HOTSPOT
-
You have a Microsoft 365 subscription and use the Microsoft Intune Suite.
You have the devices shown in the following table.
You plan to implement Microsoft Tunnel for Mobile Application Management (MAM).
Which types of tunnels are supported by the devices? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Tunnel for MAM: Device2 and Device3 only
A per-app VPN tunnel: Device1, Device2, and Device3
Explanation: Tunnel for MAM requires Android 10+ and iOS 14+, so iOS 13.7 is excluded. Per-app VPN profiles are supported on iOS 9+ and Android versions supported by Intune Tunnel, so all listed devices support per-app VPN.
Question 35
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains the dynamic membership groups shown in the following table.
You add devices to contoso.com as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Group1 matches devices whose display name starts with "Dev" or Android devices. Group2 matches Microsoft Entra registered (Workplace) devices. Group3 requires Microsoft Entra joined (AzureAD) and Android.
Question 36
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You plan to perform a security audit of all the apps detected by Cloud Discovery.
You need to track which apps were audited. The solution must ensure that the list of audited apps can be displayed in the cloud app catalog.
What should you do?
A. Apply a custom app tag to each app.
B. Deploy Conditional Access App Control.
C. Define each app as a critical asset.
D. Generate a Cloud Discovery snapshot report.
E. Enable app governance.
Show Answer
Correct Answer: A
Explanation: Use a custom app tag (for example, 'Audited') on each discovered app. Custom app tags are displayed and can be used as filters in the Cloud App Catalog and Cloud Discovery views, making it easy to track which apps have already been reviewed. The other options do not provide a persistent, catalog-visible marker for audit status.
Question 37
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
The tenant contains a standalone workgroup computer named Computer1 that runs Window 11. Computer1 contains the local users shown in the following table.
Computer1 needs to be joined to contoso.com.
Which local users can join Computer1 to contoso.com, and the Microsoft Entra credentials of which user can be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Local users: UserA only
Credentials of: Admin1 or Admin2 only
Explanation: Joining a Windows 11 workgroup device to Microsoft Entra requires the current local user to be a local Administrator. For the Entra sign-in, Global Administrator and Cloud Device Administrator have the required role-based permissions; Directory Writer does not.
Question 38
You have a Microsoft 365 E5 subscription that contains Windows 11 devices.
All the devices are onboarded to Microsoft Defender for Endpoint.
You need to compare the configuration of the devices against industry standard benchmarks.
What should you use?
A. Attack surface map
B. Events
C. Security baselines assessment
D. Initiatives
Show Answer
Correct Answer: C
Explanation: Security baselines assessment in Microsoft Defender Vulnerability Management compares device configurations against industry-standard security benchmarks (such as Microsoft security baselines/CIS where applicable) to identify configuration gaps. Attack surface map visualizes external exposure, Events shows security events, and Initiatives is an Azure/Microsoft Defender for Cloud governance concept rather than the Defender for Endpoint baseline assessment feature.
Question 39
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Graph PowerShell to assign a Microsoft 365 E5 license to a new user named
.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Retrieve the subscribed SKU for the Microsoft 365 E5 (SPE_E5) license using Get-MgSubscribedSku, then assign it to the user with Set-MgUserLicense using the retrieved SkuId.
Question 40
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You plan to create a Conditional Access policy named Policy1.
You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal, Azure PowerShell, or Azure Command-Line Interface (CLI).
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Access controls: Set Grant to Require authentication strength.
Target resources: Windows Azure Service Management API.
Explanation: To enforce only Passwordless MFA, Conditional Access must use Require authentication strength and select the Passwordless MFA authentication strength. To cover Azure portal, Azure PowerShell, and Azure CLI, target the Windows Azure Service Management API cloud app.
Question 41
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft Intune as shown in the following table.
The subscription contains the users shown in the following table.
The Remote Help Tier1 role is configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: iOS devices aren't supported for Remote Help control. The custom Intune role with Elevation implicitly includes View screen and Take full control, so Admin2 can fully control the Windows device. Unattended control requires the separate Unattended control permission, which isn't granted by Elevation alone.
Question 42
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
The subscription contains users that have devices onboarded to Microsoft Defender for Endpoint. Defender for Endpoint is configured to forward signals to Microsoft Defender for Cloud Apps.
Cloud Discovery identifies a risky web app named App1.
You need to block users from connecting to App1 from Microsoft Edge. Users must be able to bypass the restriction.
Which type of app tag should you use, and what should you configure to integrate Defender for Endpoint with Defender for Cloud Apps? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: App tag type: Monitored
Integrate by configuring: Enforce app access
Explanation: To allow users to be warned and optionally bypass access in Microsoft Edge through the Defender for Endpoint and Defender for Cloud Apps integration, use a Monitored app tag with Enforce app access. Unsanctioned is intended for hard blocking without user override.
Question 43
You use Microsoft Defender for Office 365.
You plan to automate an attack simulation campaign.
Any users that fail the simulation must take additional training based on the simulation results.
What is the maximum number of days the training will be available to the users after the simulation?
A. 7
B. 15
C. 30
D. 45
Show Answer
Correct Answer: C
Explanation: In Microsoft Defender for Office 365 Attack Simulation Training, when assigning training to users who fail a simulation, the configurable training due date options are 7, 15, or 30 days after the simulation ends. Therefore, the maximum time the training is available is 30 days.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.