Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 301–375

1279 questions total · 18pages · All types, answers revealed

Page 4

Page 5 of 18

Page 6
301
MCQeasy

Your organization wants to audit all activities related to accessing sensitive files in Microsoft SharePoint. Which Microsoft Purview solution should you use?

A.Audit (Premium)
B.Data lifecycle management
C.Information barriers
D.Data loss prevention
AnswerA

Microsoft Purview Audit (Premium) provides advanced auditing capabilities, including extended retention of audit logs (up to 10 years), intelligent insights, and access to high-value audit events crucial for forensic investigations. It captures a comprehensive record of user and admin activities across Microsoft 365 services, enabling organizations to track who accessed what, when, and from where, which is essential for security and compliance audits.

Why this answer

Audit (Premium) in Microsoft Purview provides detailed logging of user and admin activities, including granular events like file access, modification, and permission changes in SharePoint. This solution enables organizations to investigate and audit all activities related to sensitive files by capturing and retaining audit records with high-volume event support and custom alerting.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with auditing, because DLP also monitors sensitive files, but DLP focuses on preventing data exfiltration rather than providing a retrospective audit trail of all access activities.

How to eliminate wrong answers

Option B (Data lifecycle management) is wrong because it focuses on retaining, deleting, or archiving data based on policies, not on auditing access activities. Option C (Information barriers) is wrong because it restricts communication and collaboration between specific user groups to prevent conflicts of interest, not to audit file access. Option D (Data loss prevention) is wrong because it detects and prevents unauthorized sharing or leakage of sensitive data, but it does not provide a comprehensive audit trail of all access activities.

302
Drag & Dropmedium

Arrange the steps to conduct a data classification scan using Microsoft Purview Information Protection.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Data classification involves creating labels, publishing them, setting auto-labeling rules, running scans, and reviewing results.

303
MCQmedium

A healthcare organization uses Microsoft 365. They need to prevent employees from sharing emails or documents that contain patient medical record numbers (MRNs) with external recipients. If an attempt is made, the message should be blocked and the sender should receive a policy tip notification. Which Microsoft Purview solution should they configure?

A.Data Lifecycle Management
B.Records Management
C.Data Loss Prevention (DLP)
D.Information Protection
AnswerC

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to identify, monitor, and protect sensitive information across Microsoft 365 services, including email, SharePoint, and OneDrive. DLP policies leverage sensitive information types (SITs) to detect patterns like Medical Record Numbers (MRNs) within content. Upon detection, these policies can be configured to automatically block sharing with external recipients, provide policy tips to users, and generate alerts for administrators, thereby preventing unauthorized data exfiltration.

Why this answer

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and block the sharing of sensitive information, such as patient medical record numbers (MRNs), with external recipients. DLP policies can be configured to scan emails and documents for patterns (e.g., regex for MRNs), block the transmission, and display a policy tip notification to the sender, meeting all requirements.

Exam trap

The trap here is that candidates often confuse Information Protection (sensitivity labels) with DLP, but labels alone do not block sharing or provide policy tips—they require DLP policies for enforcement.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management focuses on retaining and deleting data based on age or compliance requirements, not on preventing real-time sharing of sensitive data. Option B is wrong because Records Management is used to declare records, apply retention labels, and manage disposition, not to block external sharing or provide policy tips. Option D is wrong because Information Protection (e.g., sensitivity labels) applies classification and encryption but does not inherently block external sharing or trigger policy tip notifications; it requires integration with DLP for enforcement.

304
MCQmedium

Your organization is adopting Microsoft 365 Copilot for enterprise users. Which Microsoft Purview capability should you configure to prevent sensitive data from being inadvertently shared during Copilot interactions?

A.Customer Lockbox
B.Data Loss Prevention (DLP) policies
C.Sensitivity labels
D.eDiscovery
AnswerB

Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across various Microsoft 365 services, including applications integrated with Microsoft 365 Copilot. DLP policies can detect sensitive information types (e.g., credit card numbers, PII) and enforce actions such as blocking sharing, notifying users, or encrypting content, thereby preventing accidental or intentional data exfiltration when Copilot generates or processes content.

Why this answer

Data Loss Prevention (DLP) policies are the correct Microsoft Purview capability to prevent sensitive data from being inadvertently shared during Copilot interactions. DLP policies can inspect content in real time, including Copilot prompts and responses, and apply actions such as blocking or warning when sensitive information types (e.g., credit card numbers, social security numbers) are detected. This directly addresses the requirement to prevent inadvertent sharing of sensitive data within the Copilot environment.

Exam trap

The trap here is that candidates often confuse Sensitivity labels (which apply persistent protection like encryption) with DLP policies (which enforce real-time actions like blocking), leading them to choose labels instead of the correct DLP answer for preventing inadvertent sharing during live interactions.

How to eliminate wrong answers

Option A is wrong because Customer Lockbox provides a control mechanism for Microsoft support engineers to access your data during support requests, not for preventing data sharing during user interactions like Copilot. Option C is wrong because Sensitivity labels classify and protect data at rest and in transit (e.g., encryption, visual markings), but they do not actively monitor or block data sharing in real-time during Copilot interactions; DLP policies are needed for that enforcement. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for preventing data loss or inadvertent sharing in live Copilot sessions.

305
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. Which Microsoft Entra ID feature should you use?

A.Conditional Access
B.Privileged Identity Management
C.Self-Service Password Reset
D.Identity Protection
AnswerA

Microsoft Intune assesses device compliance against organizational policies, such as requiring encryption or specific OS versions. Azure AD Conditional Access then leverages this compliance status as a condition within its policies. This allows organizations to enforce that only devices marked as 'compliant' by Intune are granted access to sensitive cloud applications and data, creating a robust security gate.

Why this answer

Conditional Access in Microsoft Entra ID is the correct feature because it allows you to enforce policies that require devices to be marked as compliant by Microsoft Intune before granting access to corporate email. By integrating with Intune, Conditional Access evaluates device compliance status in real time and blocks or allows access accordingly, ensuring only managed and compliant devices can reach email resources.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles user risk) with device compliance enforcement, but Conditional Access is the only feature that can combine device compliance signals with access control decisions.

How to eliminate wrong answers

Option B (Privileged Identity Management) is wrong because it manages just-in-time access and role activation for privileged roles, not device compliance checks. Option C (Self-Service Password Reset) is wrong because it handles password reset workflows and does not evaluate device health or compliance. Option D (Identity Protection) is wrong because it detects and remediates identity-based risks like leaked credentials or sign-ins from anonymous IPs, but it does not enforce device compliance policies.

306
MCQmedium

A company uses Exchange Online. The security team wants to protect users from malicious email attachments. They need a solution that detonates attachments in a sandbox environment to check for malware behavior before the email is delivered to the recipient. Which Microsoft Defender for Office 365 feature should they enable?

A.Safe Attachments
B.Safe Links
C.Anti-phishing
D.Anti-spam
AnswerA

Safe Attachments is a crucial component of Microsoft Defender for Office 365 that provides advanced protection against unknown malware and zero-day threats in email attachments. It uses a virtual environment, or sandbox, to "detonate" (open and analyze) attachments in real-time before they reach the user's inbox. This process identifies malicious behavior and prevents the delivery of harmful files, even if their signatures are not yet known to traditional antivirus solutions.

Why this answer

Safe Attachments is the correct feature because it specifically detonates email attachments in a virtual sandbox environment before delivery, analyzing behavior for malicious activity. This matches the requirement to check attachments for malware behavior prior to inbox arrival, a capability unique to Safe Attachments within Defender for Office 365.

Exam trap

The trap here is that candidates confuse Safe Attachments (sandbox detonation of attachments) with Safe Links (URL scanning at click-time), as both are part of Defender for Office 365 but address different threat vectors.

Why the other options are wrong

B

Safe Links protects users from malicious URLs in emails and Office documents, not from email attachments. The question specifically asks about detonating attachments in a sandbox, which is the function of Safe Attachments.

C

Anti-phishing policies protect against deceptive messages that trick users into revealing credentials or clicking malicious links, but they do not detonate attachments in a sandbox to analyze malware behavior.

D

Anti-spam filters are designed to block unwanted bulk email (spam), not to detonate attachments in a sandbox to analyze malware behavior. The question specifically requires a feature that detonates attachments, which is Safe Attachments.

When would these options actually be correct?

B

Safe Links would be correct if the question asked about protecting users from clicking malicious links in emails or Office documents, such as in a scenario where attackers use phishing URLs to deliver malware or steal credentials.

C

A company wants to protect users from phishing attacks that use impersonation of executives or domains. Which Microsoft Defender for Office 365 feature should they enable?

D

Anti-spam would be correct if the question asked: 'Which Microsoft Defender for Office 365 feature should be enabled to filter out unsolicited bulk email and reduce inbox clutter?'

Why candidates pick the wrong answer

B

Candidates may confuse Safe Links with Safe Attachments because both are part of Microsoft Defender for Office 365 and deal with malware protection, but they target different threat vectors (links vs. attachments).

C

Candidates may confuse anti-phishing with attachment protection because both address email threats, or they may think phishing includes malware delivery via attachments.

D

Candidates may confuse anti-spam with anti-malware protection, assuming that spam filters also handle malicious attachments, but they are separate functions.

307
MCQhard

A security team needs to investigate a potential data breach that may involve unauthorized access to sensitive files in SharePoint Online and OneDrive for Business. They want to search the unified audit log for file access events, including accesses from mobile devices and third-party applications. Additionally, they need to create custom alert policies that trigger when specific high-privilege users download large volumes of files in a short period. Which Microsoft Purview solution should they use?

A.Microsoft Purview Audit (Premium)
B.Microsoft Purview eDiscovery (Premium)
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Communication Compliance
AnswerA

Microsoft Purview Audit (Premium) is the correct choice because it provides advanced capabilities essential for investigating a data breach. It offers extended retention of audit logs, granular logging of user and admin activities across Microsoft 365 services like SharePoint, OneDrive, and Exchange, and the ability to create custom alert policies. These features enable security teams to conduct thorough forensic analysis, track suspicious activities, and identify the scope and impact of a potential breach.

Why this answer

Microsoft Purview Audit (Premium) is the correct solution because it provides the deep, granular logging required to investigate data breaches, including file access events from mobile devices and third-party applications in SharePoint Online and OneDrive for Business. It also supports the creation of custom alert policies that can trigger on specific activities, such as high-privilege users downloading large volumes of files in a short period, by leveraging the unified audit log's rich schema and advanced detection capabilities.

Exam trap

The trap here is that candidates often confuse eDiscovery (Premium) with audit capabilities, but eDiscovery is for searching and preserving content for legal cases, not for real-time monitoring or alerting on access patterns.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview eDiscovery (Premium) is designed for legal discovery and holds, not for real-time monitoring or custom alert policies on file access patterns. Option C is wrong because Microsoft Purview Data Lifecycle Management focuses on retention, deletion, and classification of data, not on auditing or alerting for unauthorized access events. Option D is wrong because Microsoft Purview Communication Compliance is used to detect policy violations in communications (e.g., emails, Teams messages), not to audit file access or create alerts for download anomalies.

308
MCQeasy

A company wants to enable employees to securely access on-premises applications without needing a VPN. Which Microsoft Entra feature should they implement?

A.Identity Protection
B.B2B Collaboration
C.Application Proxy
D.Privileged Identity Management
AnswerC

Azure AD Application Proxy provides secure remote access to on-premises web applications for internal users without requiring a VPN or opening inbound firewall ports. It acts as a reverse proxy, publishing internal applications through Azure AD, allowing employees to authenticate with their Azure AD credentials. This solution enables seamless and secure access to corporate resources from any location, making it the ideal choice for the scenario described.

Why this answer

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications by acting as a reverse proxy. It eliminates the need for a VPN by routing user traffic through the Entra ID service, which authenticates the user and then establishes a secure outbound connection to the on-premises application connector. This allows employees to access internal apps from anywhere using the same credentials and conditional access policies.

Exam trap

The trap here is that candidates often confuse Application Proxy with a VPN or assume that B2B Collaboration is needed for remote access, but the key differentiator is that Application Proxy is specifically designed for secure, VPN-less access to on-premises web apps through a reverse proxy architecture.

How to eliminate wrong answers

Option A is wrong because Identity Protection is a risk-based detection and remediation tool that identifies compromised identities and suspicious sign-ins, not a remote access solution for on-premises applications. Option B is wrong because B2B Collaboration enables external users (partners, vendors) to access your organization's resources using their own identities, but it does not provide a reverse proxy or secure channel to on-premises apps. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time and time-bound access to privileged roles in Azure AD and Azure resources, not general remote access to on-premises applications.

309
MCQhard

Your organization is using Microsoft Entra ID with P2 licenses. You need to ensure that all guest users are reviewed for access quarterly, and if not approved, access is automatically removed. Which Microsoft Entra feature should you configure?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Entra Identity Protection
C.Microsoft Entra Entitlement Management
D.Microsoft Entra Access Reviews
AnswerD

Microsoft Entra Access Reviews provide a systematic and efficient way for organizations to manage and attest to group memberships, access to enterprise applications, and privileged role assignments. They enable resource owners or designated reviewers to periodically verify who still requires access, and critically, can be configured to automatically revoke access for users who are not approved or fail to respond to the review, directly addressing the requirement to remove access if not approved.

Why this answer

Microsoft Entra Access Reviews (D) is the correct feature because it allows you to create recurring reviews for guest users, set the frequency to quarterly, and configure auto-apply settings to automatically remove access if the review is not approved. This directly meets the requirement for periodic attestation and automated remediation.

Exam trap

The trap here is that candidates confuse Entitlement Management (which creates access packages) with Access Reviews (which performs the actual recurring review and auto-removal), but only Access Reviews provides the quarterly schedule and automatic removal enforcement described in the scenario.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and approval workflows, not for periodic access reviews of guest users. Option B is wrong because Microsoft Entra Identity Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, sign-in anomalies), not on scheduling and automating access reviews. Option C is wrong because Microsoft Entra Entitlement Management manages access packages and catalogs for resource provisioning, but it does not natively provide the recurring review and auto-removal cycle; it relies on Access Reviews for that functionality.

310
MCQmedium

Your organization is required to retain all HR-related documents for 7 years after an employee leaves. After that period, the documents must be permanently deleted. Which two Microsoft Purview features should you use together?

A.eDiscovery and audit logs
B.DLP policies and sensitivity labels
C.Sensitivity labels and auto-labeling
D.Retention labels and retention policies
AnswerD

Retention labels are applied directly to individual items like emails or documents, allowing for granular control over their retention and disposition based on content type or business function. Retention policies, conversely, are applied to entire locations such as Exchange mailboxes, SharePoint sites, or Teams channels, enforcing a baseline retention schedule for all content within that location. Together, these mechanisms ensure that data is retained for its required lifecycle and then appropriately disposed of, meeting regulatory and organizational compliance obligations.

Why this answer

Retention labels and retention policies (option D) are the correct combination because retention labels can be applied to individual HR documents to trigger deletion 7 years after an event such as an employee's departure, while retention policies apply retention and deletion settings broadly across workloads. Together they ensure documents are kept for the required period and then permanently deleted. eDiscovery and audit logs (A) are for investigation and monitoring, not enforcement of retention/deletion. DLP policies and sensitivity labels (B), and sensitivity labels with auto-labeling (C), focus on classification and preventing data loss, not on time-based retention and deletion.

311
MCQhard

You are the identity administrator for a multinational company using Microsoft Entra ID. The company has a Microsoft 365 E5 subscription. The security team wants to enforce the following requirements: 1. All users must use multi-factor authentication (MFA) when accessing sensitive applications (e.g., finance app). 2. Users from the IT department must use passwordless authentication methods (e.g., Windows Hello for Business) when accessing any resource. 3. All access to sensitive applications must be logged and monitored for anomalous activity. 4. Guest users from partner organizations must be automatically reviewed quarterly to ensure they still need access. 5. The company wants to minimize administrative overhead by automating as much as possible. You need to design a solution that meets these requirements using Microsoft Entra ID capabilities. Which combination of actions should you take?

