Courseiva

SC-900 · domain

scenario questions

Practise Microsoft Security, Compliance, and Identity Fundamentals SC-900 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

1250 questions353 easy551 medium346 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (1250)

Click any question to see the full explanation, or start a practice session above.

1

A company hosts a line-of-business application on an Azure virtual machine. The IT team is responsible for configuring the operating system, installing security updates, and managing the application code. An auditor asks who is responsible for the physical security of the data center where the virtual machine runs. According to the shared responsibility model for cloud services, who is responsible?

Hard
2

Which TWO scenarios are addressed by Microsoft Entra ID Protection? (Choose two.)

Easy
3

A company uses Microsoft 365 and wants to protect its users from malicious links and attachments in email, as well as phishing attacks. Which Microsoft security solution is specifically designed for email and collaboration protection?

Medium
4

Your organization uses Microsoft Purview to classify data. You need to automatically apply a 'Confidential' label to documents that contain salary information. Which type of sensitivity label configuration should you use?

Medium
5

A company has been fined for failing to respond to a data subject access request (DSAR) within the required timeframe. The compliance team needs to streamline the process of identifying and exporting personal data when a DSAR is received. Which Microsoft Purview solution should they use?

Medium
6

Which TWO capabilities are provided by Microsoft Entra External ID? (Choose two.)

Easy
7

You are a security administrator for Contoso Ltd., which uses Microsoft 365 E5. The company has 10,000 users and uses Microsoft Entra ID for identity. The security team has noticed an increase in sign-in attempts from anonymous IP addresses and from locations outside the company's home country. They want to implement a solution that automatically blocks sign-ins from anonymous IP addresses and requires MFA for sign-ins from outside the home country. They also want to ensure that if a user's risk level is high, they are forced to change their password. The solution must use Microsoft Entra ID Protection and Conditional Access. You have already configured a Conditional Access policy to require MFA for all users. Which of the following is the most efficient way to meet all requirements with minimal administrative overhead?

Hard
8

A company deploys a custom application on Azure App Service (PaaS). Which of the following security responsibilities falls completely under the customer's scope according to the shared responsibility model?

Hard
9

A financial services company needs to monitor employee communications in Microsoft Teams and Exchange Online for potential policy violations, such as sharing insider trading tips. They want to automatically detect specific keywords and phrases, and then allow designated reviewers to flag and escalate the messages. Which Microsoft Purview solution should they use?

Medium
10

A company uses Microsoft Entra ID. The security team wants to configure automated actions when user sign-ins are detected as high risk due to anonymized IP addresses or leaked credentials. They need to automatically block the sign-in or force a password change based on risk level. Which Microsoft Entra ID feature should they use?

Medium
11

Your company is implementing a new application that requires users to authenticate using Microsoft Entra ID. The security team wants to enforce multifactor authentication (MFA) for all users accessing this application, but only when they are connecting from an untrusted network. Which conditional access policy should you configure?

Medium
12

A company uses Microsoft 365 and needs to identify and protect sensitive data, such as credit card numbers, stored in SharePoint Online and OneDrive for Business. They also want to prevent users from sharing this data externally. Which Microsoft Purview solution should they use?

Medium
13

Your organization uses Microsoft Defender for Cloud Apps to monitor cloud app usage. You discover that a user is accessing a sanctioned app from an unmanaged device. You need to ensure that when users access this app from unmanaged devices, they are prompted for additional authentication and their session is monitored. What should you configure?

Medium
14

Refer to the exhibit. You are a security administrator for a company using Azure Virtual Network Manager. You have deployed the security admin configuration shown. What is the impact of this rule?

Hard
15

Your organization uses Microsoft Defender for Cloud to secure Azure resources. You need to ensure that all storage accounts have soft delete enabled to protect against accidental deletion. Which policy should you implement?

Medium
16

Refer to the exhibit. You run the PowerShell command to search the unified audit log for file deletions. The command returns no results, but you know a file was deleted last week. What is the most likely reason?

Medium
17

A company uses Microsoft Purview to classify and label data. The compliance team needs to automatically apply a 'Highly Confidential' sensitivity label to any document containing a passport number that is stored in SharePoint Online. The label should also encrypt the document. What should the compliance team configure?

Hard
18

Refer to the exhibit. You are reviewing a risk detection report in Microsoft Entra Identity Protection. The report shows a user with high risk level and two risk events. What does the status 'remediated' indicate?

Medium
19

A company uses Azure virtual machines and also has physical servers in their on-premises datacenter. The security team needs a single dashboard to view security recommendations, detect misconfigurations, and get a secure score for both environments. They also want to integrate with Microsoft Defender for Cloud for threat protection. Which Microsoft security solution provides this unified visibility across hybrid workloads?

Medium
20

A company wants to improve its security awareness program by periodically sending simulated phishing emails to employees to test their ability to identify malicious messages. The results should be tracked in a dashboard that shows which employees clicked the links. Which Microsoft 365 Defender capability should they use?

Medium
21

Sequence the steps to set up Microsoft Sentinel for a new workspace.

Medium
22

A multinational corporation has data stored across multiple clouds (Azure, AWS) and on-premises. The data governance team needs to create a single inventory of all data assets, automatically classify sensitive data (e.g., credit card numbers) across these sources, and track how data moves and transforms (lineage). Which Microsoft Purview solution should they use?

Hard
23

Your organization is adopting a Zero Trust security model. You are tasked with implementing identity protection. The requirements are: enforce multi-factor authentication (MFA) for all users when accessing cloud applications, ensure that risky sign-ins are detected and blocked automatically, and provide administrators with a dashboard showing user risk levels. You have Microsoft Entra ID P2 licenses. What should you configure?

Easy
24

A security administrator is explaining authentication and authorization to new IT staff. Which statement correctly describes the difference between these two processes?

Easy
25

A company operates an e-commerce website that must remain accessible during high-traffic holiday seasons. The IT team deploys additional web servers and implements automatic failover to a secondary data center if the primary site goes down. Which security principle is the company primarily addressing?

Easy
26

A company wants to proactively detect and investigate potential insider security risks, such as a departing employee copying large amounts of data to a personal USB drive or sharing confidential files with unauthorized individuals. Which Microsoft Purview solution should they use?

Hard
27

An organization uses Microsoft Purview Information Protection to classify and protect data. Which TWO methods can be used to apply sensitivity labels automatically?

Hard
28

A security manager explains that the company's security strategy relies on multiple layers of controls, such as firewalls, antivirus software, and multi-factor authentication, so that if one layer fails, another can still prevent an attack. Which security principle does this strategy best represent?

Easy
29

An organization uses Microsoft Intune to manage devices. The security team wants to ensure that only devices with a minimum OS version and antivirus enabled can access corporate email. What should they configure?

Medium
30

An organization uses Microsoft Purview Communication Compliance. They need to monitor Microsoft Teams messages for potential insider trading language. What should they configure?

Easy
31

An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to prevent users from sharing credit card numbers via email outside the company. Which type of DLP rule action should they configure?

Easy
32

A company uses Microsoft Entra ID for identity management. They want to allow employees to sign in using their existing Facebook credentials. Which feature should they configure?

Easy
33

You run the following KQL query in Microsoft Sentinel. What is the purpose of this query? ```kusto SigninLogs | where UserPrincipalName == "admin@contoso.com" | where ResultType == "50126" | summarize FailedAttempts = count() by IPAddress | sort by FailedAttempts desc ```

Hard
34

A security administrator configures user accounts so that employees have only the permissions necessary to perform their job functions and no more. Which security concept is being applied?

Easy
35

A cybersecurity analyst uses Microsoft Sentinel to detect threats. Which THREE types of analytics rules can be created?

Medium
36

Which of the following is a primary purpose of Microsoft Entra ID Identity Protection?

Easy
37

A company uses Microsoft Entra ID and has multiple departments with separate organizational units (OUs) in its on-premises Active Directory. The help desk team needs to be able to reset passwords for users only in the Finance department. What feature should be used to delegate this administrative scope?

Hard
38

A company uses Microsoft Defender for Endpoint. An alert indicates that a device is communicating with a known malicious IP address. The security team wants to automatically block the IP address on all devices. Which action should they configure?

Hard
39

Which TWO of the following are Microsoft Purview solutions that help protect sensitive data?

Easy
40

A law firm uses Microsoft 365. They must retain all client communication records for 10 years due to regulatory requirements. After 10 years, the records must be permanently deleted. Additionally, they need to ensure that users cannot permanently delete these records before the retention period ends. Which Microsoft Purview solution should they configure?

Hard
41

You need to implement a solution that allows users to access cloud applications without entering a password, using Windows Hello for Business. Which Microsoft Entra feature integrates with Windows Hello for Business?

Hard
42

A company uses Microsoft Entra ID. The IT department has three teams: Helpdesk, Global Administrators, and Security Administrators. The company wants to allow the Helpdesk team to manage password resets and group memberships, but only for users who belong to the 'Sales' organizational unit. Which Microsoft Entra feature should the administrator use to define this delegated administrative scope?

Medium
43

Which TWO are capabilities of Microsoft Entra ID Governance? (Choose two.)

Hard
44

A company uses Microsoft Entra ID. The security team wants to automatically respond to risky user behaviors, such as sign-ins from anonymous IP addresses or impossible travel between geographically distant locations within an unrealistic time frame. They need a solution that can automatically trigger actions like forcing a password reset or blocking sign-in for users identified as high risk. Which Microsoft Entra ID capability should they configure?

Medium
45

An organization wants to automatically retain emails for 7 years and then delete them. They also need to place a legal hold on specific users' mailboxes to preserve all emails during litigation. Which combination of Microsoft Purview features should they use?

Medium
46

Which THREE actions can Microsoft Sentinel perform as part of automated incident response using playbooks?

Hard
47

Your organization uses Microsoft Purview Communication Compliance to detect potential policy violations in Microsoft Teams chats. Which action can the policy automatically take when a violation is detected?

Easy
48

Your organization is using Microsoft Entra ID. You want to provide a single sign-on (SSO) experience for users accessing multiple SaaS applications. Which feature should you implement?

Easy
49

A company has on-premises Active Directory. They want to detect advanced attacks like Pass-the-Hash, DCSync, and malicious Kerberos activity using behavioral analytics. Which Microsoft security solution should they deploy on their domain controllers?

Medium
50

A user scans their fingerprint to unlock a corporate laptop. After unlocking, the user attempts to open a confidential database. The system checks the user's role and grants access because the user is a member of the 'Data Analyst' group. Which two security concepts are demonstrated in this scenario?

Easy
51

Your organization uses Microsoft Purview to manage data classification. You need to ensure that a specific Azure Blob Storage account is automatically classified for sensitivity labels. Which step is required?

Hard
52

Your organization uses Microsoft Purview Data Lifecycle Management to retain data for regulatory compliance. You need to ensure that all documents in a SharePoint site are retained for 7 years after they are last modified. What should you create?

Medium
53

A security analyst in your organization receives an alert from Microsoft Defender XDR indicating that a user's device may be infected with ransomware. The analyst needs to immediately isolate the device from the network to prevent further spread. What should the analyst do?

Medium
54

Your company wants to use Microsoft Entra ID to provide single sign-on (SSO) to a SaaS application that supports SAML 2.0. What should you configure in Microsoft Entra ID?

Medium
55

A multinational company stores customer data across multiple Azure regions. A new regulation requires that customer data must remain within the country's borders and cannot be transferred abroad. Which concept does this regulation primarily relate to?

Medium
56

Refer to the exhibit. A Microsoft Purview Data Loss Prevention (DLP) policy is configured. What does this policy do?

Hard
57

A company uses Microsoft Entra ID. The security team wants to automatically block sign-ins from IP addresses that exhibit brute-force attack patterns. Which capability should they enable?

Easy
58

A company uses Microsoft Defender for Cloud Apps. The security team discovers that a user has granted a third-party OAuth app with 'read all mail' and 'send mail as user' permissions. They want to automatically revoke the authorization for this risky app and block similar apps in the future. Which Defender for Cloud Apps feature should they use?

Medium
59

A company uses Microsoft Entra ID and wants to automatically detect potential security risks such as leaked credentials and suspicious sign-in patterns. They also need the ability to investigate these risks and configure automated responses based on risk levels. Which Microsoft Entra capability should they use?

Medium
60

Your organization uses Microsoft Entra ID free tier. You need to synchronize user accounts from your on-premises Active Directory to the cloud. You also need to synchronize password hashes so that users can use the same password for cloud and on-premises resources. Which tool should you use?

Easy
61

A company wants to protect against malware and phishing attacks in email and collaboration tools like Microsoft Teams. Which Microsoft security solution should they use?

Medium
62

You are the identity administrator for a large enterprise using Microsoft Entra ID. The company has 50,000 users and recently acquired a smaller company with 2,000 users that uses a third-party identity provider (IdP) based on SAML 2.0. The acquisition must be fully integrated within 30 days. The CISO mandates that all users must use MFA for any access to cloud applications. The acquired company's users currently do not use MFA. You need to choose an approach that minimizes changes to the acquired company's current authentication infrastructure while meeting the MFA requirement. The solution must also allow the acquired company's users to access resources in the parent tenant using their existing credentials. What should you do?

Hard
63

Your organization wants to label emails and documents as 'Confidential' automatically based on content patterns. Which Microsoft Purview feature should you use?

Easy
64

Refer to the exhibit. You are reviewing the results of a Microsoft Purview eDiscovery search. Which statement is correct about the search results?

Medium
65

Your company is implementing Microsoft Purview Data Loss Prevention (DLP). You need to prevent users from sharing sensitive data like credit card numbers via email with external recipients, but allow internal sharing. What should you configure?

Hard
66

A security team needs to detect and investigate suspicious activities in their on-premises Active Directory environment, such as pass-the-hash attacks, Kerberoasting, and unusual service account behavior. They also want to integrate these alerts with Microsoft Defender for Cloud for a unified view across hybrid workloads. Which Microsoft security solution should they deploy on-premises?

Medium
67

You are reviewing a Microsoft Purview sensitivity label configuration. Based on the exhibit, what will happen when this label is applied to a document?

Medium
68

Which TWO of the following are features of Microsoft Sentinel? (Choose two.)

Easy
69

Refer to the exhibit. The exhibit shows an Azure Policy definition. A storage account named 'storagedev' is created with network ACLs set to allow all traffic (defaultAction: Allow) and no IP rules. What will happen when this policy is assigned?

Medium
70

A company wants to reduce the attack surface on its Windows devices by blocking common techniques used by malware, such as preventing Office applications from creating child processes or blocking executable files from running from the %TEMP% folder. Which Microsoft Defender for Endpoint feature should be configured?

Easy
71

Your company uses Microsoft Entra ID. You need to monitor and detect suspicious sign-in activities, such as sign-ins from anonymous IP addresses or unfamiliar locations. Which Microsoft Entra feature provides this capability?

Medium
72

A company uses Microsoft Intune to manage its devices. The security team wants to enforce that all devices running Windows 11 must have BitLocker enabled and a minimum operating system build version. Which Intune policy type should they use?

Easy
73

An organization uses Microsoft 365. They need to prevent users from sharing credit card numbers in emails and Microsoft Teams messages. When a user attempts to share such sensitive information externally, the message should be blocked and the user should receive a policy tip notification. Which Microsoft Purview solution should they configure?

Medium
74

A company uses Microsoft Entra ID. They want to ensure that only users with a specific role can reset passwords for other users in their organization. Which feature should they use?

Medium
75

A security architect is designing a defense strategy for the organization's network. The architect assumes that an attacker may already have breached the perimeter and is operating inside the network. Therefore, the design does not automatically trust any user or device, even if they are inside the corporate network, and requires continuous verification for every access request. Which security principle does this approach best represent?

Easy
76

Refer to the exhibit. The exhibit shows an alert from Microsoft Defender XDR. The security team needs to determine if the file 'invoice.docm' is known malware and if other devices in the organization have this file. What should they do next?

Hard
77

Which THREE capabilities are provided by Microsoft Purview? (Choose three.)

Hard
78

A company uses Microsoft Entra ID. The security manager wants to provide temporary, time-bound elevated access to the Global Administrator role only when needed, and require approval from a designated approver. Which Microsoft Entra ID capability should they use?

Easy
79

Which THREE of the following are capabilities of Microsoft Defender for Office 365?

Medium
80

A company uses Microsoft Entra ID. The security team wants to configure a policy so that when a user signs in from an unfamiliar location (not on the company's trusted IP ranges) or from an unfamiliar device, they are prompted for additional verification (e.g., MFA). However, if the sign-in is from a trusted location (e.g., office IP range) and a known device, no additional verification is required. Which Microsoft Entra ID feature should they configure?

Medium
81

Refer to the exhibit. You are reviewing a Conditional Access policy JSON in Microsoft Entra ID. What will this policy do?

Medium
82

Your organization is implementing a Zero Trust security model. Which Microsoft Entra ID capability helps verify the identity of users before granting access to resources?

Easy
83

A security architect is designing a Zero Trust strategy. Which principle ensures that network location alone does not grant trust, and all access requests must be verified?

Medium
84

A company uses Salesforce and Box as cloud apps. The security team discovers that a third-party OAuth app with excessive permissions was granted access to Salesforce data by a user. They want a solution that can detect such risky OAuth apps and automatically revoke their permissions based on policy. Which Microsoft security solution provides this capability?

Hard
85

You are the security administrator for a small business that uses Microsoft 365 Business Premium. The company wants to enable multi-factor authentication (MFA) for all users. You need to ensure that users are prompted for MFA when they sign in from unfamiliar locations or devices. The solution should be easy to deploy without additional licensing. Which of the following should you configure?

Easy
86

Your organization plans to migrate from on-premises Active Directory to Microsoft Entra ID. You need to design the identity synchronization strategy to support password hash synchronization and password writeback. Which tool should you use?

Hard
87

Match each Microsoft 365 compliance feature to its function.

Medium
88

A user logs into the company's network using their username and password. After successful login, the user attempts to open a financial report but receives an access denied message because they are not a member of the 'Finance' security group. Which security concept is best illustrated by the access denial?

Easy
89

A company wants to prevent users from setting weak passwords that are commonly found in leaked databases. They use Microsoft Entra ID (Microsoft Entra ID). Which feature should they enable?

Medium
90

A company uses a hashing algorithm to verify that a downloaded software file has not been tampered with during transmission. This practice primarily protects which security principle?

Easy
91

You run the Microsoft Graph PowerShell command in the exhibit. What information does this command retrieve about the user?

Medium
92

A security analyst needs to investigate a potential data exfiltration incident involving sensitive files being sent via email. Which Microsoft Purview solution provides the necessary monitoring?

Easy
93

Your organization uses Microsoft Entra ID and wants to automatically block sign-ins from users located in countries that are not approved for business operations. Which Microsoft Entra ID feature should you configure?

Easy
94

A company regularly performs automated backups of its critical databases and has a disaster recovery plan to restore operations quickly after a system failure. Which security principle is primarily being addressed by these measures?

Easy
95

Your organization uses Microsoft Sentinel to detect threats. A security analyst needs to create a custom analytics rule that triggers an incident when a user accesses more than 1000 files from an external IP address within 5 minutes. Which rule type should the analyst configure?

Hard
96

A user reports that they cannot access a critical application, receiving an error that their session has expired. The sign-in logs show the user was prompted for multifactor authentication (MFA) multiple times during the same session. What should an administrator review to reduce these interruptions?

Medium
97

A company wants to use Microsoft Defender for Cloud to secure their hybrid cloud environment. Which FOUR resource types can be assessed by Defender for Cloud?

Easy
98

A small consulting company, Northwind Traders, uses Microsoft 365 Business Premium and wants to implement basic compliance solutions. They have 50 users and need to: (1) prevent employees from sharing customer credit card information via email; (2) retain all deleted emails for 1 year; (3) allow users to classify documents as 'Confidential' manually; (4) generate reports on policy violations. The company has limited IT staff and wants a quick, out-of-the-box solution. What should they configure?

Easy
99

Your company is subject to GDPR and must be able to respond to data subject requests (DSRs) by finding all personal data of a specific user across Microsoft 365. Which Microsoft Purview solution should you use?

Easy
100

A company uses Microsoft Sentinel as its SIEM. They need to create a custom analytics rule that runs every hour and queries for failed logins from a specific IP address. Which rule scheduling option should they configure?

Hard
101

Your organization uses Microsoft Entra ID. Which THREE authentication methods can be used for passwordless sign-in?

Hard
102

Refer to the exhibit. A legal team needs to preserve all documents in SharePoint and OneDrive for 5 years. The current policy retains for 1 year. What should the administrator do to meet the requirement?

Medium
103

A company is implementing Microsoft Purview Information Protection. They want to automatically apply a 'Confidential' sensitivity label to emails containing credit card numbers. Which policy should they configure?

Hard
104

A security operations center (SOC) team needs to collect security logs from Azure services, on-premises servers, and third-party firewalls. They want a cloud-native solution that provides advanced threat detection through analytics, machine learning, and the ability to hunt for threats across all data sources. Which Microsoft solution should they deploy?

Medium
105

Your company uses Microsoft Defender for Cloud Apps. You notice that a user is downloading large volumes of data from a sanctioned cloud app that exceeds the normal pattern. Which action should you take to automatically block this activity?

Hard
106

Your organization needs to ensure that emails containing personally identifiable information (PII) like passport numbers are automatically encrypted before being sent externally. What should you configure in Microsoft Purview?

Hard
107

A company has a SharePoint Online library containing legal contracts. They must satisfy a regulatory requirement that contracts cannot be modified or deleted after they are signed. Additionally, they need to retain the contracts for 10 years after the contract end date, after which they can be disposed of manually. Which Microsoft Purview solution should they implement?

Medium
108

A company uses Exchange Online. The security team wants to protect users from malware hidden in email attachments by detonating them in a secure sandbox environment before delivery. Which Microsoft Defender for Office 365 feature should they enable?

Medium
109

Your organization is deploying Microsoft Entra ID. You need to ensure that users can sign in using their existing on-premises Active Directory credentials without creating new cloud passwords. Which feature should you configure?

Easy
110

A company uses Microsoft Entra ID. They need to implement a Conditional Access policy for the finance application that requires multifactor authentication (MFA) when a user accesses the app from an unmanaged device. Additionally, they want to block access if the sign-in risk level is high. Which two grant controls should they configure in the policy? (Select two.)

Medium
111

An organization wants to ensure that its security team can quickly identify and respond to threats across all workloads, including identities, endpoints, email, and cloud apps. Which Microsoft security solution provides a unified incident management experience?

Medium
112

Which THREE capabilities are provided by Microsoft Purview Compliance Manager?

Hard
113

Your company uses Microsoft Purview Information Protection to classify and protect sensitive data. You need to ensure that when a user sends an email containing a credit card number, the email is automatically encrypted and a custom footer is added. Which two components should you configure?

Medium
114

Match each compliance term to its correct definition.

Medium
115

A company has Microsoft Entra ID with Conditional Access policies. Users report being prompted for MFA every time they access the company's CRM app from their corporate laptops. However, the policy is configured to require MFA only for untrusted locations. What is the most likely cause?

Hard
116

A user reports that they cannot access Microsoft 365 apps from a public Wi-Fi network. The admin sees a Conditional Access policy requiring a compliant device and a trusted location. Which component enforces this policy?

Easy
117

A company is planning to migrate from on-premises Active Directory to Microsoft Entra ID. They have a custom line-of-business application that uses Windows Integrated Authentication and requires Kerberos. Which approach should they use to enable hybrid identity?

Hard
118

Your company is implementing records management for legal retention requirements. Documents must be locked and cannot be modified or deleted after a specific event. Which Microsoft Purview capability should you use?

Medium
119

An organization uses Microsoft Sentinel for security information and event management (SIEM) and security orchestration automated response (SOAR). They want to automatically respond to a specific incident by running a playbook. What should they configure?

Easy
120

An organization is migrating its on-premises applications to Azure Infrastructure-as-a-Service (IaaS). According to the shared responsibility model, which of the following security responsibilities remain with Microsoft? (Select two.)

Medium
121

A company runs workloads in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The security team needs a single, unified dashboard to continuously assess the security posture of all cloud resources, identify misconfigurations, and receive prioritized recommendations for remediation. Which Microsoft security solution should they use?

Medium
122

Which THREE are capabilities of Microsoft Defender XDR?

Hard
123

A university wants to provide its students with a verifiable digital transcript that the students can share with potential employers. The university uses Microsoft Entra Verified ID to issue credentials. When an employer wants to verify a student's transcript, they scan a QR code or receive a link. Which Microsoft Entra ID feature allows the university to issue these tamper-proof credentials and allows employers to verify them without contacting the university directly?

Medium
124

A healthcare organization must comply with HIPAA regulations. They store patient health information (PHI) in SharePoint Online documents. The compliance team needs to automatically detect PHI (e.g., medical record numbers) in documents, apply a sensitivity label that encrypts the document, and prevent users from removing that label. Which Microsoft Purview solution should they configure?

Hard
125

Which THREE features are part of Microsoft Entra ID? (Select three.)

Easy
126

Contoso has a hybrid identity with AD DS synced to Microsoft Entra ID. They want to block legacy authentication protocols that bypass MFA. Which security solution should they use?

Hard
127

A company uses an on-premises Active Directory (AD) and wants to enable single sign-on (SSO) for users to access Microsoft 365 and a third-party SaaS application. They plan to use an external identity provider (IdP) that supports Security Assertion Markup Language (SAML) 2.0. Which identity concept does this implementation primarily rely on?

Hard
128

A company uses Azure SQL Database, which is a Platform as a Service (PaaS) offering. The security team is reviewing the shared responsibility model and wants to know who is responsible for applying operating system patches to the underlying infrastructure that hosts the database. Who is responsible for this task?

Easy
129

Your organization has multiple on-premises directories and wants to synchronize them to Microsoft Entra ID. However, you must avoid duplicate user objects. Which feature should you configure?

Hard
130

An organization uses Microsoft Sentinel for SIEM. The security operations center (SOC) wants to automatically create an incident when a user account is compromised and suspicious activity is detected. Which Microsoft Sentinel feature should be used?

Medium
131

A user accidentally shared a confidential document with an external vendor. You need to revoke access immediately for all copies, even if the file has been downloaded. Which Microsoft Purview feature should you use?

Hard
132

Your organization uses Microsoft Intune for mobile device management. You need to ensure that users cannot copy corporate data from managed apps to personal apps. Which policy should you configure?

Medium
133

Which TWO of the following are capabilities of Microsoft Purview Insider Risk Management? (Select TWO.)

Hard
134

Which TWO of the following are features of Microsoft Purview Audit?

Hard
135

Refer to the exhibit. You are a compliance administrator running PowerShell to update a sensitivity label in Microsoft Purview. The command fails with an error that the label is not found. What is the most likely cause?

Hard
136

Refer to the exhibit. An administrator creates a Conditional Access policy in Microsoft Entra ID. What will this policy do?

Easy
137

A company wants to detect potentially malicious insider activities, such as employees copying large volumes of files to external drives or sending sensitive emails to personal accounts. The security team needs to investigate these activities with visual timelines and assign cases for review. Which Microsoft Purview solution should they use?

Hard
138

Which THREE are features of Microsoft Entra ID? (Choose three.)

Easy
139

Your organization wants to use Microsoft Entra ID to authenticate users from a partner company that uses its own identity provider. Which federation standard should you use?

Easy
140

You are the security administrator for a large healthcare organization that uses Microsoft 365 E5. The organization must comply with HIPAA and GDPR regulations. You have implemented Microsoft Purview Information Protection with sensitivity labels to classify and protect patient data. Recently, the compliance team identified that some documents containing Protected Health Information (PHI) are being shared externally without protection. You need to prevent users from sharing documents classified as 'Highly Confidential' with external users unless the document is encrypted and labeled. Additionally, you must ensure that any external sharing of such documents is automatically blocked. You have the following options available. Which action should you take?

Hard
141

An organization is deploying Microsoft Intune for mobile device management. They need to ensure that all iOS devices must have a passcode of at least 6 characters and the device must be encrypted. What should they configure?

Hard
142

Your company uses Microsoft Defender for Endpoint. A report shows that several devices are missing critical security updates. What feature should you use to deploy the missing updates?

Easy
143

Which TWO Microsoft Purview solutions can be used to discover and classify sensitive data in Microsoft 365? (Select two.)

Medium
144

A company assigns permissions to users based strictly on their job title (e.g., Sales Manager can edit documents, Sales User can only read). Which identity and access management concept is being implemented?

Easy
145

A company wants to allow external business partners to access its internal applications using their own corporate credentials (e.g., their Microsoft Entra ID or Google account), without creating separate user accounts in the company's directory. Which Microsoft Entra ID feature should they use?

Medium
146

A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically trigger a playbook when a high-severity incident is created. Which automation option should be used?

Medium
147

A company stores financial reports in SharePoint Online that contain credit card numbers. The compliance team needs to automatically apply a sensitivity label that encrypts the documents when they detect credit card data. Which Microsoft Purview solution should they configure?

Medium
148

Your organization is implementing Microsoft Purview Information Protection and needs to ensure that files shared externally cannot be forwarded or printed. Which protection mechanism should be applied?

Hard
149

A company uses Microsoft Entra ID. They want to enforce that users accessing the payroll application from outside the corporate network must use multifactor authentication and must access the app only from devices that are marked as compliant by Intune. Which Conditional Access component should they use to combine these requirements?

Medium
150

A company uses Microsoft Entra ID. They have a financial application that should only be accessible from Windows devices. The security team wants to create a Conditional Access policy to block access from other operating systems such as macOS or Linux. Which assignment condition should they configure?

Easy
151

An organization uses Microsoft Purview to manage data compliance. They need to automatically detect and protect credit card numbers stored in SharePoint Online. Which Microsoft Purview solution should they implement?

Medium
152

A company stores sensitive financial data on on-premises Windows Server file shares. The compliance team needs to automatically discover files containing credit card numbers, classify them by applying a sensitivity label, and optionally enforce protection actions like encryption. They want this solution to run on the on-premises file servers without needing to manually scan. Which Microsoft Purview solution should the compliance team deploy?

Hard
153

A company wants to automatically detect and alert the security team when a user sign-in appears to originate from a known compromised credential or from an anonymizing VPN service. The company wants to receive a risk score for each sign-in and be able to trigger automated remediation actions. Which Microsoft Entra ID feature should they enable?

Medium
154

An organization stores sensitive customer data in a cloud database. The security team uses encryption to protect the data while it is stored and while it is transmitted. They also implement role-based access control to ensure only authorized users can modify the data. Which two security principles are primarily being upheld by these actions?

Easy
155

Your organization needs to retain all customer communications data for 7 years due to regulatory requirements. Which Microsoft Purview solution should you use?

Medium
156

A company has an on-premises Active Directory domain and uses Microsoft Entra ID (Azure AD) for cloud applications. They purchase new Windows 10 laptops that are not yet joined to any domain. The IT admin wants users to be able to sign in with their existing on-premises credentials and automatically have the laptops joined to both the on-premises AD domain and Microsoft Entra ID. Which device identity option should the admin configure?

Medium
157

A company uses Microsoft Entra ID. The IT help desk team needs to be able to reset passwords and manage user account properties, but only for users located in the United Kingdom. The organization has created a dynamic group that contains all UK users. Which Microsoft Entra feature should an administrator use to delegate these administrative permissions specifically to the help desk team, limited to the UK user scope?

Medium
158

An organization uses Microsoft Intune to manage devices. They want to ensure that only devices marked as compliant can access corporate email in Exchange Online. Which Conditional Access component should they configure?

Medium
159

You are reviewing a Microsoft Purview auto-labeling policy configuration. Based on the exhibit, what happens when a document contains a credit card number and is labeled 'Confidential'?

Hard
160

A hospital encrypts patient data stored in a database using AES-256 encryption. If an attacker manages to copy the database file, they cannot read the protected information. Which security goal is primarily achieved by this encryption measure?

Easy
161

A company uses cryptographic hashes to verify that a downloaded software file has not been modified by an attacker during transmission. Which principle of the CIA triad is primarily being addressed?

