You have Microsoft 365 E5 subscription that contains the identities shown in the following table.
You create a shared mailbox named Shared1.
Which identities can you add to Shared1 as a member?
A. User1 only
B. User1 and Group1 only
C. User1 and Group2 only
D. User1 and Group3 only
E. User1, Group2, and Group3 only
Show Answer
Correct Answer: C
Explanation: Assuming the identity table contains User1 plus Group1 (Microsoft 365 group/distribution group), Group2 (mail-enabled security group), and Group3 (security group), only users and mail-enabled security groups can be added as shared mailbox members for mailbox permissions. Therefore User1 and Group2 can be added.
Question 44
HOTSPOT
-
You have a Microsoft 365 subscription that uses the following services:
• Microsoft Entra
• Exchange Online
• Microsoft Teams
• SharePoint Online.
You are planning a backup solution that will use Microsoft 365 Backup.
You need to recommend which Microsoft 365 services can be backed up and the longest retention period available.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Services: Exchange Online and SharePoint Online only
Retention period: 1 year
Explanation: Microsoft 365 Backup protects Exchange Online, SharePoint Online, and OneDrive (not listed here). It does not back up Microsoft Entra or Microsoft Teams as standalone services. The maximum backup retention is 1 year.
Question 45
You have a Microsoft 365 subscription that contains the users shown in the following table.
You plan to use Microsoft 365 Backup.
Which users can enable Microsoft 365 Backup?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2 and Admin3 only
E. Admin1, Admin2, Admin3, and Admin4
Show Answer
Correct Answer: C
Explanation: To enable Microsoft 365 Backup, the required role is either Global Administrator or SharePoint Administrator. Exchange Administrator and Compliance Administrator do not have permission to enable the service itself, although other admin roles may manage specific workloads after setup.
Question 46
Your network contains an Active Directory domain named adatum.com that is synced to a Microsoft Entra tenant.
The domain contains 100 user accounts.
The city attribute for all the users is set to the city where the user resides.
You need to modify the value of the city attribute to the three-letter airport code of each city.
What should you do?
A. From Windows PowerShell on a domain controller, run the Get-MgUser and Update-MgUser cmdlets.
B. From Azure Cloud Shell, run the Get-MgUser and Update-MgUser cmdlets.
C. From the Microsoft 365 admin center, select the users, and then use the Bulk actions option.
D. From Windows PowerShell on a domain controller, run the Get-ADUser and Set-ADUser cmdlets.
Show Answer
Correct Answer: D
Explanation: Because the users are synchronized from on-premises Active Directory to Microsoft Entra ID, the city attribute is mastered on-premises. You must update the attribute in Active Directory using Get-ADUser and Set-ADUser on a domain-joined system (such as a domain controller). Changes will then sync to Microsoft Entra. Microsoft Graph Update-MgUser or Microsoft 365 admin center cannot permanently modify synchronized attributes.
Question 47
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to create a Conditional Access policy named Policy1 that will enforce the use of phishing-resistant multifactor authentication (MFA) when a user attempts to register or join devices to a Microsoft Entra tenant.
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Assignments: Target resources
Access controls: Set Grant to Require authentication strength
Explanation: For device registration or join, configure the Conditional Access policy under Target resources by selecting the user action 'Register or join devices'. To enforce phishing-resistant MFA, use the Grant control 'Require authentication strength' and choose the built-in 'Phishing-resistant MFA' strength.
Question 48
You have a Microsoft 365 E5 subscription and use Microsoft Purview. The subscription contains the devices shown in the following table.
All the devices are onboarded to Microsoft Defender for Endpoint.
You plan to deploy Endpoint data loss prevention (Endpoint DLP) policies.
Which devices can be protected by using the DLP policies?
A. Device1 only
B. Device1 and Device2 only
C. Device1, Device2, and Device 3 only
D. Device1, Device3, and Device 4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: B
Explanation: Microsoft Purview Endpoint DLP supports Windows 10/11 and supported versions of macOS that are onboarded to Microsoft Defender for Endpoint. It does not protect Linux or mobile devices through Endpoint DLP. Therefore, only the Windows and macOS devices (Device1 and Device2) are protected.
Question 49
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Graph PowerShell to assign a Microsoft 365 E5 license to a new user named
.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Use Get-MgSubscribedSku to retrieve the Microsoft 365 E5 SKU (filter by SkuPartNumber 'SPE_E5'), then use Set-MgUserLicense with -AddLicenses and -RemoveLicenses to assign the license.
Question 50
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription.
You are implementing Microsoft Defender for Cloud Apps.
You need to ensure that you can create OAuth app policies.
Solution: You add an API token to Defender for Cloud Apps.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Adding an API token to Defender for Cloud Apps is used for integration with supported third-party apps via app connectors, not to enable OAuth app governance. To create OAuth app policies, Defender for Cloud Apps must be connected to Microsoft 365 so it can discover and evaluate OAuth apps that have been granted consent in the tenant.
Question 51
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a user named Admin1.
Your company deploys a new branch office named Branch1.
You need to provide Admin1 with the ability to manage Branch1. The solution must meet the following requirements:
• Admin1 must only be able to manage users that have Office location set to Branch1.
• Admin1 must be able to reset passwords, manage user licenses, and modify user attributes only for the users in Branch1.
What should you use to organize the Branch1 users, and which role should you assign to Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Use: An administrative unit
Role: User Administrator
Explanation: Administrative units allow scoping administrative permissions to a subset of users (such as those with Office location = Branch1). The User Administrator role scoped to that administrative unit can reset passwords, manage licenses, and modify user attributes only for users in that unit.
Question 52
Your company has offices in Seattle and Denver.
You have a Microsoft 365 subscription.
You plan to create a Conditional Access policy named Policy1 that will enforce multifactor authentication (MFA).
You need to ensure that users at the Seattle office are excluded from MFA. Users at the Denver office must always be prompted for MFA.
What should you configure for Policy1?
A. a named location that has IP ranges location set to the Seattle office
B. Authentication strengths
C. a named location that has Countries location set to United States
D. VPN connectivity from the Seattle office
Show Answer
Correct Answer: A
Explanation: Configure a named location containing the Seattle office's public IP address ranges, then exclude that named location from the Conditional Access policy while requiring MFA for all other locations. This exempts Seattle users from MFA and ensures Denver users are prompted. A country-based named location would exclude all US users, authentication strengths do not exclude by location, and VPN connectivity is not the Conditional Access configuration needed.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.