Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 601–675

1279 questions total · 18pages · All types, answers revealed

Page 8

Page 9 of 18

Page 10
601
MCQeasy

Your organization wants to protect against phishing attacks by verifying the sender's identity for incoming emails. Which Microsoft Defender for Office 365 feature should you configure?

A.Anti-malware policy
B.Safe Links policy
C.Anti-phishing policy with SPF/DKIM/DMARC settings
D.Safe Attachments policy
AnswerC

An anti-phishing policy, especially when configured with SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) settings, is specifically designed to combat phishing attacks. These authentication mechanisms verify the sender's identity and domain legitimacy, preventing spoofed emails and impersonation attempts from reaching recipients. This comprehensive approach directly addresses the core techniques used in phishing by ensuring email authenticity and enforcing policies on unauthenticated messages.

Why this answer

The anti-phishing policy in Microsoft Defender for Office 365 includes sender verification settings that leverage SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). These protocols authenticate the sender's domain and verify that the email originated from an authorized server, directly addressing the requirement to protect against phishing by verifying sender identity.

Exam trap

The trap here is that candidates often confuse anti-phishing policies with Safe Links or Safe Attachments, assuming that link scanning or attachment sandboxing is the primary defense against phishing, when in fact sender verification via SPF/DKIM/DMARC is the foundational protection against identity spoofing in phishing attacks.

How to eliminate wrong answers

Option A is wrong because anti-malware policy is designed to detect and block malicious attachments or links in email, not to verify the sender's identity via email authentication protocols. Option B is wrong because Safe Links policy provides time-of-click protection by scanning URLs in emails and Office documents, but it does not authenticate the sender's domain or verify the email's origin. Option D is wrong because Safe Attachments policy uses detonation in a sandbox to analyze email attachments for malware, but it does not perform sender authentication checks like SPF, DKIM, or DMARC.

602
MCQhard

A large enterprise uses a variety of cloud applications, including sanctioned apps like Microsoft 365 and unsanctioned apps that employees adopted without IT approval. The security team wants to discover all cloud applications in use, assess each app's risk score based on more than 80 risk factors, and control data sharing within sanctioned apps to prevent data leakage. Additionally, they need to identify which users are using a new, unknown file-sharing service. Which Microsoft security solution should be deployed to meet these requirements?

A.Microsoft Defender for Cloud
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerB

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security or MCAS) functions as a Cloud Access Security Broker (CASB). It provides comprehensive visibility into cloud applications, both sanctioned and unsanctioned (shadow IT), across an organization's network. By leveraging traffic logs from firewalls and proxies, it discovers all cloud apps, assesses their risk based on over 80 factors, and enables granular control over data and user activities within sanctioned applications to enforce security policies and prevent data leakage. This makes it ideal for managing the security posture of cloud app usage.

Why this answer

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) is a Cloud Access Security Broker (CASB) that provides visibility into both sanctioned and unsanctioned cloud apps through its Cloud Discovery feature. It assesses risk scores based on over 80 risk factors (e.g., encryption standards, data residency, and compliance certifications) and enables data sharing controls via session policies (e.g., Conditional Access App Control) to prevent data leakage. It also supports anomaly detection to identify users of new, unknown file-sharing services by analyzing traffic logs from network appliances or endpoints.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM tool for Azure) with Microsoft Defender for Cloud Apps (a CASB), or they assume that Purview DLP alone can discover and risk-assess unsanctioned apps, when in fact DLP only controls data after the app is already identified and integrated.

Why the other options are wrong

A

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection solution, not designed to discover cloud apps, assess risk scores, or control data sharing across sanctioned and unsanctioned apps. It focuses on securing cloud infrastructure (e.g., VMs, databases) rather than SaaS application governance.

C

Microsoft Defender for Endpoint focuses on endpoint protection (antivirus, EDR) and does not provide cloud app discovery, risk assessment, or control over data sharing in cloud applications like Microsoft 365.

D

Microsoft Purview Data Loss Prevention (DLP) focuses on preventing data leakage by enforcing policies on sensitive data, but it does not discover cloud applications, assess risk scores, or identify users of unsanctioned apps. The question requires cloud app discovery and risk assessment, which are capabilities of Defender for Cloud Apps, not DLP.

When would these options actually be correct?

A

A question asking for a solution to assess and improve the security posture of Azure resources (e.g., virtual machines, storage accounts) by identifying misconfigurations, enabling compliance standards, and providing threat detection for cloud workloads. For example: 'Which Microsoft solution should be used to continuously monitor and improve the security of Azure VMs and storage accounts?'

C

An exam question asking for a solution to detect and respond to advanced threats on endpoints (e.g., malware, ransomware) and investigate compromised devices would make Defender for Endpoint the correct answer.

D

Microsoft Purview DLP would be correct in a scenario where an organization needs to prevent accidental sharing of sensitive data (e.g., credit card numbers or PII) across sanctioned apps like Microsoft 365 and endpoints, without requiring cloud app discovery or risk scoring. For example: 'A company wants to block emails containing social security numbers from being sent externally.'

Why candidates pick the wrong answer

A

The name 'Defender for Cloud' suggests it covers all cloud security needs, leading candidates to assume it includes app discovery and risk assessment. The lack of familiarity with the specific capabilities of Microsoft Defender for Cloud Apps (formerly Cloud App Security) causes confusion.

C

Candidates may confuse Defender for Endpoint with Defender for Cloud Apps because both have 'Defender' in the name and relate to security, but they serve different domains (endpoints vs. cloud apps).

D

Candidates may confuse DLP's data protection capabilities with the broader cloud app security requirements, especially since the question mentions controlling data sharing within sanctioned apps, which is a DLP function. However, they overlook that the primary need is discovery and risk assessment, which DLP does not provide.

603
MCQmedium

Refer to the exhibit. The JSON snippet shows an app registration in Microsoft Entra ID. The password credential endDateTime is set to 2025-12-31. What will happen when that date is reached?

A.The secret will renew automatically.
B.The app will be unable to authenticate using that secret.
C.The app registration will be automatically deleted.
D.The app will be blocked from signing in.
AnswerB

When an application's client secret reaches its expiration date, it becomes invalid and can no longer be used to authenticate with Azure Active Directory. Any attempt by the application to acquire an access token using this expired secret will result in an authentication failure. This prevents the application from accessing protected resources or performing actions on behalf of itself.

Why this answer

When the password credential (client secret) reaches its endDateTime, the secret expires and becomes invalid. Microsoft Entra ID does not automatically renew secrets; the application must use a valid secret to authenticate. Once expired, any authentication attempt using that secret will fail, preventing the app from obtaining tokens.

Exam trap

The trap here is that candidates may assume secrets auto-renew or that the app registration is deleted, but Microsoft Entra ID treats secrets as static credentials that must be manually managed before expiration.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID does not automatically renew client secrets; the secret must be manually rotated or renewed by an administrator or via automation. Option C is wrong because an expired secret does not trigger deletion of the app registration; the registration remains intact and can be updated with a new secret. Option D is wrong because the app itself is not blocked from signing in; only the specific expired secret becomes invalid, and the app can still authenticate using a different valid secret or certificate.

604
Multi-Selecteasy

Which THREE are features of Microsoft Entra ID Protection? (Choose THREE.)

Select 3 answers
A.Privileged role management
B.Sign-in risk detection
C.Detection of leaked credentials
D.Risk-based conditional access
E.Identity governance
AnswersB, C, D

Sign-in risk detection evaluates each authentication attempt using signals like anonymous IP use, atypical travel and unfamiliar sign-in properties, then assigns a risk level. This gives Microsoft Entra ID Protection the per-session risk signal that Conditional Access policies consume to challenge or block suspicious sign-ins.

Why this answer

Microsoft Entra ID Protection is specifically designed to detect, investigate, and remediate identity-based risks, so option B (Sign-in risk detection) is correct because it evaluates each sign-in attempt in real time and flags events such as anonymous IP usage, atypical travel, or malware-linked IP addresses as low, medium, or high risk. Option C (Detection of leaked credentials) is correct because ID Protection scans for compromised username/password pairs exposed on the dark web or paste sites and surfaces them as 'leaked credentials' user-risk detections. Option D (Risk-based conditional access) is correct because ID Protection feeds its sign-in risk and user risk signals into Conditional Access policies, allowing administrators to require MFA, password change, or block access when risk is elevated.

Option A (Privileged role management) is not a feature of ID Protection; privileged identity management is delivered by Microsoft Entra Privileged Identity Management (PIM), which handles just-in-time role activation and approvals. Option E (Identity governance) is also not part of ID Protection; identity governance capabilities such as access reviews, entitlement management, and lifecycle workflows belong to Microsoft Entra ID Governance.

Exam trap

The trap here is that candidates often confuse Entra ID Protection (focused on risk detection and remediation) with Entra ID Governance (focused on identity lifecycle and access controls), leading them to select Privileged role management or Identity governance as features of ID Protection.

605
MCQmedium

A company uses Microsoft 365 and requires that users access corporate email and SharePoint from managed devices that meet security policy requirements, such as having encryption enabled and antivirus software running. The security team wants to enforce this access control within Microsoft Entra ID so that unmanaged devices are blocked. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Conditional Access
C.Access Reviews
D.Privileged Identity Management
AnswerB

Conditional Access policies in Azure AD evaluate various signals, including user, location, application, and device state, at the time of a sign-in attempt. These policies can specifically enforce requirements such as a device being marked as compliant by Microsoft Intune or being hybrid Azure AD joined, before granting access to Microsoft 365 cloud applications like Exchange Online or SharePoint Online. This directly addresses the need to control access based on specific device compliance criteria.

Why this answer

Conditional Access is the Microsoft Entra ID feature that enforces access control policies based on conditions such as device compliance, location, and user risk. By configuring a policy that requires devices to be marked as compliant (e.g., with encryption enabled and antivirus running) and blocking access from unmanaged devices, the security team can meet the stated requirement. This is the correct choice because Conditional Access directly integrates with Microsoft Intune device compliance policies to evaluate device health before granting access to corporate email and SharePoint.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based signals like leaked credentials) with Conditional Access (which enforces broader policies including device compliance), leading them to select A instead of B.

Why the other options are wrong

A

Identity Protection is used to detect and respond to identity-based risks (e.g., leaked credentials, sign-in anomalies), not to enforce device compliance or block unmanaged devices from accessing resources.

C

Access Reviews are used to audit and recertify user access rights, not to enforce real-time device compliance policies. The question requires blocking unmanaged devices at sign-in, which is a Conditional Access policy action.

When would these options actually be correct?

A

An organization wants to automatically detect and block sign-ins from compromised accounts or risky sessions, such as when a user's credentials appear on the dark web or when sign-ins originate from anonymous IP addresses.

C

A company needs to periodically verify that users still require access to sensitive SharePoint sites and remove stale accounts. The security team wants to automate this recertification process within Microsoft Entra ID.

Why candidates pick the wrong answer

A

Candidates may confuse 'protecting identities' with 'controlling access based on device health,' assuming Identity Protection handles all security policies for user access.

C

Candidates may confuse 'access control' with 'access reviews' because both involve managing permissions, but they serve different purposes: enforcement vs. attestation.

606
MCQmedium

A legal team is managing a large litigation case involving over two million documents in SharePoint Online and Exchange Online. They want to reduce the time required for manual review by using a machine learning model that learns from a seed set of relevant and non-relevant documents and then predicts the relevance of the remaining documents. Which Microsoft Purview solution provides this advanced analytical capability?

A.Communication Compliance
B.eDiscovery (Standard)
C.eDiscovery (Premium)
D.Audit (Premium)
AnswerC

eDiscovery (Premium) is specifically designed to manage large-scale, complex litigation and regulatory investigations by offering an end-to-end workflow within Microsoft Purview. It extends beyond Standard capabilities with advanced features like custodian management, legal hold orchestration, and collection from non-Microsoft 365 sources. Crucially, it incorporates machine learning-driven analytics, including predictive coding (TAR), near-duplicate detection, and email threading, which significantly streamline the review process, reduce data volumes, and lower legal costs for extensive document sets.

Why this answer

eDiscovery (Premium) in Microsoft Purview provides advanced analytics capabilities, including predictive coding, which uses machine learning models trained on a seed set of relevant and non-relevant documents to automatically predict the relevance of the remaining content. This directly addresses the legal team's need to reduce manual review time for over two million documents in SharePoint Online and Exchange Online.

Exam trap

The trap here is that candidates often confuse eDiscovery (Standard) with eDiscovery (Premium) because both involve searching and holding content, but only Premium includes the advanced analytics and machine learning capabilities described in the scenario.

Why the other options are wrong

A

Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, insider trading), not to perform machine learning-based relevance prediction on documents for eDiscovery review.

D

Audit (Premium) provides advanced auditing capabilities such as long-term retention and high-bandwidth access to audit logs, but it does not include machine learning models for predictive relevance scoring of documents in eDiscovery.

When would these options actually be correct?

A

A question asks: 'Which Microsoft Purview solution helps an organization detect and take action on inappropriate messages (e.g., offensive language or sensitive info sharing) in Microsoft Teams and Exchange Online?'

D

A question asks: 'Which Microsoft Purview solution provides extended audit log retention (e.g., 1 year or 10 years) and higher API bandwidth for retrieving audit records?' In that context, Audit (Premium) would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse the 'machine learning' aspect of Communication Compliance (which uses ML to detect policy violations) with the predictive coding ML in eDiscovery (Premium), assuming any ML-based tool can handle document relevance prediction.

D

Candidates may confuse 'Premium' with advanced analytics, assuming that Audit (Premium) includes machine learning capabilities, when in fact the 'Premium' in eDiscovery (Premium) specifically refers to the advanced analytics features like predictive coding.

607
MCQmedium

Your company uses Microsoft Entra ID. You need to ensure that when a user's account is compromised and used to send spam, the account is automatically blocked from signing in. Which feature should you configure?

A.Microsoft Entra Conditional Access policy to block sign-ins from high-risk users
B.Microsoft Entra Privileged Identity Management
C.Microsoft Entra Identity Protection with a user risk policy to block high-risk users
D.Microsoft Entra Self-Service Password Reset
AnswerC

Microsoft Entra Identity Protection is the dedicated service for detecting, investigating, and remediating identity-based risks. A user risk policy within Identity Protection continuously monitors for suspicious activities, such as leaked credentials or impossible travel, to calculate a user's aggregate risk level. When this risk level crosses a configured threshold, the policy can be set to automatically block the user's sign-in attempt, directly fulfilling the requirement to prevent high-risk users from accessing resources.

Why this answer

Microsoft Entra Identity Protection uses machine learning to detect user risk, such as when an account is compromised and used to send spam. A user risk policy can be configured to automatically block sign-ins for high-risk users, directly addressing the requirement to block the compromised account from signing in.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with Identity Protection user risk policies, but the question specifically asks for the feature that automatically blocks based on compromise (spam), which is the user risk policy in Identity Protection, not a general Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy can block sign-ins based on risk, but it requires a license (e.g., P2) and is typically used in conjunction with Identity Protection; however, the question specifically asks for the feature that automatically blocks based on compromise (spam), which is directly the user risk policy in Identity Protection. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time access and approval workflows for privileged roles, not automatic blocking of compromised accounts. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords, but it does not automatically block sign-ins when an account is compromised.

608
MCQeasy

A company wants to ensure that only users with specific IP addresses can access its critical applications. Which Microsoft Entra feature should they configure?

A.Identity Protection
B.Privileged Identity Management
C.Conditional Access
D.Self-Service Password Reset
AnswerC

Azure AD Conditional Access serves as the policy engine for enforcing access controls based on specific conditions, making it the correct solution for IP-based restrictions. Administrators can define 'named locations' using public IP address ranges or country/region lists, then create policies that grant or block access if users are signing in from these specified locations. This allows precise control over who can access resources from particular network segments, directly addressing the company's requirement for IP-specific access.

Why this answer

Conditional Access is the correct feature because it allows administrators to create policies that enforce access controls based on conditions such as IP address location. By configuring a Conditional Access policy with a 'Locations' condition that includes only trusted IP address ranges, the company can block or grant access to critical applications based on the user's network location. This directly meets the requirement to restrict access to specific IP addresses.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access (which uses IP reputation) with the explicit IP address location control provided by Conditional Access policies, leading them to select Identity Protection instead.

How to eliminate wrong answers

Option A is wrong because Identity Protection is designed to detect and respond to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not provide granular IP address-based access control policies. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not network-level access restrictions based on IP addresses. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords without administrator intervention, and it has no capability to restrict application access by IP address.

609
MCQeasy

Your organization has deployed Microsoft Intune for mobile device management. You need to ensure that users can only access corporate resources from devices that are compliant with your security policies. Which policy type should you configure?

A.A Conditional Access policy
B.An app protection policy
C.A compliance policy
D.A configuration policy
AnswerA

Conditional Access evaluates device compliance state signalled by Intune and grants or blocks access to corporate resources accordingly. This enforces the requirement that only compliant devices connect, which device compliance policies alone cannot do since they merely report state.