Easy
162

Your company uses Microsoft Defender for Cloud to secure Azure resources. You need to enable network security recommendations for all virtual networks. Which security policy should you enable?

Medium
163

A multinational corporation must comply with GDPR and requires that personal data of EU users be retained for a maximum of 90 days after account closure. After that, all personal data must be permanently deleted. Which combination of Microsoft Purview capabilities should be used?

Hard
164

Your organization has implemented Microsoft Defender for Cloud to protect Azure resources. You are responsible for security posture management. You need to ensure that all Azure VMs have the latest security updates installed. You have enabled automatic VM patching via Azure Update Manager. However, some VMs are not receiving updates because they are not registered with the Update Manager. You need to identify which VMs are missing updates and ensure they are patched. What should you do?

Hard
165

Your organization uses Microsoft Entra ID and Microsoft Sentinel. You need to analyze sign-in logs to detect risky sign-ins that are not blocked by Conditional Access policies. Which Microsoft Entra feature provides risk detection and can feed into Sentinel?

Hard
166

A large enterprise uses Microsoft Entra ID with P2 licenses. The security team wants to implement just-in-time (JIT) access for privileged roles and require approval for role activation. Additionally, they want to receive alerts when a role is activated outside business hours. Which feature should they use?

Hard
167

Refer to the exhibit. The KQL query is run in Microsoft Defender for Endpoint. What is the purpose of this query?

Hard
168

A security analyst downloads a software installer from a vendor's website. To ensure the file has not been tampered with during transmission, the analyst compares the SHA-256 hash of the downloaded file against the hash published on the vendor's official site. This practice primarily validates which security goal?

Easy
169

A company wants to use Microsoft Defender for Office 365 to protect against malicious links in email. Which feature should they enable?

Easy
170

Your organization uses Microsoft Purview to manage data governance. You need to ensure that sensitive financial data containing credit card numbers is automatically detected and labeled when stored in SharePoint Online. Which compliance solution should you configure?

Medium
171

Your organization uses Microsoft Purview to enforce data loss prevention (DLP) policies. You need to ensure that when a user attempts to share a document containing credit card numbers via email, the document is blocked and the user receives a policy tip. What should you configure in the DLP policy?

Medium
172

Your organization uses Microsoft Purview to classify data. You need to automatically apply a 'Confidential' sensitivity label to any document that contains a Social Security number. What should you create?

Medium
173

A multinational organization uses Microsoft Entra ID and wants to allow employees to sign in to a custom customer-facing application using their existing social identities (e.g., LinkedIn, Google). They also need to enforce a specific terms of use agreement and be able to revoke a user's access if their social account is compromised. Which Microsoft Entra capability should they configure?

Hard
174

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to ensure that only devices that are enrolled in Intune and compliant with your organization's security policies can access corporate email. Which Microsoft Entra feature should you use?

Medium
175

Match each identity term to its correct meaning.

Medium
176

A company manages Azure virtual machines and on-premises servers. The security team needs a single dashboard that provides a secure score and actionable recommendations to improve the security posture across both environments. Which Microsoft solution should be used?

Medium
177

A company must retain all financial records for exactly 7 years and then automatically delete them. They need to automatically apply a retention label to any document that contains the words 'Invoice' or 'Statement'. Which Microsoft Purview solution should they use?

Medium
178

Your organization is planning to implement Microsoft Entra ID for identity and access management. Which TWO capabilities are provided by Microsoft Entra ID?

Medium
179

A company needs to ensure that only approved devices can access corporate resources. Which Microsoft Entra feature should they combine with Microsoft Intune?

Medium
180

A Microsoft 365 organization needs to classify and protect sensitive documents based on their content, such as passport numbers. They want the classification to be applied automatically without user intervention. Which Microsoft Purview solution should they use?

Hard
181

A company subscribes to a cloud-based email service that is delivered as Software-as-a-Service (SaaS). According to the shared responsibility model, who is primarily responsible for the physical security of the data centers where the email data is stored?

Easy
182

Your organization needs to create a policy that prevents users from sharing credit card numbers in emails. Which Microsoft Purview solution should you configure?

Easy
183

A company is involved in a legal case and must preserve all emails and documents sent by a specific employee (custodian) that are related to a particular matter. The legal team needs to collect this data into a tamper-proof container for review, ensuring that no original items are modified or deleted. Which Microsoft Purview solution should they use?

Medium
184

A multinational company needs to enforce multi-factor authentication for all users but exclude a break-glass emergency account. Which approach should they take in Microsoft Entra ID?

Hard
185

A company uses Microsoft 365 E5. An employee's corporate laptop is infected with keylogging malware that captures the employee's credentials. The attacker uses these credentials to sign in to Exchange Online and forward sensitive emails to an external account. Under the shared responsibility model, who is primarily responsible for the security incident?

Hard
186

A company uses Microsoft Entra ID (Microsoft Entra ID) and wants to configure self-service password reset (SSPR) for all users. The security team requires that users must verify their identity with at least two methods before resetting a password. Which SSPR setting should be configured?

Medium
187

Which THREE of the following are capabilities provided by Microsoft Entra ID Protection? (Select three.)

Hard
188

A company uses Microsoft Intune for mobile device management (MDM). They need to ensure that corporate data on personal devices is encrypted. Which configuration profile type should they deploy?

Hard
189

A company deploys a custom web application on Azure App Service (PaaS). The application stores user data in Azure SQL Database. The security team is responsible for securing the application code, managing authentication, and configuring TLS for data in transit. According to the Microsoft shared responsibility model, which security responsibility remains with Microsoft for this PaaS deployment?

Hard
190

Refer to the exhibit. An administrator creates a DLP rule as shown. What is the expected outcome when a user tries to share a file containing a U.S. Social Security Number with an external recipient?

Medium
191

Your company uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The security team wants to identify resources that are missing system updates. Which feature should they use?

Easy
192

Your company uses Microsoft Entra ID with P1 licenses. You need to implement a policy that blocks access to Microsoft 365 from countries that are not authorized, except for users who are members of a specific security group. Which Microsoft Entra feature should you use?

Medium
193

Your organization uses Microsoft Purview to label documents. Users report that some documents are automatically labeled as 'Confidential' even though the content is public. Which action should you take to resolve this issue?

Medium
194

A financial services company must comply with a regulation that requires all audit-related documents to be retained for 7 years and then permanently deleted. The compliance officer wants to ensure that even if a user modifies or deletes a file, the original content is preserved for the full 7 years, and at the end of the period the files are automatically destroyed without any manual approval. The company uses Microsoft 365 and stores these documents in SharePoint Online and Microsoft Teams. Which Microsoft Purview solution should the compliance officer configure?

Hard
195

An organization must prove to an auditor that only authorized users have accessed sensitive HR files over the past year. The compliance team needs to generate a report of all access events to these files. Which Microsoft Purview solution should be used?

Hard
196

Refer to the exhibit. User2 attempts to activate the Global Administrator role. What must happen before User2 gains the role?

Hard
197

An organization uses Microsoft Entra ID to manage user access. The security policy requires that membership in the 'Finance - Sensitive Data' group must be reviewed every quarter by the group owner to confirm that each member still requires access. The group owner must approve or deny each membership, and any denied memberships should be automatically removed. Which Microsoft Entra ID feature should be configured to automate this process?

Medium
198

A compliance officer wants a central dashboard to assess the organization's compliance posture against regulatory standards such as GDPR and ISO 27001. They need actionable recommendations to improve their compliance score and track progress over time. Which Microsoft Purview solution should they use?

Medium
199

Which TWO of the following are features of Microsoft Purview Data Loss Prevention (DLP)? (Select TWO.)

Easy
200

Your organization uses Microsoft Intune to manage devices. You need to ensure that only devices with a passcode can access corporate email. What should you configure?

Easy
201

A company is implementing security controls to protect data during transmission between their on-premises database and a cloud storage service. They decide to use TLS encryption. Which security goal is primarily addressed by ensuring that data is not altered during transit?

Easy
202

The exhibit shows that a user was added to the Global Administrator role. Which Microsoft Entra feature should be used to provide just-in-time access to this role?

Easy
203

A company uses Microsoft Entra ID. Their sales team wants to use a third-party customer relationship management (CRM) application that requires the 'Sign in and read user profile' permission and also a high-risk permission to 'Read all users' full profiles'. The security team wants to allow users to request access to this application, but they want to require an administrator to review and approve the high-risk permission request before consent is granted. Which Microsoft Entra ID feature should they configure?

Medium
204

Refer to the exhibit. A security analyst in your SOC runs the provided KQL query in Microsoft Sentinel to identify users with repeated MFA or suspicious sign-in alerts. The query returns no results even though alerts exist. What is the most likely issue?

Hard
205

A financial organization is required by regulation to keep all customer transaction records for 10 years. After 10 years, the records must be permanently deleted. In addition, during the retention period, records must not be modifiable or deletable by any user, including administrators. Which Microsoft Purview solution should they use to meet these requirements?

Medium
206

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their social media accounts, such as Google or Facebook. Which feature should you configure?

Medium
207

Which THREE Microsoft Defender XDR components are included in the unified security operations platform? (Select three.)

Hard
208

Which TWO Microsoft Purview solutions can be used to automatically classify sensitive data at rest?

Easy
209

A compliance officer needs to monitor internal emails for inappropriate language and potential data leaks. The officer wants to detect policy violations and allow users to report concerns. Which Microsoft Purview solution should be used?

Medium
210

Which TWO Microsoft Purview solutions can be used to manage data retention and deletion?

Easy
211

A multinational organization uses Microsoft Entra ID. The IT help desk team is responsible for password resets and group management, but only for users located in the European region. The organization has created a group containing all European user accounts. Which Microsoft Entra feature should an administrator use to delegate these administrative tasks specifically to the help desk team, limited to the European user scope?

Medium
212

A company issues laptops to all employees with BitLocker full-disk encryption enabled. If a laptop is stolen, the data on the hard drive cannot be read without the recovery key. Which security principle does this measure primarily protect?

Easy
213

An organization wants to protect against spear-phishing attacks where attackers impersonate the company's CEO or other trusted domains to trick employees into transferring funds. They need a security solution that uses machine learning to detect and prevent such impersonation attempts in incoming emails. Which Microsoft 365 protection feature should they enable?

Medium
214

You are a compliance officer for a law firm that uses Microsoft 365 E5 licenses. The firm must comply with GDPR. You need to implement a solution that automatically identifies personal data (e.g., email addresses) in SharePoint Online documents and applies a 'GDPR-Protected' sensitivity label. Additionally, you need to ensure that if a user attempts to share a labeled document externally, they receive a policy tip warning about GDPR compliance, but the share is not blocked. You have Microsoft Purview. What should you configure?

Medium
215

An administrator needs to grant a vendor temporary access to an Azure subscription for exactly 48 hours. After that time, access must be automatically revoked. Which Microsoft Entra feature should be used?

Medium
216

A financial services company is subject to regulations that require monitoring of employee communications for potential market manipulation. The compliance team needs to create policies that automatically detect messages containing phrases like 'insider info' or 'confidential trade' in Microsoft Teams chats and Exchange Online emails. Detected messages should be routed to designated reviewers for investigation, and the company wants a built-in Microsoft Purview solution to handle this process. Which Microsoft Purview solution should they use?

Hard
217

A security analyst is explaining the concept of 'Least Privilege' to a new team member. Which statement best describes the principle of least privilege?

Easy
218

A company implements a policy where each employee is granted only the permissions necessary to perform their specific job role. For example, a marketing specialist has read-only access to the customer database and cannot modify financial records. Which security principle is primarily being applied?

Easy
219

Your organization uses Microsoft Entra ID. Which TWO features help protect against identity-based attacks by detecting and responding to risks?

Medium
220

A company wants employees to be able to access corporate applications from their personal mobile devices, but only if those devices are enrolled in mobile device management (MDM) and have a PIN code set. Which Microsoft Entra capability should the administrator use to enforce these requirements?

Medium
221

Which TWO of the following are capabilities of Microsoft Defender for Cloud? (Choose two.)

Easy
222

You are the compliance administrator for Contoso, a multinational corporation with headquarters in the US and subsidiaries in Europe and Asia. Contoso uses Microsoft 365 E5 and Microsoft Purview. The company handles personal data subject to GDPR and CCPA. You need to design a compliance solution that meets the following requirements: - Automatically classify and protect documents containing personal data in SharePoint Online and OneDrive for Business. - Ensure that data subject requests (DSRs) for access and deletion can be fulfilled within the regulatory timeframes. - Prevent accidental sharing of sensitive data via email and Teams. - Maintain an audit trail of all activities related to personal data for at least one year. - Manage data retention to comply with local laws that require different retention periods for different types of data. Which combination of Microsoft Purview solutions should you use?

Hard
223

A security administrator is explaining the Zero Trust model to a new colleague. The administrator states that trust should never be granted based solely on network location, and every access request must be fully authenticated and authorized using all available signals. Which Zero Trust principle does this statement describe?

Easy
224

A company is involved in litigation and needs to search for specific emails and documents across Exchange Online, SharePoint Online, and Teams. They also need to place a hold on relevant content to prevent deletion. Which Microsoft Purview solution should they use?

Easy
225

A company wants to improve its security posture across Microsoft 365. The security team needs a central dashboard that provides a score based on current security configurations, gives recommendations for improving the score, and allows tracking of improvement actions over time. Which Microsoft security solution should they use?

Medium
226

A company uses Microsoft 365 and wants to automatically apply a 3-year retention label to any document that contains a patent number in the format PAT-XXXXXX. The label should be applied at the time the document is created or modified. Which Microsoft Purview solution should the administrator configure?

Medium
227

An organization is moving a virtual machine to Azure Infrastructure as a Service (IaaS). According to the shared responsibility model, which of the following security tasks is the customer responsible for?

Easy
228

Refer to the exhibit. The JSON shows a conditional access policy. What is the effect of this policy?

Medium
229

A security team uses Microsoft Defender XDR to respond to incidents. Which THREE components are part of Microsoft Defender XDR?

Medium
230

An organization uses Microsoft 365 Defender. The security team receives an alert about a potential malware outbreak on multiple endpoints, and they need an integrated view that correlates signals from various Microsoft security solutions. Which Microsoft 365 Defender portal component provides this unified view?

Medium
231

Your organization wants to prevent users from installing unapproved apps on company-managed Windows devices. Which Microsoft Intune feature should you use?

Easy
232

An organization wants to classify and label data automatically based on sensitive content patterns such as credit card numbers. Which Microsoft Purview solution should they use?

Easy
233

A company has a hybrid environment with on-premises Active Directory. The security team wants to detect advanced attacks such as pass-the-hash, malicious Kerberos ticket activity, and abnormal service account behavior. They want alerts from the on-premises environment to be integrated into Microsoft Defender for Cloud for centralized monitoring. Which Microsoft security solution should they deploy on their domain controllers?

Medium
234

Your organization, Northwind Traders, uses Microsoft Intune to manage Windows 10 devices. You have created a compliance policy that requires devices to have BitLocker enabled. After assigning the policy, you notice that some devices are reporting as non-compliant due to BitLocker not being enabled. You have verified that the devices support BitLocker and that the policy is correctly assigned. You need to ensure that BitLocker is enabled on these devices automatically. What should you do?

Easy
235

Order the steps to deploy Microsoft Intune for mobile device management.

Medium
236

Which TWO Microsoft Purview compliance solutions are used to manage data retention and deletion?

Easy
237

A company wants to automatically classify sensitive documents in Microsoft 365 based on credit card numbers and retain them for 7 years. Which two Microsoft Purview solutions should they use together?

Medium
238

You have a Conditional Access policy in Microsoft Entra ID. The policy has the following settings: Assignments > Users > Include: All guest and external users; Assignments > Target resources > Cloud apps: All cloud apps; Access controls > Grant: Require multi-factor authentication. What is the effect of this policy?

Medium
239

An organization is subject to regulatory requirements that mandate retention of employee records for 5 years after termination. After the retention period, the records must be permanently deleted. The compliance team wants to automatically enforce this process across all Microsoft 365 locations (Exchange, SharePoint, Teams). Which Microsoft Purview solution should they configure?

Medium
240

A company manages Azure resources for multiple departments. The security team needs to grant IT administrators temporary, just-in-time access to high-privilege roles (e.g., Contributor, Owner) only when needed, with approval workflows. Which Microsoft Entra ID capability should they configure?

Medium
241

Which TWO capabilities are provided by Microsoft Defender for Cloud Apps? (Choose two.)

Medium
242

Your company uses Microsoft Defender for Identity to monitor on-premises Active Directory. You receive an alert about a potential lateral movement attack involving a service account. The alert indicates that the account was used to log in to multiple servers from a non-domain-joined machine. You need to investigate the alert and determine if the account is compromised. What should you do first?

Medium
243

A compliance officer needs to automatically detect documents containing passport numbers in SharePoint Online and apply a retention label that retains the documents for 10 years before deleting them. They also want to prevent users from permanently deleting these documents before the retention period ends. Which Microsoft Purview solution should they use to achieve this?

Medium
244

Refer to the exhibit. You are analyzing a Microsoft Purview Data Lifecycle Management retention policy. What is the outcome of this policy?

Hard
245

An organization wants to protect its Azure PaaS services, such as Azure SQL Database and Azure Key Vault, by detecting and alerting on suspicious activities like SQL injection attempts or unusual access patterns. They also need to integrate these alerts into a central security information and event management (SIEM) system for further analysis. Which Microsoft security solution provides the threat detection capability described?

Medium
246

You are evaluating the Conditional Access policy JSON exhibit. The policy includes MFA for Exchange Online but excludes trusted locations. A user reports that they are prompted for MFA when accessing webmail from a trusted IP address. Which is the most likely cause?

Medium
247

A financial services company uses Microsoft Purview and must comply with a regulation that requires communication surveillance for market abuse. They need to capture all electronic communications (email, Teams chats) of traders and scan for specific keywords and trading patterns. Which Microsoft Purview solution is specifically designed for this?

Hard
248

A multinational corporation wants to detect scenarios where employees in the finance department are accessing and downloading customer credit card data from a CRM system and then emailing that data to personal accounts. The security team needs to define policies that identify this pattern of activity, analyze user behavior over time (e.g., building a user's baseline), and automatically escalate high-risk incidents for investigation. Which Microsoft Purview solution should they deploy?

Hard
249

A company uses Microsoft Entra ID. They want to require users to perform multifactor authentication (MFA) every 30 days on devices that are marked as compliant, but require MFA for every sign-in attempt on non-compliant devices. Which Conditional Access control should they configure to meet this requirement?

Medium
250

Your organization uses Microsoft Purview to manage compliance. You need to create a policy that ensures data is retained for a specific period and then automatically deleted. Which solution should you use?

Medium
251

Your organization, Contoso, uses Microsoft Entra ID for identity management. The security team has recently identified that several users have had their credentials compromised. You need to implement a solution that automatically enforces a password change for high-risk users and blocks sign-ins from risky locations. Additionally, you want to allow users to self-remediate by changing their password when they are at medium risk. You have the following requirements: - Users detected as high risk must be blocked from signing in until an administrator resets their password. - Users detected as medium risk must be prompted to change their password via self-service password reset before they can access resources. - All risk detections must be logged and reported to the security team. - The solution must use built-in Microsoft Entra capabilities without third-party tools. Which of the following actions should you take to meet the requirements?

Hard
252

A company uses Microsoft Entra ID (Microsoft Entra ID) to manage access to internal applications for employees and guest users. The compliance team requires that all guest users' access to a sensitive application must be reviewed every 90 days by the application owner. If the owner does not respond to the review request, the guest's access must be automatically revoked. Which Microsoft Entra ID feature should the company use?

Medium
253

A company uses Microsoft Purview to manage data lifecycle. They configure a retention label that marks content as a regulatory record and apply it to sensitive documents. A user with edit permissions attempts to modify a document that has this label applied. What will be the outcome?

Hard
254

Which Microsoft security solution provides centralized investigation and response across identities, endpoints, email, and cloud apps by correlating alerts from multiple sources?

Easy
255

A healthcare organization must comply with HIPAA regulations. They need to classify and protect medical records stored in Microsoft 365. Which Microsoft Purview solution should they use?

Easy
256

You are investigating an alert in Microsoft Defender XDR. Based on the exhibit, what is the primary detection source for this alert?

Hard
257

A SOC analyst in Microsoft Sentinel needs to create a custom detection rule that triggers an incident when more than 10 failed logins occur from a single IP address within 5 minutes. Which rule type should they use?

Hard
258

A company uses Microsoft Entra ID and a third-party SaaS application. They want to prevent users from downloading sensitive documents from the SaaS app when accessing from unmanaged personal devices, while still allowing read-only access. Which Conditional Access control should they apply to achieve this?

Hard
259

A legal team is involved in a lawsuit and needs to ensure that all emails and documents related to the case are preserved in their original state, even if users edit or delete them. They also need the ability to search for these items and export them for legal review. Which Microsoft Purview solution should the compliance team configure to meet these requirements?

Medium
260

Which TWO Microsoft security solutions can be used to detect and respond to identity-based threats? (Choose two.)

Easy
261

Your company uses Microsoft Defender for Endpoint. You need to investigate a potential malware outbreak on a specific device. Which feature should you use to get real-time visibility into running processes and network connections?

Medium
262

A company deploys a virtual machine on Azure IaaS. According to the Microsoft shared responsibility model, which of the following security responsibilities is primarily the customer's responsibility?

Medium
263

Your company is implementing Microsoft Entra ID and wants to ensure that users can sign in using their existing social media accounts. Which feature should you configure?

Easy
264

A healthcare organization stores patient records in an encrypted database. Access to the database is restricted to authorized medical staff only. Which security principle is primarily being addressed by these measures?

Easy
265

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email via the Outlook mobile app. Which policy type should you configure?

Medium
266

Refer to the exhibit. You are configuring an access package in Microsoft Entra Entitlement Management. Based on the policy, which users can request access to the HR App?

Easy
267

A global enterprise has a hybrid environment that includes on-premises Active Directory, Azure resources, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The security team needs a single solution to collect security logs from all these sources, detect threats using advanced analytics and threat intelligence, and automate incident response via playbooks. They already have Microsoft Defender for Cloud protecting their Azure workloads. Which Microsoft security solution should they add to meet these requirements?

Hard
268

A company uses a third-party SaaS CRM application. The security team needs to monitor user sessions in real-time when sales representatives access the CRM from personal, unmanaged devices. The goal is to prevent the download of sensitive customer data to local drives. The solution should block download actions and show a warning to the user. Which Microsoft security solution should the team deploy to enforce these session controls?

Hard
269

Refer to the exhibit. An analyst runs a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

Medium
270

Your organization uses Microsoft Entra ID. A user reports that they are unable to access any Microsoft 365 services because they forgot their password. Which self-service tool should they use?

Easy
271

An organization wants to protect against password spray attacks by automatically blocking sign-ins from suspicious IP addresses. Which Microsoft Entra feature should they use?

Easy
272

Your organization uses Microsoft Entra ID and needs to block sign-ins from legacy authentication protocols to reduce risk. Which feature should you use?

Medium
273

A compliance administrator needs to generate a report showing all user activities related to accessing highly sensitive documents in SharePoint. Which Microsoft Purview solution should they use?

Easy
274

A company uses Microsoft Entra ID and wants to automatically detect and remediate over-privileged roles in their Azure subscriptions and AWS accounts. They need to get a unified view of permissions across multiple clouds. Which Microsoft Entra capability should they use?

Medium
275

Which TWO scenarios are appropriate uses of Microsoft Purview Audit (Standard)?

Hard
276

A user reports that they cannot access the company's HR application, which requires Microsoft Entra ID authentication. The user can access other apps that also use Entra ID. What is the most likely cause?

Medium
277

A company is moving its on-premises infrastructure to Azure. The CISO wants to understand the division of security responsibilities between the cloud provider and the customer. Which of the following models defines this division?

Easy
278

A company wants to allow its partners to access a specific SharePoint Online site using their own corporate credentials. The company does not want to manage partner accounts. Which Microsoft Entra feature should they use?

Medium
279

Which TWO of the following are components of the Microsoft Entra product family? (Choose two.)

Medium
280

A company uses Microsoft 365 and is concerned about phishing attacks targeting employees. They want to deploy a solution that can automatically analyze email messages for malicious links and attachments, and also provide click-time protection by rewriting URLs. Which Microsoft 365 Defender component should they use?

Medium
281

Your company uses Microsoft Purview Communication Compliance to detect and remediate inappropriate messages. You need to create a policy that monitors Microsoft Teams chats for potential harassment. Which type of policy should you create?

Hard
282

A company uses Microsoft Sentinel to centralize security logs. They want to correlate AWS CloudTrail logs with Azure AD sign-in logs. Which Microsoft Sentinel feature should they use?

Medium
283

A company is designing a Microsoft 365 Defender incident response workflow. They want to automatically isolate a compromised device when a ransomware alert is triggered. Which Microsoft 365 component should be used to execute the automated response action?

Hard
284

You are designing a compliance solution for a global company. You need to ensure that data stored in SharePoint Online is not accessible from a specific geographic region. Which Microsoft Purview feature should you use?

Hard
285

Refer to the exhibit. An administrator runs the PowerShell command against Microsoft Defender for Endpoint. The output shows an alert with Severity 'High' and Status 'New'. What should the administrator do next to investigate the alert?

Medium
286

A user reports that they are unable to sign in to a SaaS application that is configured for single sign-on (SSO) with Microsoft Entra ID. The user can sign in to other applications. What should you check first?

Easy
287

Which THREE of the following are capabilities of Microsoft Sentinel? (Select THREE.)

Hard
288

Your organization uses Microsoft Sentinel as a SIEM. You need to create a rule that triggers an incident when a user account is created in an Azure subscription and then logs in from an unfamiliar location within 24 hours. Which type of rule should you configure?

Medium
289

Your organization wants to classify documents based on whether they contain confidential business information like trade secrets. You need to use a classifier that learns from example documents. What should you use?

Easy
290

Refer to the exhibit. You are reviewing a risk detection in Microsoft Entra Identity Protection. The risk event indicates 'unfamiliarFeatures' with medium risk level for user John Doe from IP 203.0.113.5. What is the most likely cause of this risk detection?

Medium
291

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their existing social media accounts, such as Google or Facebook, while maintaining security and compliance with conditional access policies. What should you configure?

Medium
292

Refer to the exhibit. An administrator runs this PowerShell command. What is the purpose of this command?

Medium
293

A company uses Microsoft Intune to manage devices. They want to ensure that only devices with a specific minimum operating system version can access corporate email. What should they configure?

Easy
294

Your organization wants to audit all activities related to accessing sensitive files in Microsoft SharePoint. Which Microsoft Purview solution should you use?

Easy
295

Arrange the steps to conduct a data classification scan using Microsoft Purview Information Protection.

Medium
296

A healthcare organization uses Microsoft 365. They need to prevent employees from sharing emails or documents that contain patient medical record numbers (MRNs) with external recipients. If an attempt is made, the message should be blocked and the sender should receive a policy tip notification. Which Microsoft Purview solution should they configure?

Medium
297

Your organization is adopting Microsoft 365 Copilot for enterprise users. Which Microsoft Purview capability should you configure to prevent sensitive data from being inadvertently shared during Copilot interactions?

Medium
298

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. Which Microsoft Entra ID feature should you use?

Easy
299

A company uses Exchange Online. The security team wants to protect users from malicious email attachments. They need a solution that detonates attachments in a sandbox environment to check for malware behavior before the email is delivered to the recipient. Which Microsoft Defender for Office 365 feature should they enable?

Medium
300

A security team needs to investigate a potential data breach that may involve unauthorized access to sensitive files in SharePoint Online and OneDrive for Business. They want to search the unified audit log for file access events, including accesses from mobile devices and third-party applications. Additionally, they need to create custom alert policies that trigger when specific high-privilege users download large volumes of files in a short period. Which Microsoft Purview solution should they use?

Hard
301

A company wants to enable employees to securely access on-premises applications without needing a VPN. Which Microsoft Entra feature should they implement?

Easy
302

Refer to the exhibit. A compliance administrator runs the PowerShell commands to create a DLP policy. Users complain that they are blocked from sending emails containing credit card numbers but cannot override the block. The administrator wants to allow override with a business justification. What should they do?

Medium
303

Your organization is using Microsoft Entra ID with P2 licenses. You need to ensure that all guest users are reviewed for access quarterly, and if not approved, access is automatically removed. Which Microsoft Entra feature should you configure?

Hard
304

Your organization is required to retain all HR-related documents for 7 years after an employee leaves. After that period, the documents must be permanently deleted. Which two Microsoft Purview features should you use together?

Medium
305

You are the identity administrator for a multinational company using Microsoft Entra ID. The company has a Microsoft 365 E5 subscription. The security team wants to enforce the following requirements: 1. All users must use multi-factor authentication (MFA) when accessing sensitive applications (e.g., finance app). 2. Users from the IT department must use passwordless authentication methods (e.g., Windows Hello for Business) when accessing any resource. 3. All access to sensitive applications must be logged and monitored for anomalous activity. 4. Guest users from partner organizations must be automatically reviewed quarterly to ensure they still need access. 5. The company wants to minimize administrative overhead by automating as much as possible. You need to design a solution that meets these requirements using Microsoft Entra ID capabilities. Which combination of actions should you take?

Hard
306

A multinational organization uses Microsoft Entra ID for identity management. External contractors need temporary elevated access to Azure resources for a critical project. The access must be time-bound (expires after 8 hours), require manager approval, and enforce multifactor authentication (MFA) when contractors activate the role. Which Microsoft Entra capability should they configure?

Hard
307

Order the steps to create a conditional access policy in Azure AD.

Medium
308

A security analyst is explaining the concept of 'defense in depth' to a new team member. Which of the following best describes the defense in depth strategy?

Easy
309

Your organization uses Microsoft Defender for Cloud to protect Azure subscriptions. You need to enforce that all storage accounts must have encryption at rest enabled. You have enabled Azure Policy to audit this configuration. However, you notice that some storage accounts are non-compliant. You need to automatically remediate non-compliant storage accounts. What should you do?

Hard
310

A company uses Microsoft Entra ID. They want to ensure only current employees have access to a sensitive HR application. They implement a process where group membership for the HR app is reviewed quarterly by the HR manager, and any unnecessary access is automatically removed. Which Microsoft Entra feature should they use?

Medium
311

A user successfully authenticates to a system using a smart card. After authentication, the system checks whether the user's device is compliant with security policies before granting access to the network. This additional check is an example of which security concept?

Medium
312

Your organization uses Microsoft Purview to manage insider risk. You need to create a policy that detects users who exfiltrate sensitive data by copying it to personal cloud storage services like Dropbox. Which solution should you use?

Medium
313

Your organization needs to classify documents containing personally identifiable information (PII) like social security numbers. Which Microsoft Purview solution should you configure?

Easy
314

You are designing an identity solution for a new company that will use Microsoft Entra ID. The company wants employees to use biometrics (fingerprint) on their mobile devices to sign in without typing a password. Which Microsoft Entra feature should you implement?

Easy
315

A financial services company is required by regulation to prevent sensitive customer financial information from being shared externally via email. The compliance team wants to automatically scan all outgoing emails for patterns that match credit card numbers or account numbers. If a match is found, the email should be blocked and the sender should receive a policy tip. Which Microsoft Purview solution should be configured?

Medium
316

A financial services organization must comply with a regulation that requires all communications related to trades (including emails and Teams messages) to be retained for a period of 7 years. During retention, no user may edit or delete these records. After the 7 years, the records must be disposed of with an irreversible deletion that is verified by a compliance officer. Which Microsoft Purview solution should the organization use to enforce both retention and regulatory disposition?

Hard
317

An organization wants to protect its fleet of Windows 10 laptops from advanced malware and ransomware. The solution must detect suspicious behavior (e.g., a process encrypting files) and provide security teams with the ability to isolate an infected device from the network for investigation. Which Microsoft security solution should they deploy?

Medium
318

Which TWO of the following are benefits of using Microsoft Entra ID Conditional Access? (Choose two.)

Easy
319

Which TWO Microsoft Purview solutions can be used to protect sensitive data in Microsoft Teams chats and channels? (Choose two.)