A.Configure Self-Service Password Reset (SSPR) for all users. Enable Microsoft Entra ID Protection. Create an access review for guests.
B.Use Microsoft Entra ID Protection to enforce MFA based on risk. Implement Privileged Identity Management (PIM) for IT. Configure access reviews for guests.
C.Enable security defaults to enforce MFA for all users. Configure Microsoft Entra ID Protection to monitor anomalies. Use Microsoft Entra ID Governance to automate guest access reviews.
D.Create Conditional Access policies: one requiring MFA for the finance app, another requiring passwordless authentication strength for IT. Enable Microsoft Entra ID Protection to log and monitor sign-in risks. Create an access review for guest users.
AnswerD

This option directly addresses all specified requirements. Creating Conditional Access policies allows for precise enforcement: one policy can require MFA for the finance application, and another can mandate a passwordless authentication strength for the IT group. Enabling Microsoft Entra ID Protection ensures that sign-in risks are continuously logged and monitored, providing essential security insights. Finally, creating an access review for guest users fulfills the requirement for systematic management of external access.

Why this answer

It uses Conditional Access policies to enforce MFA for the finance app and passwordless authentication strength for IT, meeting requirements 1 and 2. Microsoft Entra ID Protection logs and monitors sign-in risks for sensitive apps (requirement 3), and an access review for guest users automates quarterly reviews (requirement 4). This minimizes administrative overhead by leveraging automation, aligning with requirement 5.

Exam trap

The trap here is that candidates often confuse security defaults (which enforce MFA for all users but lack granularity) with Conditional Access policies (which allow targeted MFA and authentication strength requirements), and they may overlook that passwordless enforcement requires an authentication strength policy, not just MFA.

How to eliminate wrong answers

Option A is wrong because SSPR does not enforce MFA or passwordless authentication; it only allows self-service password reset, and Entra ID Protection alone cannot enforce MFA without a Conditional Access policy. Option B is wrong because PIM is for just-in-time privileged access management, not for enforcing passwordless authentication for all IT users; it also does not address the MFA requirement for the finance app. Option C is wrong because security defaults enforce MFA for all users, not just for sensitive apps, and they do not support passwordless authentication strength policies; Entra ID Governance is not a specific feature for automating guest access reviews (access reviews are part of Entra ID Governance, but the option incorrectly implies a separate product).

312
MCQhard

A multinational organization uses Microsoft Entra ID for identity management. External contractors need temporary elevated access to Azure resources for a critical project. The access must be time-bound (expires after 8 hours), require manager approval, and enforce multifactor authentication (MFA) when contractors activate the role. Which Microsoft Entra capability should they configure?

A.Privileged Identity Management (PIM)
B.Identity Protection
C.Conditional Access
D.Access Reviews
AnswerA

Microsoft Entra Privileged Identity Management (PIM) enables organizations to manage, control, and monitor access to important resources. It provides just-in-time (JIT) access, allowing users to activate privileged roles for a limited time period. This activation often requires multi-factor authentication (MFA) and an approval workflow, ensuring that elevated permissions are granted only when necessary and with proper oversight, significantly reducing the attack surface for privileged accounts.

Why this answer

Privileged Identity Management (PIM) is the correct choice because it provides just-in-time (JIT) privileged access to Azure resources with time-bound activation (e.g., 8-hour expiry), requires approval workflows (manager approval), and enforces multifactor authentication (MFA) during role activation. PIM is specifically designed to manage, control, and monitor access to critical resources through time-limited, approved, and MFA-protected role assignments.

Exam trap

The trap here is that candidates confuse Conditional Access (which enforces MFA at sign-in) with PIM's ability to enforce MFA specifically during role activation, or they mistakenly think Access Reviews can grant time-bound access, when in fact Access Reviews only validate existing access and do not provide JIT activation or approval workflows.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) and does not provide time-bound role activation, approval workflows, or MFA enforcement for privileged access. Option C (Conditional Access) is wrong because it enforces access policies (like MFA) based on signals (user, location, device) at sign-in time, but it does not manage role activation, time-bound expiry, or approval workflows for privileged roles. Option D (Access Reviews) is wrong because it is used to periodically review and certify existing group memberships or role assignments, not to grant temporary, time-bound elevated access with approval and MFA enforcement.

313
Drag & Dropmedium

Order the steps to create a conditional access policy in Azure AD.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating a conditional access policy requires admin sign-in, navigating to Conditional Access, creating a new policy, configuring assignments and controls, then enabling it.

314
MCQeasy

A security analyst is explaining the concept of 'defense in depth' to a new team member. Which of the following best describes the defense in depth strategy?

A.Using a single strong firewall to protect all network traffic
B.Implementing multiple layers of security controls to protect assets
C.Relying on user training as the primary security measure
D.Applying encryption only to data at rest
AnswerB

Implementing multiple layers of security controls is the core principle of defense in depth. This strategy involves strategically placing diverse, independent security mechanisms—such as physical security, network segmentation, host-based firewalls, application security, and data encryption—to create redundancy. Each layer is designed to detect, delay, or prevent an attacker from reaching critical assets, even if a preceding layer is compromised.

Why this answer

Defense in depth is a cybersecurity strategy that employs multiple layers of security controls across different parts of an IT environment (network, endpoint, application, data) to ensure that if one layer fails, another layer is already in place to mitigate the threat. This approach is fundamental to Microsoft's security architecture, as seen in products like Microsoft Defender for Cloud, which integrates protections across workloads, and Azure Active Directory (now Microsoft Entra ID), which layers conditional access policies on top of identity verification. Option B correctly captures this layered, redundant approach rather than relying on a single point of defense.

Exam trap

The trap here is that candidates often confuse 'defense in depth' with 'layered security' but then incorrectly select a single-layer option like a strong firewall (A) because they think a robust perimeter is sufficient, failing to recognize that the strategy explicitly requires multiple independent and overlapping controls.

How to eliminate wrong answers

Option A is wrong because relying on a single strong firewall violates the core principle of defense in depth, which requires multiple independent layers of security; a single firewall creates a single point of failure that, if breached, exposes the entire network. Option C is wrong because user training, while valuable, is a single administrative control and not a layered strategy; defense in depth demands technical controls (e.g., network segmentation, endpoint detection, encryption) in addition to user awareness. Option D is wrong because applying encryption only to data at rest ignores the need to protect data in transit (e.g., via TLS/SSL) and data in use, leaving critical attack surfaces exposed; defense in depth requires encryption across all data states.

315
MCQmedium

A company uses Microsoft Entra ID. They want to ensure only current employees have access to a sensitive HR application. They implement a process where group membership for the HR app is reviewed quarterly by the HR manager, and any unnecessary access is automatically removed. Which Microsoft Entra feature should they use?

A.A
B.B
C.C
D.D
AnswerC

Microsoft Entra Access Reviews, a component of Entra ID Governance, are specifically designed to manage the lifecycle of access to resources by enabling organizations to periodically review who has access to groups, applications, or roles. This feature allows for scheduled reviews, automated notifications to reviewers, and the automatic removal of access for users who no longer require it, directly addressing the need for periodic access validation and cleanup.

Why this answer

The scenario describes a recurring review of group membership for the HR application, with automatic removal of unnecessary access. This is exactly what Microsoft Entra ID Governance's Access Reviews feature provides: scheduled reviews (e.g., quarterly) where a reviewer (the HR manager) attests to each member's continued need, and stale access is automatically revoked upon completion.

Exam trap

The trap here is that candidates often confuse Access Reviews with Privileged Identity Management (PIM) because both involve 'review' and 'access,' but PIM is specifically for privileged roles and time-bound activation, not for recurring attestation of standard application group memberships.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and approval workflows, not for recurring attestation of standard group membership for an application. Option B is wrong because Conditional Access policies enforce real-time access controls based on conditions (location, device, risk), but they do not provide periodic review or automatic removal of group memberships. Option D is wrong because Identity Protection focuses on detecting and responding to identity-based risks (e.g., leaked credentials, anomalous sign-ins), not on scheduling and automating group membership attestation.

316
MCQmedium

Your organization uses Microsoft Purview to manage insider risk. You need to create a policy that detects users who exfiltrate sensitive data by copying it to personal cloud storage services like Dropbox. Which solution should you use?

A.eDiscovery (Premium)
B.Audit (Premium)
C.Insider Risk Management
D.Communication Compliance
AnswerC

Insider Risk Management in Microsoft Purview is specifically designed to identify, analyze, and act on potential insider risks, including data exfiltration to unauthorized locations like personal cloud services. It leverages machine learning and customizable policies to detect risky activities based on behavioral indicators, enabling organizations to proactively address potential data loss before it escalates into a major incident.

Why this answer

Insider Risk Management in Microsoft Purview is specifically designed to detect, investigate, and act on risky user activities, including the exfiltration of sensitive data to personal cloud storage services like Dropbox. It uses predefined or custom policies with indicators such as copying files to unauthorized cloud apps, which aligns directly with the requirement to detect data exfiltration to personal cloud storage.

Exam trap

The trap here is that candidates often confuse Audit (Premium) with proactive detection, but Audit only provides logging after the fact, whereas Insider Risk Management offers real-time detection and alerting for risky behaviors like data exfiltration.

How to eliminate wrong answers

Option A is wrong because eDiscovery (Premium) is used for legal discovery and preservation of content, not for real-time detection of data exfiltration activities. Option B is wrong because Audit (Premium) provides logging and forensic investigation of past events but does not proactively detect or alert on risky data exfiltration patterns. Option D is wrong because Communication Compliance focuses on monitoring communications (e.g., email, Teams) for policy violations like harassment or insider trading, not on detecting data copying to external cloud storage services.

317
MCQeasy

Your organization needs to classify documents containing personally identifiable information (PII) like social security numbers. Which Microsoft Purview solution should you configure?

A.Information Protection
B.Records Management
C.Auditing
D.Communication Compliance
AnswerA

Information Protection is the correct solution because it specifically provides capabilities to classify and label sensitive data within documents, whether manually by users or automatically based on content inspection. This service, often delivered through Microsoft Purview Information Protection (MPIP), enables organizations to apply sensitivity labels that not only categorize data but also enforce protective actions like encryption, access restrictions, and visual markings, directly addressing the need to classify documents containing specific information.

Why this answer

Microsoft Purview Information Protection (A) is the correct solution because it provides classification and labeling capabilities specifically designed to identify, label, and protect sensitive data such as PII (e.g., social security numbers). It uses trainable classifiers and exact data match (EDM) to automatically detect sensitive content and apply appropriate protection actions like encryption or access restrictions.

Exam trap

The trap here is that candidates often confuse Records Management (which deals with retention and deletion) with Information Protection (which deals with classification and labeling), leading them to select B when the question explicitly asks about classifying documents containing PII.

How to eliminate wrong answers

Option B (Records Management) is wrong because it focuses on managing the lifecycle of records (retention, deletion, and disposition) rather than classifying or protecting sensitive content like PII. Option C (Auditing) is wrong because it logs user and admin activities for compliance review but does not perform classification or protection of documents. Option D (Communication Compliance) is wrong because it monitors communications (e.g., emails, Teams messages) for policy violations like harassment or insider trading, not for classifying documents containing PII.

318
MCQeasy

You are designing an identity solution for a new company that will use Microsoft Entra ID. The company wants employees to use biometrics (fingerprint) on their mobile devices to sign in without typing a password. Which Microsoft Entra feature should you implement?

A.Windows Hello for Business
B.Microsoft Authenticator app (passwordless)
C.SMS-based sign-in
D.FIDO2 security keys
AnswerB

The Microsoft Authenticator app provides a secure and convenient passwordless sign-in experience by leveraging the biometric capabilities (fingerprint or facial recognition) inherent to the user's mobile device. When a user attempts to sign in to an Azure AD-connected application, a notification is sent to the Authenticator app, prompting for approval using the device's native biometrics. This method securely verifies the user's identity on their registered mobile device, eliminating the need to type a password and enhancing security against phishing attacks. It directly addresses the requirement for mobile biometric authentication.

Why this answer

The Microsoft Authenticator app (passwordless) allows users to sign in to Microsoft Entra ID using biometrics (fingerprint, face, or PIN) on their mobile device without entering a password. This feature uses the device's built-in biometric capabilities to verify the user's identity, making it the correct choice for the described scenario.

Exam trap

The trap here is that candidates may confuse Windows Hello for Business with mobile biometrics, but Windows Hello for Business is specifically tied to Windows devices and not to mobile phones or tablets.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business is designed for Windows devices (PCs, laptops) using biometrics like fingerprint or facial recognition, not for mobile devices. Option C is wrong because SMS-based sign-in uses a text message code, not biometrics, and still requires a password for initial setup. Option D is wrong because FIDO2 security keys are hardware-based external devices (e.g., USB keys) that require physical possession, not mobile device biometrics.

319
MCQmedium

A financial services company is required by regulation to prevent sensitive customer financial information from being shared externally via email. The compliance team wants to automatically scan all outgoing emails for patterns that match credit card numbers or account numbers. If a match is found, the email should be blocked and the sender should receive a policy tip. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Audit
B.Microsoft Purview Data Lifecycle Management
C.Microsoft Purview Data Loss Prevention (DLP)
D.Microsoft Purview eDiscovery
AnswerC

Microsoft Purview Data Loss Prevention (DLP) proactively identifies, monitors, and protects sensitive information across Microsoft 365 services like Exchange Online, SharePoint Online, and OneDrive for Business. It uses policies to detect specific sensitive information types, such as credit card numbers or financial account details, within content. Upon detection, DLP can automatically block sharing, encrypt files, notify administrators, or provide policy tips to users, thereby preventing unauthorized data exfiltration and ensuring regulatory compliance.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and block sensitive information—such as credit card numbers and account numbers—in outgoing emails. DLP policies can scan email content and attachments for predefined sensitive information types, and when a match is found, the email can be blocked and a policy tip sent to the sender, meeting the compliance requirement.

Exam trap

The trap here is that candidates may confuse DLP with eDiscovery or Audit because all three involve compliance, but only DLP provides proactive, real-time blocking and notification for outbound sensitive data.

Why the other options are wrong

A

Microsoft Purview Audit logs user and admin activities but does not scan or block outgoing emails for sensitive content like credit card numbers.

B

Microsoft Purview Data Lifecycle Management manages retention and deletion of data, not real-time scanning and blocking of outbound emails for sensitive content like credit card numbers.

D

Microsoft Purview eDiscovery is used for searching and exporting content from Exchange, SharePoint, and Teams for legal investigations, not for real-time scanning and blocking of outgoing emails containing sensitive data.

When would these options actually be correct?

A

When the requirement is to investigate a security incident by reviewing detailed logs of who accessed or sent sensitive data, such as tracking a data breach after it occurred.

B

A company needs to automatically retain emails containing financial data for 7 years and delete them after that period. The compliance team wants to set policies for data retention and deletion based on content classification.

D

A legal team needs to search for all emails containing a specific client's account number as part of a lawsuit discovery request. eDiscovery would be the correct tool to perform this search and export the results for legal review.

Why candidates pick the wrong answer

A

Candidates may confuse auditing (monitoring) with prevention (blocking), assuming that logging email activity can also enforce policy tips and blocks.

B

Candidates may confuse lifecycle management with data loss prevention because both involve data governance and policies, but lifecycle management focuses on retention/deletion rather than blocking transmission.

D

Candidates may confuse eDiscovery's content search capabilities with DLP's content scanning, thinking that eDiscovery can also block emails, or they may mistakenly believe that eDiscovery includes policy enforcement features.

320
MCQmedium

A user reports that they cannot access a cloud app even though they are in the correct location and have a valid license. The administrator suspects a Conditional Access policy might be blocking access. Which tool should the admin use to diagnose the issue?

A.Sign-in logs
B.My Apps portal
C.Conditional Access 'What If' tool
D.Audit logs
AnswerA

Sign-in logs provide historical data about past authentication attempts, detailing success or failure, and any Conditional Access policies that were applied at that specific time. However, they do not offer a predictive capability to simulate a new sign-in scenario with hypothetical conditions, which is crucial for proactively diagnosing why a user *might* be blocked before they even attempt access under new circumstances.

Why this answer

Sign-in logs provide detailed information about every sign-in attempt, including whether Conditional Access policies were applied, which policies were triggered, and the outcome (success or failure). When a user reports they cannot access an app and a Conditional Access policy is suspected, reviewing the sign-in logs for that user's attempts will directly show if a policy blocked access and why, making it the primary diagnostic tool for an existing issue.

