HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to ensure that an alert is generated when an app is registered in Microsoft Entra and is assigned the Directory.ReadWrite.All Microsoft Graph permission.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Microsoft Defender for Cloud Apps
an OAuth apps policy
Explanation: Defender for Cloud Apps monitors Microsoft Entra OAuth app registrations and permissions. An OAuth apps policy can generate alerts when apps are registered or granted high-privilege Microsoft Graph permissions such as Directory.ReadWrite.All.
Question 28
You have a Microsoft 365 subscription that contains 500 Windows devices enrolled in Microsoft Intune.
You need to ensure that you can review vulnerability management recommendations for the devices. The solution must minimize administrative effort.
Which policy template should you select in the Microsoft Defender portal?
A. Microsoft Defender Antivirus
B. Windows Security Experience
C. Endpoint Detection and Response
D. Device Control
Show Answer
Correct Answer: C
Explanation: To review vulnerability management recommendations, devices must be onboarded to Microsoft Defender for Endpoint because Microsoft Defender Vulnerability Management is part of Defender for Endpoint. In the Microsoft Defender portal, this onboarding is done by deploying the Endpoint Detection and Response (EDR) policy template. This requires minimal administrative effort and enables collection of vulnerability data and security recommendations across all enrolled Windows devices.
Question 29
You have Microsoft 365 E5 subscription that contains the identities shown in the following table.
You create a shared mailbox named Shared1.
Which identities can you add to Shared1 as a member?
A. User1 only
B. User1 and Group1 only
C. User1 and Group2 only
D. User1 and Group3 only
E. User1, Group2, and Group3 only
Show Answer
Correct Answer: C
Explanation: Shared mailbox permissions in Microsoft 365 can be assigned to individual user accounts and to mail-enabled security groups. Microsoft 365 groups and distribution groups are not supported for shared mailbox membership. Therefore, User1 and the mail-enabled security group (Group2) can be added, but the other group types cannot.
Question 30
HOTSPOT
-
You have a Microsoft 365 subscription that uses the following services:
• Microsoft Entra
• Exchange Online
• Microsoft Teams
• SharePoint Online.
You are planning a backup solution that will use Microsoft 365 Backup.
You need to recommend which Microsoft 365 services can be backed up and the longest retention period available.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Services:
Exchange Online and SharePoint Online only
Retention period:
1 year
Explanation: Microsoft 365 Backup supports backup and restore for Exchange Online and SharePoint Online (including OneDrive content). It does not back up Microsoft Entra, and Teams isn’t selected as a separate service. The maximum retention period available is 1 year.
Question 31
You have a Microsoft 365 subscription that contains the users shown in the following table.
You plan to use Microsoft 365 Backup.
Which users can enable Microsoft 365 Backup?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2 and Admin3 only
E. Admin1, Admin2, Admin3, and Admin4
Show Answer
Correct Answer: C
Explanation: Microsoft 365 Backup can be enabled only by users who are Global Administrators or SharePoint Administrators. In the given table, Admin1 is a Global Administrator and Admin3 is a SharePoint Administrator. Exchange Administrator and Compliance Administrator roles do not have permission to enable Microsoft 365 Backup.
Question 32
Your network contains an Active Directory domain named adatum.com that is synced to a Microsoft Entra tenant.
The domain contains 100 user accounts.
The city attribute for all the users is set to the city where the user resides.
You need to modify the value of the city attribute to the three-letter airport code of each city.
What should you do?
A. From Windows PowerShell on a domain controller, run the Get-MgUser and Update-MgUser cmdlets.
B. From Azure Cloud Shell, run the Get-MgUser and Update-MgUser cmdlets.
C. From the Microsoft 365 admin center, select the users, and then use the Bulk actions option.
D. From Windows PowerShell on a domain controller, run the Get-ADUser and Set-ADUser cmdlets.
Show Answer
Correct Answer: D
Explanation: The users are sourced from on‑premises Active Directory and synced to Microsoft Entra. Attribute changes must be made in the authoritative source, which is Active Directory. Using Get-ADUser and Set-ADUser from Windows PowerShell on a domain controller allows bulk modification of the city attribute, after which the updated values will sync to Entra.
Question 33
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to create a Conditional Access policy named Policy1 that will enforce the use of phishing-resistant multifactor authentication (MFA) when a user attempts to register or join devices to a Microsoft Entra tenant.
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Assignments: Target resources
Access controls: Set Grant to Require authentication strength
Explanation: Device registration and join are configured as a user action under Target resources in Conditional Access. To enforce phishing-resistant MFA, the Grant control must require an authentication strength that includes phishing-resistant methods.
Question 34
You have a Microsoft 365 E5 subscription and use Microsoft Purview. The subscription contains the devices shown in the following table.
All the devices are onboarded to Microsoft Defender for Endpoint.
You plan to deploy Endpoint data loss prevention (Endpoint DLP) policies.
Which devices can be protected by using the DLP policies?
A. Device1 only
B. Device1 and Device2 only
C. Device1, Device2, and Device 3 only
D. Device1, Device3, and Device 4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: B
Explanation: Endpoint DLP in Microsoft Purview supports Windows 10/11 and the three most recent versions of macOS when devices are onboarded to Microsoft Defender for Endpoint. Other platforms such as Linux, iOS, or Android are not supported for Endpoint DLP. Therefore, only Device1 (Windows) and Device2 (macOS) can be protected.
Question 35
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Graph PowerShell to assign a Microsoft 365 E5 license to a new user named
.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Get-MgSubscribedSku retrieves the tenant’s available license SKUs and allows filtering for the Microsoft 365 E5 (SPE_E5). Set-MgUserLicense is the Microsoft Graph PowerShell cmdlet used to assign the selected SKU to a user.
Question 36
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription.
You are implementing Microsoft Defender for Cloud Apps.
You need to ensure that you can create OAuth app policies.
Solution: You add an API token to Defender for Cloud Apps.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Adding an API token to Defender for Cloud Apps is used for connecting third‑party apps via app connectors, not for enabling OAuth app governance in Microsoft 365. To create OAuth app policies, Microsoft 365 must be connected to Defender for Cloud Apps so it can discover and monitor OAuth apps granted consent in the tenant. Therefore, the solution does not meet the goal.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.