Why this answer

A Conditional Access policy is the correct choice because it enforces access controls at the identity level, evaluating device compliance status before granting access to corporate resources. When combined with Intune compliance policies, Conditional Access can block or allow access based on real-time device health checks, ensuring only compliant devices can connect.

Exam trap

The trap here is confusing the role of a compliance policy (which only assesses and reports device status) with a Conditional Access policy (which enforces the access decision based on that status), leading candidates to incorrectly select compliance policy as the enforcement mechanism.

How to eliminate wrong answers

Option B is wrong because an app protection policy manages how data is handled within applications (e.g., preventing copy/paste or requiring a PIN) but does not control device-level access to corporate resources. Option C is wrong because a compliance policy defines the security requirements a device must meet (e.g., encryption, OS version) but does not enforce access decisions; it only marks the device as compliant or non-compliant. Option D is wrong because a configuration policy pushes settings to devices (e.g., Wi-Fi profiles, email settings) but does not evaluate or enforce access restrictions based on compliance.

610
MCQhard

Your organization uses Microsoft Purview Communication Compliance to detect harassing messages. You receive an alert for a message that appears to be a joke between colleagues. What should you do to prevent similar false positives?

A.Train users not to joke about sensitive topics
B.Delete the alert and ignore future similar messages
C.Refine the policy conditions to exclude certain keywords or users
D.Turn off the policy and use a different solution
AnswerC

Refining the policy conditions within Microsoft Purview Communication Compliance is the most effective and technically sound solution to reduce false positives while preserving the policy's intended protective scope. This involves precisely adjusting keywords, phrases, dictionaries, or even excluding specific users or groups known to generate benign matches, thereby ensuring the policy accurately targets genuine compliance risks without generating unnecessary alerts and administrative overhead.

Why this answer

Microsoft Purview Communication Compliance policies are configurable to reduce false positives. You can refine the policy by adding conditions to exclude specific keywords (e.g., 'joke' or 'just kidding') or specific users (e.g., known colleagues) from triggering alerts, without disabling the policy or relying on user behavior changes.

Exam trap

The trap here is that candidates may choose Option A (training users) because it seems proactive, but the question specifically asks how to prevent false positives in the detection system, which requires policy refinement, not user behavior change.

How to eliminate wrong answers

Option A is wrong because training users does not prevent false positives in the detection system; it only addresses human behavior, not the policy's configuration. Option B is wrong because deleting alerts and ignoring future similar messages bypasses compliance monitoring and violates audit requirements; alerts must be investigated or the policy adjusted. Option D is wrong because turning off the policy removes the compliance control entirely, which is unnecessary when the policy can be refined to exclude benign content.

611
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that when a high-severity incident is created, a Microsoft Teams message is sent to the SOC team automatically. What should you configure?

A.Create an automation rule that triggers on incident creation and runs a playbook.
B.Create a playbook and attach it to an analytics rule.
C.Modify the analytics rule to include an automated response.
D.Configure a workbook to send email alerts.
AnswerA

Automation rules in Microsoft Sentinel are specifically designed to orchestrate responses to security incidents. By configuring an automation rule to trigger upon incident creation, it can then execute a pre-defined playbook (an Azure Logic App). This playbook can contain various actions, such as sending a notification to a Microsoft Teams channel, thereby automating the initial communication and response for new incidents.

Why this answer

Automation rules in Microsoft Sentinel allow you to define triggers (e.g., incident creation) and run a playbook as an action. A playbook can contain steps to send a Teams message. So you create an automation rule that triggers on incident creation and runs a playbook.

Option B is incorrect because attaching a playbook to an analytics rule is not the standard method; analytics rules create incidents, but automation rules handle the automated response. Option C is incorrect because analytics rules do not have a direct 'automated response' for sending notifications. Option D is incorrect because workbooks are used for data visualization and dashboards, not for automation.

612
MCQmedium

A company runs a production Kubernetes cluster in Azure. The security team needs to continuously monitor the cluster for misconfigurations, such as containers running with privileged access or secrets exposed in environment variables. They also want to detect runtime threats like crypto-mining containers. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Cloud is the correct solution because it provides comprehensive Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities specifically for Azure Kubernetes Service (AKS). It offers continuous security recommendations for AKS configurations, scans container images for vulnerabilities, and detects runtime threats within the cluster, including suspicious activities at the pod and node level, making it the primary tool for securing Kubernetes.

Why this answer

Microsoft Defender for Cloud provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities. It continuously assesses Kubernetes clusters against the CIS Kubernetes Benchmark, detecting misconfigurations like privileged containers and exposed secrets in environment variables, and uses behavioral analytics to detect runtime threats such as crypto-mining containers.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel's log aggregation capabilities with the proactive, agent-based posture management and runtime detection that Defender for Cloud provides specifically for Kubernetes workloads.

Why the other options are wrong

B

Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat intelligence, not a dedicated tool for continuous monitoring of Kubernetes misconfigurations or runtime threats like crypto-mining. Defender for Cloud provides native Kubernetes workload protection.

C

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., servers, workstations) and does not provide Kubernetes-specific misconfiguration monitoring or runtime threat detection for containers.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on SaaS applications, not on monitoring Kubernetes cluster configurations or runtime threats like crypto-mining containers.

When would these options actually be correct?

B

An organization needs to aggregate security logs from multiple sources (e.g., Azure, on-premises, other clouds) and use advanced analytics to detect and respond to complex threats across the entire environment, including custom detection rules and automated incident response.

C

An exam question asking for a solution to protect endpoints (e.g., desktops, laptops, servers) from malware, fileless attacks, or advanced persistent threats, with requirements for endpoint detection and response (EDR) and antivirus capabilities.

D

A company wants to discover and control the use of shadow IT SaaS applications, enforce data loss prevention policies for cloud apps, and detect anomalous user behavior in Office 365 or other SaaS platforms.

Why candidates pick the wrong answer

B

Candidates may confuse Sentinel's broad security analytics capabilities with the specific Kubernetes workload protection offered by Defender for Cloud, or assume that any Microsoft security tool can handle container monitoring.

C

Candidates may assume 'Defender for Endpoint' covers all security scenarios because of the broad 'Defender' branding, or they confuse container runtime protection with endpoint protection.

D

Candidates may confuse 'cloud apps' with 'cloud workloads' and think Defender for Cloud Apps covers all cloud security, including Kubernetes, due to its broad name.

613
MCQmedium

A company uses a mix of Azure virtual machines and on-premises Windows and Linux servers. The security team wants a single, integrated solution that can continuously assess these servers for missing security updates, weak operating system configurations, and common vulnerabilities. The solution should provide prioritized remediation recommendations. Which Microsoft security solution should they use?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Identity
D.Microsoft 365 Defender
AnswerA

Microsoft Defender for Cloud is the correct solution as it provides comprehensive security posture management and threat protection across hybrid and multi-cloud environments. It natively performs vulnerability assessments for Azure virtual machines and on-premises servers, integrating with Azure Arc to extend its capabilities. This service offers continuous monitoring, security recommendations, and compliance management, directly addressing the need for OS-level vulnerability scanning and configuration recommendations.

Why this answer

Microsoft Defender for Cloud provides a unified infrastructure security management solution that continuously assesses hybrid workloads, including Azure VMs and on-premises Windows/Linux servers. It integrates with Azure Policy and Microsoft Defender Vulnerability Management to detect missing security updates, weak OS configurations, and common vulnerabilities, then delivers prioritized remediation recommendations based on risk scores.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a workload protection and compliance tool) with Microsoft 365 Defender (an endpoint and identity protection suite), leading them to choose the broader-sounding but incorrect option for a specific vulnerability assessment requirement.

Why the other options are wrong

B

Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat intelligence, not a continuous server assessment tool for missing updates, weak configurations, and vulnerabilities.

C

Microsoft Defender for Identity focuses on detecting identity-based threats using Active Directory signals, not on assessing servers for missing updates, weak OS configurations, or vulnerabilities across hybrid environments.

D

Microsoft 365 Defender is designed to protect endpoints, identities, email, and applications within the Microsoft 365 ecosystem, but it does not provide continuous assessment of on-premises servers for missing security updates, weak OS configurations, or common vulnerabilities across hybrid environments.

When would these options actually be correct?

B

A question asking for a cloud-native SIEM that collects security data from across the enterprise (including multi-cloud and on-premises) to detect, investigate, and respond to threats would make Sentinel the correct answer.

C

A question asking for a solution that monitors and protects on-premises Active Directory environments from advanced identity attacks, such as pass-the-hash or lateral movement, using behavioral analytics and alerts.

D

A company wants a unified security solution to detect, investigate, and respond to advanced threats across their Microsoft 365 environment, including email, endpoints, and identities, with automated incident response and threat hunting capabilities.

Why candidates pick the wrong answer

B

Candidates may confuse Sentinel's log collection and alerting capabilities with the continuous assessment and remediation features of Defender for Cloud, especially since both involve security monitoring.

C

Candidates may confuse 'Defender for Identity' with a general security solution for servers, misinterpreting its name as covering all security aspects rather than just identity protection.

D

Candidates may assume that 'Defender' products all offer similar vulnerability assessment capabilities, or they may confuse Microsoft 365 Defender's broader threat protection with the specific continuous assessment features of Defender for Cloud.

614
MCQhard

Refer to the exhibit. You are analyzing a Microsoft Sentinel workspace using KQL. The query returns no results, but you know that malware alerts have been generated today. What is the most likely reason?

A.The table does not contain a 'AlertSeverity' column.
B.The 'order by' clause is invalid.
C.The time range is too short.
D.The column name 'AlertName' is incorrect.
AnswerD

The correct column might be 'AlertName' but some tables use 'Title'.

Why this answer

The KQL query likely returns no rows because the column reference in the query is not an exact match for the actual column in the SecurityAlert table. KQL is case-sensitive: a reference such as `alertName`, `Alertname`, or another small typo is treated as a different column, so the predicate silently matches nothing. This makes the column name as written in the query incorrect.

The SecurityAlert table does include `AlertSeverity`, `order by` is valid KQL, and `ago(1d)` covers alerts generated today, so A, B, and C are not the cause.

Exam trap

Do not assume that a familiar column name such as `AlertName` can be written with different casing or near-miss spelling. KQL column names are case-sensitive, and a small mismatch results in an unmatched column reference and no rows. Verify the exact schema with `getschema` or the table reference before interpreting empty results.

615
MCQmedium

Your company has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to ensure that users can use the same password on-premises and in the cloud without having to sync password hashes. Additionally, you want to prevent accounts from being locked out after a few bad password attempts in the cloud. Which Microsoft Entra feature should you implement?

A.Use password hash synchronization and set up custom lockout policies.
B.Deploy password writeback and enable Microsoft Entra smart lockout.
C.Implement federation with Active Directory Federation Services (AD FS).
D.Implement pass-through authentication and configure on-premises lockout thresholds.
AnswerB

Deploying password writeback, a feature of Microsoft Entra Connect, allows users to reset or change their Microsoft Entra ID password and have that new password synchronized back to their on-premises Active Directory account. This ensures password consistency across the hybrid environment and enables cloud-initiated password management for on-premises accounts. Concurrently, enabling Microsoft Entra smart lockout protects user accounts from brute-force attacks by intelligently locking out malicious actors while allowing legitimate users to continue accessing their accounts, specifically preventing lockouts in Microsoft Entra ID.

Why this answer

Password writeback enables password changes made in the cloud to be written back to on-premises Active Directory, ensuring the same password is used without syncing password hashes. Microsoft Entra smart lockout prevents accounts from being locked out after a few bad password attempts in the cloud by intelligently recognizing and blocking malicious sign-in attempts while allowing legitimate users to continue, without locking the on-premises account.

Exam trap

The trap here is that candidates often confuse pass-through authentication with password writeback, thinking that pass-through authentication alone prevents cloud lockouts, but it does not—smart lockout is required to decouple cloud lockout from on-premises lockout thresholds.

How to eliminate wrong answers

Option A is wrong because password hash synchronization requires syncing password hashes to the cloud, which contradicts the requirement to avoid syncing password hashes, and custom lockout policies in Entra ID do not prevent cloud lockouts from affecting on-premises accounts. Option C is wrong because federation with AD FS still requires password hash synchronization or pass-through authentication for cloud authentication, and it does not inherently prevent cloud lockouts from locking on-premises accounts. Option D is wrong because pass-through authentication validates passwords against on-premises Active Directory but does not prevent cloud lockouts; on-premises lockout thresholds would still cause account lockout after a few bad attempts in the cloud.

616
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Defender XDR? (Choose two.)

Select 2 answers
A.Correlate alerts from multiple domains into a single incident
B.Data loss prevention for sensitive information
C.Centralized log analytics for custom queries
D.Identity governance and access reviews
E.Automated investigation and response across domains
AnswersA, E

Microsoft Defender XDR fuses signals from endpoints, identities, email and cloud apps, correlating related alerts into one incident so analysts see the full attack story. This cross-domain correlation is the core capability distinguishing it from standalone Defender workloads.

Why this answer

Option A is correct because Microsoft Defender XDR's core capability is incident correlation: it stitches together related alerts from the different Defender workloads (Defender for Endpoint, Identity, Office 365, Cloud Apps) into a single unified incident so analysts see the full attack story rather than isolated alerts. Option E is correct because Defender XDR provides automated investigation and response (AIR) that spans those domains, automatically investigating alerts, remediating threats, and allowing actions to be taken across endpoints, identities, and email. Option B is not a Defender XDR capability; data loss prevention for sensitive information is delivered by Microsoft Purview (e.g., DLP policies in Purview/Defender for Cloud Apps context), not as a Defender XDR function.

Option C is not correct because centralized log analytics with custom KQL queries is the role of Microsoft Sentinel (or Log Analytics workspaces), not Defender XDR itself. Option D is not correct because identity governance and access reviews are capabilities of Microsoft Entra ID Governance, not Defender XDR.

Exam trap

The trap here is that candidates confuse the broad security portfolio—such as DLP, SIEM, and identity governance—with the specific cross-domain correlation and automated response capabilities that define Microsoft Defender XDR.

617
Multi-Selectmedium

Which TWO Microsoft Purview features can be used to classify and label sensitive data in Microsoft 365?

Select 2 answers
A.Auto-labeling policies
B.Data Loss Prevention policies
C.Retention policies
D.Sensitivity labels
E.Audit policies
AnswersA, D

Auto-labeling policies in Microsoft Purview are powerful tools that automatically apply sensitivity labels to content based on predefined conditions. These conditions often include the detection of specific sensitive information types, keywords, or regular expressions within documents and emails. By automatically assigning labels, these policies effectively classify data at scale, ensuring consistent application of classification without requiring manual user intervention.

Why this answer

Auto-labeling policies (A) are correct because they allow organizations to automatically apply sensitivity labels to data based on conditions such as sensitive information types or pattern matching, enabling classification and labeling without manual user intervention. Sensitivity labels (D) are correct because they are the core mechanism in Microsoft Purview for classifying and protecting sensitive data by applying persistent labels that can enforce encryption, access restrictions, and visual markings across Microsoft 365 services.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention policies with classification and labeling, but DLP policies only enforce actions based on existing labels or sensitive info types, not create or apply the labels themselves.

618
Multi-Selecteasy

Which TWO features are part of Microsoft Purview Information Protection?

Select 2 answers
A.Communication monitoring
B.Retention policies
C.Automatic classification based on sensitive content
D.Sensitivity labels
E.Audit log investigation
AnswersC, D

Automatic classification based on sensitive content is a cornerstone feature of Microsoft Purview Information Protection. This capability leverages sensitive information types, trainable classifiers, and exact data match to automatically identify and categorize sensitive data across various locations, including documents, emails, and cloud services. By proactively classifying content, Information Protection can then apply appropriate sensitivity labels and protection actions, significantly reducing the manual effort required to secure vast amounts of organizational data.

Why this answer

Microsoft Purview Information Protection (MIP) focuses on classifying, labeling, and protecting sensitive data. Automatic classification based on sensitive content (Option C) is a core capability of MIP, using built-in or custom sensitive information types to detect and label data automatically. Sensitivity labels (Option D) are the primary mechanism in MIP to apply protection actions such as encryption, access restrictions, and visual markings to documents and emails.

Exam trap

The trap here is that candidates confuse the broad scope of Microsoft Purview (which includes many compliance solutions) with the specific boundaries of Information Protection, often mistaking retention or audit features as part of MIP because they all appear under the Purview umbrella.

619
MCQhard

Your company uses Microsoft Defender for Endpoint. A security analyst reports that a device is showing multiple alerts for the same malware variant, but the alerts are being automatically suppressed after the initial detection. What is the most likely reason for this behavior?

A.Alert suppression is enabled to reduce noise from repeated detections
B.The alerts are classified as low severity
C.The device is not properly onboarded to Microsoft Defender for Endpoint
D.Automatic investigation and remediation resolved the alerts
AnswerA

Microsoft Defender for Endpoint incorporates automatic alert suppression mechanisms designed to combat alert fatigue within security operations. When the system detects multiple instances of the exact same threat or activity on a device within a short timeframe, it intelligently suppresses subsequent duplicate alerts. This ensures security analysts can focus on unique, high-fidelity threats rather than being overwhelmed by redundant notifications, streamlining incident response.