Exam trap

The trap here is that candidates might confuse the 'What If' tool (which simulates what *would* happen) with the Sign-in logs (which show what *did* happen). For diagnosing an *actual* reported access issue, the Sign-in logs provide the definitive record of the specific Conditional Access policy application and outcome.

How to eliminate wrong answers

Option A is wrong because Sign-in logs show historical sign-in events and their status (success, failure, blocked), but they do not allow proactive simulation of Conditional Access policies to determine why a specific access attempt was blocked. Option B is wrong because the My Apps portal is an end-user interface for launching assigned applications, not a diagnostic tool for analyzing Conditional Access policy impacts. Option D is wrong because Audit logs track changes made to directory resources (e.g., policy modifications, user updates), not real-time sign-in attempts or Conditional Access policy evaluations.

321
MCQhard

You are a security operations manager for Northwind Traders. The company uses Microsoft Sentinel as its SIEM. You need to create a detection rule that triggers an incident when a user account is added to the Domain Admins group. The rule should only trigger for changes made outside of approved maintenance windows. Which Sentinel feature should you use to implement this logic?

A.Scheduled analytics rule with a KQL query that filters out events during maintenance windows.
B.Microsoft Defender for Identity sensor that automatically detects privileged group modifications.
C.Workbook that visualizes group membership changes over time.
D.Fusion rule that uses machine learning to correlate alerts.
AnswerA

Scheduled analytics rules in Microsoft Sentinel allow you to run KQL queries at regular intervals to detect specific events. You can include logic in the query to exclude events that occur during approved maintenance windows, for example by checking the timestamp against a known schedule. This enables precise detection of unauthorized group membership changes.

Why this answer

A scheduled analytics rule in Microsoft Sentinel allows you to run a KQL query on a schedule. By incorporating logic to exclude events during maintenance windows, you can ensure the rule only triggers for unauthorized changes. This provides the flexibility to customize detection criteria and reduce false positives from known maintenance activities.

Exam trap

The trap here is thinking that built-in detections from Defender for Identity or Fusion rules can be customized with maintenance window exclusions, when only scheduled analytics rules offer that level of control.

322
MCQhard

A financial services organization must comply with a regulation that requires all communications related to trades (including emails and Teams messages) to be retained for a period of 7 years. During retention, no user may edit or delete these records. After the 7 years, the records must be disposed of with an irreversible deletion that is verified by a compliance officer. Which Microsoft Purview solution should the organization use to enforce both retention and regulatory disposition?

A.Microsoft Purview Records Management (regulatory retention label)
B.Microsoft Purview Data Lifecycle Management (standard retention label)
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Insider Risk Management
AnswerA

Records Management with a retention label marked as a regulatory record permanently locks the content, preventing any modification or deletion during the retention period. It also supports disposition workflows to require approval before permanent deletion.

Why this answer

Microsoft Purview Records Management with a regulatory retention label is the correct solution because it enforces immutable retention (no user edits or deletions) and mandates a disposition review by a compliance officer before irreversible deletion. Regulatory labels lock the retention policy at the highest level, preventing any user or administrator from shortening the retention period or bypassing the disposition workflow, which aligns with the 7-year retention and verified disposal requirement.

Exam trap

The trap here is that candidates confuse 'standard retention labels' (which allow edits and deletions by authorized users) with 'regulatory retention labels' (which enforce immutable retention and require disposition review), leading them to select Data Lifecycle Management instead of Records Management.

Why the other options are wrong

B

Standard retention labels in Data Lifecycle Management do not support regulatory disposition with irreversible deletion verified by a compliance officer; they lack the 'regulatory' record type and disposition verification workflow required by the regulation.

C

Communication Compliance is designed to detect and review communications that violate organizational policies (e.g., insider trading, harassment), not to enforce immutable retention or regulatory disposition. It does not provide the required 7-year retention with irreversible deletion and compliance officer verification.

D

Insider Risk Management is designed to detect, investigate, and act on risky user activities (e.g., data leaks, policy violations), not to enforce retention or regulatory disposition of records. It lacks the ability to apply retention labels or trigger irreversible deletion after a fixed period.

When would these options actually be correct?

B

An organization needs to retain emails for 3 years for general business purposes, after which users can delete them manually. Data Lifecycle Management with standard retention labels would be correct because no regulatory compliance or disposition verification is required.

C

An organization needs to monitor employee communications for potential regulatory violations (e.g., insider trading) and escalate them for legal review. The question would specify that the goal is to detect and investigate policy breaches in communications, not to retain or dispose of records.

D

An organization needs to detect and investigate potential data theft by employees who exfiltrate sensitive trade communications before the retention period ends. Insider Risk Management would be correct to identify and alert on such risky behavior.

Why candidates pick the wrong answer

B

Candidates confuse 'retention' with 'regulatory retention', assuming any retention label meets compliance needs, and overlook the specific requirements for irreversible deletion and disposition verification unique to Records Management.

C

Candidates may confuse the regulatory compliance aspect of Communication Compliance with the retention and disposition requirements, assuming that a solution named 'Communication Compliance' would handle all compliance needs for communications.

D

Candidates may confuse the 'compliance officer verification' requirement with insider risk workflows, mistakenly thinking that monitoring user actions for disposition verification is part of Insider Risk Management.

323
MCQmedium

An organization wants to protect its fleet of Windows 10 laptops from advanced malware and ransomware. The solution must detect suspicious behavior (e.g., a process encrypting files) and provide security teams with the ability to isolate an infected device from the network for investigation. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Office 365
AnswerB

Microsoft Defender for Endpoint is the correct solution because it provides comprehensive, next-generation endpoint protection specifically designed for devices like Windows 10 laptops. It includes capabilities such as antivirus, behavioral analysis, endpoint detection and response (EDR) for advanced threat hunting, and automated investigation and remediation to protect against sophisticated malware and zero-day attacks. Furthermore, it offers vulnerability management and device isolation to contain threats effectively.

Why this answer

Microsoft Defender for Endpoint (MDE) is the correct solution because it provides endpoint detection and response (EDR) capabilities, including behavioral-based detection of advanced malware and ransomware (e.g., detecting a process encrypting files via machine learning and behavioral analytics). It also includes automated investigation and remediation features, such as the ability to isolate an infected device from the network (device isolation) to prevent lateral movement while allowing security teams to investigate.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a cloud workload protection tool) with endpoint protection, or they assume Defender for Office 365 covers all devices, when in fact only Defender for Endpoint provides the specific behavioral detection and device isolation for Windows 10 laptops.

Why the other options are wrong

A

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) for Azure, on-premises, and other cloud resources. It does not provide endpoint detection and response (EDR) capabilities like behavior monitoring and device isolation for Windows 10 laptops.

C

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on securing cloud applications and services, not on endpoint-level malware detection or device isolation for Windows 10 laptops.

When would these options actually be correct?

A

An organization wants to assess and improve the security posture of its Azure virtual machines and detect threats across hybrid cloud workloads. They need a solution that provides security recommendations and just-in-time VM access. In that scenario, Microsoft Defender for Cloud would be the correct answer.

C

An organization wants to gain visibility into shadow IT, control access to cloud apps, and protect data in SaaS applications like Office 365 or Salesforce. They need to detect anomalous behavior in cloud app usage and enforce policies such as blocking downloads from unmanaged devices.

Why candidates pick the wrong answer

A

Candidates may confuse 'Defender for Cloud' with endpoint protection because the name includes 'Defender' and 'Cloud', assuming it covers all cloud-connected devices, including laptops. They may not realize it focuses on cloud infrastructure rather than endpoint devices.

C

Candidates may confuse 'cloud apps' with 'endpoint protection' or assume that any Microsoft Defender product provides comprehensive malware defense, overlooking the specific endpoint focus required for laptop protection and isolation.

324
Multi-Selecteasy

Which TWO of the following are benefits of using Microsoft Entra ID Conditional Access? (Choose two.)

Select 2 answers
A.Allow users to reset their own passwords
B.Block access from locations that are not trusted
C.Automatically grant temporary admin access
D.Enforce multi-factor authentication based on user risk
E.Eliminate the need for passwords entirely
AnswersB, D

Microsoft Entra Conditional Access, a core component of Microsoft E (Enterprise Mobility + Security), enables organizations to define granular access policies based on various conditions, including network location. By configuring trusted IP ranges or blocking specific countries/regions, administrators can prevent unauthorized access attempts from untrusted geographical locations, significantly reducing the attack surface and enhancing security posture. This directly leverages the adaptive capabilities of Entra.

Why this answer

Conditional Access in Microsoft Entra ID is a policy engine that evaluates signals (user, device, location, app, and risk) to make access decisions, so option B is correct because you can create a named-location condition and block or deny access when a sign-in originates from an untrusted or unknown location. Option D is also correct because Conditional Access can use sign-in and user risk signals from Entra ID Protection as conditions to require multi-factor authentication (or block access) when risk is elevated. Option A is not a Conditional Access benefit; self-service password reset is a separate Entra ID feature configured under Authentication methods.

Option C is not provided by Conditional Access; just-in-time privileged access is delivered by Privileged Identity Management (PIM), not by Conditional Access policies. Option E is incorrect because Conditional Access complements authentication and cannot remove the need for passwords or other credentials entirely.

Exam trap

SC-900 often tests the misconception that Conditional Access includes PIM-style privilege elevation or passwordless authentication, when it is strictly a signal-based access decision engine.

325
Multi-Selectmedium

Which TWO Microsoft Purview solutions can be used to protect sensitive data in Microsoft Teams chats and channels? (Choose two.)

Select 2 answers
A.Microsoft Purview Communication Compliance
B.Microsoft Purview Data Loss Prevention (DLP) policies
C.Microsoft Purview Sensitivity Labels
D.Microsoft Purview Information Barriers
E.Microsoft Purview Retention Policies
AnswersA, B

Microsoft Purview Communication Compliance is a powerful solution designed to actively scan and analyze communications, such as Microsoft Teams chats and emails, for policy violations. It leverages machine learning and predefined or custom policies to detect inappropriate sharing of sensitive information, harassment, or regulatory non-compliance. This solution enables organizations to identify risky content, investigate potential issues, and take remediation actions, directly addressing the protection of sensitive data within communication channels.

Why this answer

Microsoft Purview Communication Compliance is correct because it helps organizations detect and act on inappropriate or sensitive messages in Teams chats and channels by analyzing communications for policy violations such as offensive language, harassment, or sharing of sensitive data. Microsoft Purview Data Loss Prevention (DLP) policies are correct because they can be configured to automatically detect and prevent the sharing of sensitive information (e.g., credit card numbers, social security numbers) in Teams chats and channels by scanning messages and attachments in real time.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels with DLP, thinking labels alone can prevent data leakage in chats, but labels only apply classification and encryption to files, not real-time scanning of message content.

326
MCQeasy

A company uses Microsoft 365 and wants to protect against phishing attacks that impersonate their executives. They need a solution that uses machine learning to analyze email patterns and provide real-time protection. Which Microsoft 365 service should they use?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview Data Loss Prevention
D.Microsoft Defender for Identity
AnswerA

Microsoft Defender for Office 365 provides advanced threat protection for email and collaboration tools. It includes anti-phishing policies that use machine learning and impersonation detection to protect against executive impersonation. This directly addresses the requirement for real-time protection against phishing attacks targeting executives.

Why this answer

Microsoft Defender for Office 365 includes anti-phishing policies that use machine learning to detect impersonation attempts, including executive impersonation. It provides real-time protection for email. The other options serve different purposes: DLP for data protection, Defender for Identity for on-premises identity threats, and Defender for Cloud Apps for cloud app security.

Exam trap

The trap here is confusing email protection with data loss prevention or identity protection, which are separate services in Microsoft 365.

327
MCQeasy

Refer to the exhibit. The JSON snippet shows a sensitivity label configuration. What is the purpose of the 'SensitiveInfoTypes' property in this label?

A.It sets the retention period for content with this label.
B.It defines the user groups that can apply this label manually.
C.It specifies the sensitive information types that trigger automatic labeling.
D.It configures the encryption settings for the label.
AnswerC

This property precisely specifies the sensitive information types (SITs) that, when detected in content, will trigger the automatic application of this sensitivity label. These SITs act as conditions, allowing the system to identify and classify documents or emails containing specific patterns, such as credit card numbers or national identification numbers, without requiring manual user intervention, thereby enforcing data protection policies automatically.

Why this answer

The 'SensitiveInfoTypes' property in a sensitivity label configuration specifies which built-in or custom sensitive information types (e.g., credit card numbers, passport numbers) should be detected in content. When these types are matched, the label can be applied automatically through auto-labeling policies, ensuring consistent protection without requiring manual user action.

Exam trap

The trap here is that candidates often confuse the 'SensitiveInfoTypes' property with encryption or retention settings, because all three are configurable within a sensitivity label's wizard, but each serves a distinct purpose and is located in separate sections of the label configuration.

How to eliminate wrong answers

Option A is wrong because retention periods are configured via retention labels and policies, not through the 'SensitiveInfoTypes' property of a sensitivity label. Option B is wrong because user groups that can apply a label manually are defined in the label's scope and permissions settings, not by referencing sensitive information types. Option D is wrong because encryption settings (e.g., 'protect with encryption') are configured separately within the label's 'Encryption' section, not by the 'SensitiveInfoTypes' property.

328
MCQmedium

Your organization has Microsoft Sentinel deployed. The security operations team needs to automatically respond to a security incident by opening an incident in ServiceNow and sending a notification to a Teams channel. What should you configure?

A.An automation rule with a playbook
B.A workbook
C.An analytics rule
D.A watchlist
AnswerA

A playbook, built on Azure Logic Apps, supplies the connectors that create the ServiceNow incident and post the Teams notification, while the automation rule triggers that playbook automatically when the incident is created. This satisfies the requirement for automatic response without manual analyst intervention.

Why this answer

Automation rules in Microsoft Sentinel can trigger playbooks (based on Azure Logic Apps) that integrate with external systems like ServiceNow and Teams. Option B is wrong because workbooks provide visualizations, not automation. Option C is wrong because analytics rules create alerts, not automated responses.

Option D is wrong because watchlists are for correlation, not response.

329
MCQmedium

A company's security team discovers that most recent account compromises resulted from attackers exploiting legacy authentication protocols (POP3, IMAP, SMTP Auth) that do not support multi-factor authentication. The team wants to immediately block all sign-in attempts using these legacy protocols while still allowing modern authentication methods (e.g., OAuth 2.0). Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management
D.Multi-factor Authentication
AnswerA

Conditional Access policies can include a 'Block legacy authentication' condition. This allows administrators to create a policy that blocks all sign-ins from clients that do not support MFA, effectively stopping attacks that rely on legacy protocols while preserving modern authentication.

Why this answer

Conditional Access policies in Microsoft Entra ID can be configured to block authentication attempts from legacy protocols (POP3, IMAP, SMTP Auth) by targeting client apps that do not support modern authentication. This allows the security team to immediately enforce a block on all sign-ins using these protocols while still permitting modern OAuth 2.0-based methods, directly addressing the requirement without disabling MFA for users who can use modern clients.

Exam trap

The trap here is that candidates often confuse the 'block legacy authentication' capability with MFA or Identity Protection, assuming that enabling MFA alone will stop legacy protocol abuse, when in fact legacy protocols bypass MFA entirely and require a Conditional Access policy to be explicitly blocked.

Why the other options are wrong

B

Identity Protection is designed to detect and respond to identity-based risks, such as suspicious sign-ins or leaked credentials, but it does not provide the capability to block specific authentication protocols like POP3, IMAP, or SMTP Auth.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles, but it does not block legacy authentication protocols. The question requires blocking sign-in attempts based on authentication protocol, which is a Conditional Access policy capability.

D

Multi-factor Authentication (MFA) is an authentication method, not a policy to block legacy protocols. The question asks for a feature to block sign-in attempts using legacy protocols, which requires a conditional access policy to enforce MFA or block specific authentication methods.

When would these options actually be correct?

B

A company wants to automatically block sign-ins from compromised accounts or from anonymous IP addresses. Identity Protection should be configured to enforce risk-based policies, such as requiring MFA for high-risk sign-ins or blocking sign-ins from risky sessions.

C

A company wants to implement just-in-time privileged access for administrators, requiring approval and time-bound role activation for elevated permissions. In that scenario, configuring Privileged Identity Management would be the correct answer.