Medium
320

Refer to the exhibit. The JSON snippet shows a sensitivity label configuration. What is the purpose of the 'SensitiveInfoTypes' property in this label?

Easy
321

Your organization has Microsoft Sentinel deployed. The security operations team needs to automatically respond to a security incident by opening an incident in ServiceNow and sending a notification to a Teams channel. What should you configure?

Medium
322

A company's security team discovers that most recent account compromises resulted from attackers exploiting legacy authentication protocols (POP3, IMAP, SMTP Auth) that do not support multi-factor authentication. The team wants to immediately block all sign-in attempts using these legacy protocols while still allowing modern authentication methods (e.g., OAuth 2.0). Which Microsoft Entra ID feature should they configure?

Medium
323

A financial institution uses Microsoft 365 and must ensure that Microsoft support engineers cannot access the institution's content (e.g., Exchange Online mailboxes, SharePoint sites) without explicit approval from the institution's compliance officer. The compliance officer needs to review and approve or reject each access request. Which Microsoft Purview feature should be configured?

Hard
324

Refer to the exhibit. You run this PowerShell cmdlet. What is the outcome?

Easy
325

Which TWO Microsoft Security Copilot capabilities can help security analysts during incident response?

Hard
326

An organization implements a policy where users must provide two forms of verification, such as a password and a text message code, to access the corporate network. Which security concept does this demonstrate?

Easy
327

A company uses Microsoft Entra ID and wants to allow users to reset their own passwords without help desk intervention. However, they want to ensure that only users who have already registered for multifactor authentication (MFA) can use self-service password reset (SSPR). Which Microsoft Entra feature should the administrator configure to enforce this requirement?

Medium
328

A company uses digital signatures on all official emails sent to customers. The signature is created using the sender’s private key, allowing recipients to verify that the email truly came from the claimed sender and that it was not altered in transit. Which security goal is primarily achieved by the digital signature?

Medium
329

A company uses Microsoft 365 E5 and is concerned about advanced phishing attacks that use adversary-in-the-middle (AiTM) techniques to steal session cookies and bypass multifactor authentication. Which Microsoft Defender for Office 365 feature should they configure to specifically protect against this type of attack?

Medium
330

A company uses Microsoft Entra ID and Intune for mobile device management. They want to grant access to a confidential project management site only from devices that are encrypted and have the latest anti-malware updates. Which Conditional Access assignment should they configure to enforce this requirement?

Medium
331

Your organization uses Microsoft Purview eDiscovery to manage a legal case. You need to place a hold on emails for specific users, but you want to allow the system to apply the hold automatically. Which eDiscovery solution should you use?

Medium
332

Your organization uses Microsoft Defender for Endpoint. You need to investigate a potential malware outbreak on several endpoints. Which feature allows you to search for indicators of compromise (IOCs) across all endpoints?

Easy
333

A multinational corporation uses Microsoft Entra ID for identity management. They want to allow their external partners to use their own corporate credentials to access the company's resources, rather than creating guest accounts. Which Entra ID feature should they use?

Hard
334

Which TWO capabilities are part of Microsoft Entra ID Protection? (Choose two.)

Easy
335

Your organization uses Microsoft Entra ID with P1 licenses. You need to provide a temporary access pass for a new employee to set up their account without a password. Which Microsoft Entra feature should you use?

Medium
336

Your company uses Microsoft Entra ID. You need to enforce that all users register for MFA within 14 days of account creation. Which feature should you use?

Medium
337

A company wants to automatically apply a 'Confidential' sensitivity label to all documents containing credit card numbers. Which Microsoft Purview feature should be used to create the auto-labeling policy?

Easy
338

Your organization uses Microsoft Purview Information Barriers to prevent certain user groups from communicating with each other. You need to test the configuration before fully enforcing it. What should you do?

Medium
339

Your organization wants to automatically retain all customer emails for 7 years and then delete them. Which Microsoft Purview feature should you configure?

Easy
340

You are a security administrator for Contoso Ltd., a global financial services company with 5,000 employees. The company uses Microsoft 365 E5 licenses and has deployed Microsoft Entra ID, Microsoft Defender XDR, Microsoft Purview, and Microsoft Intune. Recently, the security team identified a risk: employees are sharing sensitive financial reports via external email recipients without encryption. To address this, you need to implement a solution that automatically applies encryption to emails containing the sensitive information type 'U.S. Bank Account Number' when sent to external recipients. The solution must not block the email but should encrypt it. Additionally, you want to notify the sender with a policy tip that the email will be encrypted. You have access to the Microsoft Purview compliance portal. What should you configure?

Hard
341

Your organization's security team wants to automatically investigate and respond to sophisticated email threats like business email compromise (BEC) without manual intervention. Which Microsoft 365 security solution should you use?

Easy
342

Which TWO of the following are capabilities of Microsoft Defender for Cloud Apps?

Medium
343

A company maintains an on-premises Active Directory environment with over 10,000 domain-joined computers. The security team is concerned about advanced attacks that use stolen credentials to move laterally, such as pass-the-hash attacks or DCSync attacks targeting domain controllers. They need a solution that monitors on-premises Active Directory traffic and event logs to detect these identity-based threats and provides alerts for investigation. Which Microsoft security solution should they deploy?

Medium
344

Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). A user reports receiving a suspicious email with a link. The email was not blocked by Exchange Online Protection (EOP). Which feature should you use to investigate the link's reputation in real time?

Hard
345

Your company uses Microsoft Purview to protect sensitive data in SharePoint Online. You need to automatically apply a 'Confidential' sensitivity label to documents containing credit card numbers. What should you create?

Medium
346

A security analyst wants to create a custom detection rule that tracks a specific multi-stage attack pattern: a user receives a phishing email, clicks a link, and then a script is executed on their device. The analyst needs to write a Kusto Query Language (KQL) query to detect this pattern and schedule it to run automatically, generating alerts. Which Microsoft 365 Defender capability should they use?

Hard
347

A security team wants to discover which cloud applications (such as Dropbox, Salesforce, or unsanctioned file-sharing apps) are being used by employees, even if those apps are not sanctioned by IT. They need to analyze usage patterns, risk levels, and identify potential shadow IT. Which feature of Microsoft Defender for Cloud Apps should they enable?

Medium
348

Your company uses Microsoft Defender for Cloud Apps to discover shadow IT. You have discovered a new cloud app that employees are using to store corporate data. The app is not sanctioned. You need to sanction the app but also ensure that users cannot upload sensitive data to it. You have configured a session policy to monitor the app. What additional step should you take?

Medium
349

Which THREE are capabilities of Microsoft Defender for Cloud?

Easy
350

A company wants to use Microsoft Entra ID (Azure AD) to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. Which security feature should they implement?

Easy
351

Your organization has a Microsoft Entra ID tenant with 5,000 users. You need to implement a solution that automatically detects and remediates users with leaked credentials. Additionally, you need to require users to change their password when a high risk is detected. Which Microsoft Entra features should you configure?

Hard
352

A security operations team needs to protect Windows servers from ransomware and other advanced threats. They require a solution that provides endpoint detection and response (EDR), automated investigation, and the ability to isolate compromised machines from the network. Which Microsoft security solution should they deploy?

Medium
353

Which TWO of the following are capabilities of Microsoft Entra ID? (Select two.)

Medium
354

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. The JSON snippet shows a rule designed to create an incident when a high-severity alert is generated. However, the rule is not triggering. What is the most likely reason?

Hard
355

Your company uses Microsoft Defender for Cloud to secure multicloud workloads. You need to ensure that regulatory compliance frameworks (e.g., SOC 2, ISO 27001) are continuously assessed and any drift is reported. What should you implement?

Hard
356

Refer to the exhibit. A security analyst is reviewing an alert from Microsoft 365 Defender. The alert is associated with an incident. What is the best first step to investigate this alert?

Hard
357

A company uses Microsoft Entra ID and wants to allow external business partners to request access to a specific application through an approval process. The access should be time-limited and automatically expired. Which Microsoft Entra ID feature should be configured?

Medium
358

Your company wants to allow employees to use their corporate Microsoft Entra ID credentials to sign in to third-party SaaS applications like Salesforce and ServiceNow. Which Microsoft Entra feature should you configure?

Easy
359

A company wants to use Microsoft Sentinel to collect security logs from on-premises servers and send them to Azure. Which data connector should they use?

Easy
360

A company uses Microsoft Entra ID. The security team needs to grant temporary elevated access to the Global Administrator role for a specific task, such as configuring a new security policy. They want the user to request activation, which is then approved by a manager, and the privileges automatically expire after 4 hours. Which Microsoft Entra feature should they use?

Medium
361

A company is migrating its on-premises applications to Azure Infrastructure-as-a-Service (IaaS). According to the shared responsibility model, which of the following security responsibilities shifts from the customer to Microsoft during this migration?

Medium
362

A user reports that they cannot access a sensitive document in SharePoint Online. The administrator checks the document's permissions and sees that the user is not listed directly, but a group they belong to has been granted access. Which identity concept describes this scenario?

Easy
363

Which TWO of the following are principles of the Zero Trust security model? (Select two.)

Medium
364

A security team needs to investigate a potential data leak where an employee may have emailed sensitive customer information to a competitor. They want to search the unified audit log for specific email activities, such as 'Send' or 'Forward', and generate a detailed report. Which Microsoft Purview solution should they use?

Medium
365

A company uses Azure virtual machines and on-premises Windows servers. The security team wants a single solution that provides vulnerability assessment, a regulatory compliance dashboard (e.g., for ISO 27001), and integrated threat detection such as fileless malware and anomalous logins. Which Microsoft security solution should they use?

Medium
366

A company uses Microsoft Entra ID. The security team wants to provide just-in-time (JIT) administrative access to Azure resources. They require that administrators must request approval before gaining elevated privileges, and that the elevated access automatically expires after the task is completed. Which Microsoft Entra capability should they use?

Medium
367

A company uses Microsoft 365 and must comply with a regulation that requires all business records, including emails and documents, to be retained for exactly 5 years. They need to automatically apply a retention label to any item that contains the keyword 'Contract' when the item is created or modified. Which Microsoft Purview solution should they use to configure this automatic labeling?

Medium
368

You run the following PowerShell command in your Microsoft Entra ID environment: Get-AzureADPolicy -Type TokenLifetimePolicy What is the command retrieving?

Easy
369

A company uses Microsoft Entra ID. They want to require all users accessing the external vendor portal to accept a terms of use document before they are granted access. The acceptance must be revoked after 30 days, requiring the user to accept again. Which Conditional Access component should the administrator configure?

Medium
370

Arrange the steps to configure Azure AD Privileged Identity Management (PIM) for a role in the correct order.

Medium
371

A legal team is handling a lawsuit and needs to gather all electronically stored information (ESI) related to a specific case from across Microsoft 365, including emails, Teams messages, and SharePoint documents. They need to place a hold on the custodians' data to prevent deletion or modification, and then collect, review, and export the data. Which Microsoft Purview solution should they use?

Medium
372

A company uses Microsoft 365 and needs to protect endpoints from ransomware attacks that encrypt files. The security team wants automated investigation and response capabilities for malware incidents on Windows devices. Which Microsoft security solution should they use?

Medium
373

You are configuring Microsoft Entra ID Governance. You need to ensure that when a user leaves the organization, their access to all SaaS applications is automatically revoked. Which Microsoft Entra feature should you use?

Easy
374

A company configures its identity and access management system so that employees are granted only the permissions necessary to perform their job functions. For example, a sales representative has read-only access to the customer database and cannot modify financial records. Which security principle is being applied in this scenario?

Easy
375

A security architect is explaining identity management concepts to the IT team. Which statement correctly describes the difference between authentication and authorization?

Medium
376

Which TWO features are part of Microsoft Entra ID P2 licensing? (Choose two.)

Medium
377

A legal team is preparing for a lawsuit and needs to perform a detailed investigation of user activities across Microsoft 365 services. They need to view the 'before' and 'after' values whenever a critical item in SharePoint or Exchange is updated or deleted. The investigation requires high-volume export performance and the ability to search by specific activities like 'MailboxFolderAccess' and 'Send'. Which Microsoft Purview solution should be enabled and configured to meet these advanced auditing requirements?

Hard
378

A company operates in multiple countries and must comply with GDPR (EU) and CCPA (California). The compliance officer needs a single tool to assess the company's compliance posture against both regulations, get a consolidated compliance score, and receive prioritized improvement actions that can be assigned to responsible teams. The tool should also track progress over time. Which Microsoft Purview solution should the compliance officer use?

Hard
379

A company is implementing Microsoft Purview Information Protection. They want to automatically apply a 'Highly Confidential' sensitivity label to emails containing a specific credit card pattern. Which solution should they use?

Hard
380

Your organization uses Microsoft Purview to manage data sensitivity and compliance. Which TWO capabilities are provided by Microsoft Purview Information Protection?

Easy
381

A company uses Microsoft Defender for Cloud Apps to secure its cloud applications. The security team wants to monitor and control data activities in a third-party cloud app (e.g., Box) in real time. Specifically, they need to block downloads of files that have a 'Confidential' sensitivity label when users access the app from unmanaged devices. Which capability of Microsoft Defender for Cloud Apps should they configure?

Medium
382

Refer to the exhibit. A Microsoft Purview retention policy is configured as shown. An HR manager wants to ensure that employee records are kept for at least 1 year after last modification. The policy is applied to Exchange, SharePoint, and OneDrive. What is the outcome?

Hard
383

Which three features are available in Microsoft Entra ID P2 but not in P1? (Choose three.)

Hard
384

Which TWO are features of Microsoft Entra ID?

Easy
385

Your organization uses Microsoft Purview to govern data in Azure Data Lake Storage. You need to create a data classification policy that automatically tags files containing personally identifiable information (PII) such as social security numbers. Which scanning solution should you use?

Easy
386

A company runs Windows Server virtual machines (VMs) on-premises and in Azure. The security team wants a unified view of missing security updates and known vulnerabilities (CVEs) across all VMs. They want to enable agentless scanning for Azure VMs and deploy a lightweight agent for on-premises machines. The results should be consolidated in a single dashboard with prioritized remediation recommendations. Which Microsoft security solution should they use?

Hard
387

You are troubleshooting a Conditional Access policy in Microsoft Entra ID. The policy in the exhibit is not blocking some sign-ins that you expected to block. What is the most likely reason?

Hard
388

You are the security administrator for Contoso Corporation. The company uses Microsoft 365 E5 licenses, which include Microsoft Entra ID P2, Microsoft Purview, and Microsoft Defender XDR. Contoso has a hybrid identity environment with Microsoft Entra Connect syncing on-premises Active Directory to Microsoft Entra ID. The company recently experienced a data breach where an attacker compromised a user's credentials and exfiltrated sensitive customer data from SharePoint Online. The investigation revealed that the compromised user did not have MFA enabled and had admin consent to a malicious third-party OAuth app. To prevent future incidents, management has mandated the following requirements: (1) Enforce MFA for all users, especially those accessing sensitive data. (2) Block all OAuth apps that are not pre-approved by IT. (3) Detect and respond to identity-based threats in real-time. (4) Classify and protect sensitive data in SharePoint and Teams. You need to recommend a solution that meets all requirements. Which combination of Microsoft security solutions should you implement?

Hard
389

A company has deployed Microsoft 365 Defender to unify threat detection and response. Which two components are included within the Microsoft 365 Defender integrated solution? (Select all that apply.)

Hard
390

A company stores sensitive customer data in an Azure SQL database. To protect this data, the database files are encrypted at rest using Transparent Data Encryption (TDE). Additionally, all network traffic between the application and the database is encrypted using TLS. Which security goal is primarily addressed by these encryption measures?

Easy
391

A company is subject to a legal hold for an ongoing investigation. The IT administrator must prevent the deletion of any documents related to this case across SharePoint Online and OneDrive, overriding any existing deletion policies. Which Microsoft Purview capability should the administrator use?

Medium
392

A company wants to use Microsoft Intune to enforce that mobile devices have a PIN of at least 6 characters to access corporate resources. What should they configure?

Easy
393

A company is involved in litigation. The legal team needs to preserve all relevant electronic documents that reside in Exchange Online, SharePoint Online, and OneDrive for Business. They must prevent users from deleting or modifying these documents while the lawsuit is active. Additionally, they need to search across these locations for specific keywords and export the results for review. Which Microsoft Purview solution should they use?

Medium
394

Refer to the exhibit. You run the PowerShell command shown to investigate a potential data exfiltration incident. The output is empty. Which is the most likely reason?

Hard
395

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP). You need to prevent users from sharing sensitive credit card numbers via email. The DLP policy must trigger automatically when a user attempts to send an email containing a credit card number. Which DLP configuration should you use?

Hard
396

Which TWO of the following are purposes of the 'Zero Trust' security model?

Easy
397

Your organization is implementing Microsoft Defender for Office 365 to protect against phishing attacks. You need to ensure that when a user clicks a malicious link in an email, the user is warned and the action is blocked. Which policy should you configure?

Hard
398

As a compliance administrator for Contoso Ltd., you are responsible for implementing Microsoft Purview solutions to meet regulatory requirements. The organization operates in the healthcare sector and handles Protected Health Information (PHI). Your key objectives are: (1) Automatically detect PHI in documents stored in SharePoint Online and OneDrive for Business using built-in sensitive information types. (2) Apply a 'Highly Confidential - PHI' sensitivity label that encrypts the content and adds a custom header. (3) Ensure that the label is automatically applied when PHI is detected, with a policy that allows users to override the label with justification. (4) Audit all label application activities for compliance reporting. (5) Retain documents containing PHI for a minimum of 7 years. You have access to Microsoft Purview compliance portal. Which action should you take FIRST to achieve these objectives?

Hard
399

Your organization is implementing a data loss prevention (DLP) policy to prevent sensitive data from being shared via email. Users in the finance department need to send financial reports to external auditors. What should you configure?

Easy
400

A company uses Microsoft Sentinel for security information and event management (SIEM). The security team needs to detect and automatically respond to a potential privilege escalation attack where an attacker attempts to add a new user to the Global Administrator role in Microsoft Entra ID. What should the security team configure?

Medium
401

Your organization uses Microsoft Purview to enforce retention policies. You need to retain all documents in a specific SharePoint site for 5 years after they are created, and then delete them permanently. What should you configure?

Medium
402

Refer to the exhibit. An administrator runs this KQL query in Microsoft Purview Audit. What is the purpose of this query?

Hard
403

Your organization uses Microsoft Entra ID and Microsoft Defender for Cloud Apps. You want to monitor and control the use of cloud apps by enforcing session policies, such as preventing downloads from unmanaged devices. Which integration should you use?

Medium
404

A company uses Microsoft Defender for Cloud Apps to monitor SaaS app usage. The security team wants to receive an alert when a user downloads more than 10 files from SharePoint Online within 5 minutes. Which type of policy should they create?

Medium
405

Your company uses Microsoft Sentinel to centralize security event monitoring. You need to create a custom analytics rule that triggers an alert when a user account is created outside of business hours. Which rule type should you use?

Medium
406

An organization uses Microsoft Entra ID for identity management. They want to implement a risk-based conditional access policy that requires multi-factor authentication (MFA) when sign-in risk is medium or high. Which policy settings should they configure?

Hard
407

Your organization is deploying Microsoft Purview. You need to automatically apply a sensitivity label to documents that contain passport numbers. Which TWO components must you configure?

Medium
408

You are a security architect for a large enterprise using Microsoft Entra ID. You need to implement a solution that enforces least-privilege access and reduces lateral movement. Which THREE Microsoft Entra capabilities should you include in your design?

Hard
409

Contoso Ltd. is a financial services company that must comply with strict regulatory requirements. They use Microsoft 365 E5, Microsoft Entra ID P2, Microsoft Purview, and Microsoft Defender for Cloud Apps. The compliance team needs to implement a data loss prevention (DLP) policy that detects and prevents the sharing of credit card numbers in Microsoft Teams messages. Additionally, they want to ensure that only users with a specific custom sensitivity label can access documents containing credit card numbers. The sensitivity label is named 'Financial-Confidential' and is applied automatically via auto-labeling. The DLP policy should block sharing of credit card numbers in Teams but allow users to override the block with a business justification. Which combination of actions should you configure in the Microsoft Purview DLP policy to meet these requirements?

Hard
410

An organization runs workloads in Azure, an on-premises data center, and multiple third-party cloud environments. The security team needs a single, cloud-native solution that provides a unified view of the security posture across all these environments, along with a secure score and actionable recommendations. They also want to protect these workloads with advanced threat detection. Which Microsoft security solution should they implement?

Medium
411

An organization is implementing a Zero Trust security model. Which principle requires that every access request must be fully authenticated, authorized, and verified based on all available signals, regardless of the user's network location?

Easy
412

A financial services organization must prevent employees in the Research department from communicating via email or Microsoft Teams with employees in the Investment Banking department to avoid conflicts of interest. Additionally, they need to prevent any credit card numbers from being shared in emails sent to external recipients. Which combination of Microsoft Purview solutions should they implement?

Hard
413

An organization adopts a security model that requires explicit verification of every access request, uses least privilege principles, and assumes that a breach has already occurred. Which security model does this describe?

Medium
414

A security team monitors user activities in third-party cloud apps like Box and Dropbox. They want to automatically detect when a user performs an anomalous file download after signing in from an unusual location, and then suspend the user's account and initiate an investigation. Which Microsoft security solution should they use?

Hard
415

Refer to the exhibit. A security analyst runs the KQL query in Microsoft Sentinel. The query returns sign-in logs with error code 50076. What does this error indicate?

Hard
416

A security analyst needs to investigate a phishing campaign that targeted multiple users. They want to correlate email threat data with user actions and device signals. Which Microsoft security solution should they use as the primary investigation console?

Medium
417

A compliance officer needs to create a policy that prevents users from sharing files containing medical record numbers (MRN) via email. Which Microsoft Purview solution should they use?

Easy
418

A company uses Microsoft Entra ID (Microsoft Entra ID) and wants to allow users to sign in using biometrics (fingerprint or face) on their mobile devices instead of passwords. They want this to work for both iOS and Android devices. Which Microsoft Entra ID feature should they enable?

Medium
419

Refer to the exhibit. You are reviewing a Communication Compliance policy. What does this policy do when a user sends an email containing EU GDPR PII to privacy@contoso.com?

Medium
420

Your company wants to use Microsoft Purview to classify and protect sensitive data in Microsoft 365. The compliance team needs to automatically detect credit card numbers in emails and apply a label that encrypts the email. What should they configure?

Easy
421

A security administrator needs to identify users who are repeatedly failing to authenticate from unusual locations. Which Microsoft 365 security feature provides this visibility?

Medium
422

Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the default filters. You need to create a custom mail flow rule to block similar emails based on specific keywords in the subject line. Which tool should you use?

Medium
423

Which THREE of the following are components of the Zero Trust security model?

Easy
424

Refer to the exhibit. An administrator deploys this Azure Resource Manager template. Which TWO of the following statements are true?

Hard
425

Your organization wants to automatically retain customer emails for 5 years after they are received, and then delete them. You need to configure the appropriate Microsoft Purview solution. What should you use?

Medium
426

A consulting firm is involved in a legal investigation. They need to preserve all emails and documents from two specific employees (custodians) related to a contract dispute. The data must be collected and stored in a secure location for legal review without modifying the original data. Which Microsoft Purview solution should they use?

Medium
427

A company wants to allow external business partners to access a specific SharePoint Online site using their own corporate identities (such as Google or Facebook accounts). The company also needs to enforce multi-factor authentication (MFA) for these external users. Which Microsoft Entra capability should the administrator configure?

Medium
428

A company deploys a web application on Azure virtual machines (VMs) in an Infrastructure-as-a-Service (IaaS) model. The company is responsible for managing the guest operating system, the application code, and the data stored on the VMs. According to the shared responsibility model, which of the following security responsibilities does Microsoft retain in this scenario?

Easy
429

A company runs Azure VMs and on-premises Windows servers. They need a solution that provides vulnerability assessment, regulatory compliance dashboard, and threat detection for their hybrid workloads. Which Microsoft security solution should they use?

Hard
430

Your organization has a Microsoft Purview compliance portal. You need to audit who deleted a specific file from SharePoint Online last week. What should you do?

Hard
431

Which TWO of the following are benefits of using Microsoft Entra ID Governance?

Hard
432

Refer to the exhibit. You run an Advanced Hunting query in Microsoft Defender XDR. What is the primary purpose of this query?

Hard
433

A security analyst needs to investigate a potential ransomware attack affecting multiple endpoints. They want to centralize detection and response across devices, email, and applications. Which Microsoft solution should they use?

Hard
434

A security team is evaluating Microsoft security solutions to monitor user activities across multiple SaaS applications, including Salesforce and Dropbox, for signs of compromised accounts and data exfiltration. Which solution is specifically designed for this purpose?

Easy
435

A company wants to classify and label documents in SharePoint automatically based on sensitive content like social security numbers. Which Microsoft Purview solution should they use?

Easy
436

A company has a document management system. The security policy requires that a user in the Sales department can only view documents related to sales and cannot access documents in the Finance or HR folders. Which security principle is being applied?

Easy
437

Your organization is implementing Microsoft 365 and needs to prevent sensitive data from being copied to USB drives. Which Microsoft Purview solution should you configure?

Easy
438

A company wants to automatically classify documents containing credit card numbers and apply encryption at rest in SharePoint Online. Which Microsoft Purview feature should be used?

Medium
439

Refer to the exhibit. The KQL query is used in a Microsoft Sentinel analytics rule. What is the primary purpose of this rule?

Hard
440

Refer to the exhibit. You are configuring a Conditional Access policy that requires compliant device for access to Microsoft 365. The device shown in the exhibit is Azure AD joined, compliant, and managed. However, a user signing in from this device is still blocked. What is the most likely cause?

Hard
441

Your organization uses Microsoft Entra ID with P2 licenses. You need to delegate the ability to manage role assignments in Entra ID without granting global admin rights. Which feature should you use?

Hard
442

An organization uses Microsoft Purview Compliance Manager to track compliance with regulations. The compliance officer needs to create a custom assessment for a new internal policy. What should they do?

Hard
443

A company wants to prevent users from using common passwords like 'Password123' and custom banned passwords such as 'Contoso2024' during sign-up or password change. They also need to apply a common list of banned passwords across tenant-wide. Which Microsoft Entra feature should they configure?

Medium
444

Which TWO of the following are Microsoft Purview compliance solutions?

Easy
445

Refer to the exhibit. A sensitivity label is configured as shown. Which statement about the label's behavior is accurate?

Hard
446

Your company uses Microsoft Entra ID and wants to automatically assign licenses to new employees based on their department. Which feature should you use?

Hard
447

Your organization wants to enforce multi-factor authentication (MFA) for all users accessing cloud applications. Which Microsoft Entra ID feature should you configure?

Easy
448

A company uses Microsoft Entra ID and needs to regularly review membership of a group that grants access to a sensitive HR application. The identity team wants to automate quarterly reviews and automatically remove users who fail to respond or are denied by the reviewer. Which Microsoft Entra ID feature should they use?

Hard
449

A security operations team needs a solution that can detect and stop ransomware attacks on Windows servers and desktops in real time. They also want the ability to automatically isolate affected devices and, if necessary, roll back files modified by ransomware using a built-in recovery feature. Which Microsoft security solution provides these capabilities?

Medium
450

A company uses Microsoft Entra ID and wants to provide external business partners with access to a specific internal application. The partners already use Microsoft Entra ID in their own organization. The company wants the partners to use their existing corporate credentials to sign in, without creating new user accounts in the company's tenant. The company also wants to manage the access lifecycle, including automatically removing access after a project ends. Which Microsoft Entra ID feature should they use?

Medium
451

A company is involved in a lawsuit. The legal team needs to preserve all emails, documents, and Teams messages from five key employees (custodians) that are related to a specific project. The data must be collected securely and provided for legal review without modifying the original data. Which Microsoft Purview solution should they use?

Hard
452

A company wants to allow employees to securely access internal applications from their personal devices. The security policy requires that access is only granted if the device is compliant with company security policies (e.g., encryption enabled, password required, up-to-date operating system). Which Microsoft Entra ID capability should they use?

Medium
453

A company uses Microsoft Entra ID. A junior administrator needs to occasionally reset passwords for the IT department. The security team wants to grant this permission only for a limited time and require an approval from a senior administrator before the permission becomes active. All password reset actions must be audited. Which Microsoft Entra ID feature should they configure?

Medium
454

A company wants to gain visibility into the cloud applications that employees are using (e.g., unsanctioned SaaS apps), assess the risk level of each app based on multiple factors, and block access to high-risk applications. Which Microsoft security solution should they deploy?

Medium
455

A compliance administrator configures the above retention policy. A document created on January 1, 2025, in SharePoint Online will be retained until when?

Medium
456

A security team needs to investigate a potential data breach in Microsoft 365. They require detailed forensic logs showing every instance of mailbox access, mailbox search performed by administrators, and changes to email forwarding rules in Exchange Online. The logs must be retained for 1 year. Which Microsoft Purview solution should they use?

Hard
457

Your company uses Microsoft Entra ID and wants to implement a passwordless authentication strategy for all users. You have a mix of Windows 10 devices, iOS devices, and Android devices. You need a solution that works across all platforms and does not require users to remember passwords. What should you implement?

Medium
458

Which TWO Microsoft Entra features can help protect against credential attacks?

Hard
459

Your organization uses Microsoft Purview Communication Compliance to detect potential harassment in Microsoft Teams messages. Which role is required to review and act on policy matches?

Easy
460

A security administrator is configuring permissions for a new cloud-based expense reporting application. The administrator assigns each employee only the permissions they need to perform their job functions. For example, employees in the Sales department can view expense reports but cannot approve or modify financial data. Which security principle is the administrator implementing?

Easy
461

A company runs a mix of on-premises servers and Azure virtual machines. They deploy Microsoft Defender for Endpoint on all servers. The security team wants to create custom queries to hunt for a specific attack pattern that involves a sequence of events across multiple machines, such as a PowerShell script being downloaded and then executed on several servers. They need to write their own detection rules based on advanced hunting data. Which Microsoft 365 Defender capability should they use?

Hard
462

A multinational corporation must comply with the General Data Protection Regulation (GDPR). They use Microsoft Purview Compliance Manager to manage compliance activities. The compliance manager wants to automatically assign each control to the appropriate team member for remediation. What should they configure?

Hard
463

Your organization uses Microsoft Entra ID with P2 licenses. You need to implement a policy that requires users to perform multifactor authentication (MFA) when accessing the finance application from an untrusted network, but not when accessing it from the corporate network. Which Microsoft Entra feature should you configure?

Hard
464

A company uses Microsoft Entra ID. The security team wants to grant temporary, time-limited administrative access to Azure subscriptions only when needed, with an approval workflow. Which Microsoft Entra capability should they use?

Medium
465

An organization implements a security policy where users must authenticate using a smart card and PIN. After successful authentication, the system checks whether the user's device is managed by the organization and complies with security baselines. If the device is compliant, the user is granted access to the corporate network. If not, access is denied. This approach most directly reflects which security model?

Hard
466

An organization decides to eliminate passwords for their employees. They deploy Windows Hello for Business on company-issued laptops, allowing users to sign in with a PIN or a biometric gesture (e.g., fingerprint). The IT team also enables Microsoft Authenticator and FIDO2 security keys as alternative sign-in methods. Which Microsoft Entra ID capability are they leveraging?

Medium
467

Refer to the exhibit. The Conditional Access policy is configured to block access for high-risk users. A user with a medium risk level attempts to sign in. What will happen?

Hard
468

Your organization has a Microsoft Purview Data Lifecycle Management policy that deletes emails after 3 years. A legal hold is placed on a user's mailbox. What happens to the emails?

Medium
469

Match each compliance framework to its primary focus.

Medium
470

Which THREE are benefits of using Microsoft Purview Compliance Manager?

Medium
471

An organization is migrating from on-premises Active Directory to Microsoft Entra ID. They need to synchronize user passwords so that users can use the same password for both on-premises and cloud resources. Which authentication method should they choose?