Why this answer

Microsoft Defender for Endpoint includes alert suppression as a built-in feature to reduce alert fatigue from repeated detections of the same malware variant on the same device. When the same file or behavior is detected multiple times, the system automatically suppresses subsequent alerts after the initial detection, consolidating them into a single incident. This behavior is controlled by suppression rules that are enabled by default for common malware patterns, ensuring security analysts are not overwhelmed by duplicate alerts.

Exam trap

The trap here is that candidates confuse alert suppression with automatic investigation and remediation, assuming that alerts are suppressed because they were already resolved, when in fact suppression is a separate noise-reduction mechanism that occurs before any remediation actions are taken.

How to eliminate wrong answers

Option B is wrong because low-severity classification does not cause automatic suppression of subsequent alerts; severity affects prioritization and alerting thresholds, but repeated detections of the same variant are suppressed regardless of severity. Option C is wrong because a device that is not properly onboarded would not generate any alerts in Microsoft Defender for Endpoint, let alone multiple alerts that are then suppressed. Option D is wrong because automatic investigation and remediation resolves alerts after detection, but the question describes alerts being suppressed after the initial detection, not resolved; suppression occurs before investigation and remediation actions are taken.

620
MCQeasy

Your organization needs to monitor and respond to security threats across on-premises, cloud, and hybrid environments. Which Microsoft solution provides a unified SIEM and SOAR capability?

A.Microsoft Defender XDR
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Microsoft Intune
AnswerC

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It provides comprehensive capabilities for collecting security data from diverse sources, including Microsoft services, other cloud providers, and on-premises infrastructure. Sentinel leverages AI and machine learning for threat detection, investigation, and automated response, making it the ideal platform for monitoring and responding to security threats across an entire enterprise environment.

Why this answer

Microsoft Sentinel is the correct answer because it is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration Automation and Response (SOAR) solution. It provides unified threat monitoring, detection, and response across on-premises, cloud, and hybrid environments by ingesting data from various sources, using built-in analytics, and enabling automated playbooks.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (an XDR tool) with a full SIEM/SOAR solution, but Sentinel is the only Microsoft offering that provides both SIEM and SOAR capabilities natively.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is an extended detection and response (XDR) solution that correlates alerts across endpoints, email, identities, and cloud apps, but it does not provide the full SIEM data ingestion and SOAR orchestration capabilities of Sentinel. Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that focuses on securing cloud resources, not a unified SIEM/SOAR solution. Option D is wrong because Microsoft Intune is a cloud-based endpoint management and mobile device management (MDM) service, with no SIEM or SOAR functionality.

621
MCQmedium

A user reports that they cannot access a sensitive document in SharePoint Online. The document has a 'Highly Confidential' sensitivity label. You verify the label is applied correctly. What is the most likely reason for the access issue?

A.The label's encryption settings restrict access to specific users
B.The sensitivity label is missing
C.A DLP policy is blocking access
D.A retention policy is blocking access
AnswerA

Sensitivity labels, when configured with encryption, apply rights management protection to documents. This protection can explicitly define which users or groups have specific access rights, such as view-only, edit, or full control. If a user reports being unable to access a sensitive document, it is highly probable that the label's encryption settings have been configured to restrict access to a specific set of authorized individuals, and the reporting user is not included in that authorized list. This is a fundamental capability of Microsoft Purview Information Protection.

Why this answer

The 'Highly Confidential' sensitivity label is configured with encryption that restricts access to specific users or groups. Since you verified the label is applied correctly, the most likely reason the user cannot access the document is that their account is not included in the encryption permissions defined by the label. Sensitivity labels in Microsoft Purview Information Protection use Azure Rights Management (Azure RMS) to enforce encryption, and only authorized users with the appropriate rights can decrypt and access the content.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity label encryption, assuming DLP blocks access to labeled documents, when in fact DLP only monitors and controls sharing actions, not read access to already-stored content.

How to eliminate wrong answers

Option B is wrong because the question explicitly states you verified the label is applied correctly, so the label is not missing. Option C is wrong because DLP policies detect and prevent sharing of sensitive data but do not block access to already-stored documents; they act on actions like sending or sharing, not on read access. Option D is wrong because retention policies are designed to preserve or delete content based on timeframes, not to block access; they do not enforce access control or encryption.

622
Multi-Selectmedium

Which TWO actions can be performed using Microsoft Purview Data Lifecycle Management?

Select 2 answers
A.Create a retention policy to keep financial records for 7 years
B.Monitor internal emails for policy violations
C.Create a deletion policy to remove old drafts after 30 days
D.Block sharing of sensitive files with external users
E.Automatically classify documents containing PII
AnswersA, C

Microsoft Purview Data Lifecycle Management (DLM) is specifically designed to help organizations manage their data throughout its entire lifecycle, including long-term preservation. Creating a retention policy to keep financial records for a specified duration, such as seven years, is a fundamental capability within DLM. These policies ensure compliance with legal, regulatory, and business requirements by preventing premature deletion and ensuring data availability.

Why this answer

Microsoft Purview Data Lifecycle Management allows administrators to create retention policies that specify how long data must be kept to meet regulatory or business requirements, such as retaining financial records for 7 years. Option C is correct because the same solution enables deletion policies that automatically remove outdated content, like drafts older than 30 days, ensuring data is not kept longer than necessary.

Exam trap

The trap here is that candidates confuse the capabilities of Microsoft Purview Data Lifecycle Management with those of Information Protection or Communication Compliance, leading them to select options related to monitoring, blocking, or classifying data, which belong to other compliance solutions.

623
MCQeasy

A company uses a cloud-based Customer Relationship Management (CRM) system that is delivered as Software-as-a-Service (SaaS). According to the shared responsibility model, which security responsibility is primarily handled by the customer?

A.Physical security of the data center hosting the CRM
B.Managing user identities and controlling access to the CRM
C.Patching the underlying operating system of the CRM servers
D.Ensuring network security for the CRM application's backend
AnswerB

The customer retains primary responsibility for managing user identities and controlling access within the SaaS CRM application. This involves provisioning user accounts, assigning appropriate roles and permissions, and configuring authentication methods, often integrating with their own corporate identity provider like Azure Active Directory. This ensures that only authorized personnel can access specific CRM functionalities and data, aligning with the principle of least privilege.

Why this answer

In a SaaS model, the cloud provider is responsible for the security of the underlying infrastructure, including physical data centers, operating systems, and network controls. The customer retains responsibility for securing their own data and identities, which includes managing user accounts, enforcing authentication policies (e.g., Azure AD Multi-Factor Authentication), and controlling access to the CRM application via role-based access control (RBAC). Therefore, managing user identities and access is the customer's primary security responsibility.

Exam trap

The trap here is that candidates often assume the customer is responsible for all security aspects of a SaaS application, but SC-900 emphasizes that the provider handles infrastructure and platform security, leaving the customer with identity, data, and access management.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is the sole responsibility of the cloud provider (Microsoft, in the case of Dynamics 365), not the customer. Option C is wrong because patching the underlying operating system of the CRM servers is part of the provider's responsibility for maintaining the SaaS platform's infrastructure. Option D is wrong because ensuring network security for the CRM application's backend, such as firewall rules and DDoS protection at the provider's network layer, is handled by the cloud provider, not the customer.

624
MCQhard

Your company uses Microsoft Defender for Cloud Apps to discover shadow IT. The security team wants to automatically block the use of a newly discovered high-risk cloud app across all users. What is the most efficient approach?

A.Create a Conditional Access policy to block the app for all users.
B.Manually add the app to the blocked list in the cloud discovery settings.
C.Create an app discovery policy with governance action to unsanction the app.
D.Configure session controls to monitor app usage.
AnswerC

Creating an app discovery policy with a governance action to unsanction the app is the correct and most automated method. This policy allows Microsoft Defender for Cloud Apps to continuously scan discovered applications based on defined criteria (e.g., risk score, category, usage patterns). When an app matches the policy, the configured governance action, such as 'Unsanction app,' automatically marks it as unauthorized and triggers enforcement mechanisms, effectively blocking its use across the organization.

Why this answer

Microsoft Defender for Cloud Apps (MDCA) Cloud Discovery uses app discovery policies to automate governance actions on discovered apps. Creating an app discovery policy that targets the high-risk app and applies the 'Unsanction' governance action automatically blocks it across all users, which is the most efficient and purpose-built approach. This leverages MDCA's native discovery and governance workflow rather than manual or indirect methods.

Exam trap

SC-900 often tests the confusion between Conditional Access (access control for known apps) and Cloud Discovery app policies (governance for discovered shadow IT) — candidates pick Conditional Access because it sounds like the blocking mechanism.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies control access to cloud apps based on user/session conditions but are not the mechanism for sanctioning or unsanctioning apps discovered by Cloud Discovery. Option B is wrong because manually adding the app to a blocked list is not automated and does not scale — the question asks for the most efficient approach. Option D is wrong because session controls monitor and restrict in-session activity for already-sanctioned apps, not block newly discovered shadow IT apps.

625
MCQmedium

A healthcare organization must demonstrate compliance with HIPAA by assessing their current posture against regulatory controls, tracking improvement actions, and generating reports for auditors. Which Microsoft Purview solution should they use?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Lifecycle Management
C.Microsoft Purview Compliance Manager
D.Microsoft Purview Insider Risk Management
AnswerC

Microsoft Purview Compliance Manager is the dedicated solution for simplifying compliance and reducing risk by providing pre-built assessments for common industry regulations, such as HIPAA. It allows organizations to track progress on improvement actions, assign responsibilities, and generate detailed compliance reports, offering a measurable compliance score. This service directly addresses the need to demonstrate and manage an organization's adherence to regulatory requirements through a structured workflow.

Why this answer

Microsoft Purview Compliance Manager is the correct solution because it provides a built-in assessment template for HIPAA, enabling the organization to assess its current compliance posture against regulatory controls, track improvement actions, and generate auditor-ready reports. It offers a compliance score, automated control mapping, and evidence collection workflows specifically designed for regulatory frameworks like HIPAA.

Exam trap

The trap here is that candidates confuse Compliance Manager (which assesses and tracks compliance posture) with Information Protection (which protects data) or Insider Risk Management (which detects risky behavior), because all three are Purview solutions but serve fundamentally different compliance lifecycle stages.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not on assessing compliance posture or tracking improvement actions against regulatory controls. Option B is wrong because Microsoft Purview Data Lifecycle Management handles data retention, deletion, and archiving policies (e.g., retention labels, records management), not compliance assessment or audit reporting for HIPAA. Option D is wrong because Microsoft Purview Insider Risk Management detects and investigates risky user activities (e.g., data exfiltration, policy violations), not compliance posture assessment or improvement tracking against regulatory frameworks.

626
MCQhard

A company has a Microsoft Entra ID tenant with thousands of users. They need to ensure that only users with a 'Manager' attribute populated can access a sensitive app. Which approach should they use?

A.Use HR-driven provisioning to populate an on-premises attribute and sync it
B.Create a dynamic group rule that includes users with a non-empty Manager attribute, then target the group in a Conditional Access policy
C.Create an access package in Entitlement Management that requires manager approval
D.Create an Administrative Unit for users with managers and assign the app to that unit
AnswerB

This is the most efficient and cloud-native solution. A dynamic group in Microsoft Entra ID can be configured with a rule (e.g., user.manager -ne null) to automatically include all users who have a manager assigned, ensuring membership is always up-to-date. This dynamic group can then be directly targeted by a Conditional Access policy, allowing granular control over application access or other security requirements for this specific user population.

Why this answer

A dynamic group rule can evaluate the 'Manager' attribute and include only users where it is populated. This group can then be assigned to a Conditional Access policy that requires the group membership for access to the sensitive app, ensuring only users with a manager can authenticate.

Exam trap

The trap here is confusing attribute-based dynamic group membership with approval workflows or administrative delegation, leading candidates to choose Entitlement Management or Administrative Units instead of the correct Conditional Access and dynamic group combination.

How to eliminate wrong answers

Option A is wrong because HR-driven provisioning populates attributes from an HR system, but it does not enforce access control based on the Manager attribute; it merely syncs data. Option C is wrong because an access package in Entitlement Management with manager approval manages access requests and approvals, but it does not automatically restrict access based on whether the Manager attribute is populated; it requires manual approval. Option D is wrong because Administrative Units are for delegating administrative scope over users and groups, not for controlling application access via attribute-based membership.

627
MCQhard

Your organization is implementing Microsoft Purview Communication Compliance to detect potential regulatory violations. You need to configure a policy that alerts when employees discuss insider trading in emails and Microsoft Teams messages. The solution should minimize false positives. Which action should you take?

A.Include all message types without filtering
B.Use a trainable classifier and train it with sample data
C.Create a global keyword list of insider trading terms
D.Set the policy sensitivity threshold to 90%
AnswerB

Trainable classifiers use machine learning, seeded with sample data, to identify content by its actual characteristics rather than keyword matches. Training on genuine insider-trading examples sharpens precision, directly satisfying the requirement to minimise false positives across Exchange and Microsoft Teams messages.

Why this answer

Trainable classifiers use machine learning to identify content based on patterns learned from sample data, which significantly reduces false positives compared to static keyword lists. By training the classifier with relevant examples of insider trading discussions, the policy can accurately distinguish between genuine regulatory violations and benign uses of similar terms.

Exam trap

The trap here is that candidates often assume a keyword list or sensitivity threshold is sufficient for compliance, overlooking that trainable classifiers are specifically designed to minimize false positives by learning from sample data rather than relying on static rules.

How to eliminate wrong answers

Option A is wrong because including all message types without filtering would generate excessive alerts, including irrelevant communications, leading to high false positives and analyst fatigue. Option C is wrong because a global keyword list of insider trading terms would trigger alerts on any mention of those terms, even in harmless contexts (e.g., 'I read about insider trading in the news'), causing many false positives. Option D is wrong because setting the policy sensitivity threshold to 90% would only reduce alerts based on a generic confidence score, not address the root cause of false positives from ambiguous language; trainable classifiers provide more nuanced detection.

628
MCQhard

Refer to the exhibit. An administrator runs the PowerShell cmdlet shown. What is the purpose of this command?

A.To show the dynamic membership rules of the Sales group.
B.To list all groups in the Sales department.
C.To list Azure AD roles assigned to the Sales group.
D.To display the display name and user principal name of members of the Sales group.
AnswerD

The command Get-AzureADGroupMember successfully retrieves all direct members of the Azure AD group specified by its object ID. Piping this output to Select-Object DisplayName, UserPrincipalName then precisely extracts and displays only the user's friendly name and their unique sign-in identifier. This combination accurately fulfills the objective of reporting specific identity attributes for each member of the Sales group.

Why this answer

The PowerShell cmdlet `Get-AzureADGroupMember -ObjectId <SalesGroupObjectId>` retrieves the members of a specific Azure AD group. By default, it returns the members' display names and user principal names (UPNs), which are the primary identifiers for users in Microsoft Entra ID. Option D correctly identifies this purpose.

Exam trap

The trap here is that candidates confuse retrieving group members (Option D) with viewing dynamic membership rules (Option A), because both involve Azure AD groups, but the cmdlet names and parameters differ significantly.

How to eliminate wrong answers

Option A is wrong because the cmdlet `Get-AzureADGroupMember` retrieves members, not membership rules; dynamic membership rules are viewed using `Get-AzureADMSGroup` with the `-GroupType DynamicMembership` parameter. Option B is wrong because the cmdlet targets a single group by its ObjectId, not all groups in a department; listing groups by department would require `Get-AzureADGroup` with a filter on the `Department` attribute. Option C is wrong because Azure AD role assignments are retrieved using `Get-AzureADDirectoryRoleMember` or `Get-AzureADMSRoleAssignment`, not `Get-AzureADGroupMember`.

629
MCQeasy

A compliance officer at Contoso needs to review all user and admin activities across Exchange Online, SharePoint Online, and Microsoft Entra ID for the past 90 days to investigate a potential data leak. Which Microsoft Purview solution should they use?

A.Microsoft Purview eDiscovery
B.Microsoft Purview Information Barriers
C.Microsoft Purview Audit
D.Microsoft Purview Data Loss Prevention
AnswerC

Microsoft Purview Audit logs and retains user and administrator activities across Microsoft 365 services, including Exchange Online, SharePoint Online, and Microsoft Entra ID. It provides a unified audit log that compliance officers can search to investigate incidents such as data leaks. Standard audit retention is 90 days, which matches the investigation window, making it the correct tool for reviewing activity history.

Why this answer

Microsoft Purview Audit is the correct solution because it aggregates and retains user and administrator activity logs from Microsoft 365 services, including Exchange Online, SharePoint Online, and Entra ID. Compliance officers can search these logs to trace actions such as file accesses, permission changes, and sign-ins. The other solutions address different needs: DLP prevents sharing, Information Barriers restrict communication, and eDiscovery collects content for legal matters.

