You have a Microsoft 365 tenant.
You plan to manage incidents in the tenant by using the Microsoft Defender XDR.
Which Microsoft service source will appear on the Incidents page of the Microsoft Defender portal?
A. Azure Information Protection
B. Azure Web Application Firewall
C. Microsoft Sentinel
D. Microsoft Defender for Cloud Apps
Show Answer
Correct Answer: D
Explanation: The Microsoft Defender portal Incidents page in Microsoft Defender XDR aggregates and correlates alerts from integrated Defender products. Microsoft Defender for Cloud Apps is one of the native service sources that contributes incidents. Microsoft Sentinel is a separate SIEM that can integrate with Defender but is not a native incident source on the Defender XDR Incidents page. Azure Information Protection and Azure Web Application Firewall are not listed as Defender XDR incident service sources.
Question 33
You have a Microsoft 365 E5 subscription.
You create the users shown in the following table.
You plan to use Microsoft Entra ID Protection.
Which users will be added automatically to the Users at risk detected alerts list?
A. Admin1 only
B. Admin2 only
C. Admin1 and Admin2 only
D. Admin1 and Admin3 only
E. Admin1, Admin2, and Admin3
Show Answer
Correct Answer: D
Explanation: Microsoft Entra ID Protection automatically adds users who are actively assigned the Global Administrator, Security Administrator, or Security Reader roles to the Users at risk detected alerts notification list (provided they have a valid email or alternate email configured). Security Operator is not automatically included. Therefore, with Admin1 as Security Administrator and Admin3 as Security Reader, the correct choice is Admin1 and Admin3 only.
Question 34
HOTSPOT
-
You have the Microsoft Defender XDR report schedules shown in the following exhibit.
You need to ensure that the report schedules generate reports as frequently as possible.
To what should you set the Frequency setting for each schedule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: For Microsoft Defender for Office 365 scheduled email security reports such as MailFlowStatus and ZAP, the highest supported recurring frequency is Weekly; Daily scheduling is not available for these report types.
Question 35
You have a Microsoft 365 E5 subscription that contains 1,000 Windows devices.
You need to review the exposure score of the devices.
Which portal should you use?
A. the Microsoft Intune admin center
B. the Microsoft Purview portal
C. the Microsoft Defender portal
D. the Microsoft 365 admin center
Show Answer
Correct Answer: C
Explanation: The Exposure Score for devices is part of Microsoft Defender Vulnerability Management and is viewed in the Microsoft Defender portal (formerly Microsoft 365 Defender). Intune focuses on device management and compliance, Purview is for data governance and compliance, and the Microsoft 365 admin center is for tenant administration rather than exposure scoring.
Question 36
You have a Microsoft 365 E5 subscription.
You need to create a mail-enabled contact.
Which portal should you use?
A. the Microsoft Defender portal
B. the SharePoint admin center
C. the Microsoft Purview portal
D. the Exchange admin center
Show Answer
Correct Answer: D
Explanation: Mail-enabled contacts are Exchange recipient objects and are created and managed in the Exchange admin center under Recipients > Contacts. The Defender, Purview, and SharePoint admin portals do not manage Exchange mail contacts.
Question 38
HOTSPOT
-
You have a Microsoft 365 E5 tenant that connects to Microsoft Defender for Endpoint.
You have devices enrolled in Microsoft Intune as shown in the following table.
You plan to use risk levels in Microsoft Defender for Endpoint to identify whether a device is compliant. Noncompliant devices must be blocked from accessing corporate resources.
You need to identify which devices can be onboarded to Microsoft Defender for Endpoint, and which Endpoint security policies must be configured.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Devices that can be onboarded: Device1, Device2, and Device3
Endpoint security policies: Device configuration profile, device compliance policy, and conditional access policy
Explanation: Microsoft Defender for Endpoint supports Windows, iOS, and Android onboarding. To enforce access based on Defender risk, onboard devices (configuration profile), evaluate device risk in a compliance policy, and require compliant devices through Conditional Access.
Question 39
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains Windows 11 devices.
You need to recommend a solution to prevent antivirus and real-time protection on the devices from being modified or disabled.
What should you include in the recommendation?
A. Enforcement scope
B. tamper protection
C. Auto remediation
D. endpoint detection and response (EDR) in block mode
E. Live Response
Show Answer
Correct Answer: B
Explanation: Tamper protection in Microsoft Defender for Endpoint prevents security settings such as Microsoft Defender Antivirus, real-time protection, and other critical protections from being disabled or modified by users or malware. The other options do not specifically prevent changes to antivirus and real-time protection settings.
Question 40
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You configure a new data loss prevention (DLP) policy named Policy1 that detects when sensitive content is shared externally.
Policy1 has the DLP rule shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: available to both internal and external users
no
Explanation: The rule shown has no configured action (only user notifications), so matching files are not blocked or restricted. The sensitive info condition is configured for 1–9 instances; a file with 18 credit card numbers does not match that threshold, so the rule does not trigger and no notification emails are sent.
Question 41
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to ensure that an alert is generated when an app is registered in Microsoft Entra and is assigned the Directory.ReadWrite.All Microsoft Graph permission.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Use: Microsoft Defender for Cloud Apps
Configure: an OAuth apps policy
Explanation: Microsoft Defender for Cloud Apps can monitor Microsoft Entra OAuth app registrations and permissions. An OAuth apps policy can generate alerts when apps are registered or granted high-privilege Microsoft Graph permissions such as Directory.ReadWrite.All.
Question 42
You have a Microsoft 365 subscription that contains 500 Windows devices enrolled in Microsoft Intune.
You need to ensure that you can review vulnerability management recommendations for the devices. The solution must minimize administrative effort.
Which policy template should you select in the Microsoft Defender portal?
A. Microsoft Defender Antivirus
B. Windows Security Experience
C. Endpoint Detection and Response
D. Device Control
Show Answer
Correct Answer: C
Explanation: To review vulnerability management recommendations, devices must be onboarded to Microsoft Defender for Endpoint. In the Microsoft Defender portal, the Endpoint Detection and Response policy template is used to onboard Intune-managed Windows devices with minimal administrative effort, enabling Defender Vulnerability Management data and recommendations.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.