You have a Microsoft 365 E5 subscription that contains a user named User1.
You create an anti-phishing policy named Policy1 that has the following settings:
• Include these users, groups and domains: User1
• Phishing email threshold: 3 - More Aggressive
User1 receives the email messages shown in the following table.
Which messages are phishing email?
A. Mail4 only
B. Mail3 and Mail4 only
C. Mail2, Mail3, and Mail4 only
D. Mail1, Mail2, Mail3, and Mail4
Show Answer
Correct Answer: C
Explanation: With the phishing email threshold set to **3 – More Aggressive**, Microsoft Defender treats messages with **Medium, High, or Very High** phishing confidence as phishing. Therefore, emails assessed as Medium (Mail2), High (Mail3), and Very High (Mail4) are classified as phishing, while Low (Mail1) is not.
Question 69
You have a Microsoft 365 E5 subscription.
You need to create a mail-enabled contact.
Which portal should you use?
A. the Microsoft Entra admin center
B. the Exchange admin center
C. the Intune admin center
D. the SharePoint admin center
Show Answer
Correct Answer: B
Explanation: Mail-enabled contacts are Exchange objects used for mail flow and address book purposes. In Microsoft 365, they are created and managed in the Exchange admin center, not in Entra ID, Intune, or SharePoint admin portals.
Question 70
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware.
Solution: You create an anti-malware policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: A balanced baseline protection profile in Microsoft Defender for Office 365 is implemented by using the built-in Standard protection preset (or Strict), which configures coordinated policies for spam, phishing, and malware. Creating only an anti-malware policy does not provide the balanced baseline across all threat types, so the solution does not meet the goal.
Question 71
You have a Microsoft 365 E5 subscription.
You plan to implement a data loss prevention (DLP) strategy by using Microsoft Purview.
You need to recommend a classification method for a DLP condition. The classification method must automatically recognize document types based on existing documents in Microsoft SharePoint Online.
What should you recommend?
A. sensitive information types (SITs)
B. sensitivity labels
C. trainable classifiers
D. exact data match (EDM) classifiers
Show Answer
Correct Answer: C
Explanation: Trainable classifiers in Microsoft Purview automatically learn from existing documents (such as those stored in SharePoint Online) to recognize and classify document types based on content patterns, making them ideal for DLP conditions that require automatic document type recognition.
Question 72
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware.
Solution: You create a Strict preset security policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: The goal is to apply a balanced baseline protection profile. In Microsoft Defender for Office 365 preset security policies, the Standard preset provides a balanced baseline suitable for most users. The Strict preset is more aggressive and intended for high-value or high-risk users. Therefore, creating a Strict preset security policy does not meet the stated goal.
Question 73
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You need to create a file policy named Policy1 that meets the following requirements:
• Inspects files in connected software as a service (SaaS) apps
• Inspects protected files
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Files
Microsoft Information Protection
Explanation: Files enables inspection of files stored in connected SaaS applications. Microsoft Information Protection enables inspection of protected (labeled/encrypted) files.
Question 74
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You plan to create a Conditional Access policy named Policy1.
You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal. Azure PowerShell, or Azure Command-Line Interface (CLI).
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Access controls:
Set Grant to Require authentication strength.
Target resources:
Windows Azure Service Management API.
Explanation: To enforce passwordless-only methods, Conditional Access must use **Require authentication strength** so the Passwordless MFA strength can be selected. Azure portal, Azure PowerShell, and Azure CLI are covered by the **Windows Azure Service Management API** resource.
Question 75
HOTSPOT
-
You have a hybrid deployment of Microsoft Entra that contains the users shown in the following table.
You need to identify which users can perform the following tasks:
• View sync errors in Microsoft Entra Connect Health.
• Configure Microsoft Entra Connect Health settings.
Which user should you identify for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: View sync errors in Microsoft Entra Connect Health:
User2
Configure Microsoft Entra Connect Health settings:
User1
Explanation: • A Contributor for Microsoft Entra Connect Health can view health reports and sync errors.
• The Microsoft Entra Connect sync account is used to configure and manage Microsoft Entra Connect Health settings during setup and operