Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You create an account for a new security administrator named SecAdmin1.
You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.
Solution: From the Microsoft Entra admin center, you assign SecAdmin1 the Teams Administrator role.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: The Teams Administrator role only manages Microsoft Teams workloads. Managing Microsoft Defender for Office 365 settings and policies across Teams, SharePoint, and OneDrive requires appropriate security permissions (such as Security Administrator or equivalent Defender permissions), not merely the Teams Administrator role. Therefore, assigning only the Teams Administrator role does not meet the stated goal.
Question 184
Overview -
Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle.
Litware collaborates with a third-party company named A. Datum Corporation.
Environment -
On-Premises Environment -
The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table.
The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019.
Cloud Environment -
Litware has a pilot Microsoft 365 subscription that includes Microsoft Office 365 Enterprise E3 licenses and Azure AD Premium P2 licenses.
The subscription contains a verified DNS domain named litware.com.
Azure AD Connect is installed and has the following configurations:
• Password hash synchronization is enabled.
• Synchronization is enabled for the LitwareAdmins OU only.
Users are assigned the roles shown in the following table.
Self-service password reset (SSPR) is enabled.
The Azure AD tenant has Security defaults enabled.
Problem Statements -
Litware identifies the following issues:
• Admin1 cannot create conditional access policies.
• Admin4 receives an error when attempting to use SSPR.
• Users access new Office 365 service and feature updates before the updates are reviewed by Admin2.
Requirements -
Planned Changes -
Litware plans to implement the following changes:
• Implement Microsoft Intune.
• Implement Microsoft Teams.
• Implement Microsoft Defender for Office 365.
• Ensure that users can install Office 365 apps on their device.
• Convert all the Windows 10 Pro devices to Windows 10 Enterprise ES.
• Configure Azure AD Connect to sync the Montreal Users OU and the Seattle Users OU.
Technical Requirements -
Litware identifies the following technical requirements:
• Administrators must be able to specify which version of an Office 365 desktop app will be available to users and to roll back to previous versions.
• Only Admin2 must have access to new Office 365 service and feature updates before they are released to the company.
• Litware users must be able to invite A. Datum users to participate in the following activities:
• Join Microsoft Teams channels.
• Join Microsoft Teams chats.
• Access shared files.
• Just in time access to critical administrative roles must be required.
• Microsoft 365 incidents and advisories must be reviewed monthly.
• Office 365 service status notifications must be sent to Admin2.
• The principle of least privilege must be used.
You need to configure just in time access to meet the technical requirements.
What should you use?
A. entitlement management
B. Azure AD Privileged Identity Management (PIM)
C. access reviews
D. Azure AD Identity Protection
Show Answer
Correct Answer: B
Explanation: Azure AD Privileged Identity Management (PIM) provides just-in-time (JIT) activation for privileged Azure AD and Azure resource roles, enabling eligible administrators to activate roles only when needed. This satisfies the requirement for JIT access to critical administrative roles while supporting least privilege.
Question 185
You have a Microsoft 365 subscription.
You add a domain named contoso.com.
When you attempt to verify the domain, you are prompted to send a verification email to
.
You need to change the email address used to verify the domain.
What should you do?
A. Add a TXT record to the DNS zone of the domain.
B. From the domain registrar, modify the contact information of the domain.
C. From the Microsoft 365 admin center, change the global administrator of the Microsoft 365 subscription.
D. Modify the NS records for the domain.
Show Answer
Correct Answer: B
Explanation: If Microsoft 365 is using email-based domain verification, the verification message is sent to the domain contact email (typically the registrant/admin contact from the domain registration). To change the email address available for verification, update the domain contact information with the domain registrar. Adding a TXT record is an alternative verification method, not a way to change the email address used. Changing the global administrator or NS records does not affect the domain contact email used for email verification.
Question 186
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
All corporate Windows 11 devices are managed by using Microsoft Intune and onboarded to Microsoft Defender for Endpoint.
You need to meet the following requirements:
• View an assessment of the device configurations against the Center for Internet Security (CIS) v1.0.0 benchmark.
• Protect a folder named C:\Folder1 from being accessed by untrusted applications on the devices.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Create a baseline assessment profile.
Controlled folder access
Explanation: Microsoft Defender Vulnerability Management uses a security baseline assessment profile (such as CIS v1.0.0) to assess device configurations. Controlled folder access in Microsoft Defender protects specified folders from untrusted applications.
Question 187
You have a Microsoft 365 subscription.
You create a retention label named Retention1 as shown in the following exhibit.
You apply Retention1 to all the Microsoft OneDrive content.
On January 1, 2020, a user stores a file named File1 in OneDrive.