D

A company wants to require all users to verify their identity with a second factor (e.g., phone call or app notification) during sign-in. The correct answer would be Multi-factor Authentication, as it is the feature that provides the additional verification step.

Why candidates pick the wrong answer

B

Candidates may confuse Identity Protection's risk detection with the ability to enforce access controls, not realizing that blocking legacy protocols is a Conditional Access policy action, not a risk-based detection feature.

C

Candidates may confuse PIM's role in controlling access with the ability to enforce authentication policies, or they might think that blocking legacy protocols is a privilege management task rather than an access control policy.

D

Candidates may confuse the goal of blocking legacy protocols with requiring MFA, thinking that enabling MFA will automatically prevent legacy protocol attacks, but MFA alone does not block legacy protocols unless enforced via Conditional Access.

330
MCQhard

A financial institution uses Microsoft 365 and must ensure that Microsoft support engineers cannot access the institution's content (e.g., Exchange Online mailboxes, SharePoint sites) without explicit approval from the institution's compliance officer. The compliance officer needs to review and approve or reject each access request. Which Microsoft Purview feature should be configured?

A.Customer Lockbox
B.Communication Compliance
C.Insider Risk Management
D.Data Lifecycle Management
AnswerA

Customer Lockbox for Microsoft 365 provides an explicit, auditable workflow for customer approval when a Microsoft engineer needs to access customer content to resolve a support issue. This feature ensures that no Microsoft support personnel can gain access to customer data without the customer's designated approver, such as a compliance officer, granting explicit permission for each specific access request. It directly addresses the requirement for a financial institution to control and approve any potential access to their sensitive data by external parties, including Microsoft support.

Why this answer

Customer Lockbox is the correct feature because it provides a controlled access approval process for Microsoft support engineers to access customer content. When a support case requires access to Exchange Online mailboxes or SharePoint sites, Customer Lockbox ensures the request is sent to the institution's compliance officer for explicit approval or rejection before access is granted, meeting the requirement for explicit approval.

Exam trap

The trap here is that candidates often confuse Customer Lockbox with Insider Risk Management, mistakenly thinking that controlling internal user access is the same as controlling Microsoft support access, but Customer Lockbox is specifically designed for external support engineer access approval workflows.

Why the other options are wrong

B

Communication Compliance is designed to detect and review internal/external communications for policy violations (e.g., offensive language, insider trading), not to control Microsoft support engineers' access to customer content.

C

Insider Risk Management is designed to detect and investigate risky user activities (e.g., data leaks, policy violations) but does not control or require approval for Microsoft support engineers' access to customer content.

D

Data Lifecycle Management governs retention and deletion of data based on policies, not controlling Microsoft support engineers' access to content. It does not provide approval workflows for access requests.

When would these options actually be correct?

B

A company needs to monitor employee emails and Microsoft Teams messages for regulatory compliance (e.g., FINRA, SEC) and flag potential policy breaches for review by a compliance officer.

C

An organization wants to identify and investigate potential data theft by employees who are copying sensitive files to personal cloud storage. Insider Risk Management would be correct for detecting such insider threats.

D

An organization needs to automatically retain emails for 7 years and then delete them to comply with regulatory requirements. Data Lifecycle Management would be configured to apply retention labels and policies for this purpose.

Why candidates pick the wrong answer

B

Candidates may confuse the 'compliance officer review' requirement with Communication Compliance's review workflow, not realizing Customer Lockbox is the specific feature for controlling Microsoft support access.

C

Candidates may confuse 'insider risk' with 'external support access risk,' assuming that managing insider risks includes controlling Microsoft support personnel, but the feature is focused on internal users, not Microsoft engineers.

D

Candidates may confuse data governance features, thinking 'management' implies control over access, but Data Lifecycle Management focuses on data retention and deletion, not access authorization.

331
MCQeasy

Refer to the exhibit. You run this PowerShell cmdlet. What is the outcome?

A.A guest user is created in Microsoft Entra ID and an invitation email is sent.
B.The external user is added as a member user without an invitation.
C.The external user is provisioned as a consumer account in Azure AD B2C.
D.The external user is added as a member user and cannot be a guest.
AnswerA

The New-MgInvitation or New-AzureADMSInvitation cmdlet, when executed with appropriate parameters like InvitedUserEmailAddress and SendInvitationMessage -eq $true, specifically facilitates Microsoft Entra B2B collaboration. This action creates a new guest user object in the inviting tenant's Microsoft Entra ID, representing the external user. Concurrently, an invitation email containing a unique redemption link is automatically dispatched to the specified external email address, enabling the invited user to accept the invitation and gain access.

Why this answer

The `New-MgInvitation` cmdlet creates a guest user in Microsoft Entra ID and sends an invitation email by default. This is the standard behavior for B2B collaboration, where the external user is assigned the 'Guest' user type and receives an email to accept the invitation and redeem their account.

Exam trap

The trap here is that candidates often confuse the `New-MgInvitation` cmdlet with `New-MgUser`, which creates a member user, and mistakenly think the invitation email is optional or that the user type can be changed to member without additional steps.

How to eliminate wrong answers

Option B is wrong because `New-MgInvitation` always sends an invitation email; it does not add the external user as a member user without an invitation. Option C is wrong because Azure AD B2C consumer accounts are created using separate B2C-specific cmdlets (e.g., `New-AzureADMSB2CUser`), not `New-MgInvitation`. Option D is wrong because the cmdlet explicitly creates a guest user, not a member user, and the guest user type cannot be changed to member via this cmdlet.

332
Multi-Selecthard

Which TWO Microsoft Security Copilot capabilities can help security analysts during incident response?

Select 2 answers
A.Provide guided response steps
B.Generate incident summary reports
C.Provision user accounts
D.Configure firewall rules
E.Automatically block malicious emails
AnswersA, B

Guided response steps walk analysts through recommended containment and remediation actions for the specific incident, drawing on Microsoft's threat intelligence and the incident's evidence. This directly supports incident response by reducing the time spent deciding what to do next.

Why this answer

Option A is correct because Microsoft Security Copilot's guided response capability walks analysts through recommended remediation and investigation steps during incident response, using natural-language prompts and contextual threat intelligence to suggest next actions. Option B is correct because Security Copilot can generate incident summary reports, condensing alerts, evidence, and timelines into readable summaries that speed up triage and handoff. Options C, D, and E are not Security Copilot capabilities: provisioning user accounts is handled by identity tools such as Microsoft Entra ID, configuring firewall rules is done in network security services like Azure Firewall or Defender for Cloud, and automatically blocking malicious emails is performed by Exchange Online Protection or Defender for Office 365, not by Security Copilot itself.

Exam trap

The trap here is that candidates may confuse Security Copilot's analytical and advisory capabilities with automated remediation actions (like blocking emails or configuring firewalls), which are handled by separate Microsoft security products such as Defender for Office 365 or Azure Firewall policies.

333
MCQeasy

An organization implements a policy where users must provide two forms of verification, such as a password and a text message code, to access the corporate network. Which security concept does this demonstrate?

A.Authorization
B.Authentication
C.Accounting
D.Multifactor authentication
AnswerD

Multifactor authentication (MFA) is the security method that requires a user to provide two or more distinct verification factors from different categories to prove their identity. These factors typically include something the user *knows* (like a password), something the user *has* (like a phone or token), and/or something the user *is* (like a fingerprint). By combining multiple independent factors, MFA significantly enhances security by making it much harder for unauthorized users to gain access, even if one factor is compromised.

Why this answer

Multifactor authentication (MFA) requires two or more distinct factors (e.g., something you know like a password, and something you have like a text message code) to verify identity. This is correct because the policy explicitly demands two forms of verification, which is the defining characteristic of MFA, not just single-factor authentication.

Exam trap

The trap here is that candidates may confuse 'authentication' (the general process) with 'multifactor authentication' (a specific type), failing to recognize that the question explicitly describes two different verification methods, which is the hallmark of MFA.

How to eliminate wrong answers

Option A is wrong because authorization determines what resources a user can access after authentication, not the process of verifying identity. Option B is wrong because authentication is the broader process of proving identity, but the specific requirement for two forms of verification is MFA, not single-factor authentication. Option C is wrong because accounting (auditing) tracks user activities and resource usage for compliance and billing, not the verification process itself.

334
MCQmedium

A company uses Microsoft Entra ID and wants to allow users to reset their own passwords without help desk intervention. However, they want to ensure that only users who have already registered for multifactor authentication (MFA) can use self-service password reset (SSPR). Which Microsoft Entra feature should the administrator configure to enforce this requirement?

A.Conditional Access
B.Self-Service Password Reset (SSPR) settings
C.Identity Protection
D.Privileged Identity Management
AnswerB

Self-Service Password Reset (SSPR) settings in Microsoft Entra ID directly control the user experience for password resets, including the authentication methods users must register and use. Administrators can configure the "Number of methods required to reset" and specify which "Methods available to users." Crucially, SSPR also offers an "Enforce registration" option, which can prompt users to register for SSPR (and thus their chosen authentication methods, including MFA options) at their next sign-in, ensuring they are prepared before a reset is needed.

Why this answer

Self-Service Password Reset (SSPR) settings in Microsoft Entra ID include a configuration option to require users to register for multifactor authentication (MFA) before they can use SSPR. By enabling the 'Require users to register when they sign in' setting under SSPR, the administrator ensures that only MFA-registered users can reset their own passwords, meeting the requirement without additional policies.

Exam trap

The trap here is that candidates often confuse Conditional Access (which enforces MFA during sign-in) with the SSPR registration requirement, but Conditional Access does not control the SSPR registration prerequisite—only the SSPR settings can enforce that users must be MFA-registered before using password reset.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA during sign-in) but does not directly control SSPR registration requirements; it cannot enforce that only MFA-registered users can use SSPR. Option C is wrong because Identity Protection is designed to detect and respond to identity risks (e.g., leaked credentials, anomalous sign-ins) and does not manage SSPR registration or usage restrictions. Option D is wrong because Privileged Identity Management (PIM) provides just-in-time privileged role activation and access reviews, not password reset registration enforcement.

335
MCQmedium

A company uses digital signatures on all official emails sent to customers. The signature is created using the sender’s private key, allowing recipients to verify that the email truly came from the claimed sender and that it was not altered in transit. Which security goal is primarily achieved by the digital signature?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerD

Digital signatures achieve non-repudiation by cryptographically linking a message to its sender in a way that cannot be legitimately denied later. When a sender signs an email with their unique private key, they are essentially creating an unforgeable proof of origin. This signature, verifiable by anyone using the sender's public key, confirms that only the holder of that specific private key could have sent the message, thereby preventing the sender from disavowing their actions.

Why this answer

Digital signatures use asymmetric cryptography where the sender signs the email with their private key. The recipient can verify the signature using the sender's public key, which proves the identity of the sender and ensures the message has not been tampered with. This directly achieves non-repudiation because the sender cannot deny having sent the email, as only their private key could have created the signature.

Exam trap

The trap here is that candidates often confuse integrity with non-repudiation, but while digital signatures do ensure integrity, the primary security goal they achieve is non-repudiation because they provide cryptographic proof of the sender's identity that cannot be repudiated.

Why the other options are wrong

A

Digital signatures do not encrypt the email content; they only provide authentication and integrity verification. Confidentiality is about preventing unauthorized access, which is not achieved by signing with a private key.

B

Digital signatures primarily ensure non-repudiation and integrity, but the question specifically asks for the goal 'primarily achieved.' While integrity is partially achieved (detecting tampering), the primary goal is non-repudiation—proving the sender's identity and preventing denial. Integrity alone does not tie the signature to a specific sender's private key.

C

Digital signatures primarily ensure non-repudiation and integrity, not availability. Availability refers to systems and data being accessible when needed, which is not addressed by digital signatures.

When would these options actually be correct?

A

A question asking which security goal is achieved by encrypting the email body with the recipient's public key, or by using a symmetric key to encrypt data before transmission, would have confidentiality as the correct answer.

B

A question that asks: 'Which security goal ensures that data has not been modified during transmission?' In that context, integrity is the correct answer, as it focuses solely on detecting unauthorized changes, not on sender identity or non-repudiation.

C

In a scenario where a company implements redundant servers and failover mechanisms to ensure that its email system remains operational even during a hardware failure, the security goal primarily achieved is availability.

Why candidates pick the wrong answer

A

Candidates may confuse digital signatures with encryption because both involve cryptographic keys, or they might think that signing ensures the message is hidden from eavesdroppers.

B

Candidates may confuse integrity with non-repudiation because digital signatures do verify that the message was not altered (integrity). They overlook that the signature's primary purpose is to bind the sender's identity to the message, which is non-repudiation.

C

Candidates may confuse integrity (which digital signatures also provide) with availability, or mistakenly think that signing ensures the email service is always up.

336
MCQmedium

A company uses Microsoft 365 E5 and is concerned about advanced phishing attacks that use adversary-in-the-middle (AiTM) techniques to steal session cookies and bypass multifactor authentication. Which Microsoft Defender for Office 365 feature should they configure to specifically protect against this type of attack?

A.Safe Attachments
B.Safe Links
C.Anti-Phishing (advanced policies)
D.Campaign Views
AnswerC

Advanced anti-phishing policies in Microsoft Defender for Office 365 are specifically engineered to detect and mitigate sophisticated phishing attacks, including adversary-in-the-middle (AiTM) threats. These policies leverage machine learning, behavioral analysis, and real-time signal detection to identify anomalous authentication flows, suspicious login patterns, and impersonation attempts. By analyzing various indicators, these advanced controls can effectively block phishing campaigns aimed at hijacking user sessions or stealing credentials via proxying techniques.

Why this answer

Advanced anti-phishing policies in Defender for Office 365 include protection against adversary-in-the-middle (AiTM) attacks by using machine learning models and impersonation detection to analyze and block phishing attempts that aim to steal session cookies and bypass multifactor authentication. This feature specifically detects and mitigates sophisticated phishing techniques that traditional anti-spam or link-checking mechanisms might miss, such as real-time credential harvesting and session hijacking via proxy servers.

Exam trap

The trap here is that candidates often confuse Safe Links (which protects against malicious URLs) with the broader anti-phishing protection needed for AiTM attacks, not realizing that AiTM attacks exploit the authentication process itself rather than just the URL, requiring advanced impersonation and proxy detection capabilities found only in anti-phishing policies.

How to eliminate wrong answers

Option A is wrong because Safe Attachments protects against malware in email attachments by detonating them in a sandbox, but it does not address session cookie theft or AiTM phishing techniques. Option B is wrong because Safe Links provides time-of-click protection against malicious URLs, but it focuses on blocking known malicious links at the point of click, not on detecting the proxy-based credential and session cookie interception used in AiTM attacks. Option D is wrong because Campaign Views is a reporting and analysis tool that provides visibility into phishing campaigns after they have been detected, not a proactive protection feature that prevents AiTM attacks.

337
MCQmedium

A company uses Microsoft Entra ID and Intune for mobile device management. They want to grant access to a confidential project management site only from devices that are encrypted and have the latest anti-malware updates. Which Conditional Access assignment should they configure to enforce this requirement?

A.Sign-in risk
B.Device state
C.User risk
D.Application
AnswerB

The 'Device state' Conditional Access condition specifically evaluates whether a device is marked as compliant by a Mobile Device Management (MDM) solution like Microsoft Intune. This condition enforces that the device meets predefined security baselines, such as requiring disk encryption, an up-to-date operating system, or active anti-malware protection. By leveraging Intune's compliance reporting, this condition ensures only trusted and healthy devices can access corporate resources.

Why this answer

(Device state) is correct because Conditional Access policies can use the 'Device state' condition to require that devices are marked as compliant or are hybrid Azure AD joined. Compliance is determined by Intune compliance policies, which can enforce requirements like encryption and up-to-date anti-malware. By setting the 'Device state' condition to 'Compliant device' or 'Hybrid Azure AD joined device', access to the confidential site is granted only to devices meeting those security baselines.

Exam trap

The trap here is that candidates confuse 'Device state' (which enforces device compliance like encryption and anti-malware) with 'Sign-in risk' or 'User risk', which are identity-focused risk detections unrelated to device health.

