Your network contains an Active Directory domain and an Azure AD tenant.
The network uses a firewall that contains a list of allowed outbound domains.
You begin to implement directory synchronization.
You discover that the firewall configuration contains only the following domain names in the list of allowed domains:
• *.microsoft.com
• *.office.com
Directory synchronization fails.
You need to ensure that directory synchronization completes successfully.
What is the best approach to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.
A. From the firewall, modify the list of allowed outbound domains.
B. From Azure AD Connect, modify the Customize synchronization options task.
C. From the firewall, create a list of allowed inbound domains.
D. Deploy an Azure AD Connect sync server in staging mode.
E. From the firewall, allow the IP address range of the Azure data center for outbound communication.
Show Answer
Correct Answer: A
Explanation: Azure AD Connect requires outbound access to additional Microsoft endpoints beyond only *.microsoft.com and *.office.com. The failure is caused by the firewall allowlist being too restrictive. The appropriate fix is to update the outbound allowed domains to include the required Azure AD Connect service endpoints. Changing synchronization options, configuring inbound rules, deploying a staging server, or allowing entire Azure datacenter IP ranges are not the best solution.
Question 204
Your network contains an on-premises Active Directory domain.
You have a Microsoft 365 subscription.
You implement a directory synchronization solution that uses pass-through authentication.
You configure Azure AD smart lockout as shown in the following exhibit.
You discover that Active Directory users can use the passwords in the custom banned passwords list.
You need to ensure that banned passwords are banned for all users.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. From a domain controller, install the Azure AD Password Protection Proxy.
B. From Active Directory, modify the Default Domain Policy.
C. From a domain controller, install the Azure AD Application Proxy connector.
D. From all the domain controllers, install the Azure AD Password Protection DC Agent.
E. From Password protection for Windows Server Active Directory, modify the Mode setting.
F. From Custom banned passwords, modify the Enforce custom list setting.
Show Answer
Correct Answer: A, D, E
Explanation: To enforce Azure AD Password Protection for on-premises Active Directory, you must deploy the Azure AD Password Protection Proxy service, install the DC Agent on all domain controllers, and change the Windows Server Active Directory Password Protection mode from Audit to Enforced. Smart lockout and the cloud custom banned password list alone do not enforce password restrictions on on-prem AD password changes.
Question 205
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory forest.
You deploy Microsoft 365.
You plan to implement directory synchronization.
You need to recommend a security solution for the synchronized identities. The solution must meet the following requirements:
• Users must be able to authenticate successfully to Microsoft 365 services if Active Directory becomes unavailable.
• User passwords must be 10 characters or more.
Solution: Implement pass-through authentication and configure password protection in the Azure AD tenant.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Pass-through Authentication depends on on-premises Active Directory and the PTA agents to validate user credentials. If Active Directory becomes unavailable, users cannot authenticate to Microsoft 365 using PTA. Password protection can enforce password length and banned passwords, but it does not provide authentication resilience during an on-premises AD outage. Password Hash Synchronization would be required to allow cloud authentication when Active Directory is unavailable.
Question 206
You have a Microsoft 365 subscription.
You need to create a data loss prevention (DLP) policy that is configured to use the Set headers action.
To which location can the policy be applied?
A. Exchange email
B. OneDrive accounts
C. SharePoint sites
D. Teams chat and channel messages
Show Answer
Correct Answer: A
Explanation: The DLP 'Set headers' action applies to email messages by modifying message headers, which is supported for the Exchange email location. It is not applicable to OneDrive, SharePoint, or Teams locations.
Question 207
HOTSPOT
-
Your network contains an on-premises Active Directory domain named contoso.com.
Your company purchases Microsoft 365 subscription and establishes a hybrid deployment of Azure AD by using password hash synchronization. Password writeback is disabled in Azure AD Connect.
You create a new user named User10 on-premises and a new user named User20 in Azure AD.
You need to identify where an administrator can reset the password of each new user.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User10: On-premises Active Directory only
User20: Azure AD only
Explanation: With password hash synchronization and password writeback disabled, passwords for synchronized on-premises users must be reset in on-premises Active Directory. Cloud-only users are managed in Azure AD, so their passwords are reset only in Azure AD.
Question 208
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
Each user has an Android device with the Microsoft Authenticator app installed and has set up phone sign-in.
The subscription has the following Conditional Access policy:
• Name: Policy1
• Assignments
• Users and groups: Group1, Group2
• Cloud apps or actions: All cloud apps
• Access controls
• Grant: Require multi-factor authentication
• Enable policy: On
From Microsoft Authenticator settings for the subscription, the Enable and Target settings are configured as shown in the exhibit. (Click the Exhibit tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: User1 is targeted for passwordless Microsoft Authenticator and has push notifications configured, so number matching is supported. User2 is subject to Conditional Access requiring MFA, so username/password alone is not sufficient. User3 is targeted but has no Microsoft Authenticator push notification method configured, so cannot use number matching.
Question 209
You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1.
You enable Azure AD Identity Protection.
You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Compliance Administrator
B. Security Reader
C. Reports Reader
D. User Administrator
Show Answer
Correct Answer: B
Explanation: To review users flagged for risk in Microsoft Entra ID (Azure AD) Identity Protection, the least-privileged built-in role is Security Reader. Compliance Administrator, Reports Reader, and User Administrator do not grant access to Identity Protection risk data for users.
Question 210
You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1.
You enable Azure AD Identity Protection.
You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Compliance Administrator
B. Security Administrator
C. Service Administrator
D. User Administrator
Show Answer
Correct Answer: B
Explanation: Azure AD (Microsoft Entra) Identity Protection can be accessed by roles such as Security Reader, Security Operator, Security Administrator, Global Reader, and Global Administrator. Among the provided options, only Security Administrator has the required permissions. Although Security Reader would be a lower-privilege role for viewing risk information, it is not an available choice, so Security Administrator is the least-privileged correct option.
Question 212
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Office 365 and contains a user named User1.
User emails a product catalog in the PDF format to 300 vendors. Only 200 vendors receive the email message, and User1 is blocked from sending email until the next day.
You need to prevent this issue from reoccurring.
What should you configure?
A. anti-spam policies
B. Safe Attachments policies
C. anti-phishing policies
D. anti-malware policies
Show Answer
Correct Answer: A
Explanation: The behavior described matches outbound spam protection limits. Sending a message to a large number of external recipients can trigger outbound anti-spam protections, causing the sender to be temporarily restricted from sending mail. To prevent this from recurring, configure the anti-spam policies (specifically outbound spam policy settings where appropriate), not Safe Attachments, anti-phishing, or anti-malware policies.
Question 213
You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant contains the users shown in the following table.
You create and assign a data loss prevention (DLP) policy named Policy1. Policy1 is configured to prevent documents that contain Personally Identifiable Information (PII) from being emailed to users outside your organization.
To which users can User1 send documents that contain PII?
A. User2 only
B. User2 and User3 only
C. User2, User3, and User4 only
D. User2, User3, User4, and User5
Show Answer
Correct Answer: B
Explanation: For Microsoft Purview DLP policies, 'people outside your organization' is determined by Azure AD user type in this context: users with UserType=Member are treated as internal, while UserType=Guest are treated as external. Therefore User1 can send PII-containing documents to users who are Members (User2 and User3), but not to Guest users (User4 and User5).
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.