Hard
472

Your company has Microsoft Defender for Office 365 and wants to configure anti-phishing policies to protect against spear-phishing attacks targeting executives. Which policy setting should you enable to provide the highest level of protection?

Hard
473

A legal team needs to preserve all electronic documents related to an ongoing lawsuit. These documents reside in Exchange Online mailboxes, SharePoint Online sites, and OneDrive for Business accounts. The team also needs the ability to search across these locations for specific keywords and export the results for review. Which Microsoft Purview solution should they use?

Medium
474

Which TWO of the following are capabilities of Microsoft Purview Information Protection?

Medium
475

A company uses Microsoft Entra ID. The IT department wants to ensure that users are prompted to change their password only when there is a high likelihood that their credentials have been compromised, rather than forcing periodic password changes. They also want to block users from using common passwords from a custom list of banned passwords. Which Microsoft Entra features should they use?

Medium
476

You work at a mid-sized company that uses Microsoft Defender for Business (a subscription included with Microsoft 365 Business Premium). The company has 300 devices enrolled in Microsoft Intune. Recently, a malware outbreak occurred on several devices. You need to implement a solution that automatically remediates devices that are found to be infected with malware. The solution should isolate the device from the network and run a full scan. Which action should you take?

Easy
477

A security operations team uses Microsoft Sentinel to centralize security log analysis. They need to ingest logs from a third-party firewall that does not have a native connector. What should the team use to bring the firewall logs into Microsoft Sentinel?

Easy
478

A security operations center (SOC) team uses Microsoft Sentinel with User and Entity Behavior Analytics (UEBA) enabled. They notice an alert about a user accessing a sensitive HR application from an unusual IP address at 3 AM. What does UEBA primarily use to detect this anomaly?

Hard
479

A company wants to monitor Microsoft Teams messages and corporate emails for policy violations related to potential harassment and inappropriate behavior. They need a solution that allows them to define policies with conditions (e.g., keywords, patterns), automatically flag suspicious conversations, and optionally send notifications to the sender or escalate to a reviewer. Additionally, they need the ability to train employees when a minor violation is detected. Which Microsoft Purview solution should they use?

Hard
480

A hotel uses a key card system. Guests insert their card into the door lock, which reads the card's ID number. The system checks the ID number against a list of authorized rooms. If the ID matches an authorized room, the door unlocks. In this scenario, which concept is demonstrated when the system checks the ID number against the list of authorized rooms?

Easy
481

A healthcare organization must comply with HIPAA. They need to automatically detect protected health information (PHI) such as medical record numbers in outgoing email, prevent users from sharing these emails with unauthorized external recipients, and apply a retention label that retains PHI emails for six years. Which Microsoft Purview solution should they use?

Medium
482

A healthcare company stores patient records in an Azure SQL database. To protect the data, they enable Transparent Data Encryption (TDE) for the database and require all client connections to use TLS. Which security goal is being primarily addressed by these measures?

Easy
483

Which TWO of the following are capabilities of Microsoft Purview Communication Compliance? (Select TWO.)

Medium
484

Your organization uses Microsoft Defender for Office 365. Users report receiving phishing emails that bypassed the default anti-phishing policy. What should you do to improve protection?

Medium
485

Your organization wants to enforce MFA for all users accessing the Azure portal. However, users accessing from the corporate office network should not be prompted for MFA. Which Conditional Access assignment should you configure?

Easy
486

A multinational company uses Microsoft 365 and has a retention policy that automatically applies a 7-year retention label to any document containing a credit card number. The retention label must be automatically applied at the time the document is created or modified. Which Microsoft Purview solution should the administrator use to configure this automatic labeling rule?

Medium
487

A company wants to ensure that only authorized users can access sensitive financial data stored in Microsoft SharePoint Online. Which identity feature should they use to require a second form of verification?

Easy
488

Your organization wants to enable single sign-on (SSO) for users accessing Microsoft 365 apps from unmanaged devices while enforcing multifactor authentication (MFA). Which Microsoft Entra feature should you configure?

Easy
489

Your company is implementing data loss prevention (DLP) policies in Microsoft Purview. You need to prevent users from sharing credit card numbers via email. Which type of sensitive information type should you use in the DLP rule?

Medium
490

A security administrator uses Microsoft Entra ID Protection to identify and respond to identity-based risks. Which two types of risk detections can be reviewed in Microsoft Entra ID Protection? (Choose two.)

Hard
491

Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive information. You need to create a policy that prevents users from sharing credit card numbers via email, but allows them to share internally with other employees. The policy should also notify the user when an attempt is made to share externally. What should you configure?

Hard
492

A company has a Microsoft Entra ID tenant and an on-premises Active Directory Domain Services (AD DS) forest. They need to synchronize user accounts, groups, and passwords from AD DS to Microsoft Entra ID. Due to network restrictions, they prefer a lightweight agent that can be deployed on-premises and supports staging mode for testing. Which identity synchronization tool should they use?

Medium
493

Your company, Proseware, uses Microsoft Entra ID P2. You have a custom application that integrates with Microsoft Graph API to read user profiles. The application uses client credentials flow (application permissions). You need to ensure that the application can only read user profiles and not perform any other operations. Additionally, you want to review and approve the permissions periodically. What should you do?

Medium
494

A multinational corporation must comply with the EU General Data Protection Regulation (GDPR). They need to respond to a data subject access request (DSAR) by searching for personal data across Exchange Online, SharePoint Online, and OneDrive for Business. Which Microsoft Purview solution should they use?

Hard
495

Refer to the exhibit. You are reviewing a Microsoft Purview classification rule. The rule is enabled and set to apply a sensitivity label. However, you notice that documents containing EU personal data are not being labeled automatically. What is the most likely cause?

Hard
496

An organization wants to ensure that only managed and compliant devices can access corporate email in Exchange Online. Which Microsoft Entra ID Conditional Access policy setting should they use?

Easy
497

A company uses Microsoft Purview. A compliance officer applies a retention label to a set of legal documents and configures the label to mark the items as records. After the label is applied, a user attempts to delete one of these documents from SharePoint Online. What will be the outcome?

Hard
498

Your organization, Fabrikam, has recently merged with another company. You need to provide seamless access to resources for users from both companies while maintaining separate identity directories. The users from the acquired company have their own Microsoft Entra ID tenant. You need to enable them to access applications in your tenant using their existing corporate credentials, without creating new accounts. Additionally, you want to enforce conditional access policies from your tenant for these users. Which approach should you use?

Medium
499

A company uses Microsoft 365 and many third-party SaaS apps like Salesforce and Box. The security team wants to detect when a user downloads a large number of files from a cloud storage app after hours, which may indicate data exfiltration. Which Microsoft security solution should be used to detect such anomalous behavior in cloud apps?

Medium
500

A company uses Microsoft Entra ID. They want to allow employees to access the expense reporting application only from managed devices that are compliant with security policies and from trusted IP ranges. Additionally, if the user's sign-in risk is high, access must be blocked. Which of the following conditions should the administrator configure in a Conditional Access policy to enforce these requirements?

Easy
501

A security administrator at an organization using Microsoft Entra ID needs to automatically detect user sign-ins that exhibit risky behavior, such as signing in from a suspicious IP address or using leaked credentials. The administrator also wants the system to automatically calculate a risk level for each user and take actions like requiring a password reset when risk is high. Which Microsoft Entra ID feature should the administrator use?

Medium
502

A company wants to require multi-factor authentication (MFA) for all users accessing a financial application, but only when they sign in from outside the corporate network. Which Microsoft Entra ID feature should be used?

Medium
503

A multinational organization uses Microsoft Entra ID for identity management. The security team wants to implement a Conditional Access policy that blocks access from untrusted locations unless the user's device is marked as compliant by Microsoft Intune. However, users traveling to trusted partner locations should be allowed access even if their device is non-compliant. Which two conditions should be configured in the policy?

Hard
504

A company implements regular data backups and a disaster recovery plan to restore critical systems after an outage. Which security principle is primarily being addressed by these measures?

Easy
505

Your organization, Fabrikam Inc., uses Microsoft 365 and has Microsoft Purview licensed. You need to implement a compliance solution to monitor and prevent the sharing of confidential financial data via email. Specifically, you want to: (1) Detect when users send emails containing financial account numbers (e.g., credit card numbers) to external recipients. (2) Automatically block such emails with a policy tip notifying the sender. (3) Allow the sender to override the block if they provide a business justification. (4) Create a report of all blocked emails for compliance review. Which Microsoft Purview feature should you configure?

Easy
506

Your organization uses Microsoft Entra ID and needs to allow external partners to sign in using their own identity providers (e.g., Google or Facebook). Which Microsoft Entra feature should you configure?

Easy
507

A legal department is preparing for litigation. They need to preserve all potentially relevant content in Exchange Online, SharePoint Online, and Teams to prevent deletion or modification. Additionally, they must search across these locations for specific keywords and export the results for external review. Which Microsoft Purview solution should they use?

Hard
508

A user reports frequent password reset requests. You suspect password spray attacks. Which Microsoft Entra ID feature should you use to investigate?

Medium
509

A company uses Microsoft 365 and many third-party SaaS apps like Salesforce and Box. The security team needs to discover which unsanctioned cloud apps employees are using (Shadow IT). They also want to get a risk score for each app and receive alerts when a high-risk app is used. Which Microsoft security solution should they use?

Hard
510

A security administrator needs to identify and remediate misconfigurations in Azure resources that could lead to security breaches. They want a central dashboard that provides a secure score based on security controls and recommendations. Which Microsoft solution should they use?

Easy
511

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to prevent users from copying credit card numbers from an internal web application to a personal cloud storage app. Which DLP policy setting should they configure?

Hard
512

A compliance administrator creates a retention policy as shown in the exhibit. What is the overall effect of this policy on content in SharePoint Online?

Medium
513

An organization uses Microsoft Intune to manage devices. They need to ensure that only devices with a minimum OS version can access corporate email. What should they configure?

Medium
514

A security architect is explaining the evolution of the security perimeter. They state that because users access corporate resources from anywhere on any device, the traditional network perimeter is no longer sufficient. What does the architect identify as the new primary security perimeter?

Easy
515

A company uses Microsoft Teams and wants to ensure that messages containing offensive language are flagged for review. Which Microsoft Purview solution should be used?

Medium
516

Order the steps to respond to a data breach using Microsoft 365 Defender incident response.

Medium
517

Your organization is using Microsoft Sentinel as a SIEM. You want to automatically respond to a high-severity incident by opening a ticket in ServiceNow and notifying the security team via email. What should you create?

Medium
518

Which TWO Microsoft Purview solutions can be used to protect sensitive data in Microsoft Teams?

Medium
519

Your organization uses Microsoft Entra ID for identity management. You need to enable users to sign in using a QR code from the Microsoft Authenticator app. Which Microsoft Entra feature should you configure?

Medium
520

A compliance officer needs to retain customer records for 7 years and then automatically delete them. However, during an ongoing legal case, the legal team must preserve specific documents indefinitely without affecting the retention policy for other documents. Which combination of Microsoft Purview solutions should the company use?

Medium
521

A company is implementing Microsoft Purview Communication Compliance to detect inappropriate messages. They need to monitor Microsoft Teams channel messages and chat messages for potential policy violations. Which configuration is required?

Hard
522

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that allows users to sign in using their social media accounts, such as Google or Facebook. What should you configure?

Medium
523

A user logs into a corporate laptop by inserting a smart card and entering a PIN. The user then attempts to open a confidential folder. The operating system checks the user's access rights and denies access. Which security concepts are demonstrated in this scenario?

Hard
524

Refer to the exhibit. A user reports being unable to access Exchange Online from their personal laptop. The sign-in log shows failure due to device non-compliance. What should you configure to allow access while maintaining security?

Medium
525

A company needs to provide a developer with temporary, time-bound administrative access to Azure resources to debug a production issue. The access must require approval from the manager and automatically expire after 4 hours. Which Microsoft Entra capability should they use?

Hard
526

A company uses Microsoft Purview Compliance Manager to improve their compliance posture. They are preparing for a SOC 2 audit and need to score compliance with SOC 2 controls, track improvement actions, and assign tasks to responsible teams. Which component of Compliance Manager should they use to assign and track specific actions to improve their compliance score?

Medium
527

Which TWO of the following are capabilities of Microsoft Purview Data Loss Prevention?

Easy
528

Your company is adopting a Zero Trust network architecture. You need to implement microsegmentation for workloads running in Azure. Which Azure service should you use?

Hard
529

A company uses Microsoft Entra ID. They have a critical application that requires additional security. The security team wants to enforce multifactor authentication (MFA) for every access to the application, but they also want users to reauthenticate with MFA if a session lasts longer than 60 minutes, regardless of device compliance. Which Conditional Access control should the administrator configure?

Hard
530

A user reports they cannot access the company portal from their personal device. The device is not enrolled in Microsoft Intune. The admin wants to ensure only compliant devices can access corporate resources. What should the admin configure?

Easy
531

A company wants to implement a Zero Trust security model. Which TWO of the following are core principles of Zero Trust?

Hard
532

Refer to the exhibit. You are reviewing a Microsoft Purview sensitivity label configuration. A user reports that a document containing a sensitive info type with confidence 80 was not automatically labeled. What is the most likely cause?

Hard
533

Your company uses Microsoft Purview to manage data across Azure, on-premises SQL Server, and Amazon S3. You need to create a unified map of all data sources and their sensitivity labels. Which Microsoft Purview feature should you use?

Hard
534

A company wants to ensure that data is not altered during transmission between a client and a server. They use TLS encryption. Which security goal does this primarily address?

Easy
535

Your organization wants to use Microsoft Defender for Cloud Apps to detect anomalous user behavior across cloud applications. Which feature should you enable?

Easy
536

A company uses Microsoft 365 and needs to classify and protect sensitive documents by applying encryption and visual markings (headers/footers) based on the content's sensitivity. They also want to automatically revoke access to documents that leave the organization. Which Microsoft Purview solution should they configure?

Medium
537

Refer to the exhibit. You are reviewing Microsoft Entra sign-in logs. Which statement is true?

Hard
538

A user authenticates to a company's network by entering their password and then approving a push notification on their mobile phone. After authentication, the user attempts to access a shared folder containing financial reports. The access is denied because the user's account is not a member of the 'Finance' group. Which security concept is demonstrated when the user is denied access to the folder?

Easy
539

A company uses Microsoft Entra ID. They want to ensure that users who are traveling to a high-risk country, based on the sign-in IP address, are prompted for multi-factor authentication before accessing the company's CRM application. Which Microsoft Entra ID feature should they configure?

Medium
540

A company needs to allow external business partners to securely access internal SharePoint Online sites and Teams channels. The partners use various identity providers, including Microsoft Entra ID and Google. The company wants to manage these external users in their directory and assign access policies. Which Microsoft Entra ID capability should they use?

Easy
541

A security team wants to discover all cloud applications being used by employees, including unsanctioned file sharing and collaboration apps. They plan to analyze traffic logs from their network firewall to identify usage patterns and assess each app's risk level. Which feature of Microsoft Defender for Cloud Apps should they enable?

Medium
542

You need to ensure that sensitive documents in Microsoft SharePoint Online are automatically classified and protected when they contain credit card numbers. What should you configure?

Easy
543

Your company is implementing data loss prevention (DLP) policies in Microsoft Purview. You need to create a policy that prevents users from sharing credit card numbers via email to external recipients. The policy should only apply to users in the Finance department. Which action should you take?

Medium
544

A company with Microsoft 365 wants employees to access corporate applications from their personal Android and iOS devices. The security team requires that these devices be enrolled in mobile device management (MDM) for compliance policies, and that company data can be selectively wiped from the device without affecting personal data. Which Microsoft Entra device identity type should they configure for these personal devices?

Medium
545

Which two scenarios are examples of using Microsoft Entra business-to-business (B2B) collaboration? (Choose two.)

Easy
546

You are a compliance administrator for Contoso, a multinational company that uses Microsoft 365. The company has the following requirements: 1. Automatically retain all documents containing personally identifiable information (PII) for 7 years. 2. Prevent users from sharing PII via email with external recipients unless they provide a business justification. 3. Monitor and alert when users access sensitive data outside of business hours. 4. Generate a compliance score for GDPR and ISO 27001. You need to configure the appropriate Microsoft Purview solutions. For each requirement, match the correct solution. Which combination of solutions should you use?

Hard
547

Your organization uses Microsoft Defender for Cloud Apps. You need to detect anomalous user behavior such as impossible travel. Which type of policy should you configure?

Easy
548

A company uses Microsoft Entra ID and requires that all guest users from a partner organization must sign in using Microsoft Authenticator for MFA. The partner organization manages their own identities. What should you configure?

Medium
549

A security architect is implementing a Zero Trust security model. The architect insists that the network perimeter should not be trusted and that security controls must be applied to all traffic, even within the corporate network. They also emphasize the need for continuous monitoring and detection of threats as if a breach has already occurred. Which Zero Trust principle is the architect primarily applying?

Hard
550

A company wants to reduce the risk of privileged account misuse. They need to provide temporary, time-bound access to administrative roles in Microsoft Entra ID (Microsoft Entra ID) and require approval from a manager before granting the access. Which Microsoft Entra capability should they use?

Medium
551

Your organization uses Microsoft Purview Records Management to manage high-value contracts. You need to ensure that once a contract is declared as a record, it cannot be modified or deleted by any user, including administrators. Which type of record should you use?

Medium
552

A financial services company uses Microsoft 365 and must comply with PCI DSS. They want to automatically prevent users from sending emails that contain credit card numbers to external recipients. If a user tries to send such an email, the system should block the message and notify the user with a policy tip. Which Microsoft Purview solution should they configure?

Medium
553

A security analyst receives an alert from Microsoft Sentinel indicating a potential ransomware attack. The analyst needs to quickly understand the full scope of the attack, including all affected accounts and devices. Which Microsoft Sentinel feature should they use?

Easy
554

Your organization has implemented Microsoft Entra ID Governance. You need to review and attest to the access rights of users in a specific group every quarter. The group contains both direct members and members from nested groups. Which Microsoft Entra feature should you use to automate this review?

Hard
555

Your organization uses Microsoft Intune and Microsoft Entra ID. You need to enforce that only compliant and managed devices can access corporate email in Microsoft 365. Additionally, if a device is jailbroken, access should be blocked. You also want to provide a seamless sign-in experience for compliant devices. You have Microsoft Entra ID P1 licenses. What should you configure?

Hard
556

Your organization uses Microsoft Defender for Cloud to protect Azure virtual machines. You need to ensure that critical vulnerabilities identified on the VMs are automatically remediated using a just-in-time patching mechanism. What should you configure?

Easy
557

Which TWO of the following are identity-related security best practices recommended by Microsoft? (Choose two.)

Easy
558

Which TWO of the following are capabilities of Microsoft Purview Information Protection? (Choose two.)

Medium
559

Refer to the exhibit. You are reviewing Microsoft Entra sign-in logs for a user. The user successfully signed in from a mobile device running iOS, located in the US, with medium risk level. The sign-in did not require MFA. You have a Conditional Access policy that requires MFA for all users when sign-in risk is medium or higher. Why was MFA not triggered?

Hard
560

Your organization needs to prevent sensitive data in SharePoint Online from being shared externally. Which Microsoft Purview solution should you use?

Easy
561

An organization uses Microsoft Defender for Endpoint (MDE). The security team wants to identify devices that have not received a security update in the last 30 days. Which report should they use?

Easy
562

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

Easy
563

A company implements a sign-in process where a user must provide their password and then enter a temporary code sent to their mobile phone. Which security principle is this process primarily enforcing?

Easy
564

Your company is implementing a passwordless authentication strategy. You want users to be able to sign in using the Microsoft Authenticator app on their mobile devices. Which Microsoft Entra feature should you enable?

Easy
565

A company receives a subject rights request (SRR) from a customer under GDPR, asking for the deletion of all personal data held about them. The compliance team needs a tool to orchestrate the discovery of this data across Microsoft 365 and other systems, and to track the response and fulfillment of the request. Which Microsoft Purview solution should they use?

Hard
566

A company requires that all sensitive data in Microsoft Teams messages be automatically encrypted and labeled with a 'Confidential' tag. Which Microsoft Purview solution should they use?

Medium
567

A company is designing a data governance strategy using Microsoft Purview. They need to allow data owners to define custom attributes for data assets and control who can access those assets. Which Purview feature should they use?

Hard
568

Your organization is implementing Microsoft Entra Internet Access (formerly Microsoft Entra Internet Access). You need to secure access to public internet apps by enforcing traffic routing through Microsoft's network. Which feature should you enable?

Hard
569

You are a compliance officer at a healthcare organization that uses Microsoft 365. The organization must comply with HIPAA regulations. You have Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Intune. You need to ensure that all devices accessing patient health information (PHI) are compliant with the organization's security policies, which require device encryption, a minimum OS version, and the use of a compliant mobile device management (MDM) provider. Currently, some devices are not managed by Intune. You need to enforce that only compliant devices can access PHI stored in SharePoint Online. What should you do?

Hard
570

A company runs critical applications on Windows Server virtual machines in Azure and on-premises. The security team wants to reduce the exposure of administrative ports (e.g., RDP, SSH) by requiring administrators to request just-in-time (JIT) access. The request should require approval from a central team, and the port should be opened only for a limited time. Which Microsoft security solution provides this JIT capability for both Azure and on-premises servers (when connected via Azure Arc)?

Hard
571

Match each Azure security service to its purpose.

Medium
572

A company runs virtual machines in Azure and also maintains on-premises servers connected via Azure Arc. The security team needs a single dashboard to view security recommendations, detect misconfigurations, and track a secure score across both environments. They also want to enable advanced threat protection features such as just-in-time (JIT) VM access and file integrity monitoring for these workloads. Which Microsoft security solution should they implement?

Medium
573

A compliance officer needs to investigate a potential data exfiltration incident. They must search the unified audit log for all activities where users accessed a specific sensitive SharePoint site in the last 7 days. Additionally, they need to create a custom alert that triggers when more than 10 file downloads occur from that site within an hour. Which Microsoft Purview solution should they use?

Medium
574

Your company is deploying Microsoft Entra ID Governance. They want to automate the review of guest user access to Microsoft Teams and remove access when guests leave the partner organization. Which feature should they implement?

Hard
575

Your company uses Microsoft Purview to manage records. You need to ensure that financial records are retained for 7 years and then permanently deleted. Which type of policy should you create?

Easy
576

A company uses Microsoft Entra ID (Microsoft Entra ID) to manage user access to cloud applications. The security team wants to enforce that users must provide a second form of authentication, such as a phone call or mobile app notification, in addition to their password. Which Microsoft Entra capability should they enable?

Easy
577

A company uses Microsoft Entra ID. The security team wants to automatically detect user behaviors that indicate possible compromise, such as leaked credentials, impossible travel, or anomalous login patterns. When a user is determined to be at high risk, the system should automatically require the user to reset their password the next time they sign in. Which Microsoft Entra capability should they use?

Medium
578

A company uses Microsoft Entra ID. A new IT support technician is hired and needs to be able to reset passwords for users but must not be allowed to delete user accounts or modify group memberships. Which built-in Microsoft Entra ID role should be assigned to this technician?

Easy
579

Refer to the exhibit. You are creating a Microsoft Purview sensitivity label for HR data. The JSON shows a label configuration. What is the likely effect of setting the sensitivity value to 90?

Hard
580

A company has several custom-developed web applications hosted on-premises. The company wants to provide employees with secure remote access to these applications without deploying a traditional VPN. Employees should be able to sign in using their existing Microsoft Entra ID credentials, and the solution should pass through multi-factor authentication policies. Which Microsoft Entra ID feature should they implement?

Medium
581

Your company uses Microsoft Defender for Cloud to assess security posture. A recommendation states that virtual machines should have just-in-time (JIT) network access enabled. What is the primary security benefit of enabling JIT?

Medium
582

A company wants to allow users to reset their own passwords from the login screen without contacting IT. Which Microsoft Entra ID feature enables this?

Easy
583

A company wants to automatically detect and remediate compliance issues such as sharing sensitive data externally. Which Microsoft Purview solution should they use?

Easy
584

A multinational corporation stores highly sensitive intellectual property in SharePoint Online. To meet regulatory requirements, they need an additional layer of encryption beyond Microsoft's baseline encryption. The company wants to manage their own encryption keys using Azure Key Vault, so that if they remove the key from the service, the data becomes unreadable. Which Microsoft Purview solution should they implement?

Hard
585

A company implements multiple layers of security controls: firewalls at the perimeter, intrusion detection systems on internal segments, antivirus software on all workstations, and encryption for sensitive data at rest and in transit. This strategy is intended to ensure that if one control fails, others still provide protection. Which security concept does this approach represent?

Easy
586

Refer to the exhibit. You run a KQL query in Microsoft Sentinel to investigate ransomware alerts. The query returns: AlertSeverity High: 5, Medium: 3, Low: 2. The security team wants to automate a response for all high-severity ransomware alerts. What should you configure?

Hard
587

Your organization uses Microsoft Purview Audit to investigate a security incident. You need to search for activities performed by a specific user over the past 90 days. Which solution should you use?

Medium
588

You are reviewing a Microsoft Purview DLP policy configuration as shown in the exhibit. What is the expected behavior when a user sends an email containing a credit card number to an external recipient?

Medium
589

Your organization wants to protect against phishing attacks by verifying the sender's identity for incoming emails. Which Microsoft Defender for Office 365 feature should you configure?

Easy
590

A large enterprise uses a variety of cloud applications, including sanctioned apps like Microsoft 365 and unsanctioned apps that employees adopted without IT approval. The security team wants to discover all cloud applications in use, assess each app's risk score based on more than 80 risk factors, and control data sharing within sanctioned apps to prevent data leakage. Additionally, they need to identify which users are using a new, unknown file-sharing service. Which Microsoft security solution should be deployed to meet these requirements?

Hard
591

Refer to the exhibit. The JSON snippet shows an app registration in Microsoft Entra ID. The password credential endDateTime is set to 2025-12-31. What will happen when that date is reached?

Medium
592

You are a security administrator for a company using Microsoft Entra ID P2. The company has a critical application that should only be accessible by a specific group of users (the 'Finance' group). You need to ensure that any access to this application is automatically logged and that an administrator is notified when a user outside the Finance group attempts to access it. Additionally, the CEO wants a quarterly review of all users who have access to this application. Which combination of features should you use?

Easy
593

Which THREE are features of Microsoft Entra ID Protection? (Choose THREE.)

Easy
594

A company uses Microsoft 365 and requires that users access corporate email and SharePoint from managed devices that meet security policy requirements, such as having encryption enabled and antivirus software running. The security team wants to enforce this access control within Microsoft Entra ID so that unmanaged devices are blocked. Which Microsoft Entra ID feature should they configure?

Medium
595

A legal team is managing a large litigation case involving over two million documents in SharePoint Online and Exchange Online. They want to reduce the time required for manual review by using a machine learning model that learns from a seed set of relevant and non-relevant documents and then predicts the relevance of the remaining documents. Which Microsoft Purview solution provides this advanced analytical capability?

Medium
596

Your company uses Microsoft Entra ID. You need to ensure that when a user's account is compromised and used to send spam, the account is automatically blocked from signing in. Which feature should you configure?

Medium
597

A company wants to ensure that only users with specific IP addresses can access its critical applications. Which Microsoft Entra feature should they configure?

Easy
598

Your organization has deployed Microsoft Intune for mobile device management. You need to ensure that users can only access corporate resources from devices that are compliant with your security policies. Which policy type should you configure?

Easy
599

Your organization uses Microsoft Purview Communication Compliance to detect harassing messages. You receive an alert for a message that appears to be a joke between colleagues. What should you do to prevent similar false positives?

Hard
600

Your organization uses Microsoft Entra ID with P2 licenses. You need to review and approve role activations for the Global Administrator role on a weekly basis. Which feature should you use?

Medium
601

Your organization uses Microsoft Sentinel for security operations. You need to ensure that when a high-severity incident is created, a Microsoft Teams message is sent to the SOC team automatically. What should you configure?

Medium
602

A company runs a production Kubernetes cluster in Azure. The security team needs to continuously monitor the cluster for misconfigurations, such as containers running with privileged access or secrets exposed in environment variables. They also want to detect runtime threats like crypto-mining containers. Which Microsoft security solution should they use?

Medium
603

A company uses a mix of Azure virtual machines and on-premises Windows and Linux servers. The security team wants a single, integrated solution that can continuously assess these servers for missing security updates, weak operating system configurations, and common vulnerabilities. The solution should provide prioritized remediation recommendations. Which Microsoft security solution should they use?

Medium
604

Your company has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to ensure that users can use the same password on-premises and in the cloud without having to sync password hashes. Additionally, you want to prevent accounts from being locked out after a few bad password attempts in the cloud. Which Microsoft Entra feature should you implement?

Medium
605

Which TWO of the following are capabilities of Microsoft Defender XDR? (Choose two.)

Medium
606

Which TWO Microsoft Purview features can be used to classify and label sensitive data in Microsoft 365?

Medium
607

Which TWO features are part of Microsoft Purview Information Protection?

Easy
608

Your company uses Microsoft Defender for Endpoint. A security analyst reports that a device is showing multiple alerts for the same malware variant, but the alerts are being automatically suppressed after the initial detection. What is the most likely reason for this behavior?

Hard
609

Your organization needs to monitor and respond to security threats across on-premises, cloud, and hybrid environments. Which Microsoft solution provides a unified SIEM and SOAR capability?

Easy
610

A user reports that they cannot access a sensitive document in SharePoint Online. The document has a 'Highly Confidential' sensitivity label. You verify the label is applied correctly. What is the most likely reason for the access issue?

Medium
611

Which TWO actions can be performed using Microsoft Purview Data Lifecycle Management?

Medium
612

A company uses a cloud-based Customer Relationship Management (CRM) system that is delivered as Software-as-a-Service (SaaS). According to the shared responsibility model, which security responsibility is primarily handled by the customer?

Easy
613

Your company uses Microsoft Defender for Cloud Apps to discover shadow IT. The security team wants to automatically block the use of a newly discovered high-risk cloud app across all users. What is the most efficient approach?

Hard
614

A healthcare organization must demonstrate compliance with HIPAA by assessing their current posture against regulatory controls, tracking improvement actions, and generating reports for auditors. Which Microsoft Purview solution should they use?

Medium
615

A company has a Microsoft Entra ID tenant with thousands of users. They need to ensure that only users with a 'Manager' attribute populated can access a sensitive app. Which approach should they use?

Hard
616

Your organization is implementing Microsoft Purview Communication Compliance to detect potential regulatory violations. You need to configure a policy that alerts when employees discuss insider trading in emails and Microsoft Teams messages. The solution should minimize false positives. Which action should you take?

Hard
617

Refer to the exhibit. An administrator runs the PowerShell cmdlet shown. What is the purpose of this command?

Hard
618

Refer to the exhibit. You are reviewing a Privileged Identity Management (PIM) configuration for a role in Microsoft Entra ID. The roleDefinitionId corresponds to a specific role. What is the effect of this configuration?

Hard
619

Refer to the exhibit. You are deploying a custom assessment automation in Microsoft Defender for Cloud using Bicep. The deployment fails with an error that the resource type is not valid. What is the most likely reason?

Hard
620

Your organization uses Microsoft Purview Audit (Standard) and needs to investigate a data breach that occurred 120 days ago. You discover that the required audit logs are not available. What is the most likely reason?

Hard
621

Your company uses Microsoft Purview to govern data across on-premises and cloud sources. You need to classify sensitive data such as credit card numbers and social security numbers automatically. What should you create?

Easy
622

Your company uses Microsoft 365 E5 licenses and wants to prevent sensitive data from being shared externally via email. You need to configure a solution that automatically scans outgoing emails for credit card numbers and blocks them if detected. What should you use?

Medium
623

A company configures its access control system so that each user can only access the data and perform actions that are strictly necessary for their job role. This configuration is a direct implementation of which security principle?

Easy
624

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They want to improve their secure score. What should they do?