How to eliminate wrong answers

Option A (Sign-in risk) is wrong because sign-in risk is a real-time detection of anomalous sign-in behavior (e.g., impossible travel, anonymous IP) and does not evaluate device encryption or anti-malware status. Option C (User risk) is wrong because user risk assesses the likelihood that a user's identity has been compromised based on historical events (e.g., leaked credentials), not device health attributes. Option D (Application) is wrong because the Application condition specifies which cloud apps the policy applies to, not the device compliance state; it controls scope, not device security posture.

338
MCQmedium

Your organization uses Microsoft Purview eDiscovery to manage a legal case. You need to place a hold on emails for specific users, but you want to allow the system to apply the hold automatically. Which eDiscovery solution should you use?

A.Microsoft Purview eDiscovery (Standard)
B.Microsoft Purview Audit (Premium)
C.Microsoft Purview Communication Compliance
D.Microsoft Purview eDiscovery (Premium)
AnswerD

Microsoft Purview eDiscovery (Premium) is the advanced solution specifically engineered to manage complex eDiscovery workflows, including the crucial capability of automatic legal holds. It enables organizations to identify custodians, automatically place legal holds on their associated data sources (e.g., Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats), and manage these holds centrally. This automation ensures that relevant data is preserved efficiently and consistently across the organization, significantly reducing manual effort and the risk of data spoliation during litigation or investigations.

Why this answer

Microsoft Purview eDiscovery (Premium) is the correct choice because it provides advanced legal hold capabilities, including the ability to apply holds automatically based on specified criteria such as user mailboxes or SharePoint sites. Unlike the Standard version, Premium supports policy-based holds that can be set to trigger automatically without manual intervention, which is essential for managing legal cases efficiently.

Exam trap

The trap here is that candidates often confuse eDiscovery (Standard) with eDiscovery (Premium), assuming both can handle automatic holds, but only Premium supports policy-driven, automated hold placement.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview eDiscovery (Standard) only supports manual holds that require an administrator to place and manage each hold individually, lacking the automatic hold functionality described in the question. Option B is wrong because Microsoft Purview Audit (Premium) is focused on logging and investigating user activity, not on placing holds on content for legal cases. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect and manage policy violations in communications (e.g., inappropriate language or sensitive information), not to place legal holds on emails.

339
MCQeasy

Your organization uses Microsoft Defender for Endpoint. You need to investigate a potential malware outbreak on several endpoints. Which feature allows you to search for indicators of compromise (IOCs) across all endpoints?

A.Incidents and alerts
B.Advanced hunting
C.Threat analytics
D.Device inventory
AnswerB

Advanced hunting runs KQL queries over up to 30 days of raw endpoint telemetry, letting you search for file hashes, IP addresses and process indicators across all onboarded endpoints, satisfying the requirement to locate IOCs estate-wide.

Why this answer

Advanced hunting in Microsoft Defender for Endpoint is a query-based threat hunting tool that allows security analysts to search for indicators of compromise (IOCs) across all endpoints using the Kusto Query Language (KQL). It provides access to raw, schema-based tables (e.g., DeviceEvents, DeviceFileEvents, DeviceNetworkEvents) for up to 30 days of historical data, enabling proactive detection of malware outbreak patterns across the entire fleet.

Exam trap

The trap here is that candidates confuse the reactive alert management in Incidents and alerts with the proactive, query-based hunting capability of Advanced hunting, often overlooking that only Advanced hunting supports raw IOC searches across historical endpoint data.

How to eliminate wrong answers

Option A is wrong because Incidents and alerts aggregate correlated detections and alerts into a single case view, but they do not allow raw, custom KQL-based searches for specific IOCs across all endpoints; they are reactive, not proactive hunting tools. Option C is wrong because Threat analytics provides curated threat intelligence reports, including mitigations and impact assessments, but it is not a search interface for querying raw endpoint data for custom IOCs. Option D is wrong because Device inventory lists all managed devices with their properties and health status, but it does not support querying for IOCs or historical event data across endpoints.

340
MCQhard

A multinational corporation uses Microsoft Entra ID for identity management. They want to allow their external partners to use their own corporate credentials to access the company's resources, rather than creating guest accounts. Which Entra ID feature should they use?

A.Entra ID B2C
B.Entra ID Direct Federation
C.Entra ID Verified ID
D.Entra ID External ID
AnswerD

Microsoft Entra External ID is the comprehensive suite of capabilities within Entra ID that enables organizations to securely interact with external users, including partners, customers, and other collaborators. It facilitates various forms of external access, such as B2B collaboration, allowing partners to use their own corporate credentials through federation or other identity providers to access resources in your tenant.

Why this answer

Entra ID External ID (formerly Azure AD External Identities) is the correct feature because it enables external partners to authenticate using their own corporate credentials via federation, without requiring guest accounts. This allows seamless access to the company's resources while maintaining the partner's identity lifecycle.

Exam trap

The trap here is confusing Entra ID B2C (for customers) with External ID (for partners), as both involve external identities but serve different use cases—B2C is for consumer-facing apps with self-service sign-up, while External ID is for enterprise-to-enterprise federation.

How to eliminate wrong answers

Option A is wrong because Entra ID B2C is designed for customer-facing identity management, not for partner access to corporate resources. Option B is wrong because Entra ID Direct Federation is not a standalone feature; it is a configuration within External Identities that supports federation with identity providers like SAML/WS-Fed, but the overarching capability for partner access is External ID. Option C is wrong because Entra ID Verified ID is a decentralized identity solution using verifiable credentials (W3C standards), not for federating partner corporate credentials.

341
Multi-Selecteasy

Which TWO capabilities are part of Microsoft Entra ID Protection? (Choose two.)

Select 2 answers
A.Passwordless authentication
B.Risk-based conditional access policies
C.Just-in-time privileged access
D.Reports on risky users and sign-ins
E.Conditional access policies for device compliance
AnswersB, D

Microsoft Entra ID Protection is a critical signal source for Conditional Access, enabling the creation of policies that automatically respond to detected risks. These policies can enforce actions like requiring multi-factor authentication, password change, or blocking access entirely when a user or sign-in is deemed risky by ID Protection's machine learning algorithms. This capability allows organizations to dynamically protect resources based on real-time threat intelligence.

Why this answer

Risk-based conditional access policies (B) are a core capability of Microsoft Entra ID Protection, allowing organizations to automatically enforce access controls based on detected risk levels from user and sign-in activities. Reports on risky users and sign-ins (D) provide the foundational telemetry that Entra ID Protection uses to identify and investigate potential identity compromises, making both integral to the service.

Exam trap

The trap here is that candidates confuse the risk-based policies in Entra ID Protection with general Conditional Access policies, but only risk-based policies are part of Entra ID Protection, while device compliance and other conditions belong to the broader Conditional Access service.

342
MCQmedium

Your organization uses Microsoft Entra ID with P1 licenses. You need to provide a temporary access pass for a new employee to set up their account without a password. Which Microsoft Entra feature should you use?

A.Microsoft Entra Temporary Access Pass
B.Microsoft Entra Privileged Identity Management
C.Microsoft Entra Identity Protection
D.Microsoft Entra Verified ID
AnswerA

Microsoft Entra Temporary Access Pass (TAP) is a time-limited passcode issued by an administrator, specifically designed to enable passwordless onboarding and account recovery. It allows users to sign in without their primary password, register passwordless authentication methods like FIDO2 security keys or Microsoft Authenticator, and then expire, ensuring a secure transition to a fully passwordless state. This mechanism is crucial for new employees or users who have lost their primary authentication method, providing a secure initial access point.

Why this answer

The Temporary Access Pass (TAP) is a time-limited passcode issued by an administrator that allows a user to register passwordless authentication methods (e.g., Microsoft Authenticator, FIDO2 security key) without needing an existing password. This directly meets the requirement for a new employee to set up their account without a password, and it is available with Microsoft Entra ID P1 licenses.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with any 'temporary' access feature, but PIM grants temporary privileged roles, not a passwordless onboarding token.

How to eliminate wrong answers

Option B is wrong because Privileged Identity Management (PIM) is used for just-in-time privileged role activation and access reviews, not for issuing temporary credentials for passwordless onboarding. Option C is wrong because Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies) but does not provide a mechanism to create a temporary pass for initial setup. Option D is wrong because Verified ID is a decentralized identity solution for issuing and verifying verifiable credentials (e.g., diplomas, IDs) and is unrelated to temporary access passes for passwordless registration.

343
MCQmedium

Your company uses Microsoft Entra ID. You need to enforce that all users register for MFA within 14 days of account creation. Which feature should you use?

A.Identity Protection
B.MFA registration campaign
C.Conditional Access
D.Security defaults
AnswerB

The Microsoft Entra ID MFA registration campaign policy is specifically designed to drive user adoption of multi-factor authentication by actively prompting users to register their MFA methods. This feature allows administrators to configure a grace period, expressed as a specific number of days, during which users are repeatedly prompted to register before MFA becomes mandatory for all sign-ins. It directly addresses the need to enforce registration within a customizable, set number of days.

Why this answer

The MFA registration campaign is specifically designed to nudge users to register for MFA within a configurable time frame after account creation. It sends targeted notifications and enforces registration by blocking access until the user completes MFA setup, directly meeting the 14-day requirement.

Exam trap

The trap here is that candidates often confuse Conditional Access (which enforces MFA at sign-in) with the registration campaign (which enforces the initial MFA setup process), not realizing that Conditional Access cannot force a user to register within a specific number of days—it only blocks access if MFA is absent.

How to eliminate wrong answers

Option A is wrong because Identity Protection is a risk-based detection and remediation tool (e.g., detecting leaked credentials or risky sign-ins), not a mechanism to enforce MFA registration deadlines. Option C is wrong because Conditional Access policies can require MFA during sign-in but cannot enforce a registration deadline or send reminder prompts; they only block access if MFA is not already registered. Option D is wrong because Security defaults enforce MFA registration for all users but do not allow a custom 14-day grace period—they require registration at first sign-in with no configurable delay.

344
MCQeasy

A company wants to automatically apply a 'Confidential' sensitivity label to all documents containing credit card numbers. Which Microsoft Purview feature should be used to create the auto-labeling policy?

A.Microsoft Purview Data Loss Prevention
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Auto-labeling policies
AnswerD

Microsoft Purview Auto-labeling policies are specifically engineered to automatically apply sensitivity labels to content at rest or in transit across Microsoft 365 services. These policies leverage conditions such as sensitive information types, keywords, or trainable classifiers to identify specific content patterns. Upon a match, the designated sensitivity label, like 'confidential,' is automatically applied, ensuring consistent data classification without manual user intervention.

Why this answer

Microsoft Purview Auto-labeling policies are specifically designed to automatically apply sensitivity labels to documents and emails based on conditions such as the presence of sensitive information types (e.g., credit card numbers). This feature uses exact data match or pattern-based detection to label content at rest or in transit, fulfilling the requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Data Loss Prevention (DLP) with auto-labeling because both deal with sensitive data, but DLP enforces actions like blocking or alerting, not applying sensitivity labels automatically.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention (DLP) is focused on preventing unauthorized sharing or leakage of sensitive data by enforcing policies on endpoints, apps, and networks, not on automatically applying sensitivity labels. Option B is wrong because Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) by analyzing messages, not to auto-label documents based on content patterns. Option C is wrong because Microsoft Purview Data Lifecycle Management (formerly Records Management) handles retention, deletion, and disposition of data, not the automatic application of sensitivity labels based on content inspection.

345
MCQmedium

Your organization uses Microsoft Purview Information Barriers to prevent certain user groups from communicating with each other. You need to test the configuration before fully enforcing it. What should you do?

A.Run the Information Barriers policy in test mode
B.Define user segments in the Microsoft Purview compliance portal
C.Enable audit logging and then run the policy application
D.Use the Compliance Manager assessment for Information Barriers
AnswerA

Running an Information Barriers policy in test mode is the correct approach because it simulates the policy's enforcement without actually blocking any communications. This mode generates a detailed report outlining which users and communications would be affected by the policy, allowing administrators to review potential impacts, identify unintended restrictions, and refine the policy configuration before full activation. It provides a safe, non-disruptive method to validate the policy's effectiveness and accuracy against the organization's requirements.

Why this answer

Microsoft Purview Information Barriers include a dedicated test mode that allows administrators to validate policy behavior against user segments before enforcement. Running the policy in test mode evaluates whether communications between specified segments are correctly blocked or allowed, without actually preventing messages, enabling safe validation of the configuration.

Exam trap

The trap here is that candidates may confuse prerequisite configuration steps (like defining segments or enabling audit logging) with the actual testing mechanism, or assume that Compliance Manager can validate Information Barrier policies when it is designed for broader compliance posture assessment.

How to eliminate wrong answers

Option B is wrong because defining user segments is a prerequisite step for creating Information Barrier policies, not a method to test the configuration before enforcement. Option C is wrong because enabling audit logging captures events for compliance review but does not simulate or test the blocking behavior of Information Barrier policies. Option D is wrong because Compliance Manager is a risk assessment tool for regulatory compliance, not a feature for testing Information Barrier policy enforcement.

346
MCQeasy

Your organization wants to automatically retain all customer emails for 7 years and then delete them. Which Microsoft Purview feature should you configure?

A.Data Lifecycle Management retention policy
B.Information Protection sensitivity labels
C.Audit log retention
D.eDiscovery hold
AnswerA

A Data Lifecycle Management retention policy is the correct solution because it allows an organization to define how long content should be retained and, optionally, when it should be deleted across various Microsoft 365 services. These policies can be applied broadly to entire locations, such as all Exchange mailboxes or SharePoint sites, ensuring automatic and consistent retention of all customer data according to organizational or regulatory requirements.

Why this answer

Microsoft Purview Data Lifecycle Management retention policies are designed to automatically retain and then delete content (e.g., Exchange emails, SharePoint files, Teams messages) based on a specified retention period. Configuring a retention policy with a 7-year retention period and a delete action after that period meets the requirement to retain customer emails for 7 years and then delete them.

Exam trap

SC-900 often tests the confusion between retention (lifecycle management) and eDiscovery holds—candidates may pick eDiscovery hold thinking it deletes data, but holds only preserve data indefinitely.

How to eliminate wrong answers

Option B is wrong because Information Protection sensitivity labels are used to classify and protect data (e.g., encryption, watermarking), not to enforce retention and deletion schedules. Option C is wrong because Audit log retention (now Audit in Purview) governs the retention of audit records for compliance and investigation, not the lifecycle of customer emails. Option D is wrong because eDiscovery hold is used to preserve content for legal or investigative purposes, and it does not automatically delete content after a period—it prevents deletion.

347
MCQhard

You are a security administrator for Contoso Ltd., a global financial services company with 5,000 employees. The company uses Microsoft 365 E5 licenses and has deployed Microsoft Entra ID, Microsoft Defender XDR, Microsoft Purview, and Microsoft Intune. Recently, the security team identified a risk: employees are sharing sensitive financial reports via external email recipients without encryption. To address this, you need to implement a solution that automatically applies encryption to emails containing the sensitive information type 'U.S. Bank Account Number' when sent to external recipients. The solution must not block the email but should encrypt it. Additionally, you want to notify the sender with a policy tip that the email will be encrypted. You have access to the Microsoft Purview compliance portal. What should you configure?

A.Configure an email encryption rule in Microsoft Defender for Office 365.
B.Create a Data Loss Prevention (DLP) policy in Microsoft Purview that detects 'U.S. Bank Account Number' and applies encryption to emails sent to external recipients, with a policy tip.
C.Enable Microsoft Purview Message Encryption for all users.
D.Create a sensitivity label with encryption and publish it to all users, then train users to apply it manually.
AnswerB

DLP can automatically apply encryption and show policy tips.

Why this answer

A DLP policy in Microsoft Purview is the correct solution because it can automatically detect sensitive information types like 'U.S. Bank Account Number' in email content and apply encryption actions (such as Encrypt-Only or Do Not Forward) when the email is sent to external recipients. The policy can also be configured to show a policy tip to the sender, notifying them that the email will be encrypted, without blocking the email.

This directly meets the requirement of automatic encryption with sender notification, leveraging the built-in DLP capabilities in Microsoft 365 E5.

