HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.
You plan to create 10 new users and configure group-based licensing to assign each user a Microsoft 365 E5 license.
To which group should you add the users, and which portal should you use to assign the license? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Group1
The Microsoft 365 admin center
Explanation: Group-based licensing is supported with security groups. Current Microsoft guidance is to manage group-based license assignments through the Microsoft 365 admin center.
Question 104
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the identities shown in the following table.
From the Microsoft Defender portal, you create an anti-spam inbound policy named Policy1 that has the following settings:
• Include these users, groups and domains
o Users: User3
o Groups: Group 1
• Exclude these users, groups and domains
o Users: User1
Policy1 has the following Bulk email threshold & spam properties settings:
• Mark as spam
о Empty messages: On
о Object tags in HTML On
о Sensitive words: Off
о Backscatter: On
Policy1 has the following Actions settings:
• Message actions
o Spam: Move message to Junk Email folder
o High confidence spam: Move message to Junk Email folder
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
No
Explanation: Inbound anti-spam policies apply to included recipients, with exclusions taking precedence. User1 is explicitly excluded, so Policy1 does not apply to mail for User1. Sensitive words detection is disabled. Therefore: (1) recipient User2 is not directly included by the policy scope shown, (2) sensitive words are ignored, and (3) User1 is excluded.
Question 105
You have a Microsoft 365 E5 subscription.
You need to be alerted when Microsoft Defender XDR detects high-severity incidents.
What should you use?
A. a custom detection rule
B. a threat policy
C. a notification rule
Show Answer
Correct Answer: C
Explanation: Use a notification rule to send alerts when Microsoft Defender XDR creates incidents that match criteria such as high severity. Custom detection rules generate detections from advanced hunting queries, and threat policies configure protection behavior rather than incident notifications.
Question 106
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
The subscription contains users that have devices onboarded to Microsoft Defender for Endpoint. Defender for Endpoint is configured to forward signals to Microsoft Defender for Cloud Apps.
Cloud Discovery identifies a risky web app named App1.
You need to block users from connecting to Appl from Microsoft Edge. Users must be able to bypass the restriction.
Which type of app tag should you use. and what should you configure to integrate Defender for Endpoint with Defender for Cloud Apps? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: App tag type: Monitored
Integrate by configuring: Enforce app access
Explanation: A Monitored app tag enables a user-warning (soft block) experience in Microsoft Edge through the Defender for Endpoint integration, allowing users to bypass the warning. Unsanctioned is used for hard blocking. The required integration setting is Enforce app access.
Question 107
DRAG DROP
-
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You need to configure Cloud Discovery to generate a report that identifies top potential risks and provides a workflow to mitigate and manage the risks.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Show Answer
Correct Answer: Export network traffic logs from firewall and proxy devices.
Configure automatic log upload.
Generate a Cloud Discovery executive report.
Explanation: Cloud Discovery requires firewall/proxy logs first. Automatic log upload config enables ingestion of logs. The executive report is specifically the report that identifies top potential risks and provides mitigation workflow guidance.
Question 108
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You connect a cloud app that contains a group named Group1 to Microsoft Defender for Cloud Apps.
You need to configure the Cloud apps settings to monitor all activities performed by the members of Group1.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Scoped deployment and privacy
User groups
Explanation: Import Group1 under User groups, then configure Scoped deployment and privacy to monitor that specific group for cloud app activities.
Question 109
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You have a cloud app named App1.
You need to implement a security solution for App1 that meets the following requirements:
• Enables the real-time monitoring of user activities
• Blocks specific activities as needed
What should you include in the solution for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Enables the real-time monitoring of user activities: Conditional Access App Control
Blocks specific activities as needed: A session policy
Explanation: Conditional Access App Control provides real-time session monitoring and control for supported cloud apps. Session policies enforce real-time controls such as blocking downloads or other specific user activities during a session.
Question 110
You have a Microsoft 365 E5 subscription that contains a user named User1.
You have a Conditional Access policy applied to a cloud-based app named App1. App1 has Conditional Access App Control deployed.
You need to create a Microsoft Defender for Cloud Apps policy to block User1 from printing from App1.
Which type of policy should you create?
A. activity policy
B. session policy
C. OAuth app policy
D. Cloud Discovery anomaly detection policy
Show Answer
Correct Answer: B
Explanation: Session policies in Microsoft Defender for Cloud Apps (used with Conditional Access App Control) provide real-time control over user sessions, including blocking specific actions such as printing, downloading, copying, or uploading within monitored cloud apps. Activity policies monitor activities after they occur, OAuth app policies govern connected OAuth applications, and Cloud Discovery anomaly detection policies detect unusual behavior rather than enforce session restrictions.
Question 111
HOTSPOT
-
Your company has an office in London.
You have a Microsoft 365 subscription.
You need to create a Conditional Access policy named Policy that meets the following requirements:
• Only FIDO2 security keys, Windows Hello for Business, and certificates must be supported for authentication.
• The London office must be marked as a trusted location and excluded from Policy1.
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Authentication strength: Phishing-resistant MFA
Named location: IP ranges
Explanation: Phishing-resistant MFA restricts authentication to FIDO2 security keys, Windows Hello for Business, and certificate-based authentication. To mark the London office as a trusted location, create a named location using the office's public IP ranges and mark it as trusted, then exclude that named location from the Conditional Access policy.
Question 112
You have a Microsoft 365 E5 subscription. The subscription contains a Microsoft SharePoint Online site named Site1.
Site1 contains the following files:
• File.docx
• ImportantFile.docx
• File_Important.docx
From Microsoft Defender Cloud Apps, you create a file policy named Policy that has the filter shown in the following exhibit.
To which files will Policy1 apply?
A. ImportantFile.docx and File_Important.docx only
B. File.docx only
C. File_Important.docx only
D. ImportantFile.docx only
E. File.docx, ImportantFile.docx, and File_Important.docx
Show Answer
Correct Answer: C
Explanation: The filter uses 'contains words' with matching all specified words. In Microsoft Defender for Cloud Apps, words are recognized when separated by non-alphanumeric characters (such as underscores, spaces, or hyphens). 'ImportantFile.docx' does not separate 'Important' and 'File' into distinct words, while 'File_Important.docx' does. 'File.docx' lacks the word 'Important'. Therefore only 'File_Important.docx' matches.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.