure against attacks like Kerberos Golden Ticket or pass-the-hash.

C

Microsoft Defender for Office 365 protects email and collaboration tools, not on-premises Active Directory. It cannot detect Kerberos Golden Ticket attacks or pass-the-hash targeting AD.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that protects cloud applications, not on-premises Active Directory. It cannot detect Kerberos Golden Ticket attacks or pass-the-hash on on-premises AD.

When would these options actually be correct?

A

A company wants to detect and respond to advanced attacks on endpoints, such as fileless malware, ransomware, or post-breach activities on workstations and servers, and needs integration with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.

C

A question asking for a solution to protect against phishing, malware, and advanced threats in email and Office 365 apps, with integration into Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.

D

A company wants to discover and control the use of shadow IT cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. The solution must integrate with Microsoft Sentinel for investigation.

Why candidates pick the wrong answer

A

Candidates may assume that Defender for Endpoint covers all security needs, including Active Directory, because it is a comprehensive endpoint protection solution, but it lacks the specific AD security capabilities of Defender for Identity.

C

Candidates may confuse the 'Defender' branding and assume all Defender products cover similar threats, or they may think Office 365 includes AD protection due to Azure AD Connect.

D

Candidates may think Defender for Cloud Apps covers all security aspects including on-premises, or they confuse its identity protection capabilities with those of Defender for Identity.

1196
Multi-Selecthard

Which TWO Microsoft Entra ID capabilities help detect and remediate identity risks? (Select two.)

Select 2 answers
A.Identity Protection
B.Identity Governance
C.Password protection
D.Privileged Identity Management
E.Conditional Access
AnswersA, E

Identity Protection detects risky users and sign-ins through Microsoft's threat intelligence and feeds those detections into risk-based Conditional Access, enabling automatic remediation such as requiring MFA or blocking access. This satisfies the requirement for detecting and remediating identity risks.

Why this answer

Microsoft Entra ID Protection (option A) is correct because it uses Microsoft's threat intelligence and machine learning to detect identity risks such as leaked credentials, anonymous IP usage, and atypical sign-in behavior, generating risk detections and risk levels (low/medium/high) for users and sign-ins that can trigger automated remediation. Conditional Access (option E) is correct because it enforces access controls based on signals including user risk and sign-in risk reported by Identity Protection, allowing remediation actions such as requiring multi-factor authentication, forcing a secure password change, or blocking access when risk is elevated. Together, Identity Protection detects the risk and Conditional Access remediates it, which is exactly the detect-and-remediate identity risk scenario described.

Identity Governance (option B) focuses on access reviews, entitlement management, and lifecycle workflows rather than risk detection. Password protection (option C) enforces banned-password lists and on-premises password policies but does not detect or remediate identity risk signals. Privileged Identity Management (option D) provides just-in-time privileged role activation, approval, and access reviews for admin roles, not risk-based detection or remediation.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with risk remediation, but PIM only manages privileged role activation and does not detect or automatically remediate identity risks.

1197
Multi-Selecteasy

Which TWO Microsoft Purview solutions can be used to identify and protect sensitive data in Microsoft 365?

Select 2 answers
A.Data Loss Prevention (DLP)
B.Communication compliance
C.Insider risk management
D.Sensitivity labels
E.eDiscovery
AnswersA, D

Microsoft Purview Data Loss Prevention (DLP) policies are designed to identify, monitor, and automatically protect sensitive information across various locations, including Microsoft 365 services, endpoints, and non-Microsoft cloud apps. DLP utilizes sensitive information types, keywords, and content matching to detect sensitive data, such as credit card numbers or national ID numbers, both at rest and in transit. Upon detection, DLP can block sharing, notify users, or encrypt the content, effectively identifying and protecting the data.

Why this answer

Data Loss Prevention (DLP) is correct because it uses content analysis (e.g., keyword matching, regex patterns, and machine learning classifiers) to detect and automatically protect sensitive data like credit card numbers or PII across Exchange, SharePoint, OneDrive, and Teams. Sensitivity labels are correct because they classify and protect data at rest and in transit by applying encryption, visual markings, and access restrictions based on label policies, enabling persistent protection even when data leaves Microsoft 365.

Exam trap

The trap here is that candidates confuse 'identifying and protecting sensitive data' with broader compliance solutions like Communication compliance or Insider risk management, which address behavioral monitoring rather than data classification and protection.