Exam trap

SC-900 often tests the misconception that enabling a service (like Message Encryption) or using sensitivity labels alone provides automatic protection, when in fact DLP policies are required for automatic detection and enforcement based on sensitive information types.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 does not provide email encryption rules; its email security features focus on anti-malware, anti-phishing, and safe attachments/links, not on applying encryption based on sensitive data detection. Option C is wrong because enabling Microsoft Purview Message Encryption for all users only makes the encryption service available; it does not automatically encrypt emails containing sensitive data or apply policy tips—it requires manual application or a separate rule. Option D is wrong because sensitivity labels with encryption require manual application by users (or client-side auto-labeling, which is not guaranteed for all scenarios), and the requirement is for automatic encryption without relying on user action; also, policy tips are not natively provided by sensitivity labels in the same way as DLP.

348
MCQeasy

Your organization's security team wants to automatically investigate and respond to sophisticated email threats like business email compromise (BEC) without manual intervention. Which Microsoft 365 security solution should you use?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Office 365
AnswerD

Microsoft Defender for Office 365 is the specialized security solution designed to protect organizations from sophisticated threats in email, links, and collaboration tools like Microsoft Teams, SharePoint, and OneDrive. It offers advanced anti-phishing, anti-malware, and anti-spam capabilities, along with Safe Attachments and Safe Links to neutralize threats. Crucially, it includes Automated Investigation and Response (AIR) capabilities that automatically investigate and remediate email-borne threats such as Business Email Compromise (BEC), making it the correct choice for this scenario.

Why this answer

Microsoft Defender for Office 365 includes automated investigation and response (AIR) capabilities specifically designed to handle sophisticated email threats like business email compromise (BEC). It uses machine learning models and heuristics to detect BEC patterns—such as spoofed domains, compromised accounts, and social engineering—and can automatically trigger playbooks to contain, investigate, and remediate threats without manual intervention.

Exam trap

The trap here is that candidates often confuse 'email threat protection' with 'endpoint' or 'identity' solutions, mistakenly thinking BEC is an identity attack rather than an email-specific social engineering threat.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps focuses on shadow IT discovery, cloud app permissions, and data protection across SaaS applications, not on email-specific threats like BEC. Option B is wrong because Microsoft Defender for Endpoint protects endpoints (devices) from malware, exploits, and file-based attacks, but does not natively analyze email headers or message content for BEC. Option C is wrong because Microsoft Defender for Identity monitors on-premises Active Directory signals for identity-based attacks (e.g., pass-the-hash, Kerberoasting), not email-borne social engineering attacks.

349
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Defender for Cloud Apps?

Select 2 answers
A.Information protection for files in Microsoft 365
B.Session controls to monitor and control app access in real time
C.Cloud discovery to identify shadow IT
D.Identity governance and access reviews
E.Vulnerability assessment for Azure virtual machines
AnswersB, C

Session controls are a core capability of Microsoft Defender for Cloud Apps, functioning as a Cloud Access Security Broker (CASB). These controls enable real-time monitoring and intervention for user sessions accessing cloud applications, allowing organizations to enforce policies such as blocking downloads of sensitive data, requiring step-up authentication, or protecting uploads of unclassified files. This ensures data protection and compliance even when users are accessing apps from unmanaged devices.

Why this answer

Microsoft Defender for Cloud Apps provides session controls that leverage reverse proxy architecture to monitor and control user app access in real time, enabling conditional access policies for cloud apps. Cloud discovery uses traffic logs from network appliances or Windows endpoints to identify shadow IT by analyzing app usage and risk scores.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Cloud (formerly Azure Security Center) or Microsoft Purview, leading them to select options like vulnerability assessment or information protection that belong to other services.

350
MCQeasy

A company uses Microsoft Entra ID. The IT team wants to allow users to reset their own passwords without calling the help desk, but only after they verify their identity by using a code sent to their registered mobile phone. They also want to require users to register for this capability the next time they sign in. Which Microsoft Entra feature should they enable?

A.Microsoft Entra Password Protection
B.Microsoft Entra Connect Sync
C.Microsoft Entra ID Protection
D.Self-service password reset (SSPR)
AnswerD

SSPR allows users to reset their own passwords after verifying their identity through one or more authentication methods, such as a code sent to a registered mobile phone. You can require users to register for SSPR at next sign-in, and you can restrict reset to only users who have the required methods. This directly matches the scenario.

Why this answer

Self-service password reset (SSPR) in Microsoft Entra ID lets users reset their own passwords after verifying their identity with registered methods. You can require users to register for SSPR at next sign-in, and you can configure authentication methods such as mobile phone. This reduces help desk calls and matches the requirement for phone-based verification and registration enforcement.

Exam trap

The trap here is confusing Password Protection, which blocks weak passwords, with SSPR, which allows users to reset their own passwords after identity verification.

351
MCQmedium

A company maintains an on-premises Active Directory environment with over 10,000 domain-joined computers. The security team is concerned about advanced attacks that use stolen credentials to move laterally, such as pass-the-hash attacks or DCSync attacks targeting domain controllers. They need a solution that monitors on-premises Active Directory traffic and event logs to detect these identity-based threats and provides alerts for investigation. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Cloud Apps
D.Microsoft Sentinel
AnswerA

Microsoft Defender for Identity is purpose-built to protect hybrid identity environments, specifically monitoring on-premises Active Directory domain controllers. It deploys lightweight sensors directly on domain controllers to profile network traffic and event logs, detecting advanced threats like Pass-the-Hash, Golden Ticket attacks, and DCSync. This specialized focus allows it to identify suspicious user and entity behavior patterns indicative of compromise within the AD infrastructure, providing critical alerts for security teams.

Why this answer

Microsoft Defender for Identity is the correct solution because it is specifically designed to monitor on-premises Active Directory traffic and event logs to detect advanced identity-based threats like pass-the-hash, pass-the-ticket, and DCSync attacks. It uses behavioral analytics and machine learning to identify suspicious activities, such as anomalous Kerberos ticket requests or replication attempts, and provides real-time alerts for investigation.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Identity with Microsoft Sentinel, assuming that a SIEM is always the best choice for threat detection, but Sentinel lacks the specialized Active Directory protocol-level analysis and behavioral models that Defender for Identity provides natively.

Why the other options are wrong

B

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., malware, vulnerabilities) and does not natively monitor on-premises Active Directory traffic or event logs for identity-based attacks like pass-the-hash or DCSync.

C

Microsoft Defender for Cloud Apps focuses on securing cloud applications and detecting threats in cloud services, not on-premises Active Directory traffic or lateral movement attacks like pass-the-hash or DCSync.

D

Microsoft Sentinel is a SIEM/SOAR platform that ingests logs from multiple sources, but it does not natively monitor on-premises Active Directory traffic or detect identity-based attacks like pass-the-hash or DCSync without additional data connectors and analytics rules. The question specifically asks for a solution that monitors on-premises AD traffic and event logs for identity threats, which is the core function of Defender for Identity, not Sentinel.

When would these options actually be correct?

B

A company needs to detect and respond to advanced threats on endpoints, such as fileless malware, ransomware, or suspicious PowerShell execution, and requires endpoint detection and response (EDR) capabilities for its domain-joined computers.

C

A company uses multiple SaaS applications (e.g., Office 365, Salesforce) and needs to detect anomalous user behavior, data exfiltration, or compromised accounts in the cloud. They require a Cloud Access Security Broker (CASB) to monitor and control cloud app usage.

D

A question where the requirement is to centralize security logs from multiple sources (including on-premises AD, cloud apps, and endpoints) into a single platform for advanced threat hunting, correlation, and automated response across the entire environment. For example: 'The security team needs a unified SIEM solution to collect logs from on-premises AD, Azure AD, and third-party firewalls for incident investigation and automated playbooks.'

Why candidates pick the wrong answer

B

Candidates may confuse endpoint security with identity security, assuming that protecting domain-joined computers automatically covers Active Directory threat detection.

C

Candidates may think 'cloud apps' includes Active Directory in the cloud (Azure AD) or assume the solution covers all identity threats, but it is specifically for cloud application security, not on-prem AD monitoring.

D

Candidates may think Sentinel is the most comprehensive solution and assume it can directly monitor AD traffic, not realizing it requires additional configuration and data sources, while Defender for Identity is purpose-built for on-premises AD identity threats.

352
MCQhard

Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). A user reports receiving a suspicious email with a link. The email was not blocked by Exchange Online Protection (EOP). Which feature should you use to investigate the link's reputation in real time?

A.Exchange Online Protection (EOP) filtering
B.Anti-phish policy
C.Safe Attachments policy
D.Safe Links policy
AnswerD

Safe Links policies provide real-time, click-time protection by dynamically rewriting URLs in emails and supported Office documents. When a user clicks a rewritten link, it is scanned against continuously updated reputation lists and, if necessary, detonated in a sandbox, blocking access to malicious sites. This ensures dynamic protection against evolving web-based threats and provides detailed reporting for security teams.

Why this answer

Safe Links is the correct feature because it provides real-time URL reputation checking at the time of click. When a user clicks a link in an email, Safe Links checks the link against Microsoft's threat intelligence to determine if it is malicious, even if the email itself was not blocked by EOP. This allows investigation of the suspicious link's reputation after delivery.

Exam trap

The trap here is that candidates confuse Safe Links with Safe Attachments, thinking both handle links, but Safe Attachments only scans file attachments, not URLs embedded in email bodies.

How to eliminate wrong answers

Option A is wrong because Exchange Online Protection (EOP) filtering is a pre-delivery filter that blocks known spam and malware, but it does not perform real-time link reputation checks after delivery. Option B is wrong because Anti-phish policy protects against phishing attempts by analyzing sender and message patterns, but it does not provide on-click URL reputation scanning. Option C is wrong because Safe Attachments policy scans email attachments for malware, not links within the message body.

353
MCQmedium

Your company uses Microsoft Purview to protect sensitive data in SharePoint Online. You need to automatically apply a 'Confidential' sensitivity label to documents containing credit card numbers. What should you create?

A.An auto-labeling policy
B.A Data Loss Prevention (DLP) policy
C.A retention policy
D.An eDiscovery case
AnswerA

An auto-labeling policy in Microsoft Purview Information Protection is specifically designed to automatically apply sensitivity labels to content that matches predefined conditions. These conditions can include the presence of specific sensitive information types (e.g., credit card numbers, national ID numbers), keywords, or even content identified by trainable classifiers. This proactive approach ensures consistent classification and protection of sensitive data at scale, reducing reliance on manual user labeling.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels based on sensitive info types, such as credit card numbers. Option B (DLP policy) is incorrect because while DLP can detect and protect sensitive data, it does not automatically apply labels; it applies actions like blocking or warning. Option C (retention policy) is incorrect because retention policies manage data retention and deletion, not labeling.

Option D (eDiscovery case) is incorrect because eDiscovery cases are used for searching and legal hold purposes.

354
MCQhard

A security analyst wants to create a custom detection rule that tracks a specific multi-stage attack pattern: a user receives a phishing email, clicks a link, and then a script is executed on their device. The analyst needs to write a Kusto Query Language (KQL) query to detect this pattern and schedule it to run automatically, generating alerts. Which Microsoft 365 Defender capability should they use?

A.Advanced hunting
B.Custom detection rules
C.Automation
D.Threat analytics
AnswerB

Custom detection rules in Microsoft 365 Defender run scheduled KQL queries against advanced hunting tables, letting analysts encode multi-stage patterns such as phishing click followed by script execution. They generate alerts automatically, satisfying the requirement to detect and schedule this attack chain.

Why this answer

Custom detection rules in Microsoft 365 Defender allow security analysts to write KQL queries that run on a schedule and automatically generate alerts when the query returns results. This capability is specifically designed to detect multi-stage attack patterns, such as the phishing email → link click → script execution chain described, by querying advanced hunting data and triggering incident creation.

Exam trap

The trap here is that candidates confuse Advanced hunting (a query tool) with Custom detection rules (a scheduled alerting engine), assuming that writing a KQL query in Advanced hunting alone is sufficient for automated detection, when in fact it requires the custom detection rule framework to run on a schedule and generate alerts.

How to eliminate wrong answers

Option A is wrong because Advanced hunting is an interactive query interface for exploring raw data, but it does not natively support scheduled execution or automatic alert generation; it requires manual execution or integration with custom detection rules. Option C is wrong because Automation in Microsoft 365 Defender refers to automated investigation and response (AIR) playbooks that react to alerts, not to the creation of custom detection queries or scheduled alert rules. Option D is wrong because Threat analytics provides curated threat intelligence reports and pre-built detections from Microsoft, but it does not allow users to write custom KQL queries or schedule their own detection logic.

355
MCQmedium

A multinational corporation wants to ensure that its data handling practices comply with GDPR when processing personal data of European Union citizens. The compliance team is reviewing the concept of data residency. Which statement accurately describes data residency?

A.Data residency refers to the legal right of individuals to access their personal data.
B.Data residency refers to the physical or geographic location where data is stored.
C.Data residency refers to the ability to move data freely between cloud providers.
D.Data residency refers to the process of encrypting data to protect it from unauthorized access.
AnswerB

Data residency specifically refers to the geographic location where data is stored, which is crucial for compliance with regulations like GDPR that may require data to remain within certain jurisdictions. In this scenario, understanding data residency helps the corporation ensure that EU citizen data is stored in appropriate regions. This definition aligns with Microsoft compliance offerings that allow customers to choose data residency locations.

Why this answer

Data residency is about the geographic location where data is stored. For GDPR compliance, organizations may need to ensure that personal data of EU citizens remains within certain regions. The other options describe data subject rights, encryption, and data portability, which are related but distinct compliance concepts.

Understanding data residency helps in designing compliant cloud architectures.

Exam trap

The trap here is confusing data residency with data sovereignty or data portability; residency specifically concerns the physical storage location, not legal rights or transferability.

356
MCQmedium

A security team wants to discover which cloud applications (such as Dropbox, Salesforce, or unsanctioned file-sharing apps) are being used by employees, even if those apps are not sanctioned by IT. They need to analyze usage patterns, risk levels, and identify potential shadow IT. Which feature of Microsoft Defender for Cloud Apps should they enable?

A.App Connectors (API connectors)
B.Cloud Discovery
C.Conditional Access App Control
D.Microsoft Defender for Endpoint
AnswerB

Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps (MDCA), is specifically designed to identify all cloud applications accessed by users within an organization. It achieves this by analyzing network traffic logs from firewalls, proxies, and other network devices, correlating IP addresses and URLs to known cloud services. This process provides a comprehensive overview of both sanctioned and unsanctioned "shadow IT" applications, which is precisely what a security team needs for initial discovery.

Why this answer

Cloud Discovery is the correct feature because it analyzes traffic logs from firewalls and proxies to identify cloud app usage, including unsanctioned apps like Dropbox or Salesforce, without requiring API integration. It provides risk scores, usage patterns, and shadow IT detection by comparing discovered apps against Microsoft's cloud app catalog of over 31,000 apps.

Exam trap

The trap here is that candidates often confuse Cloud Discovery (passive log analysis for unsanctioned apps) with App Connectors (active API integration for sanctioned apps), assuming both can discover shadow IT, but only Cloud Discovery identifies apps not already connected via API.

How to eliminate wrong answers

Option A is wrong because App Connectors (API connectors) require explicit admin consent and API access to sanctioned apps, so they cannot discover unsanctioned or unknown shadow IT apps. Option C is wrong because Conditional Access App Control enforces real-time access policies on sanctioned apps via reverse proxy, not discovery of unsanctioned apps. Option D is wrong because Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution focused on malware, vulnerabilities, and device threats, not cloud app discovery.

357
Multi-Selecteasy

Which TWO features are available in Microsoft Entra ID P2 licenses? (Choose two.)

Select 2 answers
A.Self-service password reset (SSPR)
B.Privileged Identity Management (PIM)
C.Multifactor authentication (MFA)
D.Identity Protection (risk-based policies)
E.Password hash synchronization
AnswersB, D

Privileged Identity Management (PIM) is a cornerstone feature of Microsoft Entra ID P2, designed to mitigate the risks associated with excessive, unnecessary, or misused access permissions. It enables just-in-time (JIT) access to resources, meaning users are granted elevated roles only when needed and for a limited duration. PIM also facilitates just-enough-administration (JEA) by requiring approval or justification for role activation, significantly enhancing an organization's security posture against privilege escalation attacks.

