HOTSPOT
-
You have a Microsoft 365 E3 subscription.
You plan to use Microsoft 365 Backup.
You need to prepare the environment before you can enable Microsoft 365 Backup.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Add: A billing profile
Create: A security group
Explanation: Microsoft 365 Backup requires a Microsoft 365 billing profile for pay-as-you-go billing. Before enabling backup, create a security group to scope which users/sites are protected.
Question 22
You have a Microsoft 365 subscription.
From the Microsoft Entra authentication methods policy, you configure the Microsoft Authenticator on companion applications settings as shown in the following exhibit.
You need to ensure that users can complete the authentication process from their mobile device.
What should each user install on their device?
A. Microsoft Teams
B. Microsoft 365 Copilot
C. Microsoft Outlook
D. Company Portal
Show Answer
Correct Answer: C
Explanation: The 'Microsoft Authenticator on companion applications' setting refers to Authenticator Lite support in companion apps. Microsoft Outlook for iOS and Android supports Authenticator Lite, allowing users to complete MFA approvals from within Outlook without installing the full Microsoft Authenticator app. Therefore, users should install Microsoft Outlook.
Question 23
HOTSPOT
-
Your company has a hybrid deployment of Microsoft 365.
An on-premises user named User1 is synced to the Microsoft Entra tenant.
Microsoft Entra Connect Sync is configured as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1 cannot change her password from any Microsoft portals.
If the password for User1 is changed in Active Directory, the password hash will be synchronized to Microsoft Entra ID.
Explanation: Password Hash Synchronization is enabled, so on-premises password changes sync their password hash to Microsoft Entra ID. Password Writeback is disabled, so cloud password changes/resets cannot be written back to on-premises Active Directory, preventing password changes through Microsoft portals for the synced user.
Question 24
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains two sensitivity labels named Label1 and Label2. The subscription contains Windows device named Device1 that is onboarded to Microsoft Purview. Device1 contains the files shown in the following table.
You create a data loss prevention (DLP) policy named Policy1 that has the following configurations:
• Locations
o Devices: All users and groups
• Rules
o Name: Rule1
o Conditions: Content contains
- Sensitivity labels: Label1
o Actions: Audit or restrict activities on devices
- Print: Block
From the Data loss prevention settings, you configure a file path exclusion for C:\Temp\.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: The DLP rule blocks printing only for files with Label1 unless excluded. The exclusion path C:\Temp\ applies only to files directly in that folder, not subfolders. File1 is excluded, File2 does not match the Label1 condition, and File3 matches the rule and is not excluded.
Question 26
HOTSPOT
-
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. Contoso.com contains the users shown in the following table.
Contoso.com contains the groups shown in the following table.
Group3 has no members.
You have a Microsoft Entra tenant.
You deploy Microsoft Entra Cloud Sync and configure a scoping filter by using the following entry.
CN=Group1,OU=OU2,DC=contoso, DC=com
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Group-based scoping in Microsoft Entra Cloud Sync includes the selected group's direct members regardless of their OU. User1 is a direct member of Group1, User2 is only a nested member through Group2, and Group3 is a direct member of Group1.
Question 27
HOTSPOT
-
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the users shown in the following table.
You have a Microsoft Entra tenant that syncs with contoso.com by using Microsoft Entra Connect Sync. Microsoft Entra Connect Sync is configured as shown in the exhibit. (Click the Exhibit tab.)
The Microsoft Entra tenant contains a cloud-only group named Group1 as shown in the following table.
You perform the following tasks at 10 AM:
• In contoso.com, you move User1 to OU2.
• In the Microsoft Entra tenant, you delete User2.
• In contoso.com, you create a computer account named Comp1 in OU1 and update the description of Comp1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
No
Explanation: Moving User1 to an unsynced OU causes the synced object to fall out of scope rather than become a new group member. Deleting a cloud-only user does not delete the on-premises AD user. A new computer object in a synced OU does not result in the Description property syncing as stated.
Question 28
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Defender XDR to identify the following:
• Information-about known malicious organizations.
• Weekly open-source intelligence (OSINT) highlights.
Which two settings should you use in the Microsoft Defender portal? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Information about known malicious organizations: Intel profiles
Weekly open-source intelligence (OSINT) highlights: Threat analytics
Explanation: Intel profiles provides intelligence on known threat actors/organizations. Threat analytics includes curated reports and weekly OSINT highlights in Microsoft Defender XDR.
Question 29
You have a Microsoft 365 E5 subscription.
You are evaluating Microsoft Defender for Cloud Apps.
Which two types of policy rely on Conditional Access App Control? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. app discovery policy
B. OAuth app policy
C. access policy
D. file policy
E. session policy
F. activity policy
Show Answer
Correct Answer: C, E
Explanation: Conditional Access App Control is used to proxy user sessions through Microsoft Defender for Cloud Apps for real-time control. Access policies determine whether and how access is granted when a proxied session begins, while session policies enforce real-time controls during the active session. App discovery, OAuth app, file, and activity policies do not rely on Conditional Access App Control.
Question 30
You have a Microsoft 365 subscription that uses a third-party multifactor authentication (MFA) product.
While reviewing Microsoft Secure Score, you discover that there are no points listed for the Ensure multifactor authentication is enabled for all users recommendation.
You need to ensure that you receive all the points for the recommendation. The solution must minimize administrative effort.
What should you do?
A. Deploy a Microsoft Defender for Identity sensor.
B. Modify the recommendation tags.
C. Modify the status of the recommendation.
D. Configure a data connector.
Show Answer
Correct Answer: C
Explanation: Microsoft Secure Score cannot automatically verify third-party MFA implementations for this recommendation. To receive credit without replacing the MFA solution, manually change the improvement action's status to indicate it has been addressed through an alternate mitigation/third-party implementation. This minimizes administrative effort. Tags, Defender for Identity sensors, and data connectors do not affect Secure Score recognition for this MFA recommendation.
Question 31
You have a Microsoft 365 subscription.
You need to view a list of known tools used by malicious actors.
What should you use in the Microsoft Defender portal?
A. Intel explorer
B. Threat analytics
C. Intel profiles
D. Intel projects
Show Answer
Correct Answer: C
Explanation: Intel profiles in the Microsoft Defender portal provide curated information on tracked threat actors, malicious tools, and vulnerabilities. They are specifically intended to let analysts view known malicious tools and related threat context.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.