Exam trap

The trap here is assuming that eDiscovery or DLP provides the same breadth of activity logging as Microsoft Purview Audit, when only Audit offers a unified, searchable log of user and admin actions across services.

630
MCQhard

Refer to the exhibit. You are reviewing a Privileged Identity Management (PIM) configuration for a role in Microsoft Entra ID. The roleDefinitionId corresponds to a specific role. What is the effect of this configuration?

A.The user is permanently activated for the role for 1 hour.
B.The user is permanently assigned the role for 1 hour.
C.The user can activate the role without approval for up to 1 hour.
D.The user is eligible for the role indefinitely, but activation requires approval and lasts up to 1 hour.
AnswerD

Eligible assignment with no end date, approval required, activation max 1 hour.

Why this answer

The configuration shown in the exhibit sets the role assignment to 'Eligible' with an activation duration of 1 hour and requires approval (the approval toggle is on). An 'Eligible' assignment means the user is not permanently active; they must activate the role when needed. The requirement for approval ensures that an authorized approver must approve each activation request.

The 1-hour duration limits how long each activation lasts. This matches the description of being eligible indefinitely, with activation requiring approval and lasting up to 1 hour.

Exam trap

The trap here is that candidates confuse 'Eligible' with 'Active' assignments, assuming that an eligible assignment with no approval required means the user is automatically active, when in fact they must still manually activate the role.

How to eliminate wrong answers

Option A is wrong because 'permanently activated' implies the user is always active in the role, but the configuration shows an 'Eligible' assignment, not an 'Active' assignment. Option B is wrong because 'permanently assigned the role for 1 hour' is contradictory; a permanent assignment has no time limit, and the 1-hour duration applies only to activation, not to the assignment itself. Option C is wrong because while the user can activate without approval (as the approval toggle is off), the configuration shows an 'Eligible' assignment, not an 'Active' one; the user is not automatically activated and must perform an activation step.

631
MCQmedium

A company uses Microsoft Entra ID. The IT team needs to ensure that when employees leave the organization, their access to all Microsoft 365 applications is revoked immediately and their account is disabled. Which Microsoft Entra capability should the team use?

A.Microsoft Entra ID Governance lifecycle workflows
B.Microsoft Entra Conditional Access policies
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra self-service password reset (SSPR)
AnswerA

Lifecycle workflows in Microsoft Entra ID Governance automate joiner, mover, and leaver processes. For a leaver, you can configure a workflow that disables the account and revokes access to all applications immediately upon triggering. This directly addresses the requirement by automating offboarding tasks, ensuring no residual access remains. It is the correct capability for this scenario.

Why this answer

Lifecycle workflows in Microsoft Entra ID Governance are designed to automate identity lifecycle tasks, including offboarding. When an employee leaves, a leaver workflow can immediately disable the account and remove access to all integrated applications, ensuring compliance and security. Other options do not provide this end-to-end automation for termination scenarios.

Exam trap

The trap here is assuming that Conditional Access or PIM can fully handle offboarding, but they lack the automation to disable accounts and revoke all access immediately upon termination.

632
MCQhard

Refer to the exhibit. You are deploying a custom assessment automation in Microsoft Defender for Cloud using Bicep. The deployment fails with an error that the resource type is not valid. What is the most likely reason?

A.The API version is not supported.
B.The property 'supportedCloud' should be 'supportedClouds' as an array.
C.The name property is missing.
D.The resource type is misspelled.
AnswerB

Azure Policy definitions, particularly for custom assessments, require the `supportedClouds` property (plural) to correctly specify the cloud environments where the policy should be active. The exhibit incorrectly uses `supportedCloud` (singular), which is not a recognized property in the Azure Policy schema. Furthermore, this property is expected to be an array of strings, even if only one cloud is specified, ensuring proper schema validation and deployment. This specific misnaming and incorrect data type are critical errors preventing successful deployment.

Why this answer

In Bicep for Microsoft Defender for Cloud custom assessments, the property that defines which cloud environments the assessment applies to must be named 'supportedClouds' and must be an array of strings (e.g., ['Azure', 'AWS', 'GCP']). Using the singular 'supportedCloud' is invalid syntax and causes the deployment to fail with a resource type validation error.

Exam trap

The trap here is that candidates may assume the error is due to a simple typo in the resource type name (Option D) or an API version mismatch (Option A), when in fact the issue is a property name/syntax error that is specific to the Bicep/ARM schema for Defender for Cloud custom assessments.

How to eliminate wrong answers

Option A is wrong because an unsupported API version would produce a different error message (e.g., 'The API version is not supported' or 'No registered resource provider found'), not a 'resource type is not valid' error. Option C is wrong because the 'name' property is required for all Azure resources, and its absence would trigger a missing required property error, not a resource type validation error. Option D is wrong because a misspelled resource type would result in a 'resource type not found' or 'invalid resource type' error, but the exhibit shows the error is about the resource type not being valid, which points to a structural/property issue, not a typo in the type name.

633
MCQhard

Your organization uses Microsoft Purview Audit (Standard) and needs to investigate a data breach that occurred 120 days ago. You discover that the required audit logs are not available. What is the most likely reason?

A.The user does not have an appropriate license
B.Audit log retention is limited to 90 days for Audit (Standard)
C.The organization has insufficient storage
D.The audit logs were manually deleted by an administrator
AnswerB

Microsoft Purview Audit (Standard) is specifically designed with a fixed retention period of 90 days for all audit logs. This means that any audit records generated will be automatically retained for exactly 90 days from their creation date. After this 90-day window expires, these logs are automatically and permanently purged from the system, making them irretrievable. This inherent limitation is a primary reason why older audit logs might appear to be missing.

Why this answer

Microsoft Purview Audit (Standard) retains audit logs for only 90 days by default. Since the data breach occurred 120 days ago, the logs would have been automatically purged after the retention period expired, making them unavailable for investigation.

Exam trap

The trap here is that candidates may assume licensing or storage issues cause log unavailability, but the SC-900 specifically tests the 90-day retention limit for Audit (Standard) as a key differentiator from Audit (Premium).

How to eliminate wrong answers

Option A is wrong because licensing affects the ability to generate or access audit logs, but the user already has access to Audit (Standard); the issue is retention duration, not licensing. Option C is wrong because insufficient storage does not cause log unavailability in Purview Audit; logs are stored in a managed, scalable backend and are not constrained by organizational storage limits. Option D is wrong because while manual deletion is possible, the most likely reason given the 120-day timeframe is the default 90-day retention policy, not deliberate administrative action.

634
MCQeasy

Your company uses Microsoft Purview to govern data across on-premises and cloud sources. You need to classify sensitive data such as credit card numbers and social security numbers automatically. What should you create?

A.Data loss prevention policies
B.Sensitivity labels
C.Sensitive information types
D.Retention labels
AnswerC

Sensitive information types (SITs) are the fundamental building blocks in Microsoft Purview for automatically identifying sensitive data. They define specific patterns, keywords, regular expressions, and proximity rules that the system uses to detect particular types of sensitive information, such as credit card numbers, national identification numbers, or medical record numbers. This automatic pattern matching is precisely how Purview discovers and classifies data at scale, making SITs the direct answer to automatic classification.

Why this answer

Sensitive information types (SITs) in Microsoft Purview are pattern-based classifiers that detect specific data formats such as credit card numbers, SSNs, and passport numbers using regex, checksums, and keyword proximity. They are the foundational building block used by DLP policies, sensitivity labels, and auto-labeling to identify sensitive content. Creating a SIT is the correct step to enable automatic classification of regulated data.

Exam trap

SC-900 often tests the confusion between detection (SITs) and enforcement (DLP policies/labels), causing candidates to pick DLP when the question asks what to create for classification.

How to eliminate wrong answers

Option A is wrong because DLP policies enforce actions on sensitive data but rely on SITs to detect it; they do not themselves define the classification patterns. Option B is wrong because sensitivity labels apply protection and classification metadata to content but depend on SITs (or trainable classifiers) to identify what to label. Option D is wrong because retention labels govern lifecycle and retention, not classification of sensitive data types.

635
MCQmedium

Your company uses Microsoft 365 E5 licenses and wants to prevent sensitive data from being shared externally via email. You need to configure a solution that automatically scans outgoing emails for credit card numbers and blocks them if detected. What should you use?

A.Microsoft Defender for Office 365 Safe Attachments policy
B.Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online
C.Microsoft Intune App Protection policy
D.Microsoft Entra ID Conditional Access policy
AnswerB

A Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online is specifically engineered to identify, monitor, and protect sensitive information sent via email. These policies utilize sensitive information types, keywords, and content matching to detect specific data patterns, such as credit card numbers or national ID numbers, within email messages and attachments. Upon detection, the policy can enforce actions like blocking the email, encrypting it, or notifying administrators, directly preventing unauthorized data egress.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online is the correct solution because it is specifically designed to inspect email content and attachments for sensitive data types, such as credit card numbers, using built-in sensitive info types. When a match is detected, the policy can automatically block the email from being sent externally, enforcing the organization's data protection requirements without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (which handles malware and phishing) with Microsoft Purview DLP (which handles data protection), leading them to select the security-focused option instead of the compliance-focused one.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 Safe Attachments policy focuses on scanning email attachments for malware and malicious content, not on detecting sensitive data like credit card numbers. Option C is wrong because Microsoft Intune App Protection policy manages data protection at the app level on mobile devices, not email transport-level scanning for sensitive content. Option D is wrong because Microsoft Entra ID Conditional Access policy controls access to applications based on user, device, and location conditions, but does not inspect email content or block outgoing messages based on data patterns.

636
MCQeasy

A company configures its access control system so that each user can only access the data and perform actions that are strictly necessary for their job role. This configuration is a direct implementation of which security principle?

A.Defense in depth
B.Least privilege
C.Separation of duties
D.Zero Trust
AnswerB

The principle of least privilege dictates that every user, program, and process should be granted only the minimum necessary permissions to perform its legitimate function. This approach significantly reduces the attack surface by limiting the potential damage an attacker can inflict if an account or system is compromised. By restricting access to only what is essential, it minimizes the risk of unauthorized actions and data breaches, aligning directly with the scenario described.

Why this answer

The configuration described—granting each user only the access and actions strictly necessary for their job role—is the direct definition of the least privilege principle. In Microsoft identity and access management, this is implemented by assigning the minimum required permissions via Azure RBAC roles (e.g., Reader instead of Contributor) or using Azure AD Privileged Identity Management (PIM) for just-in-time access. This minimizes the attack surface by ensuring users cannot exceed their authorized scope.

Exam trap

The trap here is that candidates confuse least privilege with separation of duties, but separation of duties focuses on splitting permissions across multiple people to prevent collusion, whereas least privilege restricts each individual to the minimum necessary access.

Why the other options are wrong

A

The question describes granting only necessary access per job role, which is the definition of least privilege. Defense in depth involves multiple layers of security controls, not user-specific access restrictions.

C

Separation of duties prevents fraud by requiring multiple people to complete sensitive tasks, but it does not limit individual access to only what is necessary for their job role. The question describes limiting access per user, which is least privilege.

D

Zero Trust is a security model that assumes no implicit trust and continuously verifies every access request, but it is not specifically about granting only the minimum necessary permissions per job role; that is the principle of least privilege.

When would these options actually be correct?

A

A question asking which security principle involves implementing multiple layers of security controls (e.g., firewalls, antivirus, intrusion detection) to protect against failures in any single layer would make defense in depth the correct answer.

C

A company requires that no single employee can approve a payment and also process the payment; these tasks must be performed by two different people. This scenario directly implements separation of duties.

D

A question asking: 'Which security model requires that no user or device is trusted by default, even if they are inside the corporate network?' would make Zero Trust the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse defense in depth with least privilege because both are fundamental security concepts, and they might think restricting access is part of a layered defense strategy.

C

Candidates may confuse separation of duties with least privilege because both involve dividing access, but separation of duties focuses on splitting responsibilities among multiple users, not minimizing individual permissions.

D

Candidates may confuse Zero Trust with least privilege because both involve restricting access, but Zero Trust is broader and includes continuous verification, not just minimal permissions.

637
MCQeasy

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They want to improve their secure score. What should they do?

A.Implement the security recommendations
B.Remove all virtual machines from the subscription
C.Increase the Azure budget
D.Disable Microsoft Defender for Cloud
AnswerA

Implementing the security recommendations provided by Microsoft Defender for Cloud directly addresses identified vulnerabilities and misconfigurations within your Azure environment. Each recommendation, when remediated, contributes points towards your secure score, reflecting an improved security posture by aligning resources with best practices and security controls. This is the primary mechanism for actively enhancing the secure score and reducing your attack surface.

Why this answer

Microsoft Defender for Cloud's secure score quantifies an Azure subscription's security posture based on implemented recommendations. To improve the score, the organization must remediate the identified security recommendations — such as enabling MFA, applying patches, or restricting network access. Each implemented recommendation increases the score, reflecting a stronger security posture.

Exam trap

SC-900 often tests the misconception that secure score improves through resource removal or budget changes, when it is strictly driven by implementing the security recommendations surfaced by Defender for Cloud.

How to eliminate wrong answers

Option B is wrong because removing all VMs reduces the attack surface but also eliminates workloads; it does not improve the secure score meaningfully and is operationally destructive — the score measures posture of existing resources, not resource count. Option C is wrong because increasing the Azure budget has no relationship to security posture or secure score; budget is a cost management concern. Option D is wrong because disabling Defender for Cloud removes the assessment engine entirely, eliminating the secure score rather than improving it.

638
MCQeasy

A financial services firm is required by regulatory bodies to monitor employee communications (email, Teams chats) for potential insider trading or market manipulation. They need a solution that allows them to define policies to detect messages containing specific keywords or phrases (e.g., 'confidential', 'insider info'), and then assign flagged messages to designated reviewers for investigation. Which Microsoft Purview solution should they use?

A.Microsoft Purview Communication Compliance
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview eDiscovery (Standard or Premium)
D.Microsoft Purview Audit (Standard or Premium)
AnswerA

Microsoft Purview Communication Compliance is specifically designed to help organizations detect and remediate regulatory compliance violations, such as insider trading, harassment, or sensitive data sharing, within their internal and external communications. It uses intelligent templates and customizable policies to proactively scan messages across Microsoft 365 services for specific keywords, sensitive information types, or patterns indicative of policy breaches. Compliance officers can then review, investigate, and take action on identified risky communications through a dedicated workflow.

Why this answer

Microsoft Purview Communication Compliance is the correct solution because it is specifically designed to detect policy violations in employee communications, such as email and Teams chats, by scanning for sensitive keywords or phrases like 'confidential' or 'insider info'. It then automatically flags and routes these messages to designated reviewers for investigation, directly meeting the regulatory requirement for monitoring potential insider trading or market manipulation.

Exam trap

The trap here is confusing Insider Risk Management (which focuses on behavioral analytics and user risk scores) with Communication Compliance (which directly scans communication content for specific text patterns), leading candidates to choose the wrong solution for keyword-based message monitoring.

Why the other options are wrong

B

Insider Risk Management focuses on detecting and investigating risky user activities (e.g., data exfiltration, policy violations) based on behavioral analytics, not on monitoring communications for specific keywords or phrases. The question explicitly requires keyword-based policy detection in messages, which is a core feature of Communication Compliance.

C

eDiscovery is designed for legal discovery and investigation of existing data, not for real-time policy-based detection and automated assignment of flagged messages to reviewers. The question requires proactive monitoring and policy enforcement, which is the domain of Communication Compliance.

D

Microsoft Purview Audit (Standard or Premium) provides logging and investigation of user and admin activity, but it does not include policy-based detection of keywords/phrases in communications or assignment to reviewers for investigation. The question specifically requires monitoring communications for keywords and assigning flagged messages to reviewers, which is not an Audit capability.

When would these options actually be correct?

B

A scenario where an organization needs to identify and investigate users who are exfiltrating sensitive data (e.g., copying files to USB drives, emailing to personal accounts) or violating security policies based on user behavior patterns, rather than monitoring communications for specific keywords.

C

A law firm needs to search and export all emails and chats related to a specific client matter for a court case. They require advanced search capabilities, hold management, and review sets. In this scenario, Microsoft Purview eDiscovery (Standard or Premium) would be the correct solution.

D

An organization needs to investigate a specific security incident and must search through historical audit logs to identify which users accessed sensitive files or performed specific actions. They require detailed logging of user and admin activities for forensic analysis and compliance reporting. In this scenario, Microsoft Purview Audit (Standard or Premium) would be the correct solution.

Why candidates pick the wrong answer

B

Candidates may confuse 'insider risk' with 'communication compliance' because both deal with insider threats, but they overlook that the question specifically mentions keyword-based policy detection in communications, which is unique to Communication Compliance.

C

Candidates may confuse the investigative and review capabilities of eDiscovery with the policy-based detection and review workflow of Communication Compliance, as both involve reviewing communications.