Why this answer

Microsoft Entra ID P2 includes Privileged Identity Management (PIM) (option B), which provides just-in-time role activation, approval workflows, and access reviews for privileged roles, and this capability is exclusive to the P2 tier. Option D, Identity Protection with risk-based policies, is also a P2 feature that uses Microsoft's threat intelligence to detect risky users and sign-ins and to enforce risk-based Conditional Access policies. Options A (SSPR), C (MFA), and E (password hash synchronization) are not P2-exclusive: SSPR and MFA are available in Entra ID Free/P1 (with full SSPR for cloud users in Free and broader SSPR in P1), and password hash synchronization is a core Microsoft Entra Connect capability available with any Entra ID edition, so they do not satisfy the P2-only requirement.

Exam trap

The trap here is that candidates confuse features available in P1 (like SSPR and MFA via Conditional Access) with P2-exclusive features, forgetting that Identity Protection risk policies and PIM are the only two P2-specific capabilities listed.

358
Multi-Selecteasy

Which THREE are capabilities of Microsoft Defender for Cloud?

Select 3 answers
A.Just-in-time (JIT) VM access
B.Vulnerability assessment for virtual machines
C.Cloud Security Posture Management (CSPM)
D.DDoS protection
E.SIEM and security orchestration
AnswersA, B, C

Just-in-time VM access is a Defender for Cloud capability that blocks inbound management ports by default and opens them only on approved, time-bound requests, reducing the attack surface of Azure and multicloud virtual machines against brute-force and scanning attempts.

Why this answer

Microsoft Defender for Cloud provides just-in-time (JIT) VM access (A), which locks down management ports (RDP/SSH) and grants time-limited, approved access on request, reducing the attack surface of Azure and non-Azure VMs. It also delivers vulnerability assessment for virtual machines (B), using integrated scanners such as Microsoft Defender for Endpoint or Qualys to surface OS and software CVEs and remediation guidance. Cloud Security Posture Management (CSPM) (C) is a core capability, continuously assessing configurations against benchmarks like Microsoft Cloud Security Benchmark and CIS, and providing secure score and regulatory compliance dashboards.

DDoS protection (D) is not a Defender for Cloud capability; it is delivered by Azure DDoS Protection (Basic/Network Protection) as a separate service. SIEM and security orchestration (E) belong to Microsoft Sentinel, which is a distinct product, even though it can ingest Defender for Cloud alerts.

Exam trap

The trap here is that candidates confuse the 'recommendations' or 'alerts' shown in Defender for Cloud (which may mention DDoS or SIEM integration) with Defender for Cloud's own native capabilities, leading them to incorrectly select D or E as direct features.

359
MCQeasy

A company wants to use Microsoft Entra ID (Azure AD) to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. Which security feature should they implement?

A.Privileged Identity Management (PIM)
B.Conditional Access policies
C.Password Protection
D.Identity Protection policies
AnswerB

Conditional Access policies are the primary tool within Microsoft Entra ID for enforcing specific access controls based on various conditions evaluated at sign-in. These policies allow administrators to define "if-then" statements, such as "if a user is accessing a specific cloud application, then require multi-factor authentication." This capability directly addresses the requirement to enforce MFA for designated applications, providing granular control over access.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to enforce MFA based on conditions such as user, group, application, location, and device state. This is the primary feature for requiring MFA for access to sensitive applications. It provides granular control and integrates with other signals.

Exam trap

The trap is confusing Identity Protection with Conditional Access; candidates may pick Identity Protection because it sounds security-related, but Conditional Access is the feature that actually enforces MFA.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) manages just-in-time privileged access and approvals, not MFA enforcement for applications. Option C is wrong because Password Protection detects and blocks weak or leaked passwords, not MFA enforcement. Option D is wrong because Identity Protection policies automate risk-based responses (e.g., requiring password change), but they do not directly enforce MFA for all users accessing sensitive apps; Conditional Access is the correct tool for that.

360
MCQhard

Your organization has a Microsoft Entra ID tenant with 5,000 users. You need to implement a solution that automatically detects and remediates users with leaked credentials. Additionally, you need to require users to change their password when a high risk is detected. Which Microsoft Entra features should you configure?

A.Enable Microsoft Entra Identity Protection, configure a user risk policy to require password change when risk is medium or high.
B.Create an Access Review for all users and require them to confirm their access quarterly.
C.Enable Privileged Identity Management (PIM) and require multi-factor authentication for all role activations.
D.Configure a Conditional Access policy to require password change when sign-in risk is high.
AnswerA

Microsoft Entra Identity Protection actively monitors for various risk detections, including leaked credentials, which are identified through dark web monitoring and other sources. A user risk policy, configured within Identity Protection, can then automatically enforce remediation actions like requiring a password change when a user's aggregated risk level (e.g., medium or high) indicates potential compromise. This direct linkage ensures that detected credential compromises are promptly addressed.

Why this answer

Microsoft Entra Identity Protection detects leaked credentials by monitoring for credential exposures on the dark web and other sources. Configuring a user risk policy to require a password change when risk is medium or high automatically remediates the detected risk by forcing the user to update their password, directly addressing the requirement for automatic detection and remediation.

Exam trap

The trap here is confusing user risk (which detects leaked credentials and other user-level threats) with sign-in risk (which evaluates real-time session anomalies), leading candidates to incorrectly select Option D, which only addresses sign-in risk and not the required leaked credential detection.

How to eliminate wrong answers

Option B is wrong because Access Reviews are designed for periodic attestation of access rights, not for detecting or remediating leaked credentials or enforcing password changes based on risk. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and requires MFA for those activations, but it does not detect leaked credentials or enforce user password changes for general users. Option D is wrong because a Conditional Access policy can require a password change only when sign-in risk is high, but it does not automatically detect leaked credentials; sign-in risk evaluates real-time session anomalies, not leaked credential exposure, and the question specifically requires detection of leaked credentials, which is a user risk feature.

361
MCQmedium

A security operations team needs to protect Windows servers from ransomware and other advanced threats. They require a solution that provides endpoint detection and response (EDR), automated investigation, and the ability to isolate compromised machines from the network. Which Microsoft security solution should they deploy?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Identity
C.Microsoft Defender for Office 365
D.Microsoft Defender for Endpoint
AnswerD

Microsoft Defender for Endpoint is the correct solution as it provides comprehensive endpoint detection and response (EDR), vulnerability management, and threat protection specifically for Windows servers and clients. It actively monitors for malicious activity, automates investigations, and can isolate compromised devices, directly addressing the need to protect servers from various threats.

Why this answer

Microsoft Defender for Endpoint (MDE) is the correct solution because it provides endpoint detection and response (EDR), automated investigation and remediation, and network isolation capabilities specifically for Windows servers and endpoints. These features directly address the requirement to protect against ransomware and advanced threats by detecting suspicious behavior, automatically investigating alerts, and allowing admins to isolate compromised machines from the network to prevent lateral movement.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a cloud security posture tool) with Microsoft Defender for Endpoint (an endpoint protection platform), especially since both names include 'Defender' and 'Cloud' can be misassociated with server workloads.

Why the other options are wrong

A

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) for multicloud environments, not an endpoint detection and response (EDR) solution for Windows servers. It lacks the ability to isolate compromised machines from the network.

B

Microsoft Defender for Identity focuses on protecting on-premises Active Directory identities and detecting identity-based attacks, not on endpoint detection, response, or isolation of compromised machines.

C

Microsoft Defender for Office 365 protects email and collaboration tools like Exchange Online and SharePoint, not Windows servers. It lacks endpoint detection and response (EDR) and network isolation capabilities for servers.

When would these options actually be correct?

A

A question asks: 'A company uses Azure and AWS and needs to assess security configurations, detect misconfigurations, and protect cloud workloads across both platforms. Which Microsoft solution should they use?'

B

A question asking for a solution to monitor and detect suspicious activities related to user accounts and Kerberos authentication in an on-premises Active Directory environment, especially to prevent lateral movement and privilege escalation.

C

A question asking for a solution to protect users from phishing, malicious attachments, and unsafe links in email and Office 365 apps, with features like Safe Attachments and Safe Links, would have Microsoft Defender for Office 365 as the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse 'cloud' in the name with protecting servers in the cloud, or assume it includes endpoint protection for cloud-based servers.

B

Candidates may confuse 'identity' with 'endpoint' security, or think that protecting identities is sufficient to stop ransomware, overlooking the need for EDR and machine isolation.

C

Candidates may confuse 'Office 365' with general Microsoft security, or assume it covers all Microsoft products, not realizing it is limited to cloud-based productivity suites.

362
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Entra ID? (Select two.)

Select 2 answers
A.Antivirus and antimalware protection
B.Identity as a Service (IDaaS) for cloud applications
C.Provide network firewall services
D.Manage mobile devices and applications
E.Single sign-on (SSO) to thousands of SaaS applications
AnswersB, E

Microsoft Entra ID serves as a comprehensive Identity as a Service (IDaaS) solution, providing a cloud-based platform for managing digital identities and controlling access to various cloud applications. It enables organizations to centralize user accounts, enforce authentication policies, and provision users to Software as a Service (SaaS) applications and custom cloud applications. This capability streamlines identity management operations and enhances security across diverse cloud environments.

Why this answer

Microsoft Entra ID is a cloud-based identity and access management service, providing Identity as a Service (IDaaS) for cloud applications. It enables organizations to manage user identities and control access to resources, including thousands of pre-integrated SaaS applications through single sign-on (SSO). This makes option B correct because Entra ID's core function is identity management, not endpoint security or network infrastructure.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID with broader security suites like Microsoft 365 Defender or Azure security services, mistakenly attributing endpoint protection or network firewall capabilities to identity management.

363
MCQhard

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. The JSON snippet shows a rule designed to create an incident when a high-severity alert is generated. However, the rule is not triggering. What is the most likely reason?

A.The logicAppResourceId is missing a required parameter.
B.The action should be of type 'Microsoft.SecurityInsights/AlertRule/Alert' instead.
C.Automation rules triggered on alert creation cannot create incidents; they can only run playbooks.
D.The trigger type is incorrect; it should be 'Microsoft.SecurityInsights/Incident'.
AnswerC

Automation rules configured to trigger upon the creation of an alert have a specific limitation regarding their direct actions. While they can successfully execute a playbook, which in turn can create an incident, the automation rule itself cannot directly perform a 'createIncident' action. This distinction is crucial for understanding the flow of operations, as direct incident creation is typically reserved for rules triggered by incident-related events.

Why this answer

Automation rules in Microsoft Sentinel that are triggered on alert creation (i.e., when an alert is generated) are designed only to run playbooks (automated response actions), not to create incidents. Incident creation from alerts is handled automatically by Sentinel's built-in analytics rules or by the incident creation rule type, not by an automation rule triggered on alert creation. The JSON snippet shows a trigger type of 'Microsoft.SecurityInsights/AlertRule/Alert', which confirms the rule fires on alert creation, and the action attempts to create an incident, which is not supported for this trigger type.

Exam trap

The trap here is that candidates often assume automation rules can freely create incidents from any trigger type, but Microsoft Sentinel strictly limits incident creation to analytics rule configurations or incident-scoped automation rules, not alert-scoped automation rules.

How to eliminate wrong answers

Option A is wrong because the logicAppResourceId is not missing a required parameter; the issue is not about missing parameters but about the fundamental incompatibility of the trigger type with the action. Option B is wrong because the action type 'Microsoft.SecurityInsights/AlertRule/Alert' would be incorrect for creating an incident; the correct action type for creating an incident is 'Microsoft.SecurityInsights/Incident', but even that action type is not allowed when the trigger is on alert creation. Option D is wrong because the trigger type 'Microsoft.SecurityInsights/AlertRule/Alert' is correct for an automation rule that fires when an alert is generated; changing it to 'Microsoft.SecurityInsights/Incident' would make the rule trigger on incident creation, not alert creation, which does not solve the problem of creating an incident from an alert.

364
MCQhard

Your company uses Microsoft Defender for Cloud to secure multicloud workloads. You need to ensure that regulatory compliance frameworks (e.g., SOC 2, ISO 27001) are continuously assessed and any drift is reported. What should you implement?

A.Regulatory compliance standards in Microsoft Defender for Cloud
B.Microsoft Sentinel analytics rules
C.Azure Policy initiatives
D.Microsoft Defender for Cloud Apps session policies
AnswerA

Regulatory compliance standards in Microsoft Defender for Cloud provide continuous assessment of your cloud environment against a wide array of industry and regulatory benchmarks, such as ISO 27001, SOC 2, and PCI DSS. It automatically maps security recommendations to specific controls within these standards, offering a compliance score and detailed reports. This feature helps organizations understand their current compliance posture and provides actionable insights to remediate non-compliant resources, simplifying the audit preparation process.

Why this answer

Microsoft Defender for Cloud includes a Regulatory Compliance dashboard that continuously assesses resources against built-in standards such as SOC 2, ISO 27001, PCI DSS, and NIST. It surfaces compliance drift in real time and maps failing assessments to specific controls, which is exactly what continuous regulatory assessment requires.

Exam trap

SC-900 often tests the confusion between Defender for Cloud's regulatory compliance dashboard and Azure Policy — candidates pick Azure Policy because it 'enforces compliance,' but only Defender for Cloud provides the framework-mapped continuous assessment view.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel analytics rules detect security threats and generate incidents from log data — they do not perform regulatory compliance assessment against frameworks. Option C is wrong because Azure Policy initiatives enforce and audit resource configurations but do not natively map results to regulatory frameworks like SOC 2 or ISO 27001 with a compliance dashboard. Option D is wrong because Defender for Cloud Apps session policies govern user sessions in SaaS applications (e.g., block downloads), not regulatory compliance posture.

365
MCQhard

Refer to the exhibit. A security analyst is reviewing an alert from Microsoft 365 Defender. The alert is associated with an incident. What is the best first step to investigate this alert?

A.Open the associated incident to view all related alerts and entities.
B.Isolate the affected user's device immediately.
C.Mark the alert as resolved.
D.Run an automated simulation to test the alert.
AnswerA

An incident aggregates multiple related alerts and entities (users, devices, mailboxes, IP addresses) into a single investigation unit. This holistic view is crucial for understanding the scope, impact, and attack chain, preventing siloed investigations of individual alerts. It allows for comprehensive threat hunting and response planning, making it the most effective initial step for a security analyst.

Why this answer

Microsoft 365 Defender incidents aggregate multiple alerts and entities (users, devices, mailboxes) into a single view, providing the full context needed to understand the attack chain. Opening the incident first allows the analyst to correlate the alert with related alerts, affected assets, and the incident timeline, which is the recommended initial step in incident response workflows.

Exam trap

The trap here is that candidates often jump to an immediate containment action (like isolating a device) without first gathering context, but Microsoft's incident-first approach emphasizes investigation before remediation to avoid false positives and ensure proportional response.

How to eliminate wrong answers

Option B is wrong because isolating the user's device immediately is a reactive containment step that should be taken only after confirming the device is compromised through incident investigation; premature isolation can disrupt legitimate operations and lose forensic evidence. Option C is wrong because marking the alert as resolved without investigation violates security best practices and could allow an active threat to persist undetected. Option D is wrong because running an automated simulation tests detection capabilities but does not help investigate a real, active alert; it is a testing or validation activity, not a response step.

366
MCQmedium

A company uses Microsoft Entra ID and wants to allow external business partners to request access to a specific application through an approval process. The access should be time-limited and automatically expired. Which Microsoft Entra ID feature should be configured?

A.Conditional Access
B.Entitlement management
C.Privileged Identity Management (PIM)
D.Self-service group management
AnswerB

Microsoft Entra Entitlement Management is designed to streamline the lifecycle of access for both internal and external users, particularly for external partners needing access to specific applications or resources. It utilizes access packages, which bundle resources and define policies for requesting access, including approval workflows, mandatory reviews, and automatic expiration dates. This ensures that external access is granted only when needed, for a specific duration, and with appropriate oversight, making it ideal for managing B2B collaboration securely and efficiently.

Why this answer

Entitlement management in Microsoft Entra ID (part of Identity Governance) provides access packages that bundle resources such as applications, groups, and SharePoint sites. External users can request access through a self-service portal, with approval workflows, time-limited assignments, and automatic expiration. This exactly matches the requirement for partner access requests with approval and time limits.

Exam trap

SC-900 often tests the difference between PIM (just-in-time privileged roles for internal admins) and entitlement management (access packages for internal/external users with approvals and expiration) — candidates pick PIM because it sounds like 'privileged access', but it does not handle partner access requests.