Easy
625

A financial services firm is required by regulatory bodies to monitor employee communications (email, Teams chats) for potential insider trading or market manipulation. They need a solution that allows them to define policies to detect messages containing specific keywords or phrases (e.g., 'confidential', 'insider info'), and then assign flagged messages to designated reviewers for investigation. Which Microsoft Purview solution should they use?

Easy
626

A company wants to reduce help desk calls by allowing users to reset their own passwords. The security team requires that users verify their identity using a registered mobile phone or alternative email before resetting. Additionally, the company policy states that passwords cannot be reused until at least five new passwords have been used. Which Microsoft Entra ID features should they configure to meet these requirements?

Medium
627

Your organization uses Microsoft Purview to label and protect sensitive data. The compliance team wants to automatically apply a 'Confidential' label to documents containing personally identifiable information (PII) stored in SharePoint Online. What should they create?

Medium
628

A financial services company is required by the Payment Card Industry Data Security Standard (PCI-DSS) to retain all documents containing credit card numbers for at least seven years. The compliance team has created a custom sensitive information type (SIT) to detect credit card numbers in Microsoft 365. They want to automatically apply a retention label (e.g., "7-Year Retention") to any document in SharePoint or OneDrive that matches this SIT. Which Microsoft Purview solution should they configure to apply the label automatically based on content?

Hard
629

A company uses Microsoft Purview Information Protection to classify and protect sensitive data. They want to automatically apply a sensitivity label to documents containing credit card numbers. Which should you configure?

Medium
630

A company uses Microsoft Entra ID. They want to configure a Conditional Access policy that requires multi-factor authentication (MFA) when a sign-in is assessed as medium or high risk by Microsoft's identity protection signals. For sign-ins with no detected risk, MFA should not be required. Which feature or service provides the risk assessment signals that can be consumed by Conditional Access policies?

Medium
631

You are configuring Microsoft Entra ID for a new user. The user will need to access resources in multiple Microsoft cloud services (Office 365, Azure, Dynamics 365). Which Microsoft Entra edition is minimally required to provide single sign-on (SSO) across these services?

Easy
632

Your organization uses Microsoft Entra ID P2 licenses. You need to implement a process to automatically remove users from a group if they have not signed in for 90 days. Which feature should you use?

Hard
633

An organization needs to prevent users from sharing files containing trade secrets with external parties via email. The solution must allow internal sharing. Which Microsoft Purview capability should be configured?

Medium
634

A security analyst needs to query Microsoft 365 audit logs to find all activities where a user deleted a file from SharePoint Online in the last 24 hours. Which tool should they use?

Medium
635

A multinational corporation must comply with regulations that require them to keep financial records for 7 years and then permanently delete them. However, they are currently involved in litigation that requires preservation of all documents related to a specific project. They use Microsoft Purview. Which combination of features should they use to meet both requirements?

Hard
636

A company uses Microsoft 365 and allows employees to access corporate email and documents from their personal devices. The security team wants to protect against malicious links in emails and Microsoft Teams messages. When a user clicks a link, it should be checked in real-time to see if it leads to a known malicious site. If it does, access should be blocked. Which Microsoft security solution provides this capability?

Medium
637

A company implements multiple layers of security controls including a firewall, an intrusion detection system (IDS), antivirus software on endpoints, and regular security awareness training for employees. This approach is an example of which security concept?

Easy
638

You are the security administrator for a company using Microsoft Defender XDR. A user reports receiving a suspicious email with a link. What Microsoft Defender XDR feature should you use to investigate the email's threat level?

Easy
639

A company wants to implement just-in-time (JIT) privileged access management for their Global Administrators in Microsoft Entra ID. They require that a user must request activation of the Global Administrator role, the request must be approved by a separate administrator, and the role will automatically expire after 4 hours. Additionally, they need an audit trail of all activations. Which Microsoft Entra feature should they use?

Hard
640

A company uses Microsoft Entra ID. They want to enforce multifactor authentication (MFA) for all access to a sensitive HR application. However, they only want to require MFA when the sign-in risk is assessed as medium or high, and block access if the risk is high. Which Conditional Access components must the administrator configure to meet these requirements? (Choose the best answer)

Medium
641

A company is implementing a new security policy that requires every user to have only the minimum permissions necessary to perform their job duties. Which security principle does this policy align with?

Easy
642

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to synchronize user passwords and enable password writeback for self-service password reset. Which tool should you use?

Medium
643

A company is planning to migrate from on-premises Active Directory to Microsoft Entra ID. They have multiple on-premises applications that use LDAP for authentication. They want to enable single sign-on (SSO) to these applications from the cloud without modifying the applications. Which approach should they use?

Hard
644

Your organization uses Microsoft Entra ID. You need to ensure that guest users can access resources without requiring invitation redemption. Which feature should you enable?

Medium
645

A financial company needs to prevent any communication between their mergers and acquisitions (M&A) team and the trading desk across all Microsoft 365 channels, including email, Microsoft Teams, and SharePoint. They must ensure that no user in one group can send emails to or chat with users in the other group. Which Microsoft Purview solution should they implement?

Hard
646

You are the compliance administrator for a healthcare organization that must comply with HIPAA. You need to automatically detect and prevent patients' protected health information (PHI) from being shared via email. Additionally, you need to retain all emails containing PHI for 6 years. You also need to allow users to manually classify documents as 'Medical Record' with encryption that expires after 30 days. Which combination of Microsoft Purview solutions should you implement?

Medium
647

A security architect is adopting a new security model that assumes breach and verifies every access request. The model eliminates implicit trust and requires continuous validation. Which security model is being implemented?

Easy
648

A company uses Microsoft Entra ID. They want to enforce that users accessing the finance app from outside the corporate network must use multifactor authentication (MFA) and access from a device marked as compliant. Additionally, if the user's sign-in risk is medium or higher, access must be blocked. Which component of a Conditional Access policy should the administrator configure to specify the 'Block access' action for high-risk sign-ins?

Medium
649

Your organization uses Microsoft Defender XDR. The security team wants a central dashboard showing the overall security posture and recommended actions. Which tool should they use?

Easy
650

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

Medium
651

Refer to the exhibit. A Conditional Access policy is defined as shown. Which client applications will be blocked?

Hard
652

Your company uses Microsoft Intune to manage devices. You need to ensure that only devices that are compliant with your security policies can access corporate email via Microsoft Outlook. What should you implement?

Easy
653

You are reviewing a Microsoft Purview DLP policy rule represented in JSON. What is the effect of this rule?

Hard
654

An organization uses Microsoft Purview Audit to meet compliance requirements. Which TWO types of audit logs can be accessed?

Hard
655

Which TWO Microsoft Purview solutions can help detect and prevent data exfiltration?

Easy
656

Your organization recently deployed Microsoft Defender for Cloud Apps. You need to identify which users are using a personal Dropbox account to access corporate files. Which feature should you use?

Medium
657

A security architect is designing a defense strategy for a company's IT infrastructure. The strategy includes deploying a network firewall, using an intrusion detection system, installing antivirus software on all endpoints, and requiring multi-factor authentication for all user accounts. The architect explains that if the firewall fails, the IDS can detect an intrusion, and if the IDS misses something, the antivirus might catch it, and MFA can protect even if credentials are compromised. Which security principle best describes this layered approach?

Easy
658

An organization needs to automatically apply a 'Confidential' label to documents that contain EU personal data, and also encrypt those documents. Which Microsoft Purview feature should they configure?

Medium
659

A company uses Microsoft Sentinel for security operations. They want to automatically create an incident and assign it to a senior analyst when a high-severity alert is generated. Which feature should they use?

Medium
660

An organization uses Microsoft Entra ID. They want to automatically detect when a user's sign-in shows a high risk of compromise (e.g., impossible travel, anonymous IP address) and immediately require the user to reset their password. Which Microsoft Entra capability should they use?

Medium
661

Your company uses Microsoft Entra ID with P2 licenses. You want to require approval for users to activate the Global Administrator role. Which feature should you configure?

Medium
662

You are a security administrator for a company that uses Microsoft 365. The company has a Microsoft Purview Data Loss Prevention (DLP) policy that blocks sharing of Social Security Numbers (SSNs) externally. Recently, a user accidentally sent an email containing SSNs to an external partner after overriding the policy by selecting a business justification. Management wants to prevent users from overriding the policy for SSNs. You need to update the DLP policy to ensure that users cannot override the block for SSNs. What should you do?

Medium
663

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that company data on personal devices is protected if the device is lost or stolen. What should you configure?

Easy
664

A company has multiple Azure virtual machines running various workloads. They want a central solution that continuously assesses their security posture, identifies vulnerabilities, and provides recommendations to harden the environment. Which Azure service should they use?

Medium
665

A healthcare organization uses Microsoft Entra ID and needs to enforce that only users from the United States and Canada can access patient records. Access attempts from all other locations must be blocked. Which Microsoft Entra ID Conditional Access condition should be configured to meet this requirement?

Hard
666

Which TWO of the following are benefits of using Microsoft Entra ID for identity management? (Choose two.)

Easy
667

A company uses Microsoft Entra ID (Azure AD). They have a cloud-based HR system (e.g., Workday) that contains employee records. They want to automate the process of creating user accounts in Microsoft Entra ID for new hires and deactivating accounts for terminated employees based on information from the HR system. Which Microsoft Entra ID feature should they configure?

Medium
668

A security team wants to discover which cloud applications are being used by employees, including unsanctioned file-sharing and collaboration apps. They plan to upload network traffic logs from their firewall to analyze app usage and risk levels. Which feature of Microsoft Defender for Cloud Apps should they enable?

Medium
669

An organization adopts a Zero Trust security model. Which principle requires that every access request must be explicitly verified and granted least privilege regardless of the user's location or device?

Easy
670

An attacker gains access to a company's email system and reads confidential customer emails. Which security principle has been compromised?

Easy
671

A company wants to allow its employees to reset forgotten passwords or unlock their accounts without contacting the help desk. The solution must verify the user's identity using a phone call or mobile app notification before allowing the action. Which Microsoft Entra ID feature should be enabled?

Medium
672

You find a JSON representation of a sensitivity label in a SharePoint document's metadata. The label indicates encryption is applied and access is restricted to finance@contoso.com. Based on this information, what is the effect of the label applied to the document?

Medium
673

Which THREE capabilities are part of Microsoft Purview Data Lifecycle Management?

Hard
674

An organization wants to automatically revoke access to cloud apps when an employee leaves the company. Which Microsoft Entra feature should they use?

Easy
675

Your organization uses Microsoft Purview Compliance Manager to track compliance with regulatory standards. You need to create a custom assessment for a new internal policy. What should you do first?

Medium
676

A legal team is preparing for litigation and needs to collect relevant data from Microsoft Teams chats, email, and SharePoint documents. They need to place a hold on the data to prevent deletion, review it, and then use advanced analytics such as relevance ranking and email threading to reduce the review set. Which Microsoft Purview solution should they use to perform these tasks?

Hard
677

A security architect explains the Zero Trust model to the board. They state that every access request must be fully authenticated and authorized based on identity, device health, location, and risk, regardless of whether the user is on the corporate network. Which Zero Trust principle does this statement represent?

Medium
678

Your legal team needs to search for all emails from a specific executive that mention a project name 'ProjectX' for a litigation hold. Which Microsoft Purview tool should they use?

Medium
679

A compliance administrator creates the DLP policy shown in the exhibit. When a user shares a document containing a credit card number with an external partner, what is the expected outcome?

Medium
680

A company wants to ensure that emails containing credit card numbers are blocked from being sent externally. Which Microsoft Purview solution should they use?

Easy
681

Your company, Contoso, uses Microsoft Entra ID for employee identity management. You need to ensure that when an employee leaves the company, their access to all SaaS applications is automatically revoked within 24 hours. The HR department updates the employee status in a cloud HR system (Workday). What should you do?

Easy
682

Refer to the exhibit. The exhibit shows an alert from Microsoft Defender for Endpoint. The SOC team needs to decode the PowerShell command to understand the malicious intent. Which tool or method should they use?

Hard
683

Which TWO capabilities are part of Microsoft Entra ID? (Choose two.)

Easy
684

Which TWO are capabilities of Microsoft Intune? (Choose two.)

Easy
685

You need to allow users to reset their own passwords without contacting the help desk. Which Microsoft Entra feature should you enable?

Easy
686

You are investigating a potential data leak. You need to find all emails that contain the word 'confidential' sent to external recipients in the last 30 days. Which Microsoft Purview tool should you use?

Hard
687

Refer to the exhibit. An administrator runs the Azure CLI commands shown. What is the purpose of these commands?

Hard
688

A security administrator receives an alert about a suspicious sign-in from an unfamiliar location. The user verified the sign-in as legitimate. Which Microsoft Entra ID feature should be used to reduce false positives for this user?

Medium
689

A healthcare organization is implementing Microsoft Purview Data Lifecycle Management to retain medical records for 7 years. Which THREE components must be configured to achieve this retention requirement?

Hard
690

A company runs workloads in Microsoft Azure and in Google Cloud Platform (GCP). The security team needs a single dashboard to view the security posture of both cloud environments, get recommendations for misconfigurations based on best practices, and track compliance with industry standards such as ISO 27001 and PCI DSS. Which Microsoft security solution should they use?

Medium
691

A company stores customer data in Microsoft 365 and needs to identify which data is subject to GDPR. Which Microsoft Purview solution should be used?

Easy
692

A company wants to deploy a single security operations portal that provides a unified view of alerts and incidents from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. Which Microsoft portal should the security team use?

Easy
693

A multinational corporation uses Microsoft Entra ID. The IT department wants to allow regional IT administrators in Europe to manage users and groups only for their own region, without granting them permissions to manage users in other regions. Which Microsoft Entra ID feature should they use?

Medium
694

A company wants to ensure that only users with appropriate permissions can access sensitive data stored in Microsoft SharePoint Online. Which principle should they implement?

Easy
695

An organization uses Microsoft Purview Information Protection. They want to ensure that when a user manually applies a 'Highly Confidential' sensitivity label to a document, the label is automatically applied to any new content pasted from that document into another app. Which configuration should they enable?

Hard
696

A company wants to automatically classify and protect sensitive documents stored in SharePoint Online. The compliance administrator needs to create a policy that detects credit card numbers and applies encryption. Which Microsoft Purview solution should the administrator use?

Easy
697

Refer to the exhibit. You are reviewing a sensitivity label configuration in Microsoft Purview. Based on the exhibit, what is the result when a user applies this label to a document?

Medium
698

A company requires users to enter a password and then a temporary code from a mobile app to sign in. After signing in, a user attempts to open a confidential document but is denied because they are not a member of the 'Managers' group. Which two security concepts are primarily demonstrated in this scenario?

Easy
699

Your organization uses Microsoft 365 and wants to automatically quarantine suspicious emails before they reach users' inboxes. Which solution should you configure?

Medium
700

A compliance officer needs to create a policy that automatically detects and blocks the sharing of credit card numbers in emails and Teams messages. Which Microsoft Purview solution should be used?

Medium
701

Which TWO Microsoft Purview features allow you to monitor and manage data across hybrid environments (on-premises and cloud)?

Hard
702

Which THREE of the following are key concepts of identity management in Microsoft Entra ID?

Medium
703

A multinational corporation needs to enforce data residency requirements by storing data in specific geographic locations. They are using Microsoft Purview for data governance. Which capability should they leverage to meet this requirement?

Hard
704

A company uses Microsoft Defender for Cloud to secure its hybrid cloud workload. The security team needs to ensure that all virtual machines (VMs) have Just-In-Time (JIT) VM access enabled. What should they use to enforce this across subscriptions?

Hard
705

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to prevent users from sharing credit card numbers in emails to external recipients. Which DLP rule action should you configure?

Medium
706

Your organization wants to use Microsoft Entra ID to require multi-factor authentication (MFA) for all users when accessing a financial application. What should you configure?

Easy
707

A company stores application secrets and encryption keys in Azure Key Vault. They want to move from the older vault access policy model to a more scalable and granular permission model that integrates with Azure's role-based access control (RBAC). They also need to audit permissions using Azure Policy. Which access configuration should they choose for Azure Key Vault?

Hard
708

Your organization uses Microsoft Entra ID and has deployed Microsoft Entra ID Governance for entitlement management. You need to allow external partners to request access to a specific application, but only if they have a valid email address from an approved domain. Once approved, their access should automatically expire after 30 days. You also need to ensure that the partner's access is reviewed quarterly by the application owner. What should you configure?

Hard
709

A security operations team uses multiple Microsoft security products, including Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Entra ID Protection. They want to aggregate alerts from these sources into a single dashboard, correlate them to create incidents, and use automated playbooks to respond to threats. The team also wants to query historical security data for threat hunting. Which Microsoft solution should they deploy?

Medium
710

A user is locked out of their account after multiple failed sign-in attempts. You need to reduce false lockouts while maintaining security. What should you do?

Medium
711

Which TWO capabilities are provided by Microsoft Defender for Cloud? (Choose two.)

Hard
712

A company's IT department deploys a multi-layered security strategy that includes a perimeter firewall, network segmentation, endpoint antivirus software, data encryption, and employee security awareness training. Which security model does this approach represent?

Easy
713

A company deploys a sensitivity label as shown in the exhibit. The custom sensitive information type 'Custom_PII_Type' is configured to detect employee IDs. What happens when a user creates a new document in SharePoint Online that contains an employee ID?

Hard
714

A company uses Microsoft Entra ID and Intune for mobile device management. They want to enforce different access requirements for their finance application: when users access from an unmanaged personal device, they must perform multi-factor authentication (MFA). When they access from a corporate-managed device that is marked as compliant (e.g., joined to Azure AD, antivirus up-to-date, encryption enabled), MFA should not be required. Device compliance is reported by Intune. Which Microsoft Entra ID feature should they use to define these rules?

Hard
715

A financial institution uses Microsoft 365 and needs to prevent employees from accidentally sharing sensitive financial data (e.g., account numbers) via email. They also need to inform the sender with a policy tip if they attempt to send such data and block the email if it's shared externally. Which Microsoft Purview solution should they use?

Medium
716

A company has a policy that prohibits employees from sharing confidential customer data with unauthorized parties. The compliance team needs to detect patterns of unusual user activity that may indicate insider data theft, such as downloading large volumes of data to a personal device or emailing sensitive files to external recipients. They also want to investigate the activity and take remediation actions like generating a case for litigation or notifying the user's manager. Which Microsoft Purview solution should they use?

Medium
717

A security manager wants to ensure that an employee who sends an email cannot later deny having sent it. Which security concept and associated technology is best suited to achieve this?

Hard
718

A company uses Microsoft Defender for Endpoint to secure its devices, Microsoft Defender for Office 365 for email security, and Microsoft Defender for Identity for on-premises Active Directory. The security team wants a single console to view correlated incidents across these domains, where an incident might combine a suspicious email, a malicious file download, and a compromised account. Which Microsoft solution provides this unified incident view and automatic correlation?

Medium
719

Your company uses Microsoft Sentinel to manage security incidents. You need to automatically assign incidents to a specific analyst team based on the incident category (e.g., phishing incidents to the SOC team). What should you configure?

Medium
720

Your organization is using Microsoft Entra ID with P2 licenses. You need to enforce a policy that requires administrators to request approval before activating their privileged roles, and approvals must expire after 8 hours. Additionally, you need to ensure that all privileged role activations are logged for auditing. Which combination of Microsoft Entra capabilities should you use?

Medium
721

A security team wants to receive a unified security posture assessment for their hybrid workloads including Azure VMs, on-premises SQL servers, and AWS EC2 instances. They need to get actionable recommendations to harden configurations and improve their overall security score. Which Microsoft security solution provides this capability?

Medium
722

Your company uses Microsoft Defender XDR. You need to integrate threat intelligence from external sources to enrich alerts and automate response actions. Which feature should you use?

Easy
723

A company uses a cloud-based SaaS (Software as a Service) application for customer relationship management. According to the shared responsibility model, which security responsibility is primarily handled by the customer?

Medium
724

An organization uses Microsoft Intune to manage devices. They need to ensure that only devices with a compliant antivirus solution can access corporate email. Which policy type should be configured?

Hard
725

A company's security team implements a system where every access attempt to sensitive data is recorded, including who accessed the data and when. The logs are regularly reviewed to detect unauthorized access and to hold users accountable for their actions. Which security goal is primarily being addressed by this logging practice?

Easy
726

A healthcare organization uses Microsoft 365 and wants to prevent users from sending emails that contain patient health information (PHI) to external recipients. Which Microsoft Purview solution should they implement?

Medium
727

A company implements multiple layers of security controls, including firewalls, antivirus software, access controls, and security awareness training. Which security concept does this approach best represent?

Easy
728

A company wants to prevent employees from accidentally sharing a document containing personally identifiable information (PII) with external users. The document is stored in OneDrive for Business. Which Microsoft Purview solution should they use?

Easy
729

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically block sign-ins from users whose credentials have been compromised and require them to change their password before access is granted. Which Microsoft Entra ID capability should they use?

Easy
730

An organization uses Microsoft Entra ID and wants to require users to re-authenticate every 4 hours when accessing a critical financial application, even if the user already has an active sign-in session. Which Conditional Access control should be configured?

Medium
731

A company wants to automatically detect and remediate inappropriate messages in Microsoft Teams. Which Microsoft Purview solution should be configured?

Easy
732

You are viewing an application registration in Microsoft Entra ID. What can you conclude about this app?

Easy
733

Your organization uses Microsoft Purview to manage records. For legal reasons, you need to preserve all documents related to a specific litigation case and prevent any modification or deletion. Which feature should you use?

Medium
734

A company wants to monitor employee communications in Microsoft Teams and Exchange Online for potential policy violations such as harassment or inappropriate sharing of confidential information. They need a solution that allows them to define policies, review flagged messages, and manage investigations. Which Microsoft Purview solution should they use?

Hard
735

Your organization is implementing Microsoft Purview to manage data governance. You need to classify sensitive data such as social security numbers automatically. What should you create?

Easy
736

A security operations team uses Microsoft 365 Defender and wants to detect, investigate, and automatically respond to advanced identity-based attacks targeting on-premises Active Directory, such as Pass-the-Hash (PtH) and Golden Ticket attacks. They also need to integrate these alerts into Microsoft Sentinel for central incident management. Which Microsoft security solution provides these capabilities?

Hard
737

Your organization wants to use Microsoft Defender for Cloud to secure Azure virtual machines. Which feature should they enable to get vulnerability assessment without additional agents?

Easy
738

An organization wants to allow users to reset their own passwords without help desk intervention. Which Microsoft Entra feature should they enable?

Easy
739

A compliance officer needs to evaluate their organization's security and compliance posture against multiple regulatory frameworks such as HIPAA, GDPR, and ISO 27001. The solution must provide a continuous assessment score, actionable improvement actions, and the ability to track implementation progress. Which Microsoft Purview solution should they use?

Hard
740

Your organization uses Microsoft Entra ID. You need to ensure that only users from the finance department can access a sensitive application, and they must be granted access dynamically based on their department attribute. What should you configure?

Medium
741

A company uses Microsoft Entra ID Privileged Identity Management (PIM) to manage elevated access to Microsoft Entra ID roles. They want to ensure that a user who activates a privileged role must provide a justification and receive approval from their manager before activation is complete. Which PIM configuration should be used?

Hard
742

Sequence the steps to configure a retention policy in Microsoft Purview compliance portal.

Medium
743

Which THREE of the following are core principles of the Zero Trust security model? (Choose three.)

Hard
744

A company uses a financial accounting system where the employee who creates a purchase order cannot also approve it. This policy is designed to prevent a single individual from committing fraud by both initiating and approving a transaction. Which security principle does this practice primarily implement?

Easy
745

A multinational company deploys Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers. The compliance team reports that a DLP policy blocks a legitimate payment processing workflow. What should the compliance administrator do to allow the workflow while maintaining protection?

Medium
746

A company requires that all users accessing a financial application from outside the corporate network must complete multi-factor authentication (MFA). The IT team is configuring a Microsoft Entra ID Conditional Access policy to enforce this requirement. Which component of the policy should be configured to apply the MFA requirement?

Medium
747

You need to provide external partners with access to your organization's SharePoint site. The partners must use their own credentials. Which Microsoft Entra feature should you use?

Easy
748

Fabrikam Inc., a global financial services company, uses Microsoft Purview to manage compliance. They have the following requirements: (1) Prevent users from sending emails containing credit card numbers (CCN) to external recipients; (2) automatically encrypt emails containing CCN; (3) notify users when an email is blocked; (4) allow users to override the block for business justifications; (5) generate incident reports for compliance teams. The company uses Microsoft 365 E5 licenses and has Exchange Online configured. The compliance team wants to implement a solution with minimal administrative overhead. What should the administrator configure?

Hard
749

A security architect is implementing a Zero Trust strategy. They state that all access requests must be verified continuously, regardless of where the request originates (corporate network or remote). They also emphasize that access is granted based on a policy that evaluates user identity, device health, location, and risk in real-time. Which Zero Trust guiding principle does this scenario primarily illustrate?

Medium
750

Your organization uses Microsoft Entra ID. You need to ensure that users can reset their own passwords without help desk intervention, while maintaining security by requiring multi-factor authentication (MFA) during the reset process. Which feature should you enable?

Easy
751

Match each security control type to its example.

Medium
752

A company uses Microsoft 365 and wants to deploy a security solution that can automatically detect and remediate advanced attacks on endpoints (workstations and servers), such as ransomware and fileless attacks. They also want to provide incident response teams with detailed forensic data and the ability to isolate an infected machine from the network. Which Microsoft security solution should they use?

Medium
753

Your organization wants to ensure that only users with a specific sensitivity label can access a SharePoint site. Which Microsoft Purview feature should you configure?

Medium
754

Your company uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts. Which Microsoft Entra feature should you configure?

Easy
755

Which THREE Microsoft Purview solutions help protect sensitive data in Microsoft 365? (Choose three.)

Hard
756

Your organization uses Microsoft Sentinel. You need to create an analytics rule that triggers an incident when more than 10 failed sign-ins occur from a single IP address within 5 minutes. Which rule type should you use?

Medium
757

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that allows external partners to access resources using their own identity provider. Which Microsoft Entra feature should you use?

Medium
758

A company uses Microsoft Purview to classify and protect data. They need to ensure that when a user attempts to share a file containing a credit card number externally, the file is blocked and the user is prompted with a policy tip. Which type of Microsoft Purview policy should they configure?

Hard
759

Refer to the exhibit. The Conditional Access policy shown is applied to all users accessing Office 365. A user with a compliant device but no MFA registered attempts to access Exchange Online. What will happen?

Hard
760

Your organization uses Microsoft Purview eDiscovery to manage legal holds. You need to place a hold on mailboxes and OneDrive accounts for a specific user who is involved in a litigation. Which eDiscovery solution should you use?

Hard
761

A security administrator needs to block legacy authentication protocols across all applications in Microsoft Entra ID. Which conditional access policy setting should they configure?

Hard
762

A company uses Microsoft 365 and needs to comply with a regulatory requirement to retain all customer contracts for 5 years after the contract's end date, after which they must be automatically deleted. Additionally, the legal department needs the ability to preserve all documents related to an ongoing lawsuit, overriding any deletion timelines. Which Microsoft Purview solution should the company use?

Medium
763

Which TWO Microsoft Entra features can be used together to enforce risk-based conditional access?

Medium
764

Fabrikam Inc. is a global manufacturing company that uses Microsoft Entra ID for identity management. They have recently experienced a security incident where an attacker compromised a user account and accessed sensitive intellectual property. The security team wants to implement identity protection measures to detect and respond to such attacks in the future. They need a solution that can automatically detect suspicious sign-in behavior, such as impossible travel and anomalous token issuance, and then take action to block the sign-in or require additional verification. Additionally, they want to integrate threat intelligence feeds to improve detection. Which Microsoft security solution should they use to meet these requirements?

Medium
765

Which TWO of the following are Microsoft Entra ID editions that include Identity Protection? (Choose two.)

Easy
766

A security analyst is explaining the core principles of information security to a new team member. Which principle ensures that data is not modified by unauthorized parties?

Easy
767

A company uses Microsoft Entra ID and Intune for device management. The security team wants to create a Conditional Access policy for a sensitive research application. They require that: 1) The user must use a device that is marked as compliant by Intune, and 2) The user must accept the company's terms of use before accessing the app. Which grant control combination should they configure in the policy?

Medium
768

A company wants to securely grant external business partners access to internal SharePoint sites and Teams channels. The partners use various identity providers, including Google and Microsoft personal accounts. The company needs to manage these external identities in their Microsoft Entra ID directory and enforce access policies. Which Microsoft Entra capability should they use?

Medium
769

Your company is adopting Microsoft Copilot for Microsoft 365 to improve productivity. The security team is concerned about data leakage, as Copilot can access emails, documents, and other content. You need to ensure that sensitive data, such as credit card numbers and social security numbers, is not inadvertently exposed by Copilot. The organization uses Microsoft Purview sensitivity labels and DLP. You need to configure a solution that automatically detects and prevents Copilot from accessing or generating content containing these sensitive data types. What should you do?

Easy
770

Which Microsoft Entra ID feature allows an organization to provide external partners with access to its applications while maintaining control over authentication and governance?

Easy
771

Your organization wants to enable passwordless authentication for users. Which Microsoft Entra ID feature should you use?

Easy
772

A financial services organization needs to automatically classify and protect sensitive documents containing credit card information in SharePoint Online and OneDrive for Business. They want a purple-colored label to be applied automatically when the document is saved, and the document should be encrypted with a predefined template that restricts editing to internal users only. Which Microsoft Purview solution should they configure?

Hard
773

Your organization uses Microsoft Entra ID P1. You need to implement a solution that allows users to reset their own passwords without administrator intervention. The solution must also enforce a policy that requires users to verify their identity with two methods before resetting. What should you configure?

Easy
774

The exhibit shows a sign-in failure for John Doe. The admin wants to allow the sign-in while still enforcing MFA. What should the admin do?

Medium
775

A company uses a third-party SaaS project management application. The security team wants to monitor and control user sessions when employees access the application from personal, unmanaged devices. Specifically, they want to block the download of files to local drives and display a warning message to the user if they attempt to download. Which Microsoft security solution should they deploy?

Easy
776

According to the Zero Trust security model, which principle assumes that a breach has already occurred and therefore requires segmenting access and monitoring for lateral movement?

Easy
777

Which THREE are features of Microsoft Purview Data Lifecycle Management (formerly Records Management)? (Choose three.)

Hard
778

Your organization is using Microsoft Entra ID and has deployed Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with Intune policies can access corporate email via Microsoft Outlook for iOS and Android. Additionally, you need to prevent users from copying corporate data to personal apps on the same device. Which two Microsoft Entra features should you combine?

Hard
779

Refer to the exhibit. A Microsoft Purview DLP policy is configured as shown. What will happen when a user tries to email an external recipient a document containing a credit card number?

Medium
780

A company has deployed Microsoft Defender for Identity and wants to detect pass-the-hash attacks in real time. Which alert type should they monitor?

Hard
781

Refer to the exhibit. A security analyst runs this Microsoft Graph PowerShell command. What is the most likely purpose of this command?

Hard
782

A company wants to automatically detect emails in Exchange Online that contain credit card numbers and apply encryption to those emails before they are sent. Which Microsoft Purview solution should the administrator configure?

Medium
783

A compliance officer wants to automatically classify emails containing credit card numbers as 'Highly Confidential' and apply encryption. Which Microsoft Purview feature should be used?

Easy
784

Which TWO capabilities are part of Microsoft Entra ID Governance?

Easy
785

Your organization uses Microsoft Defender for Cloud Apps. A security analyst needs to receive an alert whenever a user accesses a cloud app from a new IP address that is not in the organization's trusted IP range. What should the analyst configure?

Medium
786

A security analyst receives an alert about a suspicious process on a device. The security solution automatically investigates the device, gathers evidence, and determines that a known malware variant was detected. It then presents an action plan to the analyst for remediation. Which Microsoft security solution provides this automated investigation and response capability?

Easy
787

Refer to the exhibit. You are evaluating a custom Azure Policy definition. The policy is intended to audit whether users assigned to a management role have MFA enabled. However, the policy is not triggering alerts for non-compliant users. What is the most likely cause?