On January 10, 2020, the user modifies File1.
On February 1, 2020, the user deletes File1.
When will File1 be removed permanently and unrecoverable from OneDrive?
A. February 1, 2020
B. July 1, 2020
C. July 10, 2020
D. August 1, 2020
Show Answer
Correct Answer: B
Explanation: A retention label configured to retain content for 6 months based on the creation date keeps the file until six months after it was created, even if the user deletes it earlier. The modification date does not affect the retention period when the label uses the creation date. A file created on January 1, 2020 reaches the end of its 6-month retention on July 1, 2020, when it can be permanently removed.
Question 188
You have a Microsoft 365 E5 subscription that has Microsoft Defender for Endpoint integrated with Microsoft Intune.
Devices are enrolled to Microsoft Intune and onboarded by using Microsoft Defender for Endpoint.
You plan to block devices based on the results of the machine risk score calculated by Microsoft Defender for Endpoint.
What should you create first?
A. a device configuration policy
B. an endpoint detection and response policy
C. a device compliance policy
Show Answer
Correct Answer: C
Explanation: To block devices based on Microsoft Defender for Endpoint machine risk, Intune must evaluate that risk as part of device compliance. This is done by creating a device compliance policy that includes the Microsoft Defender for Endpoint risk level setting. Conditional Access can then use the device compliance state to block access. A device configuration policy and an EDR policy do not enforce compliance based on Defender risk.
Question 189
Your network contains an Active Directory domain named adatum.com that is synced to Azure AD.
The domain contains 100 user accounts.
The city attribute for all the users is set to the city where the user resides.
You need to modify the value of the city attribute to the three-letter airport code of each city.
What should you do?
A. From Windows PowerShell on a domain controller, run the Get-ADUser and Set-ADUser cmdlets.
B. From Azure Cloud Shell, run the Get-ADUser and Set-ADUser cmdlets.
C. From Windows PowerShell on a domain controller, run the Get-MgUser and Update-MgUser cmdlets.
D. From the Azure portal, select all the Azure AD users, and then use the User settings blade.
Show Answer
Correct Answer: A
Explanation: Because the users are synchronized from on-premises Active Directory to Azure AD, the authoritative source for synced attributes such as the city attribute is the on-premises AD. Modify the attribute in Active Directory using the Active Directory PowerShell cmdlets (Get-ADUser and Set-ADUser) on a domain-joined machine or domain controller, and Azure AD Connect will synchronize the changes. Azure AD/Microsoft Graph cannot permanently update directory-synced attributes, and the Azure portal cannot bulk edit this attribute for synced users.
Question 190
HOTSPOT
-
You have a Microsoft 365 subscription that uses a domain name of adatum.com.
In Azure AD, you set Guest invite restrictions to Only users assigned to specific admin roles can invite guest users.
A user named
reports that they can no longer invite external users from a domain named contoso.com to collaborate in Microsoft Teams.
You need to modify the Azure AD configuration to meet the following requirements:
• Ensure that User1 can invite the contoso.com users to Teams.
• Ensure that only the contoso.com users can be invited as guests to the Azure AD tenant.
• Follow the principle of least privilege.
What should you do for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Assign the Guest Inviter role to User1.
From the External collaboration settings, edit the Collaboration restrictions settings.
Explanation: With guest invitations restricted to specific admin roles, the least-privileged role that allows inviting guests is Guest Inviter. To allow invitations only from contoso.com, configure External collaboration > Collaboration restrictions to allow only that domain.
Question 191
You have a Microsoft 365 subscription that contains more than 2,000 guest users.
You need to ensure that when guest users are added to Microsoft 365 groups in the subscription, their membership is validated by the group owner every 30 days.
What should you configure?
A. group expiration policies
B. retention policies
C. access reviews
D. Conditional Access policies
Show Answer
Correct Answer: C
Explanation: Access reviews in Microsoft Entra ID Governance can be configured to require Microsoft 365 group owners to periodically review and validate guest user membership on a recurring schedule, such as every 30 days. Group expiration policies manage the lifecycle of groups, retention policies govern data retention, and Conditional Access controls sign-in conditions rather than periodic membership validation.
Question 192
HOTSPOT
-
You have a Microsoft 365 subscription.
From Azure AD Privileged Identity Management (PIM), you configure Role settings for the Global Administrator role as shown in the following exhibit.
You make a user named
eligible for the Global Administrator role.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: justification and Azure Multi-Factor Authentication (MFA)
an assignment duration and justification
Explanation: Activation requires justification and Azure MFA, while ticket information and approval are not required. Eligible assignments cannot be permanent, so creating a new eligible assignment requires a duration, and justification is required when assigning the role.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.