D

Candidates may confuse Audit with Communication Compliance because both involve monitoring and compliance. They might think that auditing communications is part of Audit, but Audit focuses on activity logs (e.g., who accessed what), not on scanning message content for keywords and routing to reviewers.

639
Multi-Selectmedium

Which TWO actions can be performed using Microsoft Purview Communication Compliance? (Choose two.)

Select 2 answers
A.Automatically encrypt emails containing sensitive data
B.Review messages for potential regulatory compliance violations
C.Detect and review emails containing confidential information
D.Prevent the sharing of sensitive data with external users
E.Enforce retention policies for communications
AnswersB, C

Microsoft Purview Communication Compliance is specifically designed to help organizations review messages for potential regulatory compliance violations. It enables the creation of policies that scan for specific content, context, or user groups within communications across various platforms, identifying instances that may violate internal policies or external regulations such as FINRA, HIPAA, or GDPR. The primary goal is to detect and facilitate the review of such communications by designated compliance investigators.

Why this answer

Communication Compliance is a Microsoft Purview insider risk solution designed to detect, capture, and review potentially inappropriate or risky communications. Option B is correct because it lets reviewers examine messages (Exchange email, Teams, Viva Engage, third-party sources) for potential regulatory compliance violations, such as policy breaches flagged by built-in or custom classifiers. Option C is correct because Communication Compliance can detect and review emails containing confidential information using sensitive information types and trainable classifiers, then surface them for review.

Option A is not correct because automatic encryption of sensitive emails is handled by Microsoft Purview Data Loss Prevention or Exchange mail flow rules, not Communication Compliance. Option D is not correct because blocking or preventing the sharing of sensitive data with external users is a DLP enforcement action, not a Communication Compliance capability. Option E is not correct because retention policies are enforced through Microsoft Purview Data Lifecycle Management (retention policies and labels), not Communication Compliance.

Exam trap

The trap here is that candidates confuse Communication Compliance with Data Loss Prevention (DLP) or Information Protection features, mistakenly thinking it can automatically encrypt or block data, when in reality it is a detection and review tool, not an enforcement or encryption mechanism.

640
MCQmedium

A company wants to reduce help desk calls by allowing users to reset their own passwords. The security team requires that users verify their identity using a registered mobile phone or alternative email before resetting. Additionally, the company policy states that passwords cannot be reused until at least five new passwords have been used. Which Microsoft Entra ID features should they configure to meet these requirements?

A.Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)
B.Self-Service Password Reset (SSPR) and Conditional Access policies
C.Multi-Factor Authentication (MFA) and password protection policies
D.Identity Protection and Authentication Strengths
AnswerA

Self-Service Password Reset (SSPR) directly enables users to reset their forgotten or expired passwords independently, significantly reducing help desk calls. When combined with password protection policies, which are a feature of Microsoft Entra ID, the system enforces rules such as preventing the reuse of a specified number of previous passwords. This combination effectively addresses both requirements: empowering users for self-service and maintaining strong password hygiene through history enforcement.

Why this answer

Self-Service Password Reset (SSPR) allows users to reset their own passwords, reducing help desk calls. The security requirement for identity verification via registered mobile phone or alternative email is met by SSPR's authentication methods. The password history enforcement (preventing reuse until at least five new passwords have been used) is configured through password protection policies, specifically the 'password history' setting that enforces a minimum of 5 unique passwords before reuse.

Exam trap

The trap here is that candidates often confuse Conditional Access with password policies, thinking that Conditional Access can enforce password history, when in fact password history is a separate setting under password protection policies, not a Conditional Access control.

Why the other options are wrong

B

Conditional Access policies control access based on conditions like location or device state, but they do not enforce password history rules. The requirement to prevent password reuse until five new passwords are used is a password protection policy, not a Conditional Access policy.

C

MFA provides identity verification but does not include password history enforcement; password protection policies alone do not enforce password history. The question requires both self-service reset with verification and password history, which SSPR and password protection policies together fulfill.

D

Identity Protection and Authentication Strengths do not include password history enforcement to prevent password reuse, which is explicitly required by the policy.

When would these options actually be correct?

B

A scenario where the company needs to require MFA during password reset or block password reset from untrusted locations would make Conditional Access policies correct. For example, 'Users must reset passwords only from corporate devices or trusted IPs.'

C

A question where the requirements are: users must use MFA for all sign-ins, and passwords must be blocked if they appear on a banned list (e.g., common passwords). No self-service reset or password history is needed.

D

A company needs to detect and block risky sign-ins (e.g., from anonymous IPs or leaked credentials) and enforce phishing-resistant authentication methods (e.g., FIDO2 keys) for privileged roles. Identity Protection would detect risks, and Authentication Strengths would require specific MFA methods.

Why candidates pick the wrong answer

B

Candidates may confuse Conditional Access with password policies, thinking it can enforce password history, or they may overestimate the scope of Conditional Access in identity management scenarios.

C

Candidates may think MFA is required for identity verification during password reset, but SSPR already includes its own verification methods. They also confuse password protection policies (banning weak passwords) with password history enforcement.

D

Candidates may confuse identity protection features with password management, or think that authentication strengths (like requiring MFA) cover password history, but they do not enforce password reuse rules.

641
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Device Management
B.Identity Protection
C.Endpoint Detection and Response
D.Privileged Identity Management
E.Information Protection
AnswersB, D

Identity Protection is a core capability within Microsoft Entra ID that focuses on detecting, investigating, and remediating identity-based risks. It leverages machine learning and heuristics to identify suspicious activities, such as anomalous sign-ins, leaked credentials, or impossible travel, across user accounts. This feature can automatically block risky sign-ins or enforce multi-factor authentication, significantly enhancing the security posture of user identities within the organization.

Why this answer

Microsoft Entra ID (formerly Azure AD) includes Identity Protection (option B), a risk-based service that detects and remediates risky sign-ins and compromised user credentials using signals like leaked credentials and atypical sign-in behavior. It also includes Privileged Identity Management (option D), which provides just-in-time privileged role activation, approval workflows, access reviews, and time-bound role assignments for administrative roles. These are both core Entra ID capabilities within the Entra suite.

Device Management (option A) is primarily a Microsoft Intune capability, not Entra ID itself. Endpoint Detection and Response (option C) belongs to Microsoft Defender for Endpoint, and Information Protection (option E) is delivered by Microsoft Purview, so neither is an Entra ID capability.

Exam trap

Microsoft often tests the distinction between identity management (Entra ID) and endpoint security (Defender for Endpoint) or comprehensive device management (Intune). While Entra ID manages device *identities* and enables device-based conditional access, the broader 'Device Management' (e.g., configuration, app deployment, patching) is primarily handled by solutions like Intune.

642
MCQmedium

Your organization uses Microsoft Purview to label and protect sensitive data. The compliance team wants to automatically apply a 'Confidential' label to documents containing personally identifiable information (PII) stored in SharePoint Online. What should they create?

A.A DLP policy to detect PII
B.A trainable classifier for PII
C.A retention label policy for PII
D.An auto-labeling policy for sensitivity labels
AnswerD

An auto-labeling policy for sensitivity labels is the precise mechanism within Microsoft Purview designed to automatically apply sensitivity labels to content that contains specific sensitive information types, such as PII. These policies scan content in designated locations (e.g., SharePoint, OneDrive, Exchange) and, upon detecting PII, automatically apply the configured sensitivity label. This label then enforces the associated protection actions, including encryption, visual markings, and access restrictions, thereby directly addressing the requirement to label and protect.

Why this answer

An auto-labeling policy for sensitivity labels in Microsoft Purview can automatically apply a 'Confidential' label to documents containing PII in SharePoint Online. This policy uses pattern-based detection (e.g., regex for PII like Social Security numbers) to classify and protect content at rest, aligning with the compliance team's requirement to label sensitive data automatically.

Exam trap

The trap here is confusing DLP policies (which detect and block) with auto-labeling policies (which classify and protect), leading candidates to choose A instead of D.

How to eliminate wrong answers

Option A is wrong because a DLP policy detects and protects sensitive data (e.g., blocking sharing) but does not automatically apply sensitivity labels; it enforces rules after detection. Option B is wrong because a trainable classifier uses machine learning to identify content patterns (e.g., PII) but does not apply labels; it is a component used within auto-labeling or DLP policies. Option C is wrong because a retention label policy manages data retention and deletion, not sensitivity classification; it does not apply 'Confidential' labels for protection.

643
MCQhard

A financial services company is required by the Payment Card Industry Data Security Standard (PCI-DSS) to retain all documents containing credit card numbers for at least seven years. The compliance team has created a custom sensitive information type (SIT) to detect credit card numbers in Microsoft 365. They want to automatically apply a retention label (e.g., "7-Year Retention") to any document in SharePoint or OneDrive that matches this SIT. Which Microsoft Purview solution should they configure to apply the label automatically based on content?

A.Data Loss Prevention (DLP)
B.Insider Risk Management
C.Communication Compliance
D.Data Lifecycle Management
AnswerD

Data Lifecycle Management provides auto-apply retention label policies that can use sensitive information types (SITs) to classify and retain content automatically. This is the correct solution to apply a retention label based on content detection.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview is the solution specifically designed for automatically applying retention labels based on conditions like sensitive information types (SITs). By creating a retention label policy with auto-labeling rules that reference the custom SIT for credit card numbers, DLM can automatically assign the '7-Year Retention' label to documents in SharePoint and OneDrive that contain PCI-DSS data, ensuring compliance with retention requirements.

Exam trap

The trap here is that candidates confuse Data Loss Prevention (DLP) with Data Lifecycle Management because both use sensitive information types, but DLP is for protection (blocking/sharing) while DLM is for governance (retention/deletion).

Why the other options are wrong

C

Communication Compliance is designed to detect and act on inappropriate or policy-violating communications (e.g., harassment, insider trading), not to apply retention labels based on sensitive content like credit card numbers.

When would these options actually be correct?

C

An organization wants to automatically detect and review emails containing confidential financial data (e.g., unreleased earnings reports) sent to external parties, and optionally escalate for legal investigation. Communication Compliance would be the correct solution to monitor communications and apply actions like notifying reviewers.

Why candidates pick the wrong answer

C

Candidates may confuse the ability to detect sensitive information in communications with the broader content classification and labeling capabilities of Data Lifecycle Management, assuming any detection of sensitive data can trigger labeling.

644
MCQmedium

A company uses Microsoft Purview Information Protection to classify and protect sensitive data. They want to automatically apply a sensitivity label to documents containing credit card numbers. Which should you configure?

A.Use a manual labeling policy requiring users to apply labels
B.Create a trainable classifier for credit card patterns
C.Configure an auto-labeling policy with a sensitive info type for credit card numbers
D.Set up a data classification activity explorer to monitor credit card usage
AnswerC

Configuring an auto-labeling policy with a sensitive information type for credit card numbers is the most effective and accurate method for automatic protection. This approach leverages Microsoft Purview's built-in capabilities to scan content for specific patterns, keywords, and checksums associated with credit card numbers, then automatically applies the appropriate sensitivity label and its associated protection actions (e.g., encryption, access restrictions) without any user intervention.

Why this answer

Microsoft Purview auto-labeling policies can automatically apply sensitivity labels to documents and emails that contain specific sensitive information types, such as credit card numbers. This enables automated classification and protection without requiring user intervention, directly meeting the requirement to automatically apply a label based on the presence of credit card data.

Exam trap

The trap here is confusing trainable classifiers with sensitive info types, leading candidates to choose Option B because they think 'trainable' implies automatic detection, but trainable classifiers are for broader content categories, not specific regex-based patterns like credit card numbers.

How to eliminate wrong answers

Option A is wrong because manual labeling requires users to apply labels themselves, which does not meet the requirement for automatic application. Option B is wrong because trainable classifiers are used to identify content based on patterns or context (e.g., contracts or resumes), not for detecting specific sensitive info types like credit card numbers; that is the role of sensitive info types. Option D is wrong because the data classification activity explorer is a monitoring and auditing tool that shows what labels and classifications have been applied, not a mechanism to automatically apply labels.

645
MCQmedium

A company uses Microsoft Entra ID. They want to configure a Conditional Access policy that requires multi-factor authentication (MFA) when a sign-in is assessed as medium or high risk by Microsoft's identity protection signals. For sign-ins with no detected risk, MFA should not be required. Which feature or service provides the risk assessment signals that can be consumed by Conditional Access policies?

A.Identity Protection
B.Privileged Identity Management (PIM)
C.Entitlement Management
D.Identity Governance
AnswerA

Microsoft Entra ID Protection continuously monitors sign-in attempts and user behavior for anomalous activities, such as impossible travel, unfamiliar sign-in properties, or leaked credentials. It assigns a real-time risk score to each sign-in and user, which can then be directly consumed as a condition within Microsoft Entra Conditional Access policies. This allows organizations to enforce adaptive access controls, like multi-factor authentication or blocking access, based on the detected risk level.

Why this answer

Identity Protection is the Microsoft Entra service that analyzes billions of sign-in signals using machine learning to assign a risk level (low, medium, high) for each authentication attempt. Conditional Access policies can then consume these risk assessments directly as a condition, enabling granular MFA enforcement only when the sign-in risk is medium or high, while allowing low-risk sign-ins to proceed without MFA.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with Identity Protection because both involve 'identity' and 'security,' but PIM handles role activation and approval workflows, not risk-based sign-in analysis.

Why the other options are wrong

B

Privileged Identity Management (PIM) manages just-in-time access and role activation, not risk assessment signals. Risk signals for Conditional Access policies come from Identity Protection, not PIM.

C

Entitlement Management manages access packages and resource access rights, not risk assessment signals. Conditional Access policies require risk signals from Identity Protection, not from Entitlement Management.

D

Identity Governance provides tools for managing user identities, access reviews, and lifecycle, but does not generate risk assessment signals for sign-ins. Risk signals come from Identity Protection, which analyzes user and sign-in behavior.

When would these options actually be correct?

B

PIM would be correct if the question asked: 'Which feature provides time-bound role activation and approval workflows for privileged roles in Microsoft Entra ID?'

C

A question asks: 'Which Microsoft Entra feature allows you to create access packages for internal and external users to request access to resources?' In that scenario, Entitlement Management is the correct answer.

D

A question asks: 'Which Microsoft Entra feature enables automated access reviews and certification campaigns to ensure users have appropriate access?' In that context, Identity Governance would be correct.

Why candidates pick the wrong answer

B

Candidates may confuse PIM with Identity Protection because both deal with security and identity, and PIM involves elevated privileges that could be associated with higher risk.

C

Candidates may confuse Entitlement Management with Identity Protection because both involve access control and governance, leading them to think Entitlement Management provides risk signals.

D

Candidates may confuse Identity Governance with Identity Protection because both involve security and identity management, and the term 'governance' sounds like it could include risk assessment.

646
MCQhard

Your organization uses Microsoft Entra ID P2 licenses. You need to implement a process to automatically remove users from a group if they have not signed in for 90 days. Which feature should you use?

A.Conditional Access policy
B.Privileged Identity Management
C.Access reviews in Identity Governance
D.Microsoft Entra ID Protection
AnswerC

Access reviews, a core component of Microsoft Entra Identity Governance, enable organizations to efficiently manage group memberships, application access, and role assignments. They allow administrators or group owners to periodically review who has access to what, and crucially, can be configured to automatically remove users from groups if they fail to attest to their continued need for access or if they are identified as inactive based on sign-in data. This capability directly addresses the requirement to maintain clean group memberships by removing inactive users.

Why this answer

Access reviews in Identity Governance allow you to automate the review and removal of group memberships based on inactivity criteria, such as users who haven't signed in for 90 days. This feature is specifically designed for periodic attestation and lifecycle management of group memberships, leveraging Microsoft Entra ID P2 licenses.

Exam trap

The trap here is confusing Access Reviews (which handle membership lifecycle based on inactivity) with Conditional Access (which controls access at sign-in) or Privileged Identity Management (which focuses on privileged roles).

How to eliminate wrong answers

Option A is wrong because Conditional Access policies enforce access controls during sign-in (e.g., requiring MFA or blocking locations) but cannot automatically remove users from groups based on inactivity. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and assignment, not general group membership lifecycle based on sign-in activity. Option D is wrong because Microsoft Entra ID Protection detects and responds to identity risks (e.g., leaked credentials, impossible travel) but does not automate group membership removal based on inactivity.

647
MCQhard

A company uses Microsoft Entra ID for authentication. The security team wants to enforce that users can only access Microsoft 365 applications from compliant devices and trusted locations. They also want to require multi-factor authentication when users access from untrusted networks. Which feature should they configure?

A.Microsoft Entra Conditional Access
B.Microsoft Entra Authentication Methods policies
C.Microsoft Intune compliance policies
D.Microsoft Entra ID Protection
AnswerA

Microsoft Entra Conditional Access allows organizations to create policies that enforce access controls based on conditions such as user, device compliance, location, and risk. It can require compliant devices, trusted locations, and multi-factor authentication for specific scenarios. This precisely matches the requirement to restrict access to compliant devices and trusted locations while enforcing MFA from untrusted networks.

