You have a Microsoft 365 E5 subscription. The subscription contains a Microsoft SharePoint Online site named Site1.
Site1 contains the following files:
• File.docx
• ImportantFile.docx
• File_Important.docx
From Microsoft Defender Cloud Apps, you create a file policy named Policy that has the filter shown in the following exhibit.
To which files will Policy1 apply?
A. ImportantFile.docx and File_Important.docx only
B. File.docx only
C. File_Important.docx only
D. ImportantFile.docx only
E. File.docx, ImportantFile.docx, and File_Important.docx
Show Answer
Correct Answer: C
Explanation: In Microsoft Defender for Cloud Apps file policies, the **Contains words** operator matches full words separated by non‑alphanumeric characters (such as spaces, hyphens, or underscores). It does not match partial strings within a single word unless those parts are separated.
- **ImportantFile.docx** → "Important" and "File" are part of one continuous word, so they are not treated as separate words and do not both match.
- **File_Important.docx** → The underscore is a word separator, so "File" and "Important" are detected as two distinct words and both match the filter.
- **File.docx** → Contains only "File", not "Important".
Therefore, the policy applies only to **File_Important.docx**.
Question 100
You have a Microsoft 365 E5 subscription that contains a user named User1.
You create an outbound anti-spam policy named Policy1 as shown in the following exhibit.
You assign Policy1 to User1.
What is the maximum number of email messages that User1 can send in a 24-hour period?
A. 30
B. 720
C. 1000
D. 1030
Show Answer
Correct Answer: B
Explanation: Policy1 enforces hourly limits of 10 external recipients/hour and 20 internal recipients/hour, for a maximum of 30 recipients per hour. Over 24 hours, the maximum possible is 30 × 24 = 720. Although the daily limit is 1000, the stricter hourly limits prevent reaching it.
Question 101
You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint.
You integrate Microsoft Defender for Cloud Apps with Defender for Endpoint.
You need identify which cloud apps and services were used most during the last 30 days.
What should you do?
A. Generate a monthly security summary report.
B. Generate a Cloud Discovery snapshot report.
C. Create a threat analytics alert notification.
D. Generate a Cloud Discovery executive report.
Show Answer
Correct Answer: D
Explanation: With Defender for Endpoint integrated into Defender for Cloud Apps, Cloud Discovery data is collected continuously from endpoint telemetry. To see which cloud apps and services were used most over a rolling period such as the last 30 days, you use the Cloud Discovery executive report (or dashboard-based reporting). Snapshot reports are ad-hoc and based on manually uploaded firewall/proxy logs, not a managed 30‑day usage view. The other options do not provide cloud app usage statistics.
Question 102
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi – require approval for non-temp folders for the endpoints.
You need to identify the impact of the Automation level setting on the endpoints.
Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Devices will be remediated only after end-user approval.
B. Devices will be remediated automatically if a threat is detected in the \program files (X86)\* folder
C. Devices will be remediated automatically if a threat is detected in the \windows\ folder.
D. Devices will be remediated automatically if a threat is detected in the \users\*\downloads\* folder.
Show Answer
Correct Answer: B, D
Explanation: With Automation level set to **Semi – require approval for non‑temp folders**, Microsoft Defender automatically remediates threats found in locations classified as *temporary folders* and requires approval only for non‑temporary locations. According to Microsoft’s definition, both **\Program Files (x86)\*** and **\Users\*\Downloads\*** are treated as temporary folders for this purpose, so remediation occurs automatically. The **\Windows\*** directory itself is not temporary (only \Windows\Temp\* is), and end‑user approval is not a factor in this automation level.
Question 103
You have a Microsoft 365 E5 subscription.
You plan to ingest syslog data from a supported firewall device to Microsoft Defender for Cloud Apps.
You need to configure automatic log upload.
Which two components should you configure for the log collector? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. the receiver type
B. the data source
C. the username and password
D. a connection string
E. the host IP address or FQDN
Show Answer
Correct Answer: B, E
Explanation: For automatic log upload in Microsoft Defender for Cloud Apps, you must configure both a data source and a log collector. The data source defines the supported firewall device and log type (including receiver type, which is part of the data source configuration). The log collector itself requires the host IP address or FQDN so the firewall can send syslog data to it. Receiver type, credentials, or connection strings are not standalone collector components.
Question 104
HOTSPOT
-
You have a Microsoft Entra tenant that has security defaults enabled.
You create a user named Admin1.
You need to ensure that Admin1 can create and apply Conditional Access policies.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Roles and administrators
Licenses
Explanation: Admin1 must be assigned an appropriate admin role (such as Conditional Access Administrator) to create and apply Conditional Access policies. Conditional Access also requires a Microsoft Entra ID P1 or higher license, which is managed under Licenses.
Question 105
You have a Microsoft 365 subscription and use Microsoft Defender for Office 365.
You need to create a policy to ensure that any email messages containing an attachment that has the .extl extension is quarantined for inspection.
Which type of policy should you create?
A. anti-phishing
B. quarantine
C. anti-spam
D. anti-malware
Show Answer
Correct Answer: D
Explanation: In Microsoft Defender for Office 365, filtering based on malicious or specific attachment file types is configured in an anti-malware policy. Anti-malware policies allow you to block or quarantine messages that contain certain file extensions. Quarantine policies do not detect or trigger quarantine themselves; they only define what happens to messages after another policy (such as anti-malware) sends them to quarantine. Anti-spam and anti-phishing policies focus on message content and sender behavior, not attachment extensions.
Question 106
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You configure a compliance policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: A compliance policy only evaluates device state and reports compliance; it does not configure or onboard devices to Microsoft Defender for Endpoint. Automatic onboarding is achieved by enabling Defender for Endpoint integration and deploying an Endpoint Detection and Response (EDR) policy (or equivalent security configuration) via Intune.
Question 107
You have a Microsoft 365 E5 subscription.
You need to assign a Microsoft Defender for Endpoint baseline.
Which portal should you use?
A. the Microsoft Intune admin center
B. the Microsoft Purview compliance portal
C. the Microsoft Defender portal
D. the Microsoft 365 admin center
Show Answer
Correct Answer: A
Explanation: Microsoft Defender for Endpoint security baselines are created and assigned through the Microsoft Intune admin center. In Intune, you go to Endpoint security > Security baselines and select the Microsoft Defender for Endpoint baseline to deploy to devices. The Defender portal is used mainly for monitoring and investigation, not for assigning baselines.
Question 108
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You enable co-management.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Enabling co-management does not automatically onboard devices to Microsoft Defender for Endpoint. Co-management only enables shared management between Configuration Manager and Intune. Automatic onboarding requires configuring Defender for Endpoint onboarding, such as deploying an Endpoint Detection and Response (EDR) policy in Intune.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.