Hard
788

Your organization uses Microsoft Sentinel. You need to create a custom analytics rule that triggers an incident when a user executes a specific command on Azure VMs. Which data source should you connect to capture the command execution logs?

Hard
789

Your company uses Microsoft Purview Information Protection. They want to automatically apply a 'Confidential' sensitivity label to documents containing a credit card number. What should they create?

Medium
790

You are the identity architect for a global organization with 100,000 users across 50 countries. The company uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. Recently, the security team identified that several compromised user accounts were used to exfiltrate data from a cloud storage app. The CISO wants to implement a solution that detects anomalous behavior (e.g., impossible travel, mass download) and automatically blocks the user session when such behavior is detected. The solution must also provide the ability to investigate and remediate after the fact. Which Microsoft Entra feature should you use in conjunction with Defender for Cloud Apps to meet these requirements?

Medium
791

A company uses Microsoft 365 and wants to automatically classify documents based on sensitive information types like Social Security numbers. Which Microsoft Purview feature should be used?

Easy
792

You are analyzing sign-in logs in Microsoft Sentinel. Based on the KQL query in the exhibit, what is the purpose of this query?

Hard
793

A company uses Microsoft Purview to map their data estate. They need to classify data stored in Azure SQL Database and Amazon S3. What should they use?

Medium
794

Your organization uses Microsoft Purview to manage data classification. You need to ensure that sensitive data containing social security numbers is automatically labeled when stored in SharePoint Online. What should you configure?

Medium
795

A company runs workloads in Azure and Amazon Web Services (AWS). The security team wants a single, unified dashboard to assess the security posture of all cloud resources, get prioritized recommendations for misconfigurations, and enable just-in-time (JIT) virtual machine access across both cloud environments. Which Microsoft security solution should they use?

Medium
796

A company wants to provide external consultants with access to a specific application using their LinkedIn or Google accounts. Which Microsoft Entra feature allows this?

Medium
797

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Microsoft 365 resources. You have configured a Conditional Access policy in Microsoft Entra ID that requires devices to be marked as compliant. However, some users report that they can still access email on their non-compliant Android devices. You need to troubleshoot and resolve the issue. What should you do?

Easy
798

A financial services company uses Microsoft 365 and must prevent employees from emailing credit card numbers in plain text. The compliance team wants to automatically detect credit card numbers in outgoing emails and block them before delivery. They also want to allow users to override the block with a business justification. Which Microsoft Purview solution should they configure?

Medium
799

Which THREE components are part of Microsoft Defender XDR? (Choose three.)

Medium
800

A company uses Microsoft Purview to manage data compliance. They need to meet regulatory requirements that mandate retention of financial records for 7 years and deletion of personal data after 3 years. Which THREE capabilities should they configure?

Medium
801

A security architect is explaining the Zero Trust model to the board. The architect emphasizes that the network perimeter can no longer be considered a safe zone. Which statement best describes the modern primary security perimeter according to Zero Trust principles?

Medium
802

A user reports that they cannot sign in to Microsoft Entra ID because they forgot their password. Which Microsoft Entra ID feature allows them to reset their password without contacting IT support?

Easy
803

A financial services firm has a strict compliance requirement to prevent insider trading. The firm must ensure that employees in the Investment Banking division cannot communicate or share documents via Microsoft Teams and SharePoint Online with employees in the Equity Research division. The solution must automatically block all communication and collaboration between the two groups, and any attempts to share must be denied. Which Microsoft Purview solution should they implement?

Hard
804

A security analyst needs to detect and investigate compromised identities in on-premises Active Directory. They want to monitor for lateral movement, reconnaissance, and credential theft using behavioral analytics. Which Microsoft security solution is designed specifically for this purpose?

Medium
805

An organization uses Microsoft Purview Compliance Manager. They need to track their progress against a specific regulatory standard and assign improvement actions to different teams. Which component should they use?

Hard
806

Refer to the exhibit. An administrator created a retention label with the settings shown. What is the behavior of this label when applied to content?

Medium
807

A security analyst needs to investigate a potential malware outbreak that started on an on-premises Windows server several days ago. They want to trace the attack timeline, see which files were modified, and understand how the attacker moved laterally across the network. Which Microsoft solution provides advanced endpoint detection and response (EDR) for on-premises servers?

Medium
808

Which TWO Microsoft security solutions can be used to detect and respond to threats across email, endpoints, and identities? (Choose two.)

Easy
809

Your organization uses Microsoft Entra ID. You need to grant external partners limited access to a SharePoint site for 30 days. After 30 days, access should automatically expire. Which Microsoft Entra feature should you use?

Medium
810

Refer to the exhibit. You are reviewing an ARM template for an Azure resource. Assuming the resource is a Key Vault, what is the effect of the networkAcls configuration?

Hard
811

Your company uses Microsoft Entra ID. You need to enforce that all users accessing the HR application must have a device that is compliant with company security policies. The device compliance is managed by Microsoft Intune. Which feature should you use to enforce this requirement?

Medium
812

A security administrator receives an alert from Microsoft Sentinel about a possible brute-force attack against a virtual machine. The administrator wants to automatically block the attacker's IP address for 24 hours using a playbook. Which automation trigger should the playbook use?

Hard
813

A company uses Microsoft Entra ID. They want to ensure that when users access the HR portal from an unmanaged personal device, they are prompted to sign a terms of use agreement and also required to perform multifactor authentication (MFA). Which Conditional Access control should they configure to enforce both requirements?

Medium
814

Your organization uses Microsoft 365 and wants to classify and protect documents based on their content, such as credit card numbers. Which Microsoft Purview feature automatically classifies content based on sensitive information types?

Easy
815

A multinational corporation needs to restrict data sharing in Microsoft Teams to comply with regional regulations. Users must not be able to share files with external domains from specific departments. What should the administrator configure?

Hard
816

An organization uses Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared externally. They need to block sharing of credit card numbers in emails and Teams messages. What should they create?

Medium
817

A company must retain all customer service emails in Exchange Online for 7 years for regulatory purposes. After 7 years, the emails must be automatically deleted. Additionally, employees must not be able to permanently delete these emails before the retention period ends. Which Microsoft Purview solution should they configure?

Medium
818

Your organization uses Microsoft Sentinel as its SIEM. You need to create an analytics rule that detects when a user account is created in Azure AD and then, within 10 minutes, that same account is used to grant admin consent to an application. You have a KQL query that joins AuditLogs and SigninLogs. However, the rule is generating too many false positives. You need to refine the query to reduce false positives. What should you do?

Hard
819

A company's security team configures network firewall rules so that only a dedicated jump server's IP address can initiate RDP connections to production servers. This is an example of which security principle?

Easy
820

Which TWO capabilities are provided by Microsoft Entra ID?

Easy
821

A company uses Microsoft Entra ID. The IT department needs to ensure that membership in the 'Global Administrator' role is regularly reviewed. Every quarter, the designated reviewers (e.g., senior managers) receive an email asking them to confirm whether each user in the role should keep their assignment. After the review deadline, any member not approved is automatically removed. Which Microsoft Entra ID feature should they configure?

Medium
822

A security team wants to detect when a user downloads an unusually large number of files from a third-party cloud storage app (e.g., Box) after logging in from an unfamiliar location. They also want to automatically suspend the user's account if such behavior is detected. Which Microsoft security solution should they use?

Medium
823

A multinational organization must comply with GDPR and local data residency requirements. The compliance team needs to ensure that personal data is not stored in regions outside the permitted locations. Which Microsoft Purview capability should they use to discover and map personal data across the organization's data estate?

Hard
824

A company wants to block all sign-ins using legacy authentication protocols because these protocols do not support multi-factor authentication (MFA). Which component of a Microsoft Entra ID Conditional Access policy should be configured to achieve this?

Medium
825

An organization wants to provide a secure way for external partners to access specific SharePoint sites without creating new user accounts. What Microsoft Entra B2B feature should they use?

Easy
826

Refer to the exhibit. You run a Kusto query in Microsoft Defender XDR Advanced Hunting. What does this query return?

Hard
827

Which TWO features are part of Microsoft Defender XDR?

Easy
828

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to ensure that only managed compliant devices can access corporate email via Outlook mobile app. What is the most efficient approach?

Hard
829

Your organization has a Microsoft Purview retention policy that retains SharePoint documents for 5 years. After 5 years, you want an administrator to review and approve deletion. Which configuration is required?

Hard
830

Your organization, Contoso Ltd., uses Microsoft 365 and Microsoft Defender XDR. You are a security administrator. Recently, a user named John Doe reported that his account is sending phishing emails internally. You suspect his account is compromised. You need to contain the threat immediately while preserving forensic data. The company has the following security solutions: Microsoft Entra ID P2, Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Microsoft Sentinel, and Microsoft Purview. You need to prevent the compromised account from causing further damage. Which action should you take first?

Medium
831

Your organization uses Microsoft Sentinel for SIEM. You receive an alert that a user account was compromised. You need to automatically disable the user's access across all cloud apps (SaaS) and reset their password. What should you use?

Hard
832

A company deploys a custom web application on Azure App Service (PaaS). The application stores data in Azure SQL Database. The security team needs to identify which security responsibilities fall under the customer according to the Microsoft shared responsibility model. Which of the following is primarily the customer's responsibility for this PaaS deployment?

Hard
833

A company is migrating its on-premises applications to Azure. The CIO states that the company is fully responsible for managing the security of its own applications and data, while Microsoft is responsible for the security of the underlying physical infrastructure, such as hardware and data centers. This division of security responsibilities is an example of which concept?

Easy
834

An organization wants to allow users to classify documents as 'Public', 'Internal', 'Confidential', or 'Highly Confidential' with different levels of protection. Which Microsoft Purview solution should they use?

Easy
835

A company stores critical financial reports in a SharePoint Online library. To ensure that the reports have not been tampered with, the security team compares a calculated hash of each file against a stored baseline. This verification process primarily protects which security goal?

Medium
836

A company uses Microsoft Entra ID. They want to enforce a policy that requires members of the 'Finance' group to use multi-factor authentication and sign in from a compliant device when accessing the financial reporting application. However, they want to exclude members of the 'Finance Admins' group from these requirements. Which Microsoft Entra ID feature should they configure?

Medium
837

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to receive alerts when a user attempts to share a file containing personally identifiable information (PII) via email. Which DLP rule component is used to define the notification action?

Hard
838

An organization uses Microsoft Entra ID Protection. A user's sign-in is flagged with a risk level of 'High' because of an anonymous IP address. The administrator wants to automatically block the sign-in while allowing the user to self-remediate. Which should be configured?

Hard
839

You are reviewing a Conditional Access policy configuration in Microsoft Entra ID. Based on the exhibit, what is the effect of this policy?

Hard
840

You are deploying Microsoft Entra Verified ID to issue verifiable credentials for employee onboarding. Which component is required to issue credentials?

Hard
841

Your organization uses Microsoft Sentinel as a SIEM. You need to collect security events from on-premises servers. Which connector should you use?

Medium
842

A company runs critical applications on Azure virtual machines and on-premises SQL servers. The security team wants to reduce VM attack surface by allowing just-in-time (JIT) access to RDP and SSH ports only when needed. Additionally, they need to monitor changes to important registry keys and system files on the SQL servers. Which Microsoft security solution should they use?

Medium
843

Your company, Fabrikam, uses Microsoft 365 and has Microsoft Purview Information Protection deployed. You need to protect sensitive documents labeled as 'Confidential' so that they cannot be printed or copied when opened in Microsoft Word. You have created a sensitivity label with the appropriate encryption settings. However, users report that they can still print and copy content from these documents. You verify that the label is published and assigned to the correct users. What should you configure to enforce the protection?

Medium
844

A company uses Microsoft Purview Information Protection to classify and label sensitive documents. The compliance team wants to automatically apply a 'Confidential' label to documents containing an employee's passport number. Which method should they use?

Easy
845

An organization wants to detect and respond to threats across their cloud infrastructure, including Azure, AWS, and GCP. Which Microsoft security solution should they centralize their security monitoring in?

Medium
846

Which THREE of the following are capabilities of Microsoft Purview Information Protection? (Select three.)

Hard
847

A user reports that they are repeatedly prompted for multifactor authentication when accessing Microsoft 365 apps from the same trusted device. What should you do to reduce the number of prompts?

Medium
848

A financial institution uses digital signatures to sign all transaction records. This ensures that the records have not been altered after signing. Which security goal does this primarily protect?

Easy
849

A company is involved in litigation and needs to preserve all Exchange Online mailboxes and SharePoint sites related to the case. The legal team also requires the ability to search, review, and export relevant content. Which Microsoft Purview solution should they use?

Medium
850

A company must retain all HR documents stored in SharePoint Online for exactly 7 years. After 7 years, the documents must be automatically deleted. Additionally, employees must not be able to permanently delete these documents before the retention period ends. Which Microsoft Purview solution should they configure?

Medium
851

Your organization wants to allow employees to use their personal mobile devices to access corporate resources, but you need to ensure that corporate data is protected if the device is lost or stolen. You also need to enforce a PIN policy on the device. Which combination of Microsoft Entra and Microsoft Intune features should you use?

Easy
852

A security analyst is using Microsoft 365 Defender to investigate a sophisticated multi-stage attack. The analyst needs to query data across endpoints, email, and identity logs to identify the attacker's behavior patterns and correlate events. Which Microsoft 365 Defender capability should the analyst use?

Hard
853

A company uses Microsoft 365. The security team wants to protect users from clicking malicious URLs in email messages. The solution should rewrite all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites. Which Microsoft Defender for Office 365 feature should they enable?

Medium
854

Which THREE of the following are capabilities of Microsoft Purview Compliance Manager? (Choose three.)

Hard
855

An organization has deployed Microsoft Entra ID Governance and wants to automate the process of revoking access to a critical application when an employee leaves the company. Which feature should they configure?

Hard
856

A company uses Microsoft Defender for Cloud to secure its hybrid cloud environment. They need to continuously assess compliance with regulatory standards like ISO 27001 and receive recommendations for remediation. Which feature should they enable?

Hard
857

Your organization uses Microsoft Sentinel. You need to create an automation rule that automatically closes a low-severity incident after 24 hours of inactivity. Which action should you include in the rule?

Medium
858

A company uses Microsoft Entra ID and wants to ensure that guest users who are inactive for 90 days have their access to internal resources automatically revoked. Additionally, a manager must review all guest accounts annually. Which Microsoft Entra feature should be used to implement these requirements?

Medium
859

Which TWO Microsoft Purview features can be used to automatically classify and protect sensitive data in documents?

Medium
860

A legal team is preparing for an internal investigation related to a potential policy violation. They need to identify all relevant documents stored in Exchange Online and SharePoint Online, but there are millions of items across the organization. The team wants to use a machine learning model that learns from a set of manually reviewed relevant and non-relevant documents to predict relevance and prioritize review. Which Microsoft Purview solution provides this capability?

Hard
861

A company uses Microsoft Entra ID. They want to require multi-factor authentication (MFA) for users who sign in from locations with a high risk score, as determined by Microsoft's analysis of the sign-in's IP address and other behavioral signals. Which Microsoft Entra ID feature should they configure?

Medium
862

Which TWO conditions can be used in a Microsoft Entra Conditional Access policy? (Choose two.)

Medium
863

A compliance officer needs to identify and monitor potentially risky user activities, such as users copying large amounts of data to external devices or sharing sensitive files with unauthorized recipients. They want to create a policy that detects these activities and automatically escalates them for investigation. Which Microsoft Purview solution should they use?

Hard
864

A manufacturing company experiences repeated ransomware attacks targeting their on-premises file servers. They have Microsoft 365 E5 and want to implement a solution to detect and automatically respond to such threats across hybrid environments. What should they deploy?

Hard
865

An organization wants to implement a zero-trust security model. They plan to require multi-factor authentication (MFA) for all users accessing sensitive applications, but only when the sign-in risk is medium or higher. Which Microsoft Entra ID capability should they use?

Hard
866

A tenant administrator runs the PowerShell cmdlet shown in the exhibit. The output shows that some compliance policies have IsAssigned = $false. What does this indicate?

Hard
867

An organization wants to automatically retain all financial documents for seven years and then delete them. Which Microsoft Purview solution should be used to create the retention policy?

Easy
868

A healthcare organization stores patient records in SharePoint Online. The compliance officer needs to ensure that records containing Protected Health Information (PHI) are retained for 7 years per regulatory requirements. Which Microsoft Purview solution should they implement?

Hard
869

Your organization is subject to GDPR and must respond to data subject deletion requests within 30 days. You have identified all personal data in Microsoft 365. Which Microsoft Purview solution should you use to permanently delete the data?

Hard
870

A company's security team discovers that several recent account compromises originated from attackers using legacy mail protocols (POP3, IMAP) which do not support multi-factor authentication. The team wants to immediately prevent any sign-in attempts using these protocols. Which Microsoft Entra ID feature should they configure to enforce this restriction?

Medium
871

Match each Microsoft Defender product to its focus area.

Medium
872

An organization wants to enable passwordless authentication for its users by using a mobile app. Which Microsoft Entra ID authentication method should they implement?

Medium
873

A company uses Microsoft 365 and needs to automatically detect documents in SharePoint Online that contain personally identifiable information (PII) such as social security numbers. When such documents are detected, they want to apply a sensitivity label that encrypts the document and restricts access to only the compliance team. Which Microsoft Purview solution should they use?

Medium
874

An organization wants to allow users to reset their own passwords without help desk intervention. They also need to enforce multifactor authentication during the reset process. Which Microsoft Entra feature should they configure?

Medium
875

A company uses Microsoft Entra ID. The IT team wants to provide remote employees with secure, single sign-on (SSO) access to a critical on-premises web application that uses password-based authentication, without requiring a VPN connection. Which Microsoft Entra ID feature should they use?

Medium
876

A security architect is designing a system where user access rights are reviewed and certified on a regular basis by data owners. The goal is to ensure that users continue to have only the permissions necessary to perform their job functions and that no excessive permissions exist. Which security principle is primarily being implemented through these regular reviews?

Easy
877

A company wants to enforce multifactor authentication for all users. Which TWO Microsoft Entra ID features can be used together to achieve this?

Easy
878

A company wants to offer a secure sign-in experience for external customers who may use personal accounts from Facebook, Google, or any OpenID Connect provider. They also need to customize the sign-in pages with their company logo and colors. Which Microsoft Entra capability should they use?

Medium
879

A company deploys Microsoft Entra ID Protection. The security team wants to automatically block sign-ins from anonymous IP addresses. They configure a Conditional Access policy. Which assignment condition should they use?

Hard
880

Your organization is implementing Microsoft Purview to manage data compliance. They need to automatically detect and protect credit card numbers in emails and documents. Which Microsoft Purview feature should they configure?

Medium
881

You are a security analyst using Microsoft Sentinel. You run the following Kusto query: SecurityAlert | where TimeGenerated > ago(7d) | where AlertName contains "MFA" | summarize Count = count() by bin(TimeGenerated, 1d) | render timechart What does this query do?

Medium
882

Your organization is implementing a new policy to ensure that only authorized users can access sensitive financial data stored in Microsoft SharePoint Online. The security team wants to enforce multi-factor authentication (MFA) for all users accessing this data, but only when accessing from outside the corporate network. Which Microsoft Entra ID conditional access policy setting should you configure to meet this requirement?

Medium
883

A company uses Microsoft 365 and sanctioned cloud apps like Salesforce and Box. The security team wants to prevent users from downloading sensitive documents from these apps when accessing from unmanaged personal devices, while still allowing read-only access. They need real-time session monitoring and control. Which Microsoft security solution should they use?

Medium
884

A company wants to automatically apply a 'Confidential' sensitivity label to any document that contains a credit card number, and also encrypt the document as part of the label. Which two components must be configured to achieve this? (Choose two.)

Medium
885

Refer to the exhibit. You are reviewing a Microsoft Purview DLP policy JSON snippet. The policy is enabled and contains one rule. What is the effect of this rule?

Hard
886

Refer to the exhibit. An administrator runs the PowerShell command shown. What is the purpose of this command?

Easy
887

Refer to the exhibit. A Microsoft Purview retention policy is configured as shown. Which statement about this policy is accurate?

Hard
888

A company uses Microsoft 365 and wants to automatically detect when employees attempt to share credit card numbers in emails or Microsoft Teams messages. The company also wants to block the message if it contains such sensitive data, and notify the sender with a policy tip. Which Microsoft Purview solution should the administrator configure?

Medium
889

A company stores HR documents in SharePoint Online. The compliance team wants to automatically apply a sensitivity label that encrypts the document whenever it contains a passport number. They do not want users to be able to override this classification. Which Microsoft Purview solution should they configure?

Hard
890

Your organization wants to use Microsoft Entra Verified ID to issue digital credentials to employees. Which Microsoft Entra service provides the ability to issue and verify verifiable credentials?

Easy
891

A security team manages a hybrid environment with on-premises Windows servers and Azure VMs. They need a solution that can detect lateral movement attacks, pass-the-hash attempts, and anomalous service account behavior on the on-premises Active Directory environment. They also want these alerts to be integrated into Microsoft Defender for Cloud for centralized monitoring. Which Microsoft security solution should they deploy on their on-premises domain controllers?

Medium
892

A security operations team investigates a multi-stage attack that began with a phishing email, then moved to credential compromise, and finally to lateral movement on endpoints. They need a single pane of glass to view the entire attack story, including the initial email, the compromised user's sign-in activities, and processes on affected devices. Which Microsoft security solution provides this unified investigation experience?

Medium
893

A company uses Microsoft 365 and needs to automatically apply a retention label to documents that contain personally identifiable information (PII) in SharePoint Online. The label should retain the documents for 5 years and then delete them. Which Microsoft Purview solution should they use?

Medium
894

A company uses Microsoft Defender for Office 365 and wants to protect users from malicious attachments in email. They need a feature that scans email attachments in a sandbox environment before they are delivered to recipients. Which Defender for Office 365 feature should they use?

Medium
895

Your organization, Contoso, uses Microsoft Entra ID P2. You have a Microsoft Entra tenant with several privileged roles including Global Administrator, Exchange Administrator, and SharePoint Administrator. The security team wants to enforce just-in-time (JIT) access for these roles, requiring users to request activation and get approval before they can use the role. Additionally, all activations must be logged and reviewed monthly. What should you configure?

Hard
896

Your organization is implementing Microsoft Purview to govern data across Microsoft 365 and Azure. Which TWO capabilities should you use to discover and classify sensitive data?

Easy
897

You are troubleshooting a Windows device that is reporting as non-compliant in Microsoft Intune. The exhibit shows the output of a PowerShell command run on the device. Based on the output, which component is likely misconfigured?

Hard
898

You are a compliance administrator for a multinational corporation that uses Microsoft Purview. The company must comply with the General Data Protection Regulation (GDPR). You need to implement a solution that allows data subjects to request access to their personal data stored in Exchange Online, SharePoint Online, and OneDrive for Business. The solution must provide a centralized portal for data subjects to submit requests and for privacy officers to manage the entire process, including searching for data, reviewing results, and exporting or redacting data. You also need to ensure that requests are automatically routed to the appropriate privacy officer based on the data subject's region. Microsoft Purview has been licensed for the entire organization. What should you configure?

Medium
899

A financial institution is deploying Microsoft Sentinel to monitor security events across its hybrid cloud environment. They want to correlate alerts from multiple sources and automate incident response. Which Microsoft Sentinel feature should they use to create automated workflows?

Medium
900

Refer to the exhibit. You are evaluating a Microsoft Purview retention policy. The policy is applied to Exchange Online, SharePoint Online, and OneDrive for Business. What is the behavior of this policy?

Hard
901

Refer to the exhibit. A Microsoft Graph PowerShell script is shown. What is the purpose of this script?

Hard
902

Your organization uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) for all users. Which policy should you create?

Easy
903

Refer to the exhibit. A Microsoft Purview DLP policy is configured. When a user attempts to share a document containing a credit card number externally, what will happen?

Medium
904

A healthcare organization needs to automatically classify documents containing patient health information (PHI) in Microsoft SharePoint. The solution should apply a 'Confidential - Healthcare' sensitivity label to any document that matches the HIPAA content pattern. Which Microsoft Purview feature should be used?

Easy
905

A company deploys firewalls, intrusion detection systems, and endpoint antivirus software at multiple layers of its network. This strategy is intended to ensure that if one security control fails, others still provide protection. Which security concept does this approach represent?

Easy
906

Contoso Pharmaceuticals is implementing Microsoft Purview to meet regulatory compliance (HIPAA and GDPR). They need to: (1) automatically classify and protect patient health information (PHI) and personally identifiable information (PII) in Exchange Online, SharePoint Online, and OneDrive for Business; (2) detect and prevent unauthorized sharing of sensitive data; (3) retain audit logs for 7 years; and (4) allow users to manually apply classification labels to documents. The company has 5,000 users and uses Microsoft 365 E5 licenses. The security team wants to minimize manual effort and ensure consistent protection. What should the compliance administrator configure first?

Medium
907

A financial services firm uses Microsoft Purview Information Barriers to prevent traders from communicating with investment bankers. A new employee in the trading department cannot access a SharePoint site used for compliance training. What should the administrator do?

Hard
908

A company implements a security policy where employees must use a smart card to log into their workstations. After logging in, they can only access file shares that correspond to their department. Which two security concepts are demonstrated in this scenario?

Easy
909

A company wants to block users from accessing phishing websites via Microsoft Edge. Which Microsoft security solution should they use?

Easy
910

A company wants to gain visibility into the use of unsanctioned cloud applications (shadow IT) within their organization. The security team has access to network proxy logs that show traffic to various cloud services. They want to use a Microsoft security solution to analyze these logs and identify which cloud apps are being used, by whom, and how much data is being consumed. Which capability of Microsoft Defender for Cloud Apps should they use?

Hard
911

An organization's security team needs to investigate a security incident that occurred two months ago. They need to search the unified audit log for specific activities performed by a user, such as file access, email actions, and sign-in events, to understand the scope of the compromise. Which Microsoft Purview solution provides these audit log search capabilities?

Hard
912

A company subscribes to a SaaS human resources application hosted by an external provider. The provider is responsible for maintaining the physical data centers, network infrastructure, and the underlying application software. The company is responsible for managing user accounts, configuring user permissions, and classifying the data they upload. Which security model does this arrangement primarily describe?

Easy
913

An organization uses Exchange Online and is concerned about phishing attacks that include malicious hyperlinks. They need a security solution that checks URLs at the time a user clicks them and blocks access to known malicious or suspicious websites. The solution must also provide real-time reputation analysis for link clicks. Which Microsoft security solution should they enable?

Medium
914

A company wants to monitor internal communications for inappropriate content such as harassment or threats, and also prevent employees from accidentally sharing credit card numbers via email. Which combination of Microsoft Purview solutions should they use?

Medium
915

A company needs to automatically detect and protect sensitive information such as credit card numbers in emails sent from Exchange Online and documents stored in SharePoint Online. They want to create policies that can block emails if such data is detected, and also automatically encrypt documents with specific labels. Which Microsoft Purview solution should they use?

Easy
916

A company wants to use Microsoft Intune to manage devices. Which TWO capabilities does Intune provide?

Easy
917

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. Which policy should you configure?

Easy
918

A company wants to collect security logs from on-premises servers, cloud applications, and network devices into a central repository, and then use advanced analytics detect threats and automate incident response. Which Microsoft security solution should they deploy?

Easy
919

An organization uses Microsoft Intune to manage devices. They want to ensure that only devices that are compliant with security policies (e.g., encryption enabled, latest patches) can access corporate email. Which Microsoft Entra feature should they use to enforce this requirement?

Medium
920

A financial services company uses Microsoft Purview to manage compliance. They need to automatically apply a 'Confidential' label to all documents containing financial data in SharePoint. What should they configure?

Medium
921

A company has discovered that many account compromise attacks are using legacy authentication protocols (e.g., IMAP, POP3, SMTP) which do not support multi-factor authentication. They want to block all sign-ins that use these protocols to reduce risk. Which Microsoft Entra ID feature should they use to enforce this block?

Medium
922

Your organization uses Microsoft Purview Records Management to manage high-value records that must not be deleted. You need to apply a label that marks content as a regulatory record. What label type should you use?

Medium
923

An organization has a Microsoft Purview Data Lifecycle Management policy that retains all documents for 5 years. However, legal requires that documents related to a specific lawsuit be preserved indefinitely. What should you do?

Hard
924

The exhibit shows a Conditional Access policy named 'Block Legacy Auth'. The admin notices that the policy is not blocking legacy authentication as intended. Based on the output, what is the most likely reason?

Hard
925

An organization wants to allow users to sign in using their mobile phone number and a verification code. Which Microsoft Entra ID feature enables this?

Easy
926

Which THREE components are part of Microsoft Entra Permissions Management (CIEM)?

Medium
927

Your organization uses Microsoft Purview to classify sensitive data. You need to create a custom sensitive information type that detects employee IDs matching the pattern 'EMP-XXXXX' (where X is a digit). Which rule pack element must you define?

Hard
928

A company uses Microsoft 365 and wants to protect its users from clicking malicious links in phishing emails. The security team needs a solution that rewrites URLs in email messages to check the link at the time of click, and blocks access if the link is malicious. Which Microsoft security solution should they use?

Easy
929

A law firm needs to retain client documents for 10 years after case closure, but automatically delete drafts after 30 days. Which two Microsoft Purview solutions should be combined?

Medium
930

Your company wants to use Microsoft Defender for Identity to detect security threats from on-premises Active Directory. What is a prerequisite for deploying Defender for Identity?

Easy
931

Your organization uses Microsoft Entra ID to manage user identities. A new employee named John joins the company and needs access to Microsoft 365 apps. You want to ensure John's identity is verified using a phone call. Which authentication method should you configure?

Easy
932

Your organization needs to monitor Microsoft Teams chats for inappropriate language and alert compliance officers. Which Microsoft Purview solution should you implement?

Easy
933

An organization needs to automatically apply a 'Highly Confidential' sensitivity label to all documents that contain a specific custom sensitive information type. The label should be applied when the document is created or modified. Which feature of Microsoft Purview Information Protection should be used?

Hard
934

Your organization uses Microsoft Entra ID P2 and wants to reduce the risk of identity compromise by requiring multifactor authentication (MFA) for all users, but excluding users when they are on the corporate network. Which policy type should you configure?

Medium
935

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers. You need to ensure that when a user attempts to share a document containing a credit card number via email, the email is blocked and the user receives a policy tip. Which action should you configure in the DLP policy?

Medium
936

A SOC analyst is investigating a potential security incident in Microsoft Sentinel. Which three are valid methods to gather additional context about a user entity? (Choose three.)

Hard
937

A company uses digital signatures to ensure that a sender cannot later deny having sent a message. Which security principle does this primarily address?

Medium
938

An organization uses Microsoft 365 Defender and wants to automate the investigation and response to common email-based phishing attacks. They want the system to automatically take actions such as deleting malicious emails from user inboxes across the organization after analysis. Which Microsoft 365 Defender component provides this automated capability?

Easy
939

Refer to the exhibit. You are configuring a sensitivity label in Microsoft Purview. The label is set to automatically apply when credit card numbers are detected. However, users report that the label is not being applied to documents containing credit card numbers. What is the most likely cause?

Hard
940

Your organization, Contoso Ltd., has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You are deploying Microsoft Defender for Identity (MDI) to protect against identity-based attacks. You have installed the MDI sensor on domain controllers and configured the service with the necessary permissions. After installation, you notice that MDI is not generating alerts for pass-the-hash attacks. You have verified that the sensors are healthy and that audit policies are correctly configured. You need to ensure that MDI can detect pass-the-hash attacks. What should you do?

Hard
941

Your company uses Microsoft 365 E5 and wants to provide a unified security dashboard showing alerts from endpoints, email, identity, and cloud apps. Which solution should you use?

Easy
942

Your organization needs to audit all changes to sensitive files in SharePoint Online for at least 180 days. Which Microsoft Purview feature should be enabled?