Why this answer

Microsoft Entra Conditional Access is the policy engine that evaluates signals like device compliance, location, and user risk to make access decisions. It can require compliant devices, trusted locations, and MFA based on conditions. Intune compliance policies and ID Protection provide input signals, but Conditional Access is the feature that enforces the access requirements.

Exam trap

The trap here is selecting Intune compliance policies because they relate to device compliance, but they do not enforce access controls; Conditional Access is the enforcement point.

648
MCQmedium

An organization needs to prevent users from sharing files containing trade secrets with external parties via email. The solution must allow internal sharing. Which Microsoft Purview capability should be configured?

A.Microsoft Purview Communication Compliance
B.Microsoft Purview Data Loss Prevention policies
C.Microsoft Purview Data Lifecycle Management
D.Microsoft Purview Sensitivity Labels with encryption
AnswerB

Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and automatically protect sensitive information across Microsoft 365 services, endpoints, and on-premises repositories. By defining rules based on sensitive information types, labels, or keywords, DLP policies can actively prevent users from sharing files containing sensitive data externally, internally, or to unauthorized applications, thus directly addressing the requirement to block file sharing. These policies enforce controls to stop data exfiltration.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect and block the sharing of sensitive information—such as trade secrets—via email or other channels, while still allowing internal sharing. DLP can inspect email content and attachments for sensitive data types and apply actions like blocking external sends, making it the correct choice for this requirement.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels with encryption as a data loss prevention mechanism, but encryption alone does not block external email transmission—DLP policies are required to enforce the 'block external sharing' action based on content inspection.

How to eliminate wrong answers

Option A is wrong because Communication Compliance focuses on monitoring and detecting inappropriate or policy-violating communications (e.g., harassment, insider trading), not on preventing data exfiltration via email. Option C is wrong because Data Lifecycle Management (formerly Records Management) governs retention and deletion of data based on policies, not real-time blocking of external sharing. Option D is wrong because Sensitivity Labels with encryption can protect files by restricting access, but they do not natively block external email sharing based on content inspection; DLP policies are needed to enforce such transmission controls.

649
MCQmedium

A security analyst needs to query Microsoft 365 audit logs to find all activities where a user deleted a file from SharePoint Online in the last 24 hours. Which tool should they use?

A.Microsoft Sentinel
B.Microsoft Purview compliance portal audit search
C.Microsoft Graph PowerShell
D.Microsoft Defender for Cloud Apps
AnswerB

The Microsoft Purview compliance portal audit search provides the native, centralized, and most user-friendly interface for security analysts to query Microsoft 365 audit logs. This dedicated portal allows for comprehensive searching across various services like Exchange Online, SharePoint Online, Teams, and Azure AD, offering extensive filtering capabilities by date, user, activity, and workload. It is specifically designed for investigative purposes, enabling efficient identification of specific user or administrator actions without requiring complex scripting.

Why this answer

Microsoft Purview compliance portal audit search is the correct tool because it provides a dedicated, searchable interface for querying the Microsoft 365 unified audit log. This log records all user and admin activities, including file deletions from SharePoint Online, and supports time-based filters (e.g., last 24 hours) to retrieve specific events. It is purpose-built for compliance and security investigations without requiring additional licensing or complex scripting.

Exam trap

The trap here is that candidates may confuse Microsoft Sentinel (a SIEM) with a simple audit log search tool, but Sentinel is designed for advanced threat detection and correlation, not for direct, ad-hoc queries of the unified audit log without additional setup.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM that ingests audit logs from multiple sources, but it requires additional licensing and configuration to query Microsoft 365 audit logs; it is not the direct tool for a simple audit log query. Option C is wrong because Microsoft Graph PowerShell can retrieve audit log data via cmdlets like Search-UnifiedAuditLog, but it requires PowerShell scripting and module installation, making it less straightforward than the Purview portal for a one-off query. Option D is wrong because Microsoft Defender for Cloud Apps focuses on cloud app discovery, session controls, and anomaly detection, not on directly querying the unified audit log for historical file deletion events.

650
MCQhard

A multinational corporation must comply with regulations that require them to keep financial records for 7 years and then permanently delete them. However, they are currently involved in litigation that requires preservation of all documents related to a specific project. They use Microsoft Purview. Which combination of features should they use to meet both requirements?

A.Data Lifecycle Management to retain for 7 years then delete, and eDiscovery (Premium) to place a legal hold on the project documents
B.Data Lifecycle Management to retain for 7 years then delete, and Sensitivity labels to mark documents
C.Audit (Premium) to log access and eDiscovery (Premium) to search
D.Information Protection to classify data and Data Lifecycle Management to retain
AnswerA

Data Lifecycle Management (DLM) effectively establishes a baseline retention policy to retain data for seven years and then automatically delete it, ensuring general compliance with record-keeping regulations. Concurrently, eDiscovery (Premium) allows for the precise application of a legal hold on specific project documents, which critically overrides any deletion policy, including the DLM policy, to preserve evidence for potential litigation. This combination ensures both routine data governance and specific, immutable preservation for legal requirements.

Why this answer

Data Lifecycle Management (DLM) allows you to create retention labels that enforce a 7-year retention period followed by automatic deletion, satisfying the regulatory requirement. eDiscovery (Premium) provides the ability to place a legal hold on specific documents, which overrides the deletion policy to preserve data relevant to ongoing litigation. This combination ensures both compliance with the retention/deletion mandate and the preservation obligation.

Exam trap

The trap here is that candidates often confuse Sensitivity labels (which mark or protect data) with retention labels (which enforce lifecycle policies), or assume eDiscovery alone can handle both retention and hold, missing the need for DLM to define the deletion schedule.

How to eliminate wrong answers

Option B is wrong because Sensitivity labels are used for classification and protection (e.g., encryption, marking) but do not provide legal hold functionality to override deletion policies. Option C is wrong because Audit (Premium) logs user activities but does not enforce retention or deletion, and eDiscovery (Premium) alone cannot set a retention schedule; it needs DLM for the lifecycle policy. Option D is wrong because Information Protection classifies data but does not enforce retention or deletion schedules, and DLM alone cannot place a legal hold to preserve documents during litigation.

651
MCQmedium

A company uses Microsoft 365 and allows employees to access corporate email and documents from their personal devices. The security team wants to protect against malicious links in emails and Microsoft Teams messages. When a user clicks a link, it should be checked in real-time to see if it leads to a known malicious site. If it does, access should be blocked. Which Microsoft security solution provides this capability?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Office 365 is the correct solution as it specifically provides advanced protection against phishing, spam, malware, and other threats delivered via email and collaboration tools like Microsoft Teams. Its key features, Safe Links and Safe Attachments, are designed to perform real-time scanning of URLs and attachments. Safe Links rewrites and scans URLs at the time of click, while Safe Attachments detonates suspicious files in a sandbox environment, directly addressing the need for real-time URL scanning in email and Teams.

Why this answer

Microsoft Defender for Office 365 includes Safe Links, which provides real-time URL scanning at the time of click. When a user clicks a link in an email or Teams message, the URL is rewritten and checked against a dynamic list of known malicious sites. If the link is determined to be malicious, access is blocked, and the user is redirected to a warning page.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (which handles email and collaboration security) with Microsoft Defender for Endpoint (which handles device-level threats), leading them to choose the endpoint solution for a link-scanning scenario.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR), antivirus, and device-level threat protection, not on scanning links in email or Teams messages. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility and control over cloud app usage, but it does not perform real-time link scanning in email or Teams. Option D is wrong because Microsoft Defender for Identity monitors on-premises Active Directory signals to detect identity-based attacks, such as lateral movement or privilege escalation, and does not inspect links in communications.

652
MCQeasy

A company implements multiple layers of security controls including a firewall, an intrusion detection system (IDS), antivirus software on endpoints, and regular security awareness training for employees. This approach is an example of which security concept?

A.Zero Trust
B.Defense in depth
C.Least privilege
D.Shared responsibility
AnswerB

Defense in depth is a cybersecurity strategy that employs multiple, independent layers of security controls to protect information and systems. The objective is to ensure that if one security control fails or is bypassed, other controls are in place to prevent or delay a breach, thereby increasing the overall resilience of the system. This layered approach often includes a combination of technical controls like firewalls and intrusion detection systems, administrative controls such as policies and training, and physical controls.

Why this answer

Defense in depth is the correct answer because the company is implementing multiple layers of security controls (firewall, IDS, antivirus, and security awareness training) to protect assets. This layered approach ensures that if one control fails, another control is in place to mitigate the threat, which is the core principle of defense in depth.

Exam trap

The trap here is that candidates often confuse defense in depth with Zero Trust because both involve multiple controls, but Zero Trust specifically focuses on identity verification and least-privilege access, not just layered defenses.

Why the other options are wrong

A

Zero Trust is a security model that assumes no implicit trust and requires continuous verification for every access request, but the question describes multiple layers of security controls, which is the definition of defense in depth, not Zero Trust.

C

The question describes multiple layers of security controls (firewall, IDS, antivirus, training), which is the definition of defense in depth, not least privilege. Least privilege restricts user access rights to only what is necessary, which is not illustrated here.

D

The question describes multiple security layers (firewall, IDS, antivirus, training), which is the definition of defense in depth. Shared responsibility is a cloud model where the provider and customer share security duties, not a multi-layered on-premises approach.

When would these options actually be correct?

A

A question that asks: 'A company requires all users to authenticate and be authorized for every access attempt, regardless of whether they are inside or outside the network. This approach is an example of which security concept?' would make Zero Trust the correct answer.

C

A question that asks: 'A company configures user accounts so that employees can only access files required for their job roles. This approach is an example of which security concept?' would make least privilege the correct answer.

D

In a scenario where a company uses a cloud service provider and the question asks who is responsible for securing the operating system, data, or physical infrastructure, shared responsibility would be the correct answer. For example: 'A company uses Azure IaaS. Who is responsible for patching the guest OS?'

Why candidates pick the wrong answer

A

Candidates may confuse Zero Trust with defense in depth because both involve multiple security measures, but Zero Trust specifically focuses on eliminating implicit trust and verifying every access, not just layering controls.

C

Candidates may confuse the layered approach with the principle of least privilege because both involve multiple security measures, but least privilege specifically focuses on minimal access rights, not layered defenses.

D

Candidates may confuse the idea of multiple security layers with the concept of dividing security tasks between parties, especially if they recall that 'defense in depth' involves layers and mistakenly think 'shared responsibility' also implies layers.

653
MCQeasy

You are the security administrator for a company using Microsoft Defender XDR. A user reports receiving a suspicious email with a link. What Microsoft Defender XDR feature should you use to investigate the email's threat level?

A.Email & collaboration in Microsoft Defender XDR
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Identity
AnswerA

Email & collaboration in Microsoft Defender XDR provides robust, integrated protection for email and collaboration tools like Microsoft Teams, identifying and mitigating threats such as phishing, malware, and spam. It unifies threat investigation and response capabilities across these communication vectors within a single portal, enabling security administrators to proactively defend against sophisticated email-borne attacks and ensure data integrity.

Why this answer

Microsoft Defender XDR's Email & collaboration feature (part of Defender for Office 365) is the correct tool for investigating a suspicious email. It provides a unified investigation experience, including threat explorer, email entity pages, and detonation analysis, allowing you to inspect the email's headers, attachments, URLs, and determine its threat level using Microsoft's threat intelligence and machine learning models.

Exam trap

The trap here is that candidates often confuse the broad 'Microsoft Defender XDR' umbrella with its specific components, mistakenly selecting a different Defender product (like Endpoint or Identity) instead of recognizing that email investigation is handled by the Email & collaboration workload within Defender for Office 365.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not email investigation; it would not provide email-specific threat analysis. Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that monitors cloud application usage and data, not email messages or links. Option D is wrong because Microsoft Defender for Identity protects on-premises Active Directory identities using behavioral analytics and alerts on identity-based attacks, not email threat investigation.

654
MCQhard

A company wants to implement just-in-time (JIT) privileged access management for their Global Administrators in Microsoft Entra ID. They require that a user must request activation of the Global Administrator role, the request must be approved by a separate administrator, and the role will automatically expire after 4 hours. Additionally, they need an audit trail of all activations. Which Microsoft Entra feature should they use?

A.Microsoft Entra Conditional Access
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management (PIM)
D.Azure Role-Based Access Control (RBAC)
AnswerC

Microsoft Entra Privileged Identity Management (PIM) is the dedicated service for managing, controlling, and monitoring access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. It enables Just-In-Time (JIT) access by allowing users to activate privileged roles only when needed, for a limited duration, and often requiring multi-factor authentication or an approval workflow. PIM also enforces time-bound assignments and provides comprehensive auditing and review capabilities for all privileged role activations, directly addressing the requirement for JIT privileged access management.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing users to activate roles like Global Administrator on-demand, requiring approval from designated approvers, setting a maximum activation duration (e.g., 4 hours), and automatically deactivating the role upon expiry. It also maintains a full audit trail of all activations, approvals, and role assignments via the PIM audit history and Azure AD audit logs, meeting all the stated requirements.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which manages Azure resource permissions) with PIM (which manages Microsoft Entra ID directory roles and JIT activation), leading them to select option D despite Azure RBAC lacking approval workflows and automatic expiry for directory roles.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access enforces access policies based on signals like user location or device compliance, but it does not provide JIT role activation, approval workflows, or automatic role expiry. Option B is wrong because Microsoft Entra Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies) but does not manage privileged role activation or approval processes. Option D is wrong because Azure Role-Based Access Control (RBAC) manages permissions for Azure resources (e.g., VMs, storage) using role definitions and assignments, but it does not support JIT activation, approval workflows, or time-bound expiry for Microsoft Entra ID directory roles like Global Administrator.

655
MCQmedium

A company uses Microsoft Entra ID. They want to enforce multifactor authentication (MFA) for all access to a sensitive HR application. However, they only want to require MFA when the sign-in risk is assessed as medium or high, and block access if the risk is high. Which Conditional Access components must the administrator configure to meet these requirements? (Choose the best answer)

A.Assignments (Users and cloud apps) and Session controls (Sign-in frequency)
B.Conditions (Sign-in risk) and Grant controls (Require multifactor authentication, Block access)
C.Conditions (Device platforms) and Grant controls (Require approved client app)
D.Grant controls (Require multifactor authentication) and Session controls (Application enforce restrictions)
AnswerB

Correct. The conditions specify when a policy applies (e.g., when risk is medium or high). Grant controls enforce the required actions: require MFA for medium/high risk and block for high risk. Block access is an available grant control.

Why this answer

The scenario requires evaluating sign-in risk as a condition, which is configured under Conditions (Sign-in risk) in Conditional Access. The Grant controls then enforce 'Require multifactor authentication' for medium/high risk and 'Block access' for high risk, directly matching the requirements.

Exam trap

The trap here is that candidates confuse Conditions (sign-in risk) with Conditions (device platforms) or Session controls, overlooking that risk-based MFA requires both the risk condition and specific grant controls to enforce different actions per risk level.

How to eliminate wrong answers

Option A is wrong because Session controls like Sign-in frequency manage session lifetime, not risk-based MFA enforcement or blocking. Option C is wrong because Device platforms condition filters by OS type, not sign-in risk, and Require approved client app is a grant control for device compliance, not risk-based access. Option D is wrong because Grant controls alone (Require MFA) cannot differentiate risk levels, and Session controls (Application enforce restrictions) do not provide risk-based blocking or conditional MFA.

656
MCQeasy

A company is implementing a new security policy that requires every user to have only the minimum permissions necessary to perform their job duties. Which security principle does this policy align with?

A.Defense in depth
B.Zero Trust
C.Principle of least privilege
D.Separation of duties
AnswerC

The Principle of Least Privilege dictates that users, applications, and systems should be granted only the minimum necessary permissions required to perform their specific job functions or tasks. This fundamental security practice significantly reduces the attack surface by limiting the potential damage an attacker can inflict if an account is compromised or an application is exploited. It directly addresses the need to restrict access to only what is absolutely essential, minimizing unauthorized actions.

Why this answer

The policy requiring every user to have only the minimum permissions necessary to perform their job duties directly aligns with the Principle of Least Privilege. This principle dictates that users, applications, and systems should be granted the minimal level of access rights needed to complete their tasks, reducing the attack surface and limiting potential damage from compromised accounts. In Microsoft 365, this is implemented through Role-Based Access Control (RBAC) roles and Azure AD roles, where administrators assign specific permissions rather than broad administrative roles.

Exam trap

The trap here is that candidates often confuse the Principle of Least Privilege with Zero Trust, but Zero Trust is a broader framework that includes least privilege as one of its core pillars, not the specific policy of minimizing permissions per user.

