You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to create a policy that will quarantine messages containing attachments that match .apk and .appx extensions.
Which type of policy should you configure?
A. anti-malware
B. anti-phishing
C. Safe Attachments
D. anti-spam
Show Answer
Correct Answer: A
Explanation: Anti-malware policies in Microsoft Defender for Office 365 allow you to filter and take actions on specific file types by configuring common attachment filter settings. You can block file extensions such as .apk and .appx and quarantine messages containing those attachments. Anti-phishing protects against impersonation, Safe Attachments detonates attachments for malware analysis, and anti-spam focuses on spam filtering rather than blocking specific attachment extensions.
Question 74
You have a Microsoft 365 subscription and use Microsoft Defender for Office 365.
You need to recommend a solution to educate users on topics that relate to social engineering risks. The users must receive a weekly reminder to complete a learning task.
What should you use in the Microsoft Defender portal?
A. Learning hub
B. Campaigns
C. Threat tracker
D. Attack simulation training
Show Answer
Correct Answer: B
Explanation: The requirement emphasizes educating users with learning tasks and sending weekly reminders. In Microsoft Defender for Office 365, Training campaigns (Campaigns) are used to assign security awareness training, schedule recurring reminder emails, and track completion. Attack simulation training is the overall feature, but the specific portal component that manages assigned learning with recurring reminders is Campaigns.
Question 75
You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1.
You plan to use Microsoft Entra ID Protection.
You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Security Reader
B. Reports Reader
C. Service Administrator
D. User Administrator
Show Answer
Correct Answer: A
Explanation: The Security Reader role provides read-only access to security-related information, including Microsoft Entra ID Protection data such as risky users. This satisfies the principle of least privilege because it allows viewing security information without granting administrative modification rights. Reports Reader does not provide the necessary security-specific visibility for ID Protection, and Service Administrator and User Administrator grant unrelated or excessive privileges.
Question 76
You have a Microsoft 365 E5 subscription. The subscription contains users that have the following types of devices:
• Windows 11
• Android
• iOS
To which devices can you apply Endpoint DLP policies?
A. Windows 11 only
B. Windows 11 and Android only
C. Windows 11 and iOS only
D. Windows 11, Android, and iOS
Show Answer
Correct Answer: A
Explanation: Endpoint Data Loss Prevention (Endpoint DLP) in Microsoft Purview supports onboarded Windows endpoints (Windows 10/11), as well as macOS and certain Windows Server versions. It does not support applying Endpoint DLP policies to Android or iOS devices; those platforms use other protection mechanisms such as Intune app protection and MAM.
Question 77
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune.
All devices run Windows 11 and are Microsoft Entra joined.
You are alerted to a zero-day attack.
You need to identify which devices were affected by the attack and send a request to Intune administrators to update the affected devices.
Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. From Threat analytics, view the list of vulnerable devices.
B. From Incidents & alerts, select the latest incident.
C. From Vulnerability management, open the security recommendation.
D. Select the affected devices and request remediation.
Show Answer
Correct Answer: A, D
Explanation: Threat analytics is the feature designed to assess emerging threats such as zero-day attacks and provides the list of impacted or vulnerable devices for a specific threat. After identifying the affected devices, you can select them and use the Request remediation action to send a remediation request to Microsoft Intune administrators to deploy the required updates. Opening a security recommendation alone is not the primary workflow described for identifying devices affected by a zero-day threat, and Incidents & alerts focuses on detected incidents rather than threat-wide exposure.
Question 78
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware.
Solution: You create an anti-phishing policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: A balanced baseline protection profile that covers spam, phishing, and malware is implemented by the Standard protection preset security policy in Microsoft Defender for Office 365. Creating only an anti-phishing policy addresses phishing but does not provide the full balanced baseline across spam, phishing, and malware.
Question 79
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.
All the devices in your organization are onboarded to Microsoft Defender for Endpoint.
You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours.
What should you do?
A. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
B. From the Microsoft Defender portal, create an alert suppression rule and assign an alert.
C. From Advanced hunting, create a query and a detection rule.
D. From the Microsoft Defender portal, create an Advanced hunting query and a detection rule.
Show Answer
Correct Answer: D
Explanation: To generate an alert based on malicious activity detected over the last 24 hours in Microsoft Defender for Endpoint, you use Advanced hunting in the Microsoft Defender portal to create a custom hunting query and then create a custom detection rule from that query. D explicitly identifies the correct location (the Microsoft Defender portal). Alert suppression rules reduce alerts rather than generate them, and DLP policies are unrelated.
Question 80
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains Windows 11 devices.
You need to create a policy to restrict users from accessing the Device security settings and the Account protection settings in Windows Defender Security Center on the devices.
Which type of policy should you create, and which template should you use? To answer, select the appropriate options in the answer area.
Explanation: To restrict access to Windows Security app areas such as Device security and Account protection, create an Endpoint security policy using the Windows Security Experience template, which manages the Windows Security user experience.
Question 81
You have a Microsoft 365 E5 subscription that contains a user named User1.
You create an anti-phishing policy named Policy1 that has the following settings:
• Include these users, groups and domains: User1
• Phishing email threshold: 3 - More Aggressive
User1 receives the email messages shown in the following table.
Which messages are phishing email?
A. Mail4 only
B. Mail3 and Mail4 only
C. Mail2, Mail3, and Mail4 only
D. Mail1, Mail2, Mail3, and Mail4
Show Answer
Correct Answer: C
Explanation: With the anti-phishing policy set to 'Phishing email threshold: 3 - More Aggressive', messages with Medium, High, or Very High phishing confidence are treated as phishing. Assuming Mail1=Low, Mail2=Medium, Mail3=High, and Mail4=Very High, the phishing messages are Mail2, Mail3, and Mail4.
Question 82
You have a Microsoft 365 E5 subscription.
You need to create a mail-enabled contact.
Which portal should you use?
A. the Microsoft Entra admin center
B. the Exchange admin center
C. the Intune admin center
D. the SharePoint admin center
Show Answer
Correct Answer: B
Explanation: Mail-enabled contacts are Exchange recipient objects and are created and managed in the Exchange admin center (EAC). While the Microsoft 365 admin center also offers contact management in some scenarios, among the given options the correct portal is the Exchange admin center.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.