HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a user named Admin1.
Your company deploys a new branch office named Branch1.
You need to provide Admin1 with the ability to manage Branch1. The solution must meet the following requirements:
• Admin1 must only be able to manage users that have Office location set to Branch1.
• Admin1 must be able to reset passwords, manage user licenses, and modify user attributes only for the users in Branch1.
What should you use to organize the Branch1 users, and which role should you assign to Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Use:
An administrative unit
Role:
User Administrator
Explanation: Administrative units allow scoping administrative permissions to a subset of users (Branch1). The User Administrator role can reset passwords, assign licenses, and modify user attributes, and when scoped to an administrative unit, these actions apply only to users in Branch1.
Question 38
Your company has offices in Seattle and Denver.
You have a Microsoft 365 subscription.
You plan to create a Conditional Access policy named Policy1 that will enforce multifactor authentication (MFA).
You need to ensure that users at the Seattle office are excluded from MFA. Users at the Denver office must always be prompted for MFA.
What should you configure for Policy1?
A. a named location that has IP ranges location set to the Seattle office
B. Authentication strengths
C. a named location that has Countries location set to United States
D. VPN connectivity from the Seattle office
Show Answer
Correct Answer: A
Explanation: To exclude Seattle users from MFA while enforcing MFA for Denver users, you must use a Conditional Access named location based on IP address ranges. Defining a named location with the Seattle office public IP ranges allows Policy1 to exclude that location, while all other locations (including Denver) are required to perform MFA. Other options do not provide location-based exclusion suitable for this requirement.
Question 39
You have a Microsoft 365 E5 subscription that contains a group named Group1. The subscription uses Microsoft Defender for Cloud Apps.
You configure cloud discovery.
You need to ensure that you can create a custom report that details shadow IT usage by the members of Group1.
What should you do first?
A. Configure user enrichment.
B. Disable anonymization.
C. Add an app connector.
D. Configure user monitoring.
Show Answer
Correct Answer: A
Explanation: To create a custom report that shows shadow IT usage specifically by members of Group1, Microsoft Defender for Cloud Apps must be able to map discovered traffic to individual users and their group memberships. Configuring user enrichment connects Defender for Cloud Apps to Microsoft Entra ID and enriches Cloud Discovery data with user and group information. Without user enrichment, you cannot filter or report shadow IT activity by Group1 membership.
Question 40
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You need to ensure that when a user-based alert is triggered in Defender for Cloud Apps, the user is marked as compromised.
Which two options can you use to automate the response? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point
A. a Microsoft Power Automate playbook
B. a user tag
C. a custom detection rule
D. a block script
E. an automated remediation level
Show Answer
Correct Answer: A, B
Explanation: In Microsoft Defender for Cloud Apps, user-based alerts can trigger automated responses. A Microsoft Power Automate playbook can be invoked by an alert to run actions such as marking the user as compromised through Entra ID integration. Additionally, Defender for Cloud Apps supports automated governance actions, including applying a user tag like "Compromised" when an alert fires. Automated remediation levels are associated with other Defender products and do not control user tagging in Defender for Cloud Apps.
Question 41
You have a Microsoft 365 subscription.
You need to identify which shadow IT apps users connect to by using Cloud Discovery in Microsoft Defender for Cloud Apps.
What should you create first?
A. a Cloud Discovery snapshot report
B. a session policy
C. an app discovery policy
D. a Conditional Access policy
Show Answer
Correct Answer: A
Explanation: To identify which shadow IT apps users connect to using Cloud Discovery, you must first generate visibility into app usage. A Cloud Discovery snapshot report analyzes uploaded network traffic logs (or Defender for Endpoint data) and provides an initial inventory of discovered cloud apps, users, and risk levels. App discovery policies, session policies, and Conditional Access policies are applied after discovery and do not provide the initial identification step.
Question 42
HOTSPOT
-
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server. The domain contains the users shown in the following table.
You have a Microsoft 365 subscription that contains the following user accounts:
•
•
On Server1, you configure Microsoft Entra Connect Sync in staging mode and select the following organizational units (OUs):
• OU=Department1,DC=Contoso,DC=LOCAL
• OU=Team1,OU=Department2,DC=Contoso,DC=LOCAL
You disable staging mode on Server1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1 syncs with [email protected]: Yes
User2 syncs with [email protected]: Yes
User3 is created as a new user in Microsoft 365: No
Explanation: Only users in the selected OUs are synchronized. User1 (Department1) and User2 (Team1 under Department2) are both in scope, so they sync and match existing Microsoft 365 users by UPN. User3 is not in a selected OU, so it is not synchronized or created in Microsoft 365.
Question 43
HOTSPOT
-
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You receive the alerts shown in the exhibit. (Click the Exhibit tab.)
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Investigating, Dismissed, or Resolved
cannot be changed
Explanation: File1.docx is in an Active state, which allows changing the alert status to Investigating, Dismissed, or Resolved. File2.docx is already in a Resolved (closed) state, which is terminal and cannot be modified further in Microsoft Purview.
Question 44
Your network contains two on-premises Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com that are connected by using a forest trust.
You have a Microsoft 365 E5 subscription.
You need to sync a subset of users from both forests to Microsoft Entra. The solution must support device objects and device writeback.
What should you use?
A. Microsoft Entra Cloud Sync
B. Microsoft Entra Domain Services
C. Microsoft Entra Connect Sync
D. Active Directory Federation Services (AD FS)
Show Answer
Correct Answer: C
Explanation: Microsoft Entra Connect Sync (formerly Azure AD Connect) is the only option that supports synchronizing a subset of users from multiple on-premises AD DS forests, including trusted forests, into Microsoft Entra ID while also supporting device objects and device writeback. Entra Cloud Sync does not support device writeback, Entra Domain Services is not a synchronization tool, and AD FS is an authentication solution rather than a directory synchronization service.
Question 45
You have a Microsoft 365 E5 subscription.
You plan to deploy Microsoft Defender for Cloud Apps and connect Microsoft 365 to Defender for Cloud Apps.
You need to ensure that you can enable all the Microsoft 365 components when you add the app connector.
What should you do first?
A. Configure Conditional Access app control.
B. Enable file monitoring for Defender for Cloud Apps.
C. Add an API token to Defender for Cloud Apps.
D. Configure Cloud Discovery.
Show Answer
Correct Answer: B
Explanation: When connecting Microsoft 365 to Defender for Cloud Apps via the app connector, file-related components (SharePoint Online and OneDrive for Business) are only fully enabled if file monitoring is turned on. Enabling file monitoring is a prerequisite to ensure all Microsoft 365 components and capabilities—such as file policies, DLP, and governance actions—are available after adding the connector.
Question 46
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription.
You are implementing Microsoft Defender for Cloud Apps.
You need to ensure that you can create OAuth app policies.
Solution: You configure Cloud Discovery.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: OAuth app policies in Microsoft Defender for Cloud Apps are available only after connecting a SaaS tenant (such as Microsoft 365) as a connected app. Cloud Discovery only identifies cloud app usage from logs and does not enable OAuth app policy creation by itself, so the solution does not meet the goal.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.