How to eliminate wrong answers

Option A is wrong because Defense in Depth is a layered security strategy that uses multiple controls (e.g., firewalls, encryption, antivirus) to protect resources, not a principle about limiting individual user permissions. Option B is wrong because Zero Trust is a security model based on the principle of 'never trust, always verify,' which includes least privilege as a component but is broader, encompassing continuous authentication, device health checks, and micro-segmentation. Option D is wrong because Separation of Duties is a control that prevents a single individual from performing conflicting tasks (e.g., both creating and approving a purchase order), which reduces fraud risk but does not specifically address minimizing permissions per user role.

657
MCQmedium

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to synchronize user passwords and enable password writeback for self-service password reset. Which tool should you use?

A.Microsoft Entra admin center
B.Microsoft Entra Connect Sync
C.Active Directory Federation Services (AD FS)
D.Azure AD Connect (deprecated)
AnswerB

Microsoft Entra Connect Sync is the designated on-premises agent responsible for synchronizing user identities, groups, and other objects from an on-premises Active Directory to Microsoft Entra ID. It supports various synchronization features crucial for migration, including password hash synchronization (PHS), which securely transfers a hash of the on-premises password to the cloud, enabling single sign-on for users. This tool is fundamental for hybrid identity scenarios, ensuring a consistent user experience across both environments.

Why this answer

Microsoft Entra Connect Sync (formerly Azure AD Connect) is the correct tool because it synchronizes on-premises Active Directory objects, including password hashes, to Microsoft Entra ID and supports password writeback, which enables self-service password reset (SSPR) to write changed passwords back to on-premises AD. The question specifically requires both password synchronization and writeback, which are core features of Entra Connect Sync.

Exam trap

The trap here is that candidates may confuse the deprecated name 'Azure AD Connect' (Option D) with the current tool, or mistakenly think that AD FS (Option C) can handle password synchronization and writeback, when in fact AD FS only handles authentication federation and not directory synchronization or writeback operations.

How to eliminate wrong answers

Option A is wrong because the Microsoft Entra admin center is a web-based management portal for configuring cloud settings, but it cannot perform the actual synchronization or writeback of passwords from on-premises AD; it relies on a sync engine like Entra Connect Sync. Option C is wrong because Active Directory Federation Services (AD FS) is a federation service used for single sign-on and claims-based authentication, not for synchronizing password hashes or enabling password writeback for SSPR. Option D is wrong because Azure AD Connect is the deprecated name for the tool that has been rebranded as Microsoft Entra Connect Sync; while it functionally could perform the task, the exam expects the current, correct name.

658
MCQhard

A company is planning to migrate from on-premises Active Directory to Microsoft Entra ID. They have multiple on-premises applications that use LDAP for authentication. They want to enable single sign-on (SSO) to these applications from the cloud without modifying the applications. Which approach should they use?

A.Microsoft Entra Domain Services
B.Federation with Active Directory Federation Services (AD FS)
C.Pass-through authentication
D.Password hash synchronization with Seamless SSO
AnswerA

Microsoft Entra Domain Services provides a managed domain environment that is fully compatible with traditional Active Directory Domain Services (AD DS). It offers essential domain services like LDAP, Kerberos, and NTLM authentication, which are critical for legacy applications that cannot be easily re-architected to use modern authentication protocols. This service allows companies to lift-and-shift these applications to the cloud without deploying or managing domain controllers, while still leveraging their existing Microsoft Entra ID identities for authentication and directory lookups.

Why this answer

Microsoft Entra Domain Services provides managed domain services such as LDAP, Kerberos, and NTLM authentication without requiring you to deploy and manage domain controllers. Since the on-premises applications use LDAP for authentication and cannot be modified, Entra Domain Services can be used to lift and shift these applications into Azure while enabling SSO from the cloud, as it presents a compatible LDAP interface that the applications can continue to use.

Exam trap

The trap here is that candidates often confuse authentication methods (like Pass-through or Federation) with directory services, not realizing that legacy LDAP-based applications require a domain service that exposes an LDAP endpoint, not just a cloud authentication protocol.

How to eliminate wrong answers

Option B is wrong because Federation with AD FS requires modifying the applications to support SAML or WS-Federation, and it does not natively provide an LDAP interface for legacy applications. Option C is wrong because Pass-through authentication validates passwords against on-premises Active Directory but does not expose an LDAP endpoint for applications to authenticate against; it is an authentication method for cloud apps, not a replacement for LDAP directory services. Option D is wrong because Password hash synchronization with Seamless SSO enables cloud authentication for web-based apps using Kerberos tickets but does not provide an LDAP interface for legacy on-premises applications that require direct LDAP binds.

659
MCQhard

A financial company needs to prevent any communication between their mergers and acquisitions (M&A) team and the trading desk across all Microsoft 365 channels, including email, Microsoft Teams, and SharePoint. They must ensure that no user in one group can send emails to or chat with users in the other group. Which Microsoft Purview solution should they implement?

A.Information Barriers
B.Communication Compliance
C.Data Lifecycle Management
D.Data Loss Prevention (DLP)
AnswerA

Information Barriers define policies that block communication and collaboration between specified segments, enforcing restrictions across Exchange email, Microsoft Teams chats, and SharePoint sites. This directly prevents the M&A team and trading desk from contacting each other in any Microsoft 365 channel.

Why this answer

Information Barriers (IB) is the correct solution because it is specifically designed to prevent communication and collaboration between two user groups across Microsoft 365 services, including email, Teams, and SharePoint. By defining policies that block segments (e.g., M&A team and trading desk), IB enforces restrictions at the transport, chat, and document level, ensuring no email, chat, or file sharing occurs between the groups. This directly addresses the requirement to isolate the M&A team from the trading desk across all channels.

Exam trap

The trap here is that candidates often confuse Information Barriers with Communication Compliance, mistakenly thinking that monitoring and blocking are the same, but Communication Compliance only detects and reports violations after the fact, whereas Information Barriers proactively prevents communication from occurring.

How to eliminate wrong answers

Option B (Communication Compliance) is wrong because it is designed for monitoring and detecting policy violations (e.g., insider trading, harassment) after communication occurs, not for proactively blocking communication between groups. Option C (Data Lifecycle Management) is wrong because it focuses on retaining or deleting data based on age or classification, not on restricting communication between users. Option D (Data Loss Prevention) is wrong because it prevents sensitive data from being shared externally or with unauthorized users, but it does not block all communication between two internal groups across all channels.

660
MCQmedium

You are the compliance administrator for a healthcare organization that must comply with HIPAA. You need to automatically detect and prevent patients' protected health information (PHI) from being shared via email. Additionally, you need to retain all emails containing PHI for 6 years. You also need to allow users to manually classify documents as 'Medical Record' with encryption that expires after 30 days. Which combination of Microsoft Purview solutions should you implement?

A.Data Loss Prevention (DLP) policy to block PHI; retention policy for 6 years on emails containing PHI; sensitivity label with encryption and expiration
B.Data Loss Prevention (DLP) policy to block PHI; eDiscovery to retain emails; sensitivity label with encryption
C.Retention label for 6 years; sensitivity label with encryption; communication compliance to monitor sharing
D.Data Loss Prevention (DLP) policy to block PHI; auto-labeling policy to apply retention label; no manual label needed
AnswerA

DLP blocks sharing; retention policy retains; sensitivity label provides manual classification with encryption and expiration.

Why this answer

The correct combination is a DLP policy to detect and block PHI in email, a retention policy for 6 years on emails containing PHI, and a sensitivity label with encryption and expiration for manual classification. DLP handles prevention, retention handles the 6-year hold, and the sensitivity label provides user-driven classification with encryption that expires after 30 days.

Exam trap

SC-900 often tests the confusion between retention policies, retention labels, and eDiscovery, and between DLP (prevention) and communication compliance (monitoring), causing candidates to pick a combination that misses either prevention or the manual label requirement.

How to eliminate wrong answers

Option B is wrong because eDiscovery is for legal hold and investigation, not for applying a 6-year retention policy to emails containing PHI. Option C is wrong because it omits DLP, which is required to automatically detect and prevent PHI sharing, and communication compliance only monitors rather than blocks. Option D is wrong because it removes the manual sensitivity label needed for user-driven 'Medical Record' classification with encryption and 30-day expiration, and auto-labeling alone does not satisfy the manual classification requirement.

661
MCQeasy

A security architect is adopting a new security model that assumes breach and verifies every access request. The model eliminates implicit trust and requires continuous validation. Which security model is being implemented?

A.Defense in Depth
B.Zero Trust
C.Least Privilege
D.Shared Responsibility
AnswerB

Zero Trust is a modern security model that fundamentally shifts from perimeter-based security to a 'never trust, always verify' approach. It mandates explicit verification for every access request, regardless of whether the request originates inside or outside the traditional network perimeter. This model assumes breach and continuously validates identity, device health, and other contextual factors before granting and maintaining access to resources.

Why this answer

Zero Trust is the correct model because it explicitly assumes breach, eliminates implicit trust, and requires continuous validation of every access request. This aligns with the core Zero Trust principle of 'never trust, always verify,' which mandates that no user, device, or network is trusted by default, even if they are inside the corporate perimeter.

Exam trap

The trap here is that candidates often confuse Zero Trust with Least Privilege, but Zero Trust is a broader architectural model that includes continuous validation and breach assumption, whereas Least Privilege is only one component of access control.

Why the other options are wrong

A

Defense in Depth is a layered security approach using multiple controls, but it does not inherently eliminate implicit trust or require continuous validation of every access request. The question specifically describes assuming breach and verifying every request, which is the core of Zero Trust.

C

Least Privilege is a principle of granting only necessary permissions, but it does not inherently assume breach or require continuous validation of every access request. The question describes Zero Trust's core tenets of eliminating implicit trust and continuous verification.

D

The question describes a model that eliminates implicit trust and continuously validates access, which is Zero Trust. Shared Responsibility is a cloud security model that defines security obligations between provider and customer, not a model for access validation.

When would these options actually be correct?

A

A question asking: 'Which security model uses multiple layers of defense to protect resources, such as firewalls, antivirus, and encryption, to ensure that if one layer fails, others still provide protection?' would make Defense in Depth the correct answer.

C

A question asks: 'Which security principle ensures that users and processes have only the minimum access rights needed to perform their tasks?' In that context, Least Privilege is the correct answer.

D

A question asking: 'A company is migrating to the cloud and needs to understand which security tasks are handled by the cloud provider versus their own team. Which security model defines these boundaries?' would make Shared Responsibility correct.

Why candidates pick the wrong answer

A

Candidates may confuse Defense in Depth with Zero Trust because both involve multiple security controls, but they fail to recognize that Zero Trust uniquely focuses on eliminating implicit trust and continuous verification.

C

Candidates may confuse Least Privilege with Zero Trust because both involve restricting access, but they fail to recognize that Zero Trust is a broader model that includes continuous verification and assumes breach, not just permission minimization.

D

Candidates may confuse Shared Responsibility with Zero Trust because both involve security concepts, but Shared Responsibility is about division of labor, not continuous verification of access requests.

662
MCQeasy

Your organization uses Microsoft Defender XDR. The security team wants a central dashboard showing the overall security posture and recommended actions. Which tool should they use?

A.Microsoft Purview
B.Microsoft Entra ID
C.Microsoft Sentinel
D.Microsoft Secure Score
AnswerD

Microsoft Secure Score aggregates your security posture across Microsoft 365 services and surfaces prioritised improvement actions. It satisfies the requirement for a central dashboard showing overall posture and recommended actions, unlike Defender-specific incident views or compliance reports.

Why this answer

Microsoft Secure Score is the dashboard within Microsoft Defender XDR that quantifies an organization's security posture and provides prioritized, actionable improvement recommendations. It aggregates signals from Microsoft 365 services and Defender workloads, assigning points for implemented controls so the security team can track posture over time.

Exam trap

SC-900 often tests whether candidates can distinguish posture-management tools (Secure Score) from operational security tools (Sentinel) and compliance tools (Purview), since all three appear in the same Defender XDR portal.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance, compliance, and information-protection suite (data classification, DLP, eDiscovery), not a posture-scoring dashboard. Option B is wrong because Microsoft Entra ID is the identity and access management service (authentication, conditional access, PIM), not a security posture measurement tool. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR platform for log ingestion, analytics, and incident response, not a posture score dashboard.

663
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

A.A device compliance policy
B.A conditional access policy
C.A device configuration policy
D.An app protection policy
AnswerB

A conditional access policy is the correct mechanism because it acts as the enforcement engine, evaluating various signals including the device's compliance status reported by Intune. This policy can be configured to explicitly require that a device be marked as 'compliant' before granting access to specific cloud applications or services. It effectively bridges device health with access control decisions, ensuring only trusted devices can reach sensitive data.

Why this answer

Conditional Access policies in Azure AD evaluate signals (like device compliance status reported by Intune) to enforce access controls. By configuring a Conditional Access policy that requires device compliance for the Exchange Online or corporate email app, only devices marked as compliant by Intune will be granted access. This is the correct mechanism to gate access based on compliance.

Exam trap

The trap here is that candidates confuse a device compliance policy (which only evaluates and marks compliance) with a Conditional Access policy (which enforces the access decision based on that compliance status), leading them to select option A instead of B.

How to eliminate wrong answers

Option A is wrong because a device compliance policy defines the rules (e.g., requiring encryption or a minimum OS version) that a device must meet to be considered compliant, but it does not enforce access control itself—it only marks the device as compliant or non-compliant. Option C is wrong because a device configuration policy manages device settings (e.g., Wi-Fi profiles, certificates) but does not evaluate or enforce compliance-based access to email. Option D is wrong because an app protection policy (MAM) manages data protection within apps (e.g., preventing copy-paste) and does not check device compliance; it applies even to unmanaged devices.

664
MCQhard

Refer to the exhibit. A Conditional Access policy is defined as shown. Which client applications will be blocked?

A.Browser-based applications accessing Office 365.
B.Exchange ActiveSync clients only.
C.Legacy authentication clients such as IMAP, POP, and SMTP.
D.Applications using modern authentication (e.g., Outlook for Windows with OAuth).
AnswerC

This Conditional Access policy specifically targets legacy authentication clients by including both "Exchange ActiveSync clients" and "Other clients" in its scope. Protocols like IMAP, POP, and SMTP inherently utilize legacy authentication methods, which are encompassed within the "Other clients" category. By targeting these client types, the policy effectively applies its controls to connections made using these older, less secure authentication flows.

Why this answer

The policy targets 'Legacy authentication clients' such as IMAP, POP, and SMTP, which do not support modern authentication protocols like OAuth 2.0. These protocols rely on basic authentication and are blocked by Conditional Access policies configured to require modern authentication. Option C is correct because the policy explicitly blocks these legacy protocols.

Exam trap

The trap here is that candidates may confuse 'Exchange ActiveSync clients' (which can use modern authentication) with legacy protocols like IMAP/POP/SMTP, or assume that all browser-based apps are blocked, when the policy specifically targets legacy authentication clients only.

How to eliminate wrong answers

Option A is wrong because browser-based applications accessing Office 365 typically use modern authentication (e.g., OAuth 2.0 via the browser) and are not blocked unless the policy specifically targets browser-based apps. Option B is wrong because Exchange ActiveSync clients can use modern authentication (e.g., OAuth 2.0) and are not inherently blocked; the policy targets legacy authentication, not all ActiveSync clients. Option D is wrong because applications using modern authentication (e.g., Outlook for Windows with OAuth) are explicitly allowed by the policy, as it only blocks legacy authentication clients.

665
MCQeasy

Your company uses Microsoft Intune to manage devices. You need to ensure that only devices that are compliant with your security policies can access corporate email via Microsoft Outlook. What should you implement?

A.Windows Information Protection
B.Device compliance policies
C.App protection policies
D.Conditional Access policies
AnswerD

Conditional Access policies in Azure Active Directory are the robust control plane for enforcing access decisions to cloud applications, including email, based on various signals. These policies evaluate conditions such as user identity, location, application, and crucially, the device's compliance status as reported by Intune. Based on this evaluation, Conditional Access can grant access, block access, or require additional authentication methods, making it the definitive mechanism for enforcing access control based on device compliance.

Why this answer

Conditional Access policies (D) are the correct choice because they evaluate device compliance status—determined by Intune compliance policies—as a condition for granting access. By configuring a Conditional Access policy that requires compliant devices, only devices meeting your security policies can authenticate to Microsoft Outlook and access corporate email. This is the Azure AD/Entra ID mechanism that enforces access control based on compliance state.

Exam trap

The trap here is that candidates confuse device compliance policies (which only define and report compliance) with Conditional Access (which enforces access decisions based on that compliance state), leading them to select Option B instead of D.

How to eliminate wrong answers

Option A is wrong because Windows Information Protection (WIP) is a data-loss prevention technology that protects corporate data on devices by separating personal and business data, but it does not control which devices can access email based on compliance. Option B is wrong because Device compliance policies define the security requirements (e.g., encryption, OS version) and mark devices as compliant or non-compliant, but they do not themselves block or allow access to email—they only generate a compliance state that must be enforced by another service. Option C is wrong because App protection policies (MAM) protect data at the app level (e.g., preventing copy/paste from Outlook) and do not evaluate device compliance or control initial access to corporate email based on device health.

