You have a Microsoft 365 E5 subscription.
You are evaluating Microsoft Defender for Cloud Apps.
Which two types of policy rely on Conditional Access App Control? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. app discovery policy
B. OAuth app policy
C. access policy
D. file policy
E. session policy
F. activity policy
Show Answer
Correct Answer: C, E
Explanation: Conditional Access App Control works by routing user sessions through a reverse proxy to enforce controls in real time. In Microsoft Defender for Cloud Apps, only Access policies and Session policies rely on this mechanism. Access policies control whether a session is allowed at sign-in, and Session policies control in-session behavior such as blocking downloads or monitoring actions. Other policy types do not depend on Conditional Access App Control.
Question 16
You have a Microsoft 365 subscription that uses a third-party multifactor authentication (MFA) product.
While reviewing Microsoft Secure Score, you discover that there are no points listed for the Ensure multifactor authentication is enabled for all users recommendation.
You need to ensure that you receive all the points for the recommendation. The solution must minimize administrative effort.
What should you do?
A. Deploy a Microsoft Defender for Identity sensor.
B. Modify the recommendation tags.
C. Modify the status of the recommendation.
D. Configure a data connector.
Show Answer
Correct Answer: C
Explanation: Microsoft Secure Score cannot automatically detect third-party MFA solutions, so the MFA recommendation remains at 0 points. To receive the points without changing your MFA setup and with minimal administrative effort, you should manually modify the recommendation’s status (for example, mark it as completed or implemented through alternate mitigation) in Secure Score.
Question 17
You have a Microsoft 365 subscription.
You need to view a list of known tools used by malicious actors.
What should you use in the Microsoft Defender portal?
A. Intel explorer
B. Threat analytics
C. Intel profiles
D. Intel projects
Show Answer
Correct Answer: C
Explanation: Intel profiles in the Microsoft Defender portal provide curated, continuously updated information from Microsoft Threat Intelligence on tracked threat actors, including the malicious tools they use. This directly matches the requirement to view a list of known tools used by malicious actors.
Question 18
You have a Microsoft 365 tenant.
You plan to manage incidents in the tenant by using the Microsoft Defender XDR.
Which Microsoft service source will appear on the Incidents page of the Microsoft Defender portal?
A. Azure Information Protection
B. Azure Web Application Firewall
C. Microsoft Sentinel
D. Microsoft Defender for Cloud Apps
Show Answer
Correct Answer: D
Explanation: The Microsoft Defender XDR Incidents page aggregates alerts from Defender services such as Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender for Cloud Apps. Among the options, only Microsoft Defender for Cloud Apps is a supported service source that contributes alerts and incidents in the Defender portal. Azure Information Protection, Azure Web Application Firewall, and Microsoft Sentinel do not appear as incident sources on the Defender XDR Incidents page.
Question 19
You have a Microsoft 365 E5 subscription.
You create the users shown in the following table.
You plan to use Microsoft Entra ID Protection.
Which users will be added automatically to the Users at risk detected alerts list?
A. Admin1 only
B. Admin2 only
C. Admin1 and Admin2 only
D. Admin1 and Admin3 only
E. Admin1, Admin2, and Admin3
Show Answer
Correct Answer: D
Explanation: Microsoft Entra ID Protection automatically adds users to the *Users at risk detected* alerts list if they are actively assigned the Global Administrator, Security Administrator, or Security Reader roles and have a valid email or alternate email configured. Based on the roles in the table, Admin1 and Admin3 meet these criteria, while Admin2 does not. Therefore, the correct answer is Admin1 and Admin3 only.
Question 21
You have a Microsoft 365 E5 subscription that contains 1,000 Windows devices.
You need to review the exposure score of the devices.
Which portal should you use?
A. the Microsoft Intune admin center
B. the Microsoft Purview portal
C. the Microsoft Defender portal
D. the Microsoft 365 admin center
Show Answer
Correct Answer: C
Explanation: Device exposure score is part of Microsoft Defender Vulnerability Management, which is accessed through the Microsoft Defender portal. Intune focuses on device management and compliance, Purview on data governance, and the Microsoft 365 admin center does not provide exposure scoring.
Question 22
You have a Microsoft 365 E5 subscription.
You need to create a mail-enabled contact.
Which portal should you use?
A. the Microsoft Defender portal
B. the SharePoint admin center
C. the Microsoft Purview portal
D. the Exchange admin center
Show Answer
Correct Answer: D
Explanation: Mail-enabled contacts are Exchange directory objects used for email routing. They are created and managed in the Exchange admin center, not in Defender, Purview, or SharePoint admin portals.
Question 24
HOTSPOT
-
You have a Microsoft 365 E5 tenant that connects to Microsoft Defender for Endpoint.
You have devices enrolled in Microsoft Intune as shown in the following table.
You plan to use risk levels in Microsoft Defender for Endpoint to identify whether a device is compliant. Noncompliant devices must be blocked from accessing corporate resources.
You need to identify which devices can be onboarded to Microsoft Defender for Endpoint, and which Endpoint security policies must be configured.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1, Device2, and Device3
A device configuration profile only
Explanation: Microsoft Defender for Endpoint supports Windows, iOS, and Android devices enrolled in Intune, so all listed devices can be onboarded. To integrate Defender for Endpoint risk signals with Intune for device risk evaluation, the required Intune endpoint security setup is the Defender for Endpoint device configuration profile; no additional compliance or conditional access policies are required for the onboarding requirement itself.
Question 25
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains Windows 11 devices.
You need to recommend a solution to prevent antivirus and real-time protection on the devices from being modified or disabled.
What should you include in the recommendation?
A. Enforcement scope
B. tamper protection
C. Auto remediation
D. endpoint detection and response (EDR) in block mode
E. Live Response
Show Answer
Correct Answer: B
Explanation: Tamper protection in Microsoft Defender for Endpoint is specifically designed to prevent unauthorized changes to security settings such as antivirus and real-time protection, including attempts to disable or modify them. The other options do not directly prevent changes to antivirus or real-time protection settings.
Question 26
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You configure a new data loss prevention (DLP) policy named Policy1 that detects when sensitive content is shared externally.
Policy1 has the DLP rule shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: restricted to internal users only
no
Explanation: The DLP rule protects content that matches the conditions by restricting external access. Email notifications are triggered only when the instance count meets the configured range (1–9); detecting 18 credit card numbers exceeds this range, so the rule doesn’t apply and no notifications are sent.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.