Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory forest.
You deploy Microsoft 365.
You plan to implement directory synchronization.
You need to recommend a security solution for the synchronized identities. The solution must meet the following requirements:
• Users must be able to authenticate successfully to Microsoft 365 services if Active Directory becomes unavailable.
• User passwords must be 10 characters or more.
Solution: Implement pass-through authentication and configure password protection in the Azure AD tenant.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Pass-through authentication relies on on-premises Active Directory being available at sign-in to validate credentials. If AD is unavailable, users cannot authenticate to Microsoft 365, which violates the requirement. Meeting the requirement would require password hash synchronization. While Azure AD password protection can enforce password length, pass-through authentication fails the availability requirement.
Question 193
You have a Microsoft 365 subscription.
You need to create a data loss prevention (DLP) policy that is configured to use the Set headers action.
To which location can the policy be applied?
A. Exchange email
B. OneDrive accounts
C. SharePoint sites
D. Teams chat and channel messages
Show Answer
Correct Answer: A
Explanation: The **Set headers** action in Microsoft 365 DLP is used to add or modify **email message headers**, which only applies to **Exchange email**. This action is not available for OneDrive, SharePoint, or Teams locations.
Question 194
HOTSPOT
-
Your network contains an on-premises Active Directory domain named contoso.com.
Your company purchases Microsoft 365 subscription and establishes a hybrid deployment of Azure AD by using password hash synchronization. Password writeback is disabled in Azure AD Connect.
You create a new user named User10 on-premises and a new user named User20 in Azure AD.
You need to identify where an administrator can reset the password of each new user.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User10:
On-premises Active Directory only
User20:
Azure AD only
Explanation: User10 is created on-premises and synchronized via password hash sync; without password writeback, administrators must reset the password in on-premises AD. User20 is cloud-only in Azure AD, so the password can be reset only in Azure AD.
Question 195
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
Each user has an Android device with the Microsoft Authenticator app installed and has set up phone sign-in.
The subscription has the following Conditional Access policy:
• Name: Policy1
• Assignments
• Users and groups: Group1, Group2
• Cloud apps or actions: All cloud apps
• Access controls
• Grant: Require multi-factor authentication
• Enable policy: On
From Microsoft Authenticator settings for the subscription, the Enable and Target settings are configured as shown in the exhibit. (Click the Exhibit tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1: Yes
User2: No
User3: No
Explanation: User1 is in Group1, which is targeted for Microsoft Authenticator passwordless sign-in, so number matching is available. User2 is in Group2 and is subject to Conditional Access requiring MFA, so username and password alone are insufficient. User3, although in both groups, has not set up the Microsoft Authenticator app, so number matching cannot be used.
Question 196
You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1.
You enable Azure AD Identity Protection.
You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Compliance Administrator
B. Security Reader
C. Reports Reader
D. User Administrator
Show Answer
Correct Answer: B
Explanation: Reviewing users flagged for risk in Azure AD (Microsoft Entra ID) Identity Protection requires access to security-related reports. The Security Reader role has read-only access to Identity Protection reports, including risky users, and is the least-privileged role that can perform this task. Other roles either lack access (Reports Reader) or grant unnecessary additional permissions (Compliance Administrator, User Administrator).
Question 197
You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1.
You enable Azure AD Identity Protection.
You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Compliance Administrator
B. Security Administrator
C. Service Administrator
D. User Administrator
Show Answer
Correct Answer: B
Explanation: Azure AD Identity Protection can be reviewed by users assigned Security Reader, Security Operator, Security Administrator, Global Reader, or Global Administrator roles. Among the provided options, only Security Administrator grants the necessary access while adhering to the principle of least privilege. The other roles either do not provide access to Identity Protection data or are unrelated.
Question 199
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Office 365 and contains a user named User1.
User emails a product catalog in the PDF format to 300 vendors. Only 200 vendors receive the email message, and User1 is blocked from sending email until the next day.
You need to prevent this issue from reoccurring.
What should you configure?
A. anti-spam policies
B. Safe Attachments policies
C. anti-phishing policies
D. anti-malware policies
Show Answer
Correct Answer: A
Explanation: The issue describes outbound email being blocked after sending the same message with an attachment to a large number of external recipients. This behavior is controlled by outbound anti-spam policies in Microsoft Defender for Office 365, which include limits and protections against mass mailing and spam-like activity. Configuring anti-spam policies (such as adjusting outbound spam thresholds or allowed sending limits) will prevent the user from being blocked in this scenario. Other options focus on content inspection rather than sending behavior.
Question 201
You are testing a data loss prevention (DLP) policy to protect the sharing of credit card information with external users.
During testing, you discover that a user can share credit card information with external users by using email. However, the user is prevented from sharing files that contain credit card information by using Microsoft SharePoint.
You need to prevent the user from sharing the credit card information by using email and SharePoint.
What should you configure?
A. the locations of the DLP policy
B. the conditions of the DLP policy rule
C. the user overrides of the DLP policy rule
D. the status of the DLP policy
Show Answer
Correct Answer: A
Explanation: The DLP policy already detects credit card information and blocks it in SharePoint, but it does not apply to email. To prevent sharing via both email and SharePoint, you must configure the policy locations to include Exchange Online (email) and SharePoint Online. Changing conditions, overrides, or policy status is not required when the issue is that a workload is not covered by the policy.
Question 202
You have a Microsoft 365 E5 tenant.
You create an auto-labeling policy to encrypt emails that contain a sensitive info type. You specify the locations where the policy will be applied.
You need to deploy the policy.
What should you do first?
A. Run the policy in simulation mode.
B. Configure Azure Information Protection analytics.
C. Review the sensitive information in Activity explorer.
D. Turn on the policy.
Show Answer
Correct Answer: A
Explanation: Auto-labeling policies in Microsoft 365 must be run in simulation mode before they can be enforced. Simulation lets you see which emails would be labeled and encrypted without actually applying the labels, validating scope and sensitive info detection. Only after at least one simulation can the policy be turned on for automatic labeling.
Question 203
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You have labels in Microsoft 365 as shown in the following table.
The content in Microsoft 365 is assigned labels as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Admin1 has both Content Explorer List Viewer and Content Viewer roles, which together allow viewing item contents in Content Explorer. Admin2 lacks the Content Explorer Content Viewer role, so cannot view file contents. Admin2 does have access to Content Explorer and the List Viewer role, which allows viewing item metadata, including verifying that Label2 is assigned to Mail1.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.