666
Multi-Selectmedium

Which TWO Microsoft Entra ID features can be used to protect against credential theft? (Choose two.)

Select 2 answers
A.Passwordless authentication
B.Self-Service Password Reset (SSPR)
C.Microsoft Entra ID Domain Services
D.Microsoft Entra ID Connect
E.Conditional Access policies that require MFA
AnswersA, E

Passwordless authentication significantly enhances security by eliminating the primary target for many credential theft attacks: the password itself. By replacing passwords with more secure methods like FIDO2 security keys, Windows Hello for Business, or the Microsoft Authenticator app, organizations remove the risk of passwords being phished, brute-forced, or stolen through credential stuffing. This approach fundamentally reduces the attack surface for identity-based breaches.

Why this answer

Passwordless authentication (A) is correct because it removes the password from the sign-in process entirely, using methods such as Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app, so there is no password credential for attackers to phish, replay, or steal. Conditional Access policies that require MFA (E) are correct because they enforce a second verification factor at sign-in, so even if a password is compromised through phishing or breach, the stolen credential alone is insufficient to authenticate. SSPR (B) only lets users reset forgotten passwords and does not itself prevent credential theft.

Microsoft Entra ID Domain Services (C) provides managed domain services such as LDAP and domain join for legacy workloads, and Microsoft Entra ID Connect (D) synchronizes on-premises identities to Entra ID; neither feature directly protects credentials from theft.

Exam trap

The trap here is that candidates often confuse SSPR (a recovery mechanism) with a preventive control, or mistakenly think Entra ID Connect or Domain Services offer security features they do not, when the question specifically asks for features that protect against credential theft.

667
Multi-Selecthard

Which THREE components are part of the Microsoft Entra External Identities suite?

Select 3 answers
A.B2B direct connect
B.Conditional Access
C.B2C (business-to-consumer)
D.B2B collaboration
E.Identity Protection
AnswersA, C, D

Azure AD B2B, now a foundational component within Microsoft Entra External ID, specifically enables organizations to collaborate securely with external partners. It allows guest users from other Microsoft Entra tenants or social identity providers to access applications and resources in your directory using their existing credentials, streamlining external access management. This capability is central to managing external identities for business-to-business scenarios.

Why this answer

Microsoft Entra External Identities is the suite of capabilities for managing external users, and it comprises three components: B2B collaboration (D), B2B direct connect (A), and B2C (business-to-consumer) (C). B2B collaboration (D) lets you invite partner users as guests into your tenant, where they authenticate with their own credentials and appear as guest objects in your directory. B2B direct connect (A) enables a mutual, two-way trust with another Microsoft Entra tenant so users can seamlessly access shared resources such as Teams shared channels without being represented as guests in your directory.

B2C (C) provides identity and access management for consumer-facing applications, letting customers sign in with local or social identities. Conditional Access (B) and Identity Protection (E) are Microsoft Entra ID security features that govern and protect sign-ins, but they are not components of the External Identities suite.

Exam trap

The trap here is that candidates often confuse security features like Conditional Access or Identity Protection with the core identity management components of the External Identities suite, because Microsoft bundles these services under the broader Microsoft Entra umbrella, but the exam specifically tests which services directly handle external user identity lifecycle and collaboration.

668
MCQhard

You are reviewing a Microsoft Purview DLP policy rule represented in JSON. What is the effect of this rule?

A.It blocks the sending of an email if it contains 10 or more credit card numbers with high confidence
B.It notifies the user when a single credit card number is detected in email
C.It triggers a policy tip when a single credit card number is detected
D.It blocks access to a SharePoint site containing credit card numbers
AnswerA

This option accurately describes a Microsoft Purview DLP policy configured to prevent data exfiltration. The policy rule is set to detect the presence of 10 or more credit card numbers, identified with a high confidence level, within an email message. Upon this condition being met, the specified action is to block the sending of that email, ensuring sensitive data remains within organizational boundaries.

Why this answer

The JSON rule defines a condition where the DLP policy blocks email transmission when the count of credit card numbers detected with high confidence meets or exceeds 10. The 'BlockAccess' action in the rule enforces this by preventing the email from being sent, and the 'NotifyUser' action with 'NotifyOnly' set to false ensures the user is notified of the block. This matches the behavior of a Microsoft Purview DLP policy that uses a threshold-based condition with high confidence to block sensitive data sharing.

Exam trap

The trap here is that candidates often confuse the 'NotifyUser' action with a simple policy tip or notification, overlooking that the 'BlockAccess' action combined with a threshold count (10) means the email is blocked, not just flagged, and that the rule is scoped to Exchange, not SharePoint.

How to eliminate wrong answers

Option B is wrong because the rule specifies a minimum count of 10 credit card numbers (via the 'Count' parameter set to 10), not a single instance, and the action is 'BlockAccess' with notification, not merely a notification without blocking. Option C is wrong because a policy tip is a type of notification that appears in Outlook or other apps, but the rule's 'NotifyUser' action with 'NotifyOnly' set to false indicates a block occurs, not just a tip; a policy tip alone would require 'NotifyOnly' set to true. Option D is wrong because the rule's 'Location' is set to 'Exchange' (email), not SharePoint; DLP policies are location-specific, and this rule applies to email transport, not SharePoint site access.

669
Multi-Selecthard

An organization uses Microsoft Purview Audit to meet compliance requirements. Which TWO types of audit logs can be accessed?

Select 2 answers
A.Windows Security event logs
B.Azure Active Directory audit logs
C.Purview advanced audit logs
D.Microsoft 365 unified audit log
E.Azure SQL Database audit logs
AnswersC, D

Purview advanced audit logs represent an enhanced set of auditing capabilities available with specific Microsoft 365 E5 compliance licenses. These logs provide higher fidelity events, such as detailed mailbox item access or eDiscovery search activities, and offer extended audit log retention periods up to 10 years. They are integral to advanced forensic investigations and meeting stringent regulatory compliance requirements, building upon the foundational unified audit log.

Why this answer

Microsoft Purview Audit provides two primary audit log access methods: the Microsoft 365 unified audit log, which aggregates audit records from various Microsoft 365 services, and Purview advanced audit logs, which offer extended retention (up to 10 years) and high-value events like investigation of privileged access. These two options directly correspond to the core audit capabilities within Purview for compliance requirements.

Exam trap

The trap here is that candidates confuse Azure AD audit logs (which are part of Azure Monitor) with the Microsoft 365 unified audit log (which is part of Purview), leading them to select Option B as a correct answer when it is actually a separate service.

670
Multi-Selecteasy

Which TWO Microsoft Purview solutions can help detect and prevent data exfiltration?

Select 2 answers
A.Microsoft Purview Insider Risk Management
B.Microsoft Purview Audit
C.Microsoft Purview Data Loss Prevention
D.Microsoft Purview Compliance Manager
E.Microsoft Purview eDiscovery
AnswersA, C

Microsoft Purview Insider Risk Management proactively detects and acts on malicious or inadvertent insider activities that could lead to data exfiltration. It leverages machine learning and behavioral analytics across Microsoft 365 services to identify unusual or risky user behaviors, such as downloading large amounts of sensitive data or sharing it externally, providing alerts and enabling remediation actions to prevent data loss.

Why this answer

Microsoft Purview Insider Risk Management (A) is correct because it uses behavioral analytics and signals (e.g., file downloads, exfiltration to personal cloud storage, USB activity) to detect risky user activity and trigger alerts, policies, and remediation workflows aimed at preventing data exfiltration. Microsoft Purview Data Loss Prevention (C) is correct because DLP policies detect and block sensitive data (based on sensitive information types, trainable classifiers, or labels) as it is shared across endpoints, Exchange Online, SharePoint, OneDrive, Teams, and other locations, directly preventing exfiltration. Microsoft Purview Audit (B) only records and searches activity logs for later investigation; it does not detect or prevent exfiltration in real time.

Microsoft Purview Compliance Manager (D) assesses and tracks regulatory compliance posture via assessments and improvement actions, not data exfiltration. Microsoft Purview eDiscovery (E) is used to identify, preserve, collect, and review content for legal or investigative cases, not to detect or block exfiltration.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Audit (logging) with a detection or prevention capability, or assume Compliance Manager or eDiscovery have a security monitoring role, when in fact they serve compliance and legal functions respectively.

671
MCQmedium

Your organization recently deployed Microsoft Defender for Cloud Apps. You need to identify which users are using a personal Dropbox account to access corporate files. Which feature should you use?

A.Activity policies
B.Cloud Discovery
C.File policies
D.App permissions
AnswerB

Cloud Discovery is a core capability of Microsoft Defender for Cloud Apps (MDCA) that analyzes traffic logs from firewalls and proxies to identify all cloud services accessed by users in an organization. It provides comprehensive visibility into shadow IT by detecting unsanctioned cloud applications, assessing their risk levels, and generating reports that help administrators understand usage patterns and potential security or compliance gaps.

Why this answer

B is correct because Cloud Discovery in Microsoft Defender for Cloud Apps analyzes traffic logs from your network to identify shadow IT usage, including users accessing personal Dropbox accounts from corporate devices. It uses anonymized data from Microsoft Intelligent Security Graph to detect unsanctioned cloud apps and map user activity, enabling you to pinpoint which users are bypassing corporate storage policies.

Exam trap

The trap here is that candidates confuse Cloud Discovery (which identifies unsanctioned app usage) with Activity policies (which monitor actions within already-sanctioned apps), leading them to choose A because they think monitoring user actions is sufficient to detect personal account use.

How to eliminate wrong answers

Option A is wrong because Activity policies monitor and respond to specific user actions (e.g., multiple failed logins) but do not discover unknown cloud apps or identify personal account usage. Option C is wrong because File policies focus on detecting and protecting sensitive content within sanctioned apps (e.g., files containing credit card numbers), not on discovering unsanctioned app usage like personal Dropbox. Option D is wrong because App permissions manage OAuth token grants for third-party apps connected to Microsoft 365, not the detection of personal cloud storage accounts.

672
MCQeasy

A security architect is designing a defense strategy for a company's IT infrastructure. The strategy includes deploying a network firewall, using an intrusion detection system, installing antivirus software on all endpoints, and requiring multi-factor authentication for all user accounts. The architect explains that if the firewall fails, the IDS can detect an intrusion, and if the IDS misses something, the antivirus might catch it, and MFA can protect even if credentials are compromised. Which security principle best describes this layered approach?

A.Defense in depth
B.Least privilege
C.Zero Trust
D.Shared responsibility
AnswerA

Defense in depth is a security strategy that employs a series of layered and overlapping security controls to protect assets. The principle is that if one security control fails or is bypassed, another control will be in place to prevent or detect an attack. This multi-layered approach, encompassing administrative, technical, and physical safeguards, significantly enhances an organization's overall resilience against diverse threats, ensuring no single point of failure compromises security.

Why this answer

Defense in depth is the correct principle because it describes a layered security strategy where multiple independent controls (firewall, IDS, antivirus, MFA) are deployed so that if one layer fails, another layer can still prevent or detect an attack. This approach explicitly relies on redundancy and diversity of controls to provide resilience against failures or bypasses, as illustrated by the architect's explanation of how each subsequent layer compensates for potential gaps in the previous one.

Exam trap

The trap here is that candidates may confuse 'Defense in depth' with 'Zero Trust' because both involve multiple controls, but Zero Trust is specifically about continuous verification and micro-segmentation, not the layered redundancy described in the scenario.

Why the other options are wrong

B

The question describes multiple overlapping security controls (firewall, IDS, antivirus, MFA) working together, which is the essence of defense in depth. Least privilege focuses on granting only necessary permissions, not layering controls.

C

The question describes multiple overlapping security controls (firewall, IDS, antivirus, MFA) working together, which is the essence of defense in depth, not Zero Trust. Zero Trust is a security model that assumes no implicit trust and requires continuous verification, but it is not specifically about layering multiple independent defenses.

D

The question describes multiple overlapping security controls (firewall, IDS, antivirus, MFA) working together, which is the essence of defense in depth. Shared responsibility refers to the division of security tasks between a cloud provider and customer, not a layered defense strategy.

When would these options actually be correct?

B

A question asks: 'Which security principle ensures that users have only the access rights necessary to perform their job functions?' In that context, least privilege would be the correct answer.

C

A question that asks: 'A company implements a policy where every access request is authenticated, authorized, and encrypted regardless of the network location, and no device is trusted by default. Which security principle does this represent?' In that scenario, Zero Trust would be the correct answer.

D

An exam question might ask: 'A company uses a cloud provider for infrastructure. The provider secures the physical data center, while the company configures access controls and encrypts data. Which principle does this illustrate?' In that context, shared responsibility is correct.

Why candidates pick the wrong answer

B

Candidates may confuse 'layered' with 'restrictive' and think that limiting privileges is part of the layered approach, but least privilege is about access control, not defense layers.

C

Candidates may confuse Zero Trust with defense in depth because both involve multiple security measures. However, Zero Trust focuses on eliminating implicit trust and verifying every access, while defense in depth is about layering independent defenses to provide redundancy.

D

Candidates may confuse 'shared responsibility' with 'layered defense' because both involve multiple parties or layers, but shared responsibility is about dividing security duties between provider and customer, not stacking controls.

673
MCQmedium

An organization needs to automatically apply a 'Confidential' label to documents that contain EU personal data, and also encrypt those documents. Which Microsoft Purview feature should they configure?

A.Data Loss Prevention (DLP) policy
B.Retention label policy
C.Data classification service
D.Auto-labeling policy
AnswerD

An auto-labeling policy for sensitivity labels is specifically configured to automatically detect and apply predefined sensitivity labels to content that matches specific conditions, such as the presence of sensitive information types, keywords, or patterns. This capability directly addresses the need to automatically apply a 'confidential' label, which can then enforce protective actions like encryption, visual markings, and access restrictions, ensuring consistent data protection without manual intervention.

Why this answer

Auto-labeling policies can be configured to automatically apply sensitivity labels based on sensitive info types like EU personal data. Sensitivity labels support encryption. Data classification is a prerequisite, but auto-labeling is the feature that applies the label automatically.

674
MCQmedium

A company uses Microsoft Sentinel for security operations. They want to automatically create an incident and assign it to a senior analyst when a high-severity alert is generated. Which feature should they use?

A.Analytics rule
B.Automation rule
C.Workbook
D.Playbook
AnswerB

Automation rules are a core component of Microsoft Sentinel's Security Orchestration, Automation, and Response (SOAR) capabilities, enabling automated responses to alerts and incidents. They can be configured to automatically create incidents from incoming alerts, apply specific tags, change the incident status, and assign the incident to a designated owner or group. This direct capability to create and assign incidents makes them the correct choice for streamlining security operations.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically trigger incident creation, assignment, and other actions when an alert is generated. By configuring an automation rule with a condition for high-severity alerts, you can set it to create an incident and assign it to a specific senior analyst, streamlining the response process.

Exam trap

The trap here is that candidates often confuse playbooks with automation rules, thinking playbooks are required for incident creation, when in fact automation rules can directly create and assign incidents without needing a playbook.

How to eliminate wrong answers

Option A is wrong because analytics rules are used to generate alerts based on data queries, not to automate incident creation or assignment after an alert is generated. Option C is wrong because workbooks are visualization tools for dashboards and reports, not for automating incident workflows. Option D is wrong because playbooks are automated response workflows (often using Azure Logic Apps) that can be triggered by automation rules, but they are not the feature that directly creates and assigns incidents; automation rules handle that initial incident creation and assignment.

675
MCQmedium

An organization uses Microsoft Entra ID. They want to automatically detect when a user's sign-in shows a high risk of compromise (e.g., impossible travel, anonymous IP address) and immediately require the user to reset their password. Which Microsoft Entra capability should they use?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Access Reviews
AnswerB

Microsoft Entra ID Protection is the correct service for this scenario, as it specializes in detecting identity-based risks, including compromised credentials and suspicious sign-ins. It leverages machine learning to identify user and sign-in risks, and its risk-based policies can be configured to automatically enforce remediation actions. When a high user risk is detected, Identity Protection can be set to require a user to perform a secure password change as a self-remediation step, directly addressing the compromised identity.

Why this answer

B is correct because Microsoft Entra ID Identity Protection uses machine learning to detect risk signals such as impossible travel and anonymous IP addresses. When a user's sign-in is flagged as high risk, Identity Protection can be configured to automatically trigger a password reset as a remediation action, enforcing the principle of least privilege and reducing the window of compromise.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, but Conditional Access is the policy enforcement layer that can use Identity Protection risk detections as a condition, not the detection and remediation engine itself.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-in) based on conditions, but it does not itself detect risk signals or automatically trigger password resets; it relies on Identity Protection risk detections as a condition. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not user sign-in risk detection or password reset automation. Option D is wrong because Access Reviews are used for periodic attestation of group memberships or role assignments, not for real-time risk-based sign-in detection or password reset enforcement.

Page 8

Page 9 of 18

Page 10