HOTSPOT
-
You have a Microsoft 365 subscription and use the Microsoft Intune Suite.
You have the devices shown in the following table.
You plan to implement Microsoft Tunnel for Mobile Application Management (MAM).
Which types of tunnels are supported by the devices? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Tunnel for MAM:
Device2 and Device3 only
A per-app VPN tunnel:
Device2 and Device3 only
Explanation: Microsoft Tunnel for MAM requires Android 10+ or iOS 14+. Device1 runs iOS 13.7 and is not supported, while Device2 (Android 13) and Device3 (iOS 15.8.x) are supported. Per-app VPN tunnels in the context of Microsoft Tunnel also rely on supported OS versions, so the same two devices qualify.
Question 34
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains the dynamic membership groups shown in the following table.
You add devices to contoso.com as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1 is a member of Group1 only: Yes
Device2 is a member of Group1 and Group2: Yes
Phone1 is a member of Group1 and Group3: No
Explanation: Group1 uses an OR rule: device name starts with "Dev" OR OS is Android. Device1 and Device2 (names start with Dev) and Phone1 (Android) satisfy Group1. Group2 requires deviceTrustType = Workplace, which applies to Microsoft Entra registered devices, so only Device2 qualifies. Group3 requires AzureAD trust AND Android OS; Phone1 is Android but only Entra registered, not AzureAD joined.
Question 35
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You plan to perform a security audit of all the apps detected by Cloud Discovery.
You need to track which apps were audited. The solution must ensure that the list of audited apps can be displayed in the cloud app catalog.
What should you do?
A. Apply a custom app tag to each app.
B. Deploy Conditional Access App Control.
C. Define each app as a critical asset.
D. Generate a Cloud Discovery snapshot report.
E. Enable app governance.
Show Answer
Correct Answer: A
Explanation: To track which discovered cloud apps have been audited and display that status in the Cloud App Catalog, you should apply a custom app tag to each audited app. Custom app tags are designed for labeling and tracking apps (for example, “Audited,” “Approved by Security”) and are visible and filterable in the Cloud App Catalog. The other options do not provide a persistent, visible audit-tracking label in the catalog.
Question 36
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
The tenant contains a standalone workgroup computer named Computer1 that runs Window 11. Computer1 contains the local users shown in the following table.
Computer1 needs to be joined to contoso.com.
Which local users can join Computer1 to contoso.com, and the Microsoft Entra credentials of which user can be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Local users:
UserA or UserC only
Credentials of:
Admin1 only
Explanation: Joining a Windows 11 workgroup device to Microsoft Entra requires signing in locally with a user that has administrative privileges on the device; local Administrators qualify, and the Device Owners group is also permitted in this context.
The Entra credentials used to complete the join must have permission to join devices. From the listed roles, only the Global Administrator role guarantees this capability; Cloud Device Administrator and Directory Writer are not accepted by the provided answer choices.
Question 37
You have a Microsoft 365 E5 subscription that contains Windows 11 devices.
All the devices are onboarded to Microsoft Defender for Endpoint.
You need to compare the configuration of the devices against industry standard benchmarks.
What should you use?
A. Attack surface map
B. Events
C. Security baselines assessment
D. Initiatives
Show Answer
Correct Answer: C
Explanation: To compare Windows 11 devices onboarded to Microsoft Defender for Endpoint against industry-standard benchmarks, you use Security baselines assessment. Defender Vulnerability Management security baselines allow you to assess and monitor device configurations against recognized benchmarks (such as Microsoft security baselines), highlighting deviations and compliance status. The other options do not provide benchmark-based configuration comparison.
Question 38
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Graph PowerShell to assign a Microsoft 365 E5 license to a new user named
.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Get-MgSubscribedSku retrieves the Microsoft 365 E5 (SPE_E5) SKU and stores its SkuId in a variable. Set-MgUserLicense assigns that SKU to the specified user using the SkuId, without removing any existing licenses.
Question 39
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You plan to create a Conditional Access policy named Policy1.
You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal, Azure PowerShell, or Azure Command-Line Interface (CLI).
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Access controls:
Set Grant to Require authentication strength
Target resources:
Windows Azure Service Management API
Explanation: Authentication strength allows enforcing Passwordless MFA methods only. The Windows Azure Service Management API covers Azure portal, Azure PowerShell, and Azure CLI access for administrative management.
Question 40
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft Intune as shown in the following table.
The subscription contains the users shown in the following table.
The Remote Help Tier1 role is configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
No
Explanation: Device2 is iOS, which doesn’t support Remote Help full control. Admin2’s custom role grants only Elevation, which allows UAC elevation during a session but not full control or unattended control. Therefore, Admin2 can’t take full control of Device1 (Windows) nor unattended control of Device3 (Android).
Question 41
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
The subscription contains users that have devices onboarded to Microsoft Defender for Endpoint. Defender for Endpoint is configured to forward signals to Microsoft Defender for Cloud Apps.
Cloud Discovery identifies a risky web app named App1.
You need to block users from connecting to App1 from Microsoft Edge. Users must be able to bypass the restriction.
Which type of app tag should you use, and what should you configure to integrate Defender for Endpoint with Defender for Cloud Apps? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Monitored
Enforce app access
Explanation: To block access in Microsoft Edge while allowing users to bypass, the app must be tagged Monitored so a warning with user override can be applied. Integration between Defender for Endpoint and Defender for Cloud Apps is required via Enforce app access to apply browser-based controls.
Question 42
You use Microsoft Defender for Office 365.
You plan to automate an attack simulation campaign.
Any users that fail the simulation must take additional training based on the simulation results.
What is the maximum number of days the training will be available to the users after the simulation?
A. 7
B. 15
C. 30
D. 45
Show Answer
Correct Answer: C
Explanation: In Microsoft Defender for Office 365 attack simulation training, the training due date options are 7, 15, or 30 days after the simulation ends. Since the question asks for the maximum number of days the training will be available, the correct answer is 30 days.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.