Why the other options are wrong

A

Conditional Access enforces access policies based on signals like user location or device state, but it does not provide time-limited access requests with approval workflows for external partners.

C

Privileged Identity Management (PIM) manages just-in-time access for privileged roles (e.g., admin roles), not for external partners requesting access to a specific application with time-limited, auto-expiring access.

D

Self-service group management allows users to create and manage their own groups in Microsoft Entra ID, but it does not provide time-limited access or automated expiration for external partners. It lacks the approval workflows and access packages needed for this scenario.

When would these options actually be correct?

A

A company needs to require multi-factor authentication for all users accessing a sensitive application from outside the corporate network. Which feature should be configured?

C

A question asks: 'A company needs to provide time-limited, approvable access to Azure AD administrative roles (e.g., Global Administrator) for IT staff, with automatic expiration.' In that scenario, PIM is the correct feature.

D

An exam question might ask: 'A company wants to allow employees to create and manage their own groups for collaboration without IT intervention. Which feature should be configured?' In that case, self-service group management would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse Conditional Access with access management features, thinking it can handle external partner access requests and approvals, but it lacks the lifecycle and approval capabilities of Entitlement Management.

C

Candidates confuse PIM's time-limited role activation with entitlement management's time-limited resource access, and both involve approvals, leading to a mistaken choice.

D

Candidates may confuse self-service group management with entitlement management because both involve user-driven access requests, but they overlook the specific requirements for time-limited access and approval processes for external partners.

367
MCQeasy

Your company wants to allow employees to use their corporate Microsoft Entra ID credentials to sign in to third-party SaaS applications like Salesforce and ServiceNow. Which Microsoft Entra feature should you configure?

A.Conditional Access policies.
B.Microsoft Entra B2B collaboration.
C.Microsoft Entra Identity Protection.
D.Enterprise applications with pre-integrated gallery apps.
AnswerD

Enterprise applications in Microsoft Entra ID provide the central framework for integrating various applications, including Software as a Service (SaaS) applications. The pre-integrated gallery apps offer ready-to-use templates with pre-configured settings for popular SaaS applications, significantly simplifying the process of enabling Single Sign-On (SSO). This allows employees to access corporate applications using their existing Microsoft Entra credentials without needing to re-authenticate, streamlining access and enhancing security.

Why this answer

Configuring a third-party SaaS application like Salesforce or ServiceNow as an Enterprise Application in Microsoft Entra ID allows you to set up federation using SAML 2.0 or OpenID Connect, enabling users to sign in with their corporate Entra ID credentials. The pre-integrated gallery apps provide pre-configured templates that simplify the setup of single sign-on (SSO) and user provisioning, making it the appropriate feature for this requirement.

Exam trap

The trap here is that candidates confuse Conditional Access (which controls access after authentication) with the actual SSO configuration feature, or they mistakenly think B2B collaboration is for internal users accessing external apps, when it is specifically for external users accessing internal resources.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies are used to enforce access controls (e.g., MFA, location restrictions) after SSO is configured, not to enable the initial sign-in with corporate credentials. Option B is wrong because Microsoft Entra B2B collaboration is designed for inviting external users (guests) from other organizations, not for enabling internal employees to use their corporate credentials for third-party SaaS apps. Option C is wrong because Microsoft Entra Identity Protection is a risk-based security tool that detects and responds to identity threats (e.g., leaked credentials, impossible travel), not a feature for configuring SSO or authentication to external applications.

368
MCQeasy

A company wants to use Microsoft Sentinel to collect security logs from on-premises servers and send them to Azure. Which data connector should they use?

A.Azure Monitor Agent (AMA)
B.Syslog connector
C.Microsoft Monitoring Agent (MMA)
D.Office 365 connector
AnswerA

The Azure Monitor Agent (AMA) is the correct and recommended solution for collecting security logs from both Windows and Linux servers, including on-premises, for ingestion into Microsoft Sentinel. It offers a more secure, efficient, and flexible data collection experience compared to its predecessor, allowing granular control over which logs are collected via Data Collection Rules (DCRs). AMA supports a wide range of log types, including security events, performance counters, and Syslog, making it ideal for comprehensive security monitoring.

Why this answer

The Azure Monitor Agent (AMA) is the correct choice because it is the current, unified data collection agent for Microsoft Sentinel that supports collecting security logs from Windows and Linux on-premises servers. It replaces the legacy Microsoft Monitoring Agent (MMA) and provides a more secure, scalable, and performant method to send logs to Azure Log Analytics workspaces, which underpin Sentinel.

Exam trap

The trap here is that candidates often confuse the Syslog connector (Option B) as the correct answer for on-premises Linux servers, but the question specifically asks for a data connector that directly collects logs from on-premises servers, and AMA is the modern, unified agent that handles both Windows and Linux without requiring an intermediate Syslog forwarder.

How to eliminate wrong answers

Option B (Syslog connector) is wrong because it is not a data connector for on-premises servers; it is a legacy method that requires a separate Syslog forwarder (e.g., rsyslog) and does not directly collect logs from servers without additional configuration. Option C (Microsoft Monitoring Agent) is wrong because it is the deprecated agent that Microsoft has announced will be retired by August 2024; it lacks the security and performance improvements of AMA, such as support for Azure Private Link and data collection rules. Option D (Office 365 connector) is wrong because it is specifically designed to ingest logs from Microsoft 365 services (e.g., Exchange, SharePoint) and cannot collect security logs from on-premises servers.

369
MCQmedium

A company uses Microsoft Entra ID. The security team needs to grant temporary elevated access to the Global Administrator role for a specific task, such as configuring a new security policy. They want the user to request activation, which is then approved by a manager, and the privileges automatically expire after 4 hours. Which Microsoft Entra feature should they use?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Self-Service Password Reset (SSPR)
AnswerC

Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within an organization by implementing just-in-time (JIT) access. It enables users to activate privileged roles only when needed and for a limited, predefined duration, often requiring an approval workflow. PIM also provides automatic expiration of assignments and comprehensive auditing, significantly reducing the attack surface associated with standing privileged access.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access, allowing users to request activation of roles like Global Administrator. The activation can require approval from a manager and is automatically deactivated after a configurable maximum duration (e.g., 4 hours), directly meeting the security team's requirements.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with Conditional Access, because both involve policies and access control, but PIM specifically handles just-in-time privileged role activation with approval and expiration, while Conditional Access focuses on access conditions for all users.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces policies based on signals like user location or device compliance, but it does not provide time-bound role activation with approval workflows. Option B is wrong because Identity Protection detects and remediates identity-based risks (e.g., leaked credentials), not manage privileged role activation or expiration. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords, not to elevate or manage role assignments.

370
MCQmedium

You are the identity administrator for a company that uses Microsoft Entra ID. The security team wants to ensure that any user who is assigned the Privileged Role Administrator role must activate the role only after providing a justification and passing an MFA challenge. They also want to require approval from a designated approver before the role becomes active. What should you configure?

A.Create an access review for the Privileged Role Administrator role and require reviewers to approve the user's continued assignment.
B.Set the user's per-user MFA status to Enabled and create a Conditional Access policy requiring MFA for the Privileged Role Administrator role.
C.Assign the user the Privileged Role Administrator role as a permanent active assignment and enable Azure AD Identity Protection risk policies.
D.Configure Privileged Identity Management (PIM) with role settings that require multi-factor authentication on activation, require justification, and require approval.
AnswerD

PIM provides just-in-time privileged access. By configuring role settings for Privileged Role Administrator, you can require MFA on activation, require a justification, and require approval from specified approvers. This exactly matches the scenario: the controls apply only when the user activates the role, not at every sign-in.

Why this answer

Privileged Identity Management (PIM) is the Microsoft Entra feature that provides just-in-time role activation with activation-time controls such as MFA, justification, and approval. Unlike Conditional Access or access reviews, PIM governs the role assignment lifecycle itself, ensuring privileged roles are not permanently active and that activation is auditable and gated by the required conditions. This directly satisfies the security team's requirements.

Exam trap

The trap here is assuming that Conditional Access or per-user MFA can enforce controls at the moment of privileged role activation, when only PIM provides activation-time gating with justification and approval.

371
MCQmedium

A company is migrating its on-premises applications to Azure Infrastructure-as-a-Service (IaaS). According to the shared responsibility model, which of the following security responsibilities shifts from the customer to Microsoft during this migration?

A.Physical security of the data center infrastructure
B.Configuring network security groups (NSGs)
C.Patching the operating system on virtual machines
D.Managing user identities and access to the application
AnswerA

In the Azure Shared Responsibility Model, particularly for Infrastructure as a Service (IaaS) deployments, the cloud provider (Microsoft) is solely responsible for the physical security of the underlying data centers. This includes implementing robust access controls, continuous surveillance, environmental monitoring, and fire suppression systems to protect the hardware and infrastructure where customer data resides. Customers do not have any control or responsibility over the physical facilities.

Why this answer

When migrating on-premises applications to Azure IaaS, the shared responsibility model shifts physical security responsibilities—such as data center access controls, environmental controls, and hardware security—from the customer to Microsoft. Microsoft is responsible for the physical security of all Azure data centers, including perimeter security, surveillance, and facility access management, which were previously the customer's responsibility in their own on-premises environment.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS or SaaS, mistakenly believing that Microsoft takes responsibility for OS patching or network security in IaaS, when in fact those remain customer responsibilities.

How to eliminate wrong answers

Option B is wrong because configuring network security groups (NSGs) remains the customer's responsibility under IaaS, as the customer controls network traffic filtering and segmentation for their virtual networks. Option C is wrong because patching the operating system on virtual machines is the customer's responsibility in IaaS, as Microsoft only manages the underlying hypervisor and physical hosts. Option D is wrong because managing user identities and access to the application is always the customer's responsibility, regardless of deployment model, as Microsoft provides identity services (like Azure AD) but the customer controls who has access and how permissions are configured.

372
MCQeasy

A user reports that they cannot access a sensitive document in SharePoint Online. The administrator checks the document's permissions and sees that the user is not listed directly, but a group they belong to has been granted access. Which identity concept describes this scenario?

A.Role-based access control (RBAC)
B.Privilege escalation
C.Group-based access control
D.Attribute-based access control (ABAC)
AnswerC

Group-based access control allows permissions to be assigned to groups rather than individuals, simplifying management. This directly matches the scenario where a user gains access because they belong to a group that has been granted access.

Why this answer

The scenario describes group-based access control: the user is not directly granted permission, but inherits access because a security group they belong to has been granted access to the document. This is the standard mechanism in SharePoint Online and Microsoft 365 for scaling permissions management.

Exam trap

SC-900 often tests whether candidates can distinguish group-based access control (inheritance via membership) from RBAC (role assignment) and ABAC (attribute-driven, dynamic evaluation) — candidates pick RBAC because both involve granting access, but RBAC is role-centric, not membership-centric.

How to eliminate wrong answers

Option A is wrong because RBAC assigns permissions based on roles (e.g., SharePoint permission levels like Contribute or Read, or Azure roles), not based on group membership inheritance — the scenario specifically hinges on group membership, not role assignment. Option B is wrong because privilege escalation is an attack technique where a user gains higher privileges than intended; here the user legitimately inherits access through group membership, which is by design. Option D is wrong because ABAC evaluates attributes (e.g., department, project, sensitivity label) at access time to make dynamic decisions; the scenario describes static group membership inheritance, not attribute-based evaluation.

373
Multi-Selectmedium

Which TWO of the following are principles of the Zero Trust security model? (Select two.)

Select 2 answers
A.Verify explicitly
B.Perimeter-based security
C.Implicit trust
D.Trust but verify
E.Least privilege access
AnswersA, E

Verify explicitly satisfies Zero Trust by requiring every access request to be authenticated and authorised using all available signals — user identity, device health, location and risk — before granting resource access. This directly implements the model's core premise that no request is trusted by default, even from inside the corporate network perimeter.

Why this answer

Option A, "Verify explicitly," is a core Zero Trust principle: every access request must be authenticated and authorized based on all available data points (identity, device health, location, workload, data classification) rather than assumed from network location. Option E, "Least privilege access," is also a foundational Zero Trust principle, requiring just-in-time and just-enough-access (JIT/JEA), risk-based adaptive policies, and data protection to limit each user's exposure. The unmarked options do not belong because B, "Perimeter-based security," reflects the traditional castle-and-moat model that Zero Trust explicitly replaces; C, "Implicit trust," is the assumption Zero Trust eliminates by treating every session as untrusted until verified; and D, "Trust but verify," is a Cold War-era adage (and a contrasting posture) rather than a Zero Trust principle, since Zero Trust never grants trust in the first place.

Exam trap

SC-900 often tests the confusion between 'trust but verify' (a traditional security adage) and 'verify explicitly' (the actual Zero Trust principle), catching candidates who rely on familiar phrases rather than the official framework.

374
Multi-Selecthard

Which TWO of the following are required to use Microsoft Purview Audit (Premium)?

Select 2 answers
A.Unified audit log enabled in the Microsoft 365 Defender portal
B.An E5 or A5 license for each user
C.An Azure subscription for log storage
D.Power BI Pro licenses for all users
E.Microsoft Sentinel enabled
AnswersA, B

Microsoft Purview's auditing capabilities, including Audit (Standard) and Audit (Premium), fundamentally rely on the Unified Audit Log (UAL). The UAL captures a comprehensive record of user and administrator activities across various Microsoft 365 services, making it essential for forensic investigations, compliance, and regulatory adherence. Without the UAL enabled, Purview cannot collect the necessary activity data to provide audit insights or support eDiscovery.

Why this answer

Option A is correct because Microsoft Purview Audit (Premium) builds on the unified audit log, so auditing must first be turned on in the Microsoft 365 Defender portal (or via Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true) before premium features such as longer retention and high-value events can be captured. Option B is correct because Audit (Premium) capabilities are licensed through Microsoft 365 E5/A5 (or the E5/A5 Compliance add-on) assigned to each user whose premium audit data is generated. Option C is not required because audit records are stored in Microsoft's service, not in a customer Azure subscription.

Option D is not required because Power BI Pro is unrelated to audit ingestion or retention. Option E is not required because Microsoft Sentinel is a separate SIEM product and is not a prerequisite for Audit (Premium).

Exam trap

The trap here is that candidates assume an Azure subscription or additional services like Sentinel are required for premium auditing, when in fact the only prerequisites are the unified audit log being enabled and an E5/A5 license per user.

375
MCQmedium

A security team needs to investigate a potential data leak where an employee may have emailed sensitive customer information to a competitor. They want to search the unified audit log for specific email activities, such as 'Send' or 'Forward', and generate a detailed report. Which Microsoft Purview solution should they use?

A.Microsoft Purview Compliance Manager
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Audit (Standard or Premium)
D.Microsoft Purview eDiscovery (Premium)
AnswerC

Microsoft Purview Audit (Standard or Premium) is the essential service for investigating user and administrator activities across Microsoft 365 services, including potential data leaks. It provides access to the unified audit log, which records a vast array of events such as file access, sharing, deletions, and email activities. Investigators can use the Audit log search tool to pinpoint specific actions, users, and timeframes related to a suspected leak, with Premium offering extended retention and advanced capabilities for in-depth forensic analysis.

Why this answer

Microsoft Purview Audit (Standard or Premium) is the correct solution because it captures and logs specific email activities such as 'Send' and 'Forward' from Exchange Online. The security team can search the unified audit log for these operations and export a detailed report for investigation. Compliance Manager, DLP, and eDiscovery do not provide this direct audit log search capability for individual email actions.

Exam trap

The trap here is that candidates confuse Data Loss Prevention (DLP) with audit logging, assuming DLP can retrospectively search for past email actions, when in fact DLP only applies proactive policies and alerts, not historical audit log queries.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a risk-assessment and compliance-score tool, not an audit log search tool; it cannot retrieve specific email activities like 'Send' or 'Forward'. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent data leaks by applying policies to block or alert on sensitive content, but it does not provide a searchable audit log of past email actions for forensic investigation. Option D is wrong because Microsoft Purview eDiscovery (Premium) is used for legal hold, collection, and review of content for litigation, not for searching the unified audit log for email send/forward events.

Page 4

Page 5 of 18

Page 6