Easy
943

A company uses Azure virtual machines (IaaS) and on-premises Windows servers. The security team needs a single solution that provides a continuous assessment of security posture, a regulatory compliance dashboard for NIST SP 800-53, and integrated threat detection for hybrid workloads (e.g., brute force attacks on SSH). Which Microsoft security solution should they use?

Medium
944

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the most likely purpose of this query?

Hard
945

A security operations team needs to protect their organization's Windows 10 and Windows 11 devices from advanced persistent threats (APTs), ransomware, and fileless malware. They also require a centralized dashboard to view device security posture, investigate incidents, and perform proactive threat hunting using advanced queries. Which Microsoft security solution should they deploy?

Medium
946

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to prevent users from sharing credit card numbers via email, but allow sharing via Microsoft Teams messages. What should they configure?

Hard
947

An organization is redesigning its security architecture based on the Zero Trust model. Which principle requires that every access request must be fully authenticated, authorized, and encrypted before granting access, regardless of the network location?

Medium
948

A company has several on-premises web-based applications that need to be securely accessed by remote employees without requiring a VPN. The IT team wants to provide single sign-on (SSO) using Microsoft Entra ID. Which Microsoft Entra ID feature should they implement?

Medium
949

A company uses Microsoft Entra ID (Azure AD). The IT team has created a security group named 'SalesTeam' that contains all sales department users. They want to ensure that only members of this group can access the company's CRM application, which is registered as an enterprise application in Entra ID. What should the IT team configure?

Medium
950

A company is using Microsoft Entra ID to manage identities for a multi-tenant SaaS application. They want to allow users from partner organizations to access the application using their own corporate credentials, without needing to manage separate accounts. Which solution should they implement?

Medium
951

Your organization, Fabrikam Inc., uses Microsoft 365 E5 licenses. The security team is deploying Microsoft Purview to protect sensitive data. They need to ensure that when a user attempts to share a document containing credit card numbers with an external partner, the action is blocked and the user receives a policy tip. Additionally, the incident should be logged for investigation. You have already created a sensitivity label for credit card data and auto-labeled documents. Which Microsoft Purview feature should you configure to meet these requirements?

Hard
952

Your company uses Microsoft Purview to meet data privacy regulations. You need to discover and classify personal data stored in Azure SQL Database. Which THREE tools or features can you use?

Hard
953

Your organization wants to automatically investigate and remediate email-based threats in Microsoft 365. Which security solution should you use?

Easy
954

A company implements a security model where no user or device is automatically trusted, even if they are inside the corporate network. Every access request must be authenticated, authorized, and encrypted before granting access, regardless of the request origin. This model is known as:

Easy
955

Your organization needs to retain all email communications with customers for 7 years due to regulatory requirements. Which Microsoft Purview solution should you use?

Easy
956

A company has many guest users in Microsoft Entra ID who collaborate on a project in a specific SharePoint site. The compliance team needs to periodically verify that these guest users still require access to the site. If a reviewer does not respond within 30 days, the guest's access should be automatically removed. Additionally, the company wants to ensure that once access is removed, the guest user object is eventually deleted from the directory after 90 days. Which Microsoft Entra Identity Governance features should they use together?

Medium
957

A company is implementing a Microsoft Entra ID tenant for a new subsidiary. They require that all users authenticate using passwordless methods, specifically the Microsoft Authenticator app. What is the minimum configuration required to enforce this?

Hard
958

A company runs a consumer-facing e-commerce website and wants to allow customers to sign in using their existing social media accounts such as Google, Facebook, or LinkedIn. Which Microsoft Entra ID solution should they implement?

Medium
959

A user reports that they cannot access a sensitive document in SharePoint. The document has a sensitivity label of 'Highly Confidential' applied. The user is a member of the 'Finance' group, which has the label permission. However, the user is located in a country that is blocked by a conditional access policy. What is the most likely reason the user cannot access the document?

Easy
960

Your organization uses Microsoft Entra ID. You need to ensure that when a user is terminated, all access to SaaS applications is automatically revoked. What should you configure?

Hard
961

An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to ensure that when a user tries to share a document containing a credit card number externally via email, the user sees a policy tip and the email is blocked. Which DLP rule action should they configure?

Medium
962

A financial organization needs to automatically detect emails containing the phrase 'Non-Public Material Information' and apply a retention policy that retains those emails for 7 years. They also need to train senders with a policy tip before sending, and if they still send the email, it should be encrypted and blocked from being forwarded outside the organization. Which Microsoft Purview solution should they use?

Medium
963

A company uses Microsoft Defender for Endpoint on all workstations and Microsoft Defender for Office 365 for email protection. The security operations team wants a single console to see all incidents from both products, automatically investigate and respond to threats across endpoints and email, and integrate with Microsoft Sentinel for advanced hunting. Which Microsoft security solution should they use?

Hard
964

Your company wants to provide a single sign-on experience for all cloud applications. Which Microsoft Entra ID feature should you implement?

Easy
965

A company is subject to a legal investigation and must preserve all email communications related to the case for an indefinite period, even if users try to delete them. The compliance officer needs a solution that can place a hold on specific user mailboxes and prevent any permanent deletion of relevant content. Which Microsoft Purview feature should be used?

Medium
966

A company has an on-premises web-based expense report application. The IT team wants to make this application accessible to remote employees over the internet without requiring a VPN. They need to use Microsoft Entra ID for authentication and apply Conditional Access policies such as requiring multi-factor authentication. Which Microsoft Entra ID feature should they implement?

Medium
967

A company uses Microsoft Entra ID and Intune for device management. They want to ensure that only devices marked as compliant (e.g., updated, encrypted) can access the corporate HR portal. Which Conditional Access assignment condition should the administrator configure?

Medium
968

A financial services firm must comply with regulatory requirements that mandate supervisory review of communications between advisors and clients. They need to automatically capture emails and Microsoft Teams messages from a specific group of advisors, assign them to a supervisor for review, and flag messages containing potential code words for insider trading. Which Microsoft Purview solution should they use?

Hard
969

Your organization must ensure that financial reports are protected with encryption and cannot be forwarded. Which two Microsoft Purview features should you combine?

Medium
970

Tailspin Toys is a toy manufacturer with headquarters in the US and subsidiaries in Europe and Asia. You are the compliance administrator. The company must comply with the EU General Data Protection Regulation (GDPR). Requirements: 1) Personal data of EU residents must be retained only for as long as necessary (max 5 years after last interaction). 2) If a user tries to share personal data outside the EU, the action must be blocked. 3) Users must be able to manually mark documents as 'GDPR High Risk' which will encrypt them and add a watermark 'GDPR PROTECTED'. 4) All access to personal data must be audited. You have Microsoft Purview with E5 compliance licenses. What is the most efficient solution?

Hard
971

A user authenticates with a smart card and is then granted access to a specific database based on their job role in the finance department. Which security concept describes the process of determining what the authenticated user is allowed to do?

Medium
972

Your organization is implementing a Zero Trust security model. Which Microsoft Entra ID feature should you use to verify that users and devices meet specific health requirements before granting access to corporate resources?

Medium
973

A company uses Microsoft 365 and several third-party SaaS apps. The security team wants to detect when a user signs in from a remote location that is significantly far from their typical sign-in location within a very short time, indicating possible account compromise. Which Microsoft security solution should they use?

Easy
974

An organization wants to use a cloud-based SIEM to collect security data from multiple sources, including on-premises servers and cloud applications. Which Microsoft solution should they choose?

Easy
975

Your organization wants to ensure that all external emails are automatically tagged with a disclaimer at the top of the email body. Which Microsoft Exchange Online feature should you configure?

Easy
976

Which TWO of the following are capabilities of Microsoft Entra ID?

Easy
977

An organization uses Microsoft Defender for Cloud to secure its Azure workloads. They want to receive recommendations for improving the security posture of their virtual machines. What should they enable?

Medium
978

An organization wants to protect against business email compromise (BEC) attacks where attackers impersonate the CEO to trick employees into transferring funds. Which Microsoft Defender for Office 365 capability should they configure to detect such impersonation?

Medium
979

Your company uses Microsoft Purview Information Protection to classify sensitive data. A user reports that when they try to share a document containing a credit card number via email, the email is blocked. Which Purview feature is most likely causing this behavior?

Hard
980

A company uses Microsoft Entra ID and wants to enable employees to reset their own passwords without needing to contact the help desk. They want to enforce multifactor authentication when the employee performs the reset. Which Microsoft Entra feature should they enable?

Easy
981

Which TWO of the following are benefits of using Microsoft Entra ID for identity management?

Medium
982

A company wants to allow external customers to sign in to their custom web application using their own social identities, such as Google or Facebook. They also need to support self-service registration and custom branding for the sign-in pages. Which Microsoft Entra External ID solution should they use?

Hard
983

A company runs containerized applications on Azure Kubernetes Service (AKS) and stores container images in Azure Container Registry. The security team wants to automatically scan container images for vulnerabilities every time a new image is pushed to the registry and receive recommendations for remediation. Which Microsoft security solution should they enable?

Hard
984

A security administrator is using Microsoft Defender for Cloud to improve the security posture of Azure resources. The administrator wants to view a consolidated assessment of compliance with industry standards such as CIS and NIST. Which feature should be used?

Easy
985

An organization needs to detect and address potential policy violations in Microsoft Teams chat messages and channel conversations. They want to configure a policy that automatically scans for keywords related to confidential information and for sensitive data patterns like credit card numbers. When a violation is found, the policy should notify the user and their manager, and optionally escalate to a designated reviewer. Which Microsoft Purview solution should they configure?

Medium
986

A company wants to prevent users from sharing files containing personally identifiable information (PII) with external recipients. They also need to notify users if they attempt to share such files. Which Microsoft Purview solution should be configured?

Hard
987

A company uses Microsoft 365 and wants to protect users from malicious attachments in email. The security team wants a solution that detonates attachments in a sandbox environment before delivery, and only allows the email through if the attachment is deemed safe. Which Microsoft security solution should they use?

Medium
988

Your organization is using Microsoft Entra Permissions Management (CIEM). You need to identify overprivileged identities in AWS. Which capability should you use?

Hard
989

A company uses Microsoft Defender for Cloud to secure its Azure resources. The security team wants to receive a single recommendation for all resources that are missing just-in-time (JIT) VM access. Which Microsoft Defender for Cloud feature should they use?

Medium
990

A company uses Microsoft Entra ID with a custom line-of-business application that only supports SAML 2.0. They want to enable single sign-on for users. What should they configure in Microsoft Entra ID?

Hard
991

A company uses Azure SQL Database for a critical line-of-business application. The security team wants to enable threat protection that specifically detects and alerts on SQL injection attempts and anomalous database access patterns. Which workload protection plan should they enable within Microsoft Defender for Cloud?

Hard
992

Your organization uses Microsoft Purview to classify documents containing health information. You need to ensure that only users with explicit permission can access these documents. Which Microsoft Purview capability should you use?

Easy
993

Which Microsoft cloud service provides a unified data governance solution that helps you manage and protect data across your entire data estate, including multi-cloud and on-premises?

Easy
994

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to ensure that when a user's on-premises account is disabled, their cloud account is automatically disabled within 5 minutes. Which configuration should you use?

Hard
995

A healthcare organization subject to HIPAA regulations stores patient health information (PHI) in SharePoint Online and OneDrive. The compliance team needs to automatically detect and classify medical record numbers and other PHI when documents are uploaded. Detected sensitive content must be protected by encryption and restricted to authorized users only. Additionally, the team wants to prevent users from sharing such documents externally. Which TWO Microsoft Purview solutions should they combine to achieve these requirements? (Choose two.)

Hard
996

A security operations center (SOC) wants to enrich their detection capabilities by automatically correlating internal network logs with external threat intelligence feeds containing known malicious IP addresses and domains. They need to ingest, normalize, and prioritize these indicators and generate alerts when matches are found. Which Microsoft security solution provides built-in capabilities for this purpose?

Hard
997

Your company is deploying Microsoft Defender for Office 365. The security team wants to automatically remove malicious attachments from emails before they reach user inboxes. Which protection feature should be configured?

Easy
998

A data analyst is planning to leave the company in two weeks and has access to a large volume of sensitive customer data. The compliance team wants to detect if the analyst starts downloading large amounts of files to a personal USB drive or sending sensitive content to an external email address. They need to set up a policy that alerts on such anomalous data exfiltration activities without blocking operations until a thorough investigation is completed. Which Microsoft Purview solution should they configure?

Hard
999

Which TWO Microsoft security solutions can be used to centrally manage security policies across hybrid environments including on-premises and cloud? (Choose TWO.)

Easy
1000

A company uses a cloud-based email service. The service provider ensures that the physical data centers are secure and that the email platform is patched and available. The company is responsible for managing user accounts and ensuring that employees use strong passwords. This division of responsibilities is an example of which concept?

Easy
1001

Your company uses Microsoft 365 Copilot to assist employees with drafting emails and documents. The security team needs to ensure that when Copilot accesses sensitive data, it respects the organization's sensitivity labels and does not expose highly confidential information to unauthorized users. What should the security team configure?

Hard
1002

You are a security administrator for Contoso Ltd. The company uses Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Entra ID. Recently, several users reported receiving phishing emails that bypassed the existing anti-phishing policies. The security team suspects that attackers are using sophisticated techniques to evade detection. You need to enhance the email security posture by implementing a solution that uses AI and machine learning to detect advanced phishing attempts, including those using social engineering and impersonation. Which Microsoft solution should you use?

Medium
1003

A company uses Microsoft Entra ID. The compliance team requires that membership in highly privileged roles, such as Global Administrator, is reviewed quarterly. The review must be automated: role owners are sent an email notification with a list of current members to approve or deny. If a member does not respond within 30 days, their access should be automatically revoked. Which Microsoft Entra ID feature should the team use to set up this periodic review and automatic removal?

Medium
1004

A user receives a sensitivity label that automatically marks the email as 'Confidential' and prevents forwarding. The label was applied without user intervention. Which mechanism most likely applied the label?

Medium
1005

Which THREE are capabilities of Microsoft Purview Data Loss Prevention (DLP)? (Choose three.)

Medium
1006

A security operations center (SOC) team needs to ingest security logs from on-premises servers, Azure virtual machines, and SaaS applications like Salesforce. They want a cloud-native solution that uses machine learning to detect threats, provides a unified query language for hunting, and supports automated incident response through playbooks. Which Microsoft solution should they deploy?

Hard
1007

A company uses Microsoft Entra ID. They frequently collaborate with an external partner organization. The IT team wants to allow the partner's users to access the company's internal SharePoint site using their existing corporate credentials from their own Microsoft Entra tenant. The partner users should not have to create separate guest accounts or remember another password. Which Microsoft Entra feature should the IT team configure?

Medium
1008

Your organization wants to use Microsoft Entra ID to provide single sign-on (SSO) for a third-party SaaS application. What must you configure in Microsoft Entra ID?

Medium
1009

A multinational corporation must retain all financial records for 7 years and then permanently delete them. The compliance officer wants to ensure that even a global administrator cannot modify or delete the retention policy. Which Microsoft Purview solution and configuration should they use?

Medium
1010

Your organization uses Microsoft Entra ID to manage identities for employees and external partners. You need to ensure that external partners can access only specific applications and that their access expires automatically after 60 days. Which Microsoft Entra feature should you use?

Easy
1011

You are the compliance administrator for a retail company that uses Microsoft 365 Business Premium. The company needs to: - Block customers' credit card numbers from being sent via email. - Retain all sales invoices for 3 years as per financial regulations. - Allow managers to search and export employee emails for HR investigations. - Ensure that only HR can access employee salary information. Which Microsoft Purview solutions should you use?

Easy
1012

Refer to the exhibit. You are configuring a Microsoft Entra ID group. What does the exhibit represent?

Easy
1013

Refer to the exhibit. A company has configured the above Conditional Access policy in Microsoft Entra ID. A user attempts to access Exchange Online from an untrusted location. What happens?

Medium
1014

Your organization uses Microsoft Purview to manage compliance. You need to ensure that financial documents are automatically labeled as 'Financial' and retained for 7 years. Additionally, if a user tries to share a financial document externally, they must see a policy tip warning them and be blocked if they proceed. You also need to audit all access to financial documents. Which configuration should you implement?

Medium
1015

Your organization uses Microsoft 365 and needs to identify internal users who are sending confidential data to external domains repeatedly. Which Microsoft Purview solution should you use?

Medium
1016

A financial services organization needs to prevent communication between its research analysts and investment bankers to comply with regulatory requirements. Which Microsoft Purview solution should the compliance team implement?

Medium
1017

A company uses Microsoft Entra ID and wants to automate the lifecycle of guest users. When a contractor's project ends, the guest account should be automatically blocked and then removed after 30 days. Which Microsoft Entra capability should they configure to manage this process?

Medium
1018

A security operations center (SOC) receives a high volume of low-fidelity alerts from various security tools. They need a solution that can automatically correlate alerts into incidents, use built-in machine learning to reduce false positives, and provide a unified console for investigation and response across Azure, on-premises, and Microsoft 365. Which Microsoft security solution should they use?

Hard
1019

A company uses Azure resources, on-premises servers, and third-party cloud apps. The security team wants a single solution to collect security logs from all these sources, detect threats using advanced analytics, and automate responses to incidents. Which Microsoft security solution should they use?

Medium
1020

Your organization uses Microsoft Purview Insider Risk Management. You need to create a policy that detects users exfiltrating sensitive data via email to external recipients. Which policy type should you configure?

Hard
1021

A company wants to classify and label data in Microsoft SharePoint Online automatically based on content containing passport numbers. Which Microsoft Purview feature should they use?

Easy
1022

A company's security team has adopted a strategy that assumes a breach has already occurred. They implement network segmentation, apply strict least privilege access, continuously verify all access requests, and never trust users or devices solely because they are inside the network perimeter. This approach best describes which security model?

Medium
1023

An organization has Microsoft Sentinel and Microsoft Defender XDR. They want to automatically block a user's sign-in if a high-risk alert is triggered. Which Microsoft Entra feature integrates with these products to enforce access controls?

Medium
1024

A healthcare organization must comply with HIPAA regulations. They use Microsoft Purview to classify and label patient data. Which Microsoft Purview capability helps them enforce data protection policies automatically?

Medium
1025

Your organization is planning to deploy Microsoft Defender for Cloud Apps to discover shadow IT. You need to ensure that logs from your network proxy servers are ingested. Which method should you use to connect the logs?

Hard
1026

Your organization uses Microsoft Entra ID for identity management. You need to allow external partners to access a specific SharePoint Online site without requiring them to have a Microsoft Entra ID account in your tenant. Which feature should you use?

Medium
1027

A user is unable to access a cloud app and receives a message that their sign-in was blocked by a Conditional Access policy. The admin wants to allow the user to self-remediate by meeting policy requirements. What should the admin enable?

Easy
1028

Refer to the exhibit. A security administrator is reviewing an Azure Resource Manager template for a virtual machine. What is the purpose of the 'identity' section shown?

Medium
1029

Your company uses Microsoft Defender for Endpoint. You need to configure attack surface reduction (ASR) rules. Which TWO of the following are ASR rules?

Medium
1030

Your company is using Microsoft Entra ID to manage identities. You want to allow users to reset their own passwords without help desk intervention, but only if they have registered for self-service password reset (SSPR). What should you configure?

Medium
1031

You are reviewing a conditional access policy in Microsoft Entra ID. The policy is enabled, applies to all cloud apps, and is configured to include users assigned to the Global Administrator or Exchange Administrator roles. Which users are affected by this policy?

Easy
1032

You are an identity consultant for a mid-sized company with 5,000 employees. They use Microsoft Entra ID P1 and Microsoft Intune for device management. The company wants to implement passwordless authentication for all employees to improve security and user experience. Currently, users sign in with username and password plus MFA via the Microsoft Authenticator app. The company has a mix of Windows 10/11 devices (both domain-joined and Microsoft Entra joined) and iOS/Android mobile devices. They want to support passwordless sign-in on all platforms. The CTO is concerned about cost and wants to minimize additional licensing. Which passwordless method should you recommend?

Medium
1033

A healthcare organization uses digital signatures on electronic medical records to ensure that the records have not been tampered with during transmission. Which security goal is primarily being addressed by this practice?

Easy
1034

Which TWO components are part of the 'Zero Trust' security model? (Choose two.)

Medium
1035

A company uses Microsoft Defender for Cloud to secure their multi-cloud environment, which includes Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). They want a unified view of security posture, continuous assessment of resources, and recommendations to improve security across all clouds. Which feature of Defender for Cloud provides this capability?

Medium
1036

A company is migrating its on-premises workloads to Azure. The CISO wants to understand the division of security responsibilities between Microsoft and the customer across cloud service models. For which cloud service model does the customer have the most security responsibility?

Medium
1037

A security analyst runs the above KQL query in Microsoft Sentinel. What is the primary purpose of this query?

Hard
1038

Your organization implements a Microsoft Entra ID tenant with a custom domain (contoso.com). You need to ensure that all users are assigned a unique user principal name (UPN) based on their email address. What should you do?

Hard
1039

A security operations center (SOC) team needs a centralized platform to collect logs from firewalls, servers, and cloud applications. They want to analyze these logs to detect threats, create custom alerts, and automate response actions using playbooks. The solution should also provide threat intelligence feeds and allow for advanced hunting with Kusto Query Language (KQL). Which Microsoft security solution should the team implement?

Medium
1040

Your organization uses Microsoft Copilot for Security. You want to use natural language to generate a KQL query for threat hunting. What should you do?

Medium
1041

You work for a law firm that uses Microsoft 365 E5. The firm handles highly confidential client information and must comply with attorney-client privilege. You need to implement a compliance solution that: - Prevents unauthorized sharing of privileged documents via email. - Enables lawyers to easily classify documents as 'Privileged' and automatically encrypt them. - Allows the compliance team to monitor for accidental exposure of privileged information in Teams chats. - Ensures that privileged documents are retained for 7 years after case closure, then automatically deleted. - Provides the ability to search for privileged documents in case of a legal hold. What should you configure?

Medium
1042

A company uses Microsoft Entra ID. The IT department wants to automatically assign a Microsoft 365 E5 license to all users in the Sales department based on their department attribute. Which Microsoft Entra ID feature should they use?

Medium
1043

A company uses Microsoft Defender for Cloud to secure their Azure environment. The security team needs to check whether their resources comply with the CIS (Center for Internet Security) benchmark. How can they view their compliance status against CIS in Defender for Cloud?

Medium
1044

Your organization is deploying Microsoft Defender XDR to detect and respond to advanced threats. You need to ensure that security alerts from Microsoft Defender for Endpoint are automatically correlated with alerts from Microsoft Defender for Office 365. What should you configure?

Medium
1045

A company wants to allow employees to use their corporate Microsoft Entra ID credentials to sign in to third-party SaaS applications like Salesforce and ServiceNow. Which feature provides this capability?

Easy
1046

Which THREE capabilities are included in Microsoft Purview Audit (Premium)?

Hard
1047

Your organization uses Microsoft Purview eDiscovery to manage legal holds. A legal hold has been placed on a user’s mailbox, but the user has left the company and their mailbox has been converted to a shared mailbox. You need to ensure that the legal hold remains effective. What should you do?

Easy
1048

Refer to the exhibit. A security analyst is reviewing a Microsoft Defender XDR alert. Which two tactics identified are most relevant? (This is a multiple-choice question asking which two tactics are shown, but the format is single answer. We need to adjust: The question asks: 'Which two tactics are identified?' The correct answer is the option listing both 'InitialAccess and LateralMovement'.)

Hard
1049

You run the PowerShell command shown in the exhibit. What is the purpose of this command?

Easy
1050

Your organization uses Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from their CEO asking for a wire transfer. The email passed through the spam filter. What additional protection should be enabled to detect such attacks?

Medium
1051

Which TWO are principles of the Zero Trust security model?

Medium
1052

Your organization uses Microsoft Purview to manage data lifecycle. You need to ensure that after a project ends, all related files are automatically deleted after 3 years. What should you configure?

Medium
1053

A multinational corporation must comply with several regulatory frameworks, including GDPR, SOX, and HIPAA. The compliance officer wants to continuously assess the organization's compliance posture against these regulations, receive prioritized improvement actions, and track the implementation progress of those actions. Which Microsoft Purview solution should the compliance officer use?

Hard
1054

A company wants to ensure that all users access corporate resources using multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure to enforce MFA for all users?

Medium
1055

Which TWO are capabilities of Microsoft Defender for Cloud Apps? (Choose two.)

Medium
1056

Your company is implementing a hybrid identity solution with Microsoft Entra ID. You need to ensure that password changes on-premises are synchronized to the cloud within minutes. Which feature should you enable?

Medium
1057

A company uses Microsoft 365. The compliance department requires that all financial documents be retained for 10 years and then automatically deleted, while marketing documents must be retained for 3 years and then deleted. Additionally, they want to apply a default retention policy to all SharePoint Online sites. Which Microsoft Purview solution should the company use?

Easy
1058

A company uses Microsoft 365 and Azure. They want a unified security solution that provides threat protection across email, endpoints, identities, and cloud apps, with automated investigation and response capabilities. Which Microsoft solution should they use?

Medium
1059

A company is required by a compliance regulation to retain all user and admin activity audit logs for 2 years. They also need the ability to perform faster, historical searches on this audit data. Which Microsoft Purview solution should they use?

Medium
1060

A healthcare organization must comply with HIPAA regulations. They need to automatically detect and classify sensitive health information such as medical record numbers stored in SharePoint Online and OneDrive. When detected, the solution should apply encryption and restrict access to only authorized personnel. Which Microsoft Purview solution should they configure?

Medium
1061

A company uses a hybrid environment with Azure virtual machines (IaaS) and on-premises Windows servers. The security team needs a single solution that continuously assesses the security posture of these workloads, provides a regulatory compliance dashboard with actionable recommendations, and enables threat detection. Which Microsoft security solution should they use?

Medium
1062

Your company uses Microsoft Entra ID and wants to allow external partners to sign in using their own Google or Facebook accounts. Which feature should you enable?

Medium
1063

Your company needs to detect and prevent employees from sharing confidential product plans via email with external parties. Which Microsoft Purview solution should you configure?

Easy
1064

A company implements a security measure to ensure that only authorized employees can view sensitive customer records. Which principle of the CIA triad does this measure primarily protect?

Easy
1065

Refer to the exhibit. You are a compliance administrator managing a DLP policy in Microsoft Purview. The policy is set to 'enforce' mode but you notice that internal users can still share credit card numbers via email to external recipients. What is the most likely cause?

Hard
1066

Which TWO of the following are types of identity in Microsoft Entra ID? (Select two.)

Easy
1067

A company wants to automatically prevent users from sharing files containing personal data (e.g., passport numbers) via email. Which Microsoft Purview solution should they configure?

Easy
1068

Your organization uses Microsoft Defender XDR. You need to investigate a potential lateral movement attack where a compromised user account is used to access multiple workstations. Which feature should you use to visualize the attack path?

Medium
1069

A company uses Microsoft Entra ID. The security team needs to ensure that when users sign in to a critical financial application from an untrusted network, they must first complete multi-factor authentication (MFA). Additionally, the team wants to block the sign-in if the device is not marked as compliant by Microsoft Intune. Which conditional access grant control should they configure to meet both requirements?

Medium
1070

Refer to the exhibit. A Microsoft Purview DLP policy is configured in Test mode. An administrator notices that a user is still able to share a document containing a credit card number. What is the most likely reason?

Hard
1071

Your organization wants to centrally manage security policies for all devices (Windows, iOS, Android) and ensure they meet compliance requirements before accessing corporate resources. Which Microsoft solution should you use?

Easy
1072

Which TWO of the following are features of Microsoft Defender for Cloud? (Choose two.)

Medium
1073

A multinational organization uses Microsoft 365 and must demonstrate compliance with both GDPR and ISO 27001. The compliance team needs a centralized tool to assess their current compliance posture against these frameworks, receive prioritized improvement actions, and track the implementation of those actions over time. Which Microsoft Purview solution should they use?

Medium
1074

Refer to the exhibit. A security analyst runs this Kusto Query Language (KQL) query in Microsoft Sentinel. What is being identified?

Easy
1075

A healthcare organization runs a mix of workloads on Azure (Azure VMs, SQL Database) and on-premises (Windows Servers). They must continuously assess their compliance against the HIPAA and HITRUST regulatory frameworks. They want a unified dashboard that shows their compliance score against these standards and provides step-by-step recommendations to remediate violations. Which Microsoft Defender for Cloud capability should they use?

Hard
1076

Contoso uses Microsoft Sentinel. They want to automate response to a high-severity incident by blocking the source IP in Azure Firewall and sending a notification to the SOC team via email. Which feature should they use?

Hard
1077

A multinational corporation must comply with several regulations including GDPR, ISO 27001, and NIST. They need a single solution that provides a compliance score, tracks their progress, and recommends specific improvement actions that can be assigned to different departments. Which Microsoft Purview solution meets these requirements?

Medium
1078

Your company wants to protect sensitive data in Microsoft Teams. Which two Microsoft Purview features can help prevent accidental sharing of confidential information? (Choose two.)

Easy
1079

Your organization uses Microsoft Purview eDiscovery to manage legal cases. You need to place a hold on a user's mailbox to preserve data for an ongoing litigation. Which role do you need to assign to the eDiscovery manager?

Medium
1080

A company's security policy requires that customer data must only be accessible by authorized sales representatives. Which security principle does this requirement directly enforce?

Easy
1081

A healthcare organization must comply with HIPAA. They need to automatically detect protected health information (PHI) in emails sent from Exchange Online, prevent users from sharing these emails with unauthorized external recipients, and apply a retention label that retains PHI emails for six years. Which Microsoft Purview solution should they configure?

Hard
1082

A company wants to provide employees with single sign-on access to both Microsoft 365 and a third-party SaaS application. Which feature of Microsoft Entra ID should they use?

Easy
1083

A user downloads a software update from a company's internal website. The update file is hashed, and the hash value is published on a separate secure page. After downloading, the user computes the hash of the downloaded file and compares it to the published hash. The two values match. Which security concept is primarily demonstrated by this comparison?

Easy
1084

A company uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) only for external guest users, while allowing internal employees to sign in without MFA. Which Conditional Access setting should be configured?

Medium
1085

A company uses Azure virtual machines for a production database. The security team wants to minimize the attack surface by blocking all inbound RDP (port 3389) traffic. However, administrators occasionally need to connect for maintenance. The team needs a solution that allows administrators to request temporary access to the RDP port, which is automatically revoked after a specified time. Which Microsoft Defender for Cloud feature should they use?

Easy
1086

A security administrator is explaining the shared responsibility model to a new team member. The company uses a Software-as-a-Service (SaaS) application such as Microsoft 365. For which of the following items is the customer primarily responsible under this model?

Easy
1087

A company wants to protect its employees from phishing attacks delivered via email. The solution must analyze all URLs embedded in incoming emails in real-time. If a URL points to a known malicious site, the link should be blocked at the time of click. Additionally, the solution should sandbox URLs in attachments and provide time-of-click verification. Which Microsoft security solution should they implement?

Medium
1088

A healthcare organization stores sensitive patient records in a cloud database. The database is encrypted at rest using AES-256. If an attacker gains access to the physical storage media, they cannot read the data. Which security concept does this encryption primarily provide?

Easy
1089

Refer to the exhibit. You are reviewing a Microsoft Purview DLP policy configuration for a compliance team. What is the effect of this policy?

Medium
1090

A company wants to discover which cloud applications are being used by employees, assess the risk of those apps, and control data sharing in sanctioned apps like Box or Dropbox. Which Microsoft security solution should they implement?

Medium
1091

A company's security operations team needs to centralize security log collection from multiple sources including on-premises firewalls, AWS CloudTrail, and Azure Active Directory sign-in logs. They want to use built-in analytics to detect threats across all data sources and create automated response playbooks, such as isolating a compromised user account when a specific attack pattern is detected. Which Microsoft security solution should they deploy?

Medium
1092

Match each Microsoft identity service to its description.

Medium
1093

A company has a SharePoint Online site that stores project documents. Due to legal requirements, all documents in this site must be retained for exactly 5 years from the date they were created, and then automatically deleted. No user should be able to permanently delete a document before the retention period ends. Which Microsoft Purview solution should the administrator configure?

