You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You plan to perform a security audit of all the apps detected by Cloud Discovery.
You need to track which apps were audited. The solution must ensure that the list of audited apps can be displayed in the cloud app catalog.
What should you do?
A. Define each app as a critical asset.
B. Deploy Conditional Access App Control.
C. Enable app governance.
D. Generate a Cloud Discovery snapshot report.
E. Apply a custom app tag to each app.
Show Answer
Correct Answer: E
Explanation: Custom app tags in Microsoft Defender for Cloud Apps can be applied to discovered apps to classify and track them (for example, marking them as audited). These tags are visible and filterable in the cloud app catalog, making it easy to display the audited apps. The other options do not provide a mechanism for tracking audit status in the cloud app catalog.
Question 124
You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender XDR.
All users have devices that run Windows 11.
From the Microsoft Defender portal, you review the Microsoft Secure Score recommendations. One of the top recommendations is to block all Microsoft Office applications from creating child processes.
You need to increase the secure score by addressing the recommendation.
What should you do?
A. Select Safe Documents for Office clients.
B. Create a policy for Office applications.
C. Configure an endpoint detection and response (EDR) policy.
D. Create an attack surface reduction (ASR) policy.
Show Answer
Correct Answer: D
Explanation: The recommendation to block Microsoft Office applications from creating child processes is implemented through a Microsoft Defender Attack Surface Reduction (ASR) rule. To increase Microsoft Secure Score for this recommendation, create and deploy an ASR policy in Microsoft Intune or Microsoft Defender that enables the 'Block all Office applications from creating child processes' rule.
Question 125
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Defender for Cloud Apps to monitor user mailbox activities.
What should you do?
A. Create an activity policy.
B. Create an access policy.
C. Enable mailbox audit logging.
D. Create an app connector for Microsoft 365.
Show Answer
Correct Answer: D
Explanation: To monitor Exchange Online mailbox activities in Microsoft Defender for Cloud Apps, Microsoft 365 must be connected as a connected app (app connector) so activity data is ingested into Defender for Cloud Apps. Activity policies are used after data is available to generate alerts on specific activities. Access policies are unrelated. Mailbox audit logging is a prerequisite for Exchange activity collection, but in modern Microsoft 365 tenants it is enabled by default, and the key Defender for Cloud Apps configuration step is connecting the Microsoft 365 app.
Question 126
You have a Microsoft 365 E5 subscription.
You plan to create an anti-malware policy named Policy1.
You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user's mailbox.
What should you do in the Microsoft Defender portal?
A. Enable zero-hour auto purge (ZAP).
B. Enable enhanced filtering.
C. Configure a quarantine policy.
D. Modify the common attachments filter.
Show Answer
Correct Answer: A
Explanation: Zero-hour auto purge (ZAP) is the Microsoft Defender for Office 365 feature that can detect messages later determined to be malicious after delivery and automatically move them out of users' mailboxes (for example, to quarantine). Enhanced filtering is for complex mail routing, quarantine policies define handling of quarantined items, and the common attachments filter blocks specified attachment types rather than retroactively detecting delivered malware.
Question 127
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
The subscription contains users that have Windows 11 devices.
You need to use the Cloud Discovery snapshot report to analyze cloud app usage on the devices.
What should you do before generating a report?
A. Create an activity policy.
B. Deploy the Azure Monitor Agent on the devices.
C. Export traffic logs from firewalls and proxies.
D. Create an app discovery policy.
Show Answer
Correct Answer: C
Explanation: A Cloud Discovery snapshot report is generated by uploading and analyzing traffic logs collected from network devices such as firewalls and proxies. Before generating the report, you must export the relevant traffic logs. Activity policies and app discovery policies are used after data ingestion for monitoring and governance, and Azure Monitor Agent is not a prerequisite for snapshot reports.
Question 128
HOTSPOT
-
You have an Azure subscription.
You have a Microsoft 365 E5 subscription.
You are licensed to use Microsoft Defender XDR.
You need to monitor activities from suspicious IP addresses and unusual administrative activities in Azure.
What should you use to monitor the activities, and what should you use to integrate Azure with Microsoft Defender XDR? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Monitor: Microsoft Defender for Cloud Apps
Integrate: An app connector
Explanation: Microsoft Defender for Cloud Apps provides anomaly detection for suspicious IP address activity and unusual Azure administrative activities. Azure is integrated with Defender for Cloud Apps (and thus Defender XDR visibility) by using an app connector.
Question 129
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
From Microsoft Defender Vulnerability Management, you review the top security recommendations and discover a recommendation to update Microsoft Edge (Chromium) to a later version.
You need to ensure that a security task is added to Intune to address the recommendation.
What should you do?
A. From the Microsoft Intune admin center, configure Windows Autopatch.
B. From the Microsoft Intune admin center, configure a security baseline.
C. From the Microsoft Defender portal, select Request remediation.
D. From the Microsoft Defender portal add an incident notification rule.
Show Answer
Correct Answer: C
Explanation: In Microsoft Defender Vulnerability Management, security recommendations can be turned into remediation workflows by selecting Request remediation. When Defender for Endpoint is integrated with Microsoft Intune, this creates a security task in Intune to track and remediate the recommendation, such as updating Microsoft Edge (Chromium).
Question 130
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
From Policy management, you open Information protection as shown in the following exhibit.
Which type of policy can you create?
A. session policy
B. activity policy
C. OAuth app policy
D. access policy
E. file policy
Show Answer
Correct Answer: E
Explanation: In Microsoft Defender for Cloud Apps, the Policy management category 'Information protection' is where file policies are created and managed. Session and access policies belong to Conditional access, while activity and OAuth app policies are under Threat detection.
Question 131
You have a Microsoft 365 E5 subscription that includes Microsoft Intune.
You manage all iOS devices by using Intune.
You plan to protect corporate-owned iOS devices by using Microsoft Defender for Endpoint. You configure a connection between Intune and Defender for Endpoint.
You need to onboard the devices to Defender for Endpoint.
What should you do?
A. Download an onboarding package.
B. Create an app protection policy.
C. Enable Microsoft Defender for Cloud.
D. Add an app to Intune.
Show Answer
Correct Answer: D
Explanation: For enrolled, corporate-owned iOS devices managed by Intune, Microsoft Defender for Endpoint onboarding is accomplished by deploying the Microsoft Defender for Endpoint iOS app through Intune (for example, as an iOS Store app). iOS devices do not use the onboarding package approach that is used for platforms such as Windows and macOS. App protection policies are for MAM scenarios, and Defender for Cloud is unrelated to onboarding iOS devices.
Question 132
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a social engineering awareness solution that meets the following requirements:
• To reset a user’s password, emulate an email message that contains a link.
• Track any user that selects the email message link.
• Suggest further social engineering training.
What should you use in the Microsoft Defender portal?
A. Attack simulation training
B. Learning hub
C. Exposure insights
D. Threat tracker
Show Answer
Correct Answer: A
Explanation: Attack simulation training in Microsoft Defender for Office 365 is designed to run phishing and social engineering simulations, including credential harvesting or link-based password reset scenarios, track which users click the simulated links, and automatically assign or recommend targeted training based on user behavior.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.