You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a social engineering awareness solution that meets the following requirements:
• To reset a user’s password, emulate an email message that contains a link.
• Track any user that selects the email message link.
• Suggest further social engineering training.
What should you use in the Microsoft Defender portal?
A. Attack simulation training
B. Learning hub
C. Exposure insights
D. Threat tracker
Show Answer
Correct Answer: A
Explanation: Attack simulation training in Microsoft Defender for Office 365 allows you to run phishing and social engineering simulations, including emails with links that mimic password reset messages. It tracks which users click the links and automatically provides targeted follow-up training recommendations, meeting all the stated requirements.
Question 120
You have a Microsoft 365 E5 subscription.
Administrators are issued FIDO2 security keys.
You need to create a Conditional Access policy that will use a FIDO2 security key as an authentication method.
Which Access controls option should you select for the policy?
A. Require approved client app
B. Require token protection for sign-in sessions
C. Require multifactor authentication
D. Require authentication strength
Show Answer
Correct Answer: D
Explanation: To require the use of a FIDO2 security key in a Conditional Access policy, you must use **Require authentication strength**. Authentication strengths let you specify allowed authentication methods (such as FIDO2 security keys) rather than just requiring generic MFA. The other options do not allow enforcing a specific method like FIDO2.
Question 121
You have a Microsoft 365 E5 subscription.
You plan to use a third-party protection service to scan email messages before they are delivered to Microsoft 365.
You configure a mail flow rule to bypass spam filtering for incoming messages.
Which two messages will still be scanned by Microsoft 365 and cannot be bypassed by the mail flow rule? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. a message that contains malware
B. a high-confidence phishing message
C. an encrypted message
D. a message that includes HTML code
E. a messages that includes URL links
Show Answer
Correct Answer: A, B
Explanation: Mail flow rules can bypass spam filtering, but they cannot override Microsoft 365’s security-by-default protections. Messages containing malware and high-confidence phishing are always scanned and enforced by Defender for Office 365, regardless of mail flow rules. Other message types (encryption, HTML, URLs) do not automatically trigger non-bypassable scanning.
Question 122
You have a Microsoft 365 E5 subscription. The subscription contains users that have the following types of devices:
• Windows 10
• Android
• iOS
To which devices can you apply Endpoint DLP policies?
A. Windows 10 only
B. Windows 10 and Android only
C. Windows 10 and iOS only
D. Windows 10, Android, and iOS
Show Answer
Correct Answer: A
Explanation: Endpoint DLP in Microsoft Purview applies only to supported endpoint operating systems: Windows 10/11 and macOS. It does not support Android or iOS devices. Since the question’s device list includes Windows 10, Android, and iOS, only Windows 10 is eligible for Endpoint DLP policies.
Question 123
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint.
Defender for Endpoint has tamper protection enabled.
You have a device named Device1 that is onboarded to Defender for Endpoint.
You need to configure antivirus and real-time protection for Device1.
What should you do in the Microsoft Defender portal?
A. Initiate a live response session.
B. Create a device group.
C. Enable troubleshooting mode.
D. Isolate Device1.
Show Answer
Correct Answer: C
Explanation: With tamper protection enabled, antivirus and real-time protection settings are locked against changes. Enabling troubleshooting mode in Microsoft Defender for Endpoint temporarily relaxes these restrictions on a specific device, allowing you to configure antivirus and real-time protection settings.
Question 124
You have a Microsoft 365 E5 subscription.
You plan to configure multi-factor authentication (MFA).
You need to select an authentication method for users. The solution must ensure that each time a user is prompted for MFA, the application name that requires MFA is provided.
What should you select?
A. SMS
B. Microsoft Authenticator
C. a voice call
D. email OTP
E. a FIDO2 security key
Show Answer
Correct Answer: B
Explanation: Only Microsoft Authenticator supports MFA push notifications that can display additional context, including the application name requesting authentication. SMS, voice calls, email OTP, and FIDO2 security keys do not provide per-prompt application name details.
Question 125
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You configure a Multifactor authentication registration policy that has the following settings:
• Assignments:
o Include: Group1
o Exclude: Group2
• Controls: Require Microsoft Entra ID multifactor authentication registration
• Policy enforcement: Enabled
You create a conditional access policy that has the following settings:
• Name: Policy1
• Assignments:
o Include: Group2
o Exclude: Group1
• Grant: Require multifactor authentication
• Enable policy: On
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1: Yes
User2: No
User3: No
Explanation: The MFA registration policy applies to Group1 (excluding Group2), so User1 is prompted to register at next sign-in. User2 is excluded and already has MFA enabled. User3 is excluded from the registration policy, and the Conditional Access policy only requires MFA use, not registration.
Question 126
You use Microsoft Defender for Office 365.
You plan to automate an attack simulation campaign.
Any users that fail the simulation must take additional training based on the simulation results.
What is the maximum number of days the training will be available to the users after the simulation?
A. 7
B. 15
C. 30
D. 45
Show Answer
Correct Answer: C
Explanation: In Microsoft Defender for Office 365 Attack simulation training, when users fail an automated attack simulation, the assigned training content remains available for a maximum of 30 days after the simulation. This is defined in Microsoft documentation for attack simulation training availability.
Question 127
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains the devices shown in the following table.
You need to create the Endpoint security policies shown in the following table.
To which device can you apply each policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Policy1:
Device1 only
Policy2:
Device1 only
Explanation: Endpoint security Antivirus and Device Control templates in Intune apply only to Windows 10/11 devices. Android uses app-based protection, and Linux is managed via Defender for Endpoint but not through these Intune endpoint security policies.
Question 129
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You are configuring Attack simulation training that will target all users and use the Credential Harvest social engineering technique.
You need to ensure that the simulation sends an email message that contains a custom phishing link and company-based terminology and branding.
How should you configure the simulation?
A. Create a Tenant payload.
B. Select a Global payload.
C. Select custom end-user notifications.
D. Create a tenant landing page.
Show Answer
Correct Answer: A
Explanation: To send a phishing email with a custom phishing link and company-specific terminology and branding in Attack simulation training, you must create a Tenant payload. Tenant payloads allow full customization of the email content, links, and branding. Global payloads are built-in and not customizable, end-user notifications are sent before or after simulations (not the phishing email itself), and tenant landing pages only customize the post-click experience, not the email message.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.