1198
MCQmedium

You are a security administrator for Adventure Works, which uses Microsoft Defender for Cloud to protect its Azure and on-premises resources. The company has a hybrid environment with Windows Server virtual machines in Azure and on-premises. You need to ensure that Microsoft Defender for Cloud can assess vulnerabilities on these servers. What should you do?

A.Enable the Microsoft Defender for Servers plan and deploy the integrated vulnerability assessment solution.
B.Enable the Microsoft Defender for Storage plan for all storage accounts.
C.Install the Microsoft Monitoring Agent on each server and configure a Log Analytics workspace.
D.Configure Azure Policy to enforce vulnerability assessment on all virtual machines.
AnswerA

Microsoft Defender for Servers includes a built-in vulnerability assessment solution powered by Qualys. By enabling the Defender for Servers plan and deploying the integrated solution, you can automatically scan your Azure and on-premises servers for vulnerabilities. This provides continuous assessment and actionable recommendations in Defender for Cloud.

Why this answer

To assess vulnerabilities on Azure and on-premises servers, you must enable the Microsoft Defender for Servers plan and deploy the integrated vulnerability assessment solution. This solution, powered by Qualys, scans servers for vulnerabilities and provides findings in Microsoft Defender for Cloud. Other options do not provide vulnerability assessment capabilities.

Exam trap

The trap here is assuming that installing a monitoring agent or using Azure Policy alone can enable vulnerability assessment, when the Defender for Servers plan is required.

1199
MCQmedium

Your company uses Microsoft Entra ID. You need to enable users to sign in to third-party SaaS applications using their corporate credentials without storing passwords in those apps. Which Microsoft Entra feature should you configure?

A.Configure single sign-on (SSO) using federation
B.Deploy Microsoft Entra Self-Service Password Reset
C.Configure conditional access policies with MFA
D.Enable Microsoft Entra Identity Protection
AnswerA

Configuring single sign-on (SSO) using federation establishes a trust relationship where Microsoft Entra ID acts as the identity provider. When users access an application, they are redirected to Entra ID for authentication. Upon successful verification, Entra ID issues a security token to the application, granting access without the application ever storing or directly handling the user's password, thereby centralizing authentication and eliminating application-specific credential storage.

Why this answer

Configuring single sign-on (SSO) using federation allows users to authenticate against Microsoft Entra ID (their corporate identity provider) and then pass a security token to third-party SaaS applications. This eliminates the need for the SaaS app to store or manage user passwords, as authentication happens via standards like SAML 2.0 or WS-Federation, and the app trusts the token issued by Entra ID.

Exam trap

The trap here is that candidates often confuse Conditional Access or Identity Protection with the core mechanism for passwordless federation, not realizing that SSO via federation is the specific feature that removes password storage in the third-party app.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Self-Service Password Reset (SSPR) enables users to reset their own passwords, but it does not provide a mechanism to sign in to third-party SaaS apps without storing passwords in those apps. Option C is wrong because Conditional Access policies with MFA enforce additional security controls (like requiring multi-factor authentication) during sign-in, but they do not eliminate the need for password storage in the SaaS app itself. Option D is wrong because Microsoft Entra Identity Protection detects and responds to identity-based risks (e.g., leaked credentials, anomalous sign-ins), but it does not enable passwordless or federated authentication to third-party applications.

1200
Multi-Selecteasy

Which TWO are capabilities of Microsoft Entra ID Protection?

Select 2 answers
A.Risk-based conditional access policies
B.Device enrollment policies
C.Self-service password reset
D.Privileged role activation
E.Detection of leaked credentials
AnswersA, E

Microsoft Entra ID Protection continuously monitors user and sign-in behavior to detect various types of risks, such as impossible travel or anomalous IP addresses. It then feeds these real-time risk detections into Microsoft Entra Conditional Access policies. These policies can be configured to automatically enforce specific access controls, like blocking access, requiring multifactor authentication (MFA), or forcing a password change, based on the calculated user or sign-in risk level. This capability is central to adaptive access control.

Why this answer

Microsoft Entra ID Protection uses risk-based conditional access policies to automatically respond to detected risks, such as blocking access or requiring multi-factor authentication, based on real-time risk levels. Option E is correct because Entra ID Protection continuously monitors for leaked credentials by analyzing known credential breaches and flagging accounts whose credentials have been exposed, enabling proactive remediation.

Exam trap

The trap here is that candidates confuse Entra ID Protection with other Entra ID features like SSPR or PIM, but Entra ID Protection is specifically about risk detection and automated remediation, not password management or privileged access control.

Page 15

Page 16 of 18

Page 17