Easy
1094

A user is locked out of their account due to multiple failed sign-in attempts. Which Microsoft Entra ID feature can automatically block suspicious sign-in attempts based on risk?

Easy
1095

A company hosts a mission-critical customer portal on Azure virtual machines. To ensure continuous availability, they deploy the application across two separate Azure regions. If one region experiences a failure, traffic is automatically routed to the other region with minimal disruption. Which security goal is primarily being addressed by this architecture?

Easy
1096

You are investigating an alert in Microsoft 365 Defender. The KQL query in the exhibit retrieves evidence for alert-5678. What type of entities does this query filter for?

Hard
1097

Your organization uses Microsoft Entra ID. You need to enforce multi-factor authentication (MFA) for all users accessing the company's financial application. Which security feature should you use?

Easy
1098

A company needs to ensure that employees cannot share sensitive financial reports with external parties via email. They want to automatically detect and block emails that contain the phrase 'Confidential-Financial' in the subject line or body, regardless of the recipient's domain. Which Microsoft Purview solution should they configure?

Medium
1099

A company uses Microsoft 365. The compliance team needs to create a policy that automatically blocks outgoing emails that contain personally identifiable information (PII) such as social security numbers. However, they want to allow users to override the block with a business justification if necessary. Which Microsoft Purview solution should they configure?

Easy
1100

A security team manages a hybrid environment with Azure VMs and on-premises Windows servers. They want a single dashboard that provides continuous assessment of security posture, actionable recommendations to harden configurations, and integration with Microsoft Defender for Cloud to detect threats. Which Microsoft security solution should they use?

Medium
1101

Your company wants to allow partners to use their own corporate credentials to access a specific SharePoint site. Which Microsoft Entra ID feature supports this?

Easy
1102

A user reports that a sensitive document labeled 'Highly Confidential' was accidentally shared with an external vendor. You need to investigate how the sharing occurred. Which two Microsoft Purview tools should you use together?

Medium
1103

A company uses Microsoft Entra ID and Intune to manage devices. They want to enforce a policy that allows access to financial data from SharePoint Online only when the user's device is compliant (e.g., encrypted, patched) AND the user authenticates from a trusted IP address range. Additionally, if the sign-in risk is assessed as medium or high by Identity Protection, the user must also perform multifactor authentication (MFA). Which Conditional Access components should the administrator configure?

Medium
1104

A company needs to retain all customer emails for 7 years for regulatory compliance. After 7 years, they must be permanently deleted. They also need a legal hold for an ongoing investigation. Which Microsoft Purview solution should they use for the retention and deletion requirement?

Medium
1105

A company must retain all vendor contracts for 10 years to meet regulatory requirements. After 10 years, the contracts must be permanently destroyed with no possibility of recovery. The compliance team wants to automate this lifecycle and ensure that during the retention period, the contracts cannot be edited or deleted by users. Which Microsoft Purview solution should they use?

Medium
1106

A large enterprise is concerned about insider threats. The compliance team needs to detect and investigate potential data theft scenarios, such as when employees nearing their resignation date suddenly copy large amounts of sensitive data to USB drives or email confidential files to personal accounts. They require a solution that uses machine learning to identify risky activities and create alerts for investigation. Which Microsoft Purview solution should they deploy?

Hard
1107

A company wants to allow employees to access corporate resources such as email and internal apps using their personal smartphones. The IT team does not want to fully manage or domain-join these devices but needs each device to have a simple identity that links the user's work account to the device. Which Microsoft Entra ID device identity option should they implement?

Easy
1108

Refer to the exhibit. You are reviewing a Microsoft Defender for Cloud Apps alert. Based on the evidence, which action should you take first?

Hard
1109

Your organization uses Microsoft Entra ID and wants to provide a single sign-on (SSO) experience for a third-party SaaS application that supports SAML 2.0. The app must also enforce multifactor authentication (MFA) for external users. What should you configure?

Medium
1110

A company's security operations center wants to detect advanced attacks targeting their on-premises Active Directory, such as Kerberos Golden Ticket attacks, pass-the-hash, and skeleton key malware. They need a solution that monitors domain controller traffic, correlates with entity behavior, and integrates with Microsoft Sentinel for incident response. Which Microsoft security solution should they deploy?

Hard
1111

Refer to the exhibit. A sensitivity label is configured as shown. A user applies the parent label to a document containing credit card numbers. What is the expected behavior?

Hard
1112

A company wants to create a sensitivity label called 'Highly Confidential' in Microsoft 365. When applied to a document, the label should automatically encrypt the document and restrict access to employees in the finance department only. Which Microsoft Purview solution should the administrator use to configure this label?

Easy
1113

An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for all users accessing sensitive data from outside the corporate network. Which Microsoft Entra capability should they configure?

Medium
1114

A company has implemented a security model where every access request is fully authenticated, authorized, and encrypted before granting access, regardless of where the request originates (corporate network or internet). The model assumes that no entity is inherently trustworthy and requires continuous verification. This model is known as:

Medium
1115

Refer to the exhibit. The JSON shows a Microsoft Purview DLP policy. A user sends an email with a credit card number to an external recipient. What will happen?

Medium
1116

A company is deploying a web application on Azure App Service. The security officer states that according to the shared responsibility model, the customer is responsible for managing access to the application and securing the application code. Which of the following responsibilities does Microsoft retain for Azure App Service?

Hard
1117

A company runs a web application in Azure that is publicly accessible. They want to protect it against large-scale distributed denial-of-service (DDoS) attacks from multiple sources. Which Azure service is specifically designed for this purpose?

Medium
1118

A company must retain all customer contracts for 10 years to comply with industry regulations. After 10 years, the contracts must be permanently deleted. Which Microsoft Purview solution should be used to automate this process?

Medium
1119

A company has an on-premises Active Directory and wants to synchronize user accounts to Microsoft Entra ID. They also need to enable password hash synchronization so users can sign in to cloud resources with the same password. Which Microsoft tool should they use?

Medium
1120

What is the primary purpose of Microsoft Defender for Cloud Apps?

Easy
1121

A company needs to grant IT administrators temporary and time-limited access to privileged roles in Microsoft Entra ID (Azure AD). The access must require approval from a manager and be automatically revoked after the task is completed. Which Microsoft Entra ID feature should be used?

Medium
1122

You are the identity administrator for Contoso Ltd., a global company with over 10,000 employees. The company uses Microsoft Entra ID P2 and Microsoft Intune. Employees use both company-owned and personal devices. The security team requires that all access to corporate applications be protected with multifactor authentication (MFA). However, to minimize user friction, they want to exempt MFA for users who are on the corporate network and using compliant devices. Additionally, for users with privileged roles (e.g., Global Administrator), MFA must always be required regardless of location or device. You need to configure a Conditional Access policy to meet these requirements. Which of the following approaches should you take?

Hard
1123

An organization needs to grant its IT administrators temporary access to the Global Administrator role. The access should require a separate approval from a designated manager before activation, and the permissions should automatically expire after 4 hours. Which Microsoft Entra ID feature should they configure?

Medium
1124

Your organization uses Microsoft Defender for Cloud Apps. A security analyst notices anomalous file downloads from a SharePoint site by a user flagged as high risk. What should the analyst configure to automatically block such activity?

Medium
1125

Refer to the exhibit. You are reviewing Microsoft Entra role assignments for a user. The first assignment has a roleDefinitionId of '62e90394-69f5-4237-9190-012177145e10' at scope '/'. The second assignment has a roleDefinitionId of '194ae4cb-b126-40b2-bd5b-6091b380977d' at a subscription scope. What can you infer?

Medium
1126

A company wants to provide secure external access to a partner application without creating user accounts manually. They need to allow partners to authenticate using their existing corporate identities (e.g., from other organizations) and configure policies for access. Which Microsoft Entra feature should they use?

Easy
1127

Your company uses Microsoft Entra ID. Security policy requires that all external guest users must be reviewed and their access approved by their sponsor every 90 days. If not approved, access should be automatically removed. Which feature should you use?

Medium
1128

A company runs critical Windows virtual machines on Azure. To reduce the attack surface, the security team wants to block all inbound RDP (port 3389) traffic from the internet by default. When a security engineer needs to connect via RDP for troubleshooting, they must request access through a portal, and the RDP port will be opened for a limited time (e.g., 4 hours) only to their source IP address. Which Microsoft security solution should they use to implement this control?

Hard
1129

A company uses Microsoft Entra ID and wants to enforce multifactor authentication (MFA) for all users accessing a sensitive customer relationship management (CRM) application, but only when the access request originates from outside the corporate network. Which component of a Conditional Access policy should the administrator configure to specify this location-based requirement?

Medium
1130

A compliance administrator creates the above custom sensitive information type for detecting social security numbers (SSNs). What is required for a document to be classified as containing an SSN?

Easy
1131

A multinational corporation wants to implement a Zero Trust security model. They plan to verify every access request explicitly, use least privilege access, and assume breach. Which Microsoft security solution should they use to enforce conditional access policies based on user, device, location, and risk?

Hard
1132

You are a security administrator for a company that uses Microsoft 365. The compliance team needs to automatically classify and protect sensitive data such as credit card numbers in emails and documents. Which Microsoft Purview solution should you recommend?

Easy
1133

Your company wants to use Microsoft Security Copilot to help analysts investigate security incidents. Which data source can Security Copilot ingest to provide contextual insights?

Easy
1134

A company uses Microsoft Entra ID. Employees often forget their passwords and contact the IT helpdesk to reset them. The company wants to reduce helpdesk costs by allowing users to reset their own passwords using a verified mobile phone number or email address. Which Microsoft Entra ID feature should the administrator enable?

Easy
1135

Your organization uses Microsoft Purview for data governance. You need to ensure that when a user marks an email as 'Confidential' using a sensitivity label, the email is automatically encrypted and cannot be forwarded. What configuration is required?

Hard
1136

A company's security team needs to detect and investigate potential data theft by employees who have legitimate access to sensitive data. They want a solution that uses heuristics and behavioral analytics to identify risky user actions such as data exfiltration to personal cloud storage. Which Microsoft Purview solution should they use?

Hard
1137

A security team wants to discover all cloud apps being used by employees, including unsanctioned personal apps like unauthorized file-sharing services. They plan to analyze firewall logs to identify traffic patterns and assess each app's risk score. Which feature of Microsoft Defender for Cloud Apps should they enable?

Medium
1138

A company requires all employees to provide a one-time passcode generated by an authenticator app in addition to their password when accessing the corporate VPN. This practice is an example of which security concept?

Medium
1139

Your company uses Microsoft Purview Data Lifecycle Management. You need to ensure that emails in users' mailboxes are retained for 7 years for compliance, but users should be able to delete emails they no longer need before that period. Which configuration achieves this?

Medium
1140

A company wants to enforce conditional access policies that require multifactor authentication (MFA) for all users accessing financial apps from outside the corporate network. Which Microsoft Entra ID license is minimally required to create conditional access policies?

Easy
1141

A company uses Microsoft Defender for Cloud Apps to protect its SaaS apps. The security team needs to detect when a user downloads more than 100 files from SharePoint Online within 10 minutes. Which policy type should they create?

Medium
1142

A company uses Microsoft Entra ID to manage identities. They want to enforce access policies based on user location, device compliance, and application sensitivity. Which Microsoft Entra ID capability should they use?

Medium
1143

Refer to the exhibit. You have a Data Loss Prevention (DLP) policy in Microsoft Purview. What will happen when a user tries to share a document containing a credit card number via email?

Easy
1144

A multinational company uses a hybrid infrastructure with on-premises Active Directory and Azure resources. They have deployed Microsoft Defender for Cloud to protect their Azure workloads. They now want to extend threat detection to their on-premises Active Directory by collecting security events from domain controllers to detect attacks like Golden Ticket, DCSync, and malicious Kerberos activity. The solution should integrate with Microsoft Sentinel for automated response. Which security solution should they deploy on the on-premises domain controllers?

Hard
1145

A financial organization implements a security control that logs every access attempt to sensitive financial records, including who accessed the data, when it was accessed, and from which device. The logs are regularly reviewed by the security team. This control primarily addresses which security concept?

Medium
1146

A company is involved in a legal dispute and must preserve all emails and documents related to the case. The legal team needs to identify specific custodians (employees) and place a hold on their Exchange Online mailboxes and SharePoint sites to prevent any deletion or alteration of relevant content. Additionally, they need to collect the preserved data for review and analysis. Which Microsoft Purview solution should they use?

Medium
1147

A company wants to grant temporary, time-limited access to a critical Azure resource for an external consultant. Which Microsoft Entra feature should they use?

Easy
1148

A user receives an encrypted email from their bank. They use their private key to decrypt the message. After reading it, they verify that the message content has not been altered during transit. Which security principle is primarily demonstrated by the verification that the content was not altered?

Easy
1149

Which TWO Microsoft Purview solutions can help protect sensitive data in Microsoft Teams?

Medium
1150

A user logs into a company's financial application using their Microsoft Entra ID credentials. After successful sign-in, the application displays a dashboard with data for only the regions the user is authorized to manage. Which two security concepts are demonstrated in this scenario? (Select all that apply.)

Medium
1151

A security team needs to continuously assess the security posture of Azure resources, including virtual machines, storage accounts, and SQL databases. They also want to identify vulnerabilities in both Windows and Linux servers running in Azure and on-premises, and receive prioritized recommendations for remediation. Which Microsoft security solution should they use?

Medium
1152

Your company is deploying Microsoft Defender for Cloud Apps. You need to detect and block the use of unsanctioned cloud apps that exhibit risky behavior. Which feature should you configure?

Medium
1153

Your organization uses Microsoft Entra ID Governance. You need to ensure that access to a critical application is reviewed every 90 days by the application owner. If the review is not completed, access should be revoked automatically. Which feature should you configure?

Hard
1154

Refer to the exhibit. You run the Azure PowerShell command for a storage account. What is the current network access configuration?

Medium
1155

A multinational company uses Microsoft Entra ID. They want to ensure that users from a specific country only access a sensitive application from compliant devices. Additionally, they want to block access if the sign-in risk is medium or high. Which combination of policies should they create?

Hard
1156

A small business wants to enable single sign-on (SSO) for its employees using their existing on-premises Active Directory. They plan to migrate to cloud-based identity management. Which Microsoft service should they use to connect their on-premises directory to Microsoft Entra ID?

Easy
1157

Refer to the exhibit. You are creating a custom analytics rule in Microsoft Sentinel. What does this rule detect?

Hard
1158

A company wants to gain visibility into which cloud applications are being used by employees (shadow IT) and assess the risk level of each app. They use Microsoft Defender for Cloud Apps. Which feature should they enable to discover and analyze these apps?

Medium
1159

Which TWO of the following are features of Microsoft Sentinel? (Choose two.)

Easy
1160

Which THREE of the following are features of Microsoft Entra ID Protection?

Medium
1161

A company uses Microsoft 365 and Microsoft Azure. The security team wants a single portal that provides a unified view of alerts and incidents from their endpoints, email, and cloud applications to accelerate threat investigation and response. Which Microsoft security solution should they use?

Easy
1162

A security operations team uses Microsoft Defender for Cloud and has connected their AWS and GCP accounts. They want to continuously assess the security posture of AWS EC2 instances against the CIS AWS Foundations Benchmark and receive prioritized recommendations. Which feature of Defender for Cloud should they use?

Medium
1163

Your company uses Microsoft Defender for Cloud Apps. You want to discover which cloud apps are being used in your organization and assess their risk levels. What should you use?

Easy
1164

A compliance officer needs to search for emails containing trade secrets across all mailboxes in the organization. Which Microsoft Purview solution should they use?

Easy
1165

You are investigating an alert in Microsoft Sentinel. The exhibit shows the JSON output of an alert that was generated from a sign-in log. The alert is linked to an active incident. Which action should you take to prioritize the incident for investigation?

Hard
1166

Your company uses Microsoft Defender for Cloud to secure Azure resources. You need to assess compliance with the CIS benchmark. What should you enable?

Easy
1167

A user logs into a company's application using their username and password. After logging in, the application checks whether the user belongs to the 'Admin' role before granting access to the user management page. Which security concept is primarily illustrated by the role check?

Easy
1168

Your company uses Microsoft Intune for device management. You need to ensure that all company data on a user's personally owned device is removed when the user is offboarded, but the user's personal data should remain. Which wipe action should you use?

Medium
1169

A company wants to detect and respond to advanced attacks targeting their on-premises Active Directory infrastructure, such as Kerberos Golden Ticket attacks, pass-the-hash, and brute-force attempts. The solution should integrate with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations. Which Microsoft security solution should they deploy?

Medium
1170

Which TWO Microsoft Entra ID capabilities help detect and remediate identity risks? (Select two.)

Hard
1171

Which TWO Microsoft Purview solutions can be used to identify and protect sensitive data in Microsoft 365?

Easy
1172

Your company uses Microsoft Entra ID. You need to enable users to sign in to third-party SaaS applications using their corporate credentials without storing passwords in those apps. Which Microsoft Entra feature should you configure?

Medium
1173

Which TWO are capabilities of Microsoft Entra ID Protection?

Easy
1174

A company wants to protect against ransomware by detecting and blocking malicious files in email attachments. Which Microsoft security solution should be used?

Easy
1175

A company has a hybrid identity environment with Active Directory synchronizing to Microsoft Entra ID. They want users to be able to reset their own on-premises passwords via the cloud SSPR portal. What is the minimum license required for this capability?

Easy
1176

A company has enabled Microsoft Defender for Cloud. They want to assess their Azure resources for compliance with security benchmarks like CIS and Azure Security Benchmark, and view a secure score. Which feature of Defender for Cloud provides this capability?

Easy
1177

Your organization needs to automatically detect and prevent accidental sharing of sensitive data in Microsoft Teams messages. Which Microsoft Purview solution should you use?

Easy
1178

A compliance officer is tasked with continuously assessing the organization's compliance posture against GDPR and ISO 27001. The solution should generate a compliance score based on implemented controls, provide recommended improvement actions, and track remediation progress over time. Which Microsoft Purview solution should they use?

Hard
1179

Your company uses Microsoft Entra ID and is implementing a zero-trust security model. You need to ensure that all access requests to sensitive applications are verified continuously, not just at the initial sign-in. Which Microsoft Entra ID capability should you use?

Hard
1180

Your organization uses Microsoft Defender for Cloud Apps. You need to discover shadow IT usage. Which feature should you enable?

Hard
1181

Your organization requires that all external guest users must sign in using Microsoft Authenticator for MFA. What should you configure?

Medium
1182

Which THREE of the following are capabilities of Microsoft Purview Data Loss Prevention (DLP)? (Choose three.)

Hard
1183

A company uses Microsoft Entra ID. The security team needs to block all sign-in attempts from a list of known malicious IP addresses. They also want to block sign-ins that originate from anonymous proxy services. Which Microsoft Entra capability should they configure to meet these requirements?

Medium
1184

Your company is implementing a zero-trust security model. Which principle requires verifying every access request as though it originates from an untrusted network, even if the request comes from within the corporate network?

Medium
1185

Your organization uses Microsoft Defender for Cloud Apps. Security team wants to be alerted when a user accesses a cloud app from a risky IP address. Which solution should you use to create a policy that triggers an alert based on this activity?

Medium
1186

A company wants to monitor employee communications for potential harassment or policy violations. Which Microsoft Purview solution should they use?

Easy
1187

A financial company processes stock trades. To ensure that a trader cannot later deny having submitted a specific trade order, the system captures a digital signature from the trader for each order. Which security goal is being addressed by this practice?

Medium
1188

A company secures its network by deploying a firewall at the perimeter, an intrusion prevention system on internal segments, endpoint antivirus on all workstations, and encrypting sensitive data at rest and in transit. This layered approach ensures that if one control fails, others still provide protection. Which security concept does this strategy best represent?

Easy
1189

A hospital stores patient medical records electronically. An attacker gains access to the system and modifies patient diagnoses. Which principle of the CIA triad has been violated?

Easy
1190

Your organization uses Microsoft Sentinel. You need to create a custom analytics rule that triggers an incident when a user fails to sign in more than five times within an hour. Which rule type should you use?

Medium
1191

A security team wants to monitor and proactively defend against cyber threats across their entire infrastructure, including Azure virtual machines, on-premises servers, and AWS workloads. They need a unified solution that provides endpoint detection and response (EDR), vulnerability management, and threat hunting capabilities. Which Microsoft security solution should they use?

Medium
1192

Your organization is using Microsoft Defender for Cloud to secure a multi-cloud environment including Azure and AWS. You need to identify misconfigurations that could lead to security breaches. Which feature should you use?

Medium
1193

A financial services firm must monitor employee communications (email and Microsoft Teams) for potential insider trading. The compliance team wants to automatically detect messages containing specific financial keywords (e.g., 'non-public material information') and flag them for review. They also need to be able to remove violating messages from recipients' inboxes. Which Microsoft Purview solution should they configure?

Medium
1194

Your organization wants to protect sensitive documents from being copied to unauthorized cloud services. Which Microsoft Purview capability should you use?

Easy
1195

A security team needs to detect and investigate advanced attacks targeting on-premises Active Directory accounts, such as Pass-the-Hash (PtH) and Golden Ticket attacks. Which Microsoft security solution should they deploy?

Medium
1196

A healthcare organization must comply with HIPAA regulations regarding the protection of patient health information (PHI). Which cloud compliance concept ensures that the organization has controls in place to meet regulatory requirements?

Easy
1197

A company uses Microsoft Purview Data Lifecycle Management. To comply with regulatory requirements, the company must retain financial records for 7 years and then delete them. Which THREE actions should the company configure? (Select THREE.)

Hard
1198

A security team needs to collect and analyze security logs from a hybrid environment consisting of on-premises Windows servers, Azure virtual machines, and AWS workloads. They want to correlate events, detect anomalous behavior, and create custom security alerts with automated response playbooks. Which Microsoft security solution should they use?

Hard
1199

A user reports that they cannot access the corporate portal after a password reset. The user can access other cloud apps. You verify that the user account is enabled and not locked. What should you check next?

Medium
1200

Your organization uses Microsoft Purview Information Protection to classify and protect documents. You have created a sensitivity label that applies encryption to documents marked as 'Confidential'. Users are able to apply the label manually. However, you need to ensure that all documents containing personally identifiable information (PII) are automatically labeled as 'Confidential' when they are saved to SharePoint Online. What should you configure?

Hard
1201

A company uses Microsoft Defender for Cloud to improve their cloud security posture. They want to see an aggregated score that reflects how well their resources are protected against threats. Which feature in Defender for Cloud provides this?

Easy
1202

Your organization uses Microsoft Entra ID for identity management. You need to require multi-factor authentication (MFA) for all users when accessing the Azure portal. Which feature should you use?

Easy
1203

A security team needs to detect and automatically respond to ransomware attacks on Windows servers and desktops. They require the solution to automatically isolate affected devices from the network and, if necessary, roll back files that have been modified by ransomware using a built-in recovery feature. Which Microsoft security solution provides these specific capabilities?

Hard
1204

A company uses Microsoft Entra ID. They want to require users to perform multifactor authentication (MFA) every 90 days on trusted devices, but force MFA for every sign-in on untrusted devices. Which Conditional Access session control must they configure to meet this requirement?

Medium
1205

Which THREE of the following are capabilities of Microsoft Purview Information Protection?

Medium
1206

A company's IT department implements a policy for server administrators: they must submit an access request to perform privileged tasks on critical servers. Each request is approved by a manager, and the granted elevated permissions automatically expire after four hours. This approach reduces the risk of standing privileges being exploited. Which security concept is primarily being applied?

Medium
1207

Your organization needs to control which users can access Microsoft Purview compliance portal. Which method should you use to grant access?

Easy
1208

A company's security policy requires that all data transferred between the corporate data center and the cloud must be protected from unauthorized access during transmission. They use encryption protocols such as TLS to achieve this. Which security goal is primarily being addressed?

Easy
1209

A company implements a security strategy that includes multiple layers of controls: a perimeter firewall, an intrusion detection system, endpoint antivirus software, and multi-factor authentication for user access. The goal is that if one layer fails, another layer is in place to prevent or mitigate an attack. Which security principle does this approach best represent?

Easy
1210

Arrange the steps to investigate a user compromise using Azure AD Identity Protection.

Medium
1211

Your organization is implementing Microsoft Purview to manage sensitive data. You need to ensure that documents containing credit card numbers are automatically detected and protected. Which Microsoft Purview solution should you configure?

Easy
1212

A company has deployed Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. The security operations team wants a single, unified portal where they can view alerts from all these products, perform cross-domain investigations, and orchestrate automated response actions. Which Microsoft security solution should they use?

Medium
1213

Which TWO of the following are capabilities of Microsoft Sentinel? (Choose two.)

Hard
1214

A company wants to improve password security across its Microsoft Entra ID tenant. The security team wants to prevent users from setting passwords that appear on Microsoft's global banned password list, which includes commonly compromised passwords. Additionally, they need to add a custom banned password containing the company name so that users cannot use variations of it. Which Microsoft Entra ID feature should they configure to enforce these password policies?

Medium
1215

A company deploys Microsoft Defender for Cloud Apps. They want to detect when a user downloads more than 100 files from SharePoint in 10 minutes. Which policy type should they create?

Hard
1216

Which THREE are features of Microsoft Defender for Cloud?

Medium
1217

A security administrator is explaining the concept of defense in depth to a new team member. Which statement best describes this approach?

Easy
1218

Which THREE actions can be performed by Microsoft Purview Data Loss Prevention (DLP) policies?

Hard
1219

Refer to the exhibit. You run the cmdlet and get a list of risk detections. What does this cmdlet retrieve?

Hard
1220

An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for users who sign in from sessions that Microsoft Entra ID Protection determines to have medium or high sign-in risk. Users signing in from low-risk sessions should not be prompted for MFA. Which feature should the security team configure?

Medium
1221

Refer to the exhibit. A Microsoft Purview administrator imported this JSON policy for automatic sensitivity labeling. After deployment, users report that emails containing German social security numbers are not being automatically labeled. What is the most likely cause?

Hard
1222

A company uses Microsoft Entra ID. The security team wants to enforce a policy that prevents users from choosing commonly used weak passwords like 'Winter2024!' or 'Password@123', and also blocks customized variants based on organizational context (e.g., company name). Users must create passwords that meet standard complexity requirements. Which Microsoft Entra ID feature should they enable?

Medium
1223

A healthcare organization must automatically detect documents containing patient health information (PHI) in SharePoint Online and apply a retention label that retains the documents for 10 years. Additionally, they want to prevent users from permanently deleting these documents during the retention period. Which Microsoft Purview solution should they use to achieve this?

Medium
1224

A company uses Microsoft 365 and wants to protect against sophisticated phishing attacks that use malicious links in email. They also want real-time analysis of URLs at the time of click. Which Microsoft Defender for Office 365 feature provides this?

Medium
1225

A financial institution uses digital signatures to ensure that a transaction record has not been altered after it was processed. Which security principle is primarily addressed?

Easy
1226

An organization uses Microsoft Entra ID for identity management and wants to allow external partners to access their resources using their own corporate credentials. Which feature should they enable?

Medium
1227

Which TWO Microsoft Purview solutions help organizations respond to data subject requests under GDPR?

Easy
1228

A company uses Microsoft 365 and stores many business documents in SharePoint Online and OneDrive. The security team wants to automatically detect and block malicious files (e.g., those containing ransomware or other malware) that are uploaded to these document libraries. Files should be scanned and held until proven safe. Which Microsoft security solution should they enable to provide this protection?

Medium
1229

Your organization uses Microsoft Purview eDiscovery (Premium) to manage a legal case. You need to place a hold on custodians' mailboxes and SharePoint sites to preserve relevant data. Which step must you first take in the eDiscovery workflow?

Medium
1230

A financial services company needs to comply with GDPR and requires that personal data be automatically classified and protected when stored in Microsoft SharePoint and OneDrive. They also need to retain certain records for a minimum of 7 years. Which combination of Microsoft Purview capabilities should they use?

Hard
1231

Which Microsoft Purview solution should you use to automatically retain or delete content based on regulations?

Easy
1232

A company uses Microsoft Entra ID. The security team wants to enforce multifactor authentication (MFA) only when users sign in from devices that are not compliant with company security policies. They also want to block sign-ins from unknown geographic locations. Which Microsoft Entra feature should they configure?

Medium
1233

Which two capabilities are provided by Microsoft Entra ID? (Choose two.)

Medium
1234

Your organization is deploying Microsoft Entra ID Governance. You need to automate the process of removing user access to a critical application when the user leaves the company. Which feature should you configure?

Medium
1235

Which THREE Microsoft Purview solutions support data classification and labeling? (Choose THREE.)

Hard
1236

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their existing Facebook accounts without creating a separate Microsoft Entra ID account. What should you configure?

Medium
1237

A company uses Microsoft Entra ID. The security team wants to grant temporary, time-bound administrative access to the Microsoft 365 user management role for IT support staff. The access should require an approval from a senior administrator, and all actions should be audited. Which Microsoft Entra ID feature should they configure?

Medium
1238

A company is migrating its on-premises virtual machines to Azure Infrastructure-as-a-Service (IaaS). Which security responsibility primarily shifts from the customer to Microsoft during this migration?

Easy
1239

A company deploys full disk encryption on all employee laptops to protect data in case a device is lost or stolen. Which security goal does this measure primarily address?

Easy
1240

AdventureWorks, a multinational manufacturing company, uses Microsoft Purview and Microsoft Communication Compliance to monitor and manage internal communications. They need to: (1) detect and review emails containing offensive language or harassment; (2) allow employees to report inappropriate messages; (3) retain reviewed messages for 5 years; (4) ensure that only designated reviewers can access the communication compliance data; (5) integrate with Microsoft Teams and Exchange Online. The company has 10,000 users and Microsoft 365 E5 licenses. The compliance team wants a solution that automates detection and provides secure review. What should they configure?

Hard
1241

A company uses Microsoft 365 and needs to prevent employees in the Mergers & Acquisitions (M&A) department from communicating with employees in the Trading department via Microsoft Teams chat, email, and SharePoint sharing. They must ensure that these restrictions are automatically enforced by Microsoft 365. Which Microsoft Purview solution should the administrator configure?

Easy
1242

A company is moving its on-premises database to Azure SQL Database. According to the shared responsibility model, which security tasks remain the responsibility of the customer?

Medium
1243

A security administrator needs to enforce that all Microsoft 365 documents containing credit card numbers are automatically encrypted before being shared externally. Which Microsoft Purview solution should they use?

Medium
1244

A healthcare organization uses Microsoft 365 and must comply with HIPAA regulations. They need to assess their current compliance posture, identify gaps, and implement improvement actions. They want a tool that provides a compliance score based on best practices and regulatory frameworks, and offers recommended actions to improve the score. Which Microsoft Purview solution should they use?

Medium
1245

During a security incident, a SOC analyst needs to investigate a compromised user account that accessed multiple cloud apps. Which Microsoft Defender XDR feature provides a unified view of the attack timeline across endpoints, identities, and cloud apps?

Hard
1246

A company runs Azure SQL databases containing customer transaction data. The security team needs to detect and alert on suspicious database access patterns, such as SQL injection attempts or access from unusual locations. Which Microsoft security solution should they enable?

Medium
1247

Refer to the exhibit. A security analyst runs the KQL query in Microsoft Defender for Endpoint. The query returns no results. What is the most likely cause?

Hard
1248

Refer to the exhibit. The JSON shows a Conditional Access policy. What is the primary purpose of this policy?

Easy
1249

A global company uses Microsoft Teams and SharePoint Online. They need to automatically detect and prevent sharing of intellectual property files containing 'Project X' with external users. What should they configure?

Medium
1250

Your company is implementing a hybrid identity solution with Microsoft Entra ID. Users report that they can sign in to Microsoft 365 but cannot access on-premises applications that are configured for integrated Windows authentication. You need to ensure seamless single sign-on (SSO) for both cloud and on-premises resources. What should you implement?

Medium

Frequently asked questions

What does the scenario questions domain cover on the SC-900 exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 1250 scenario questions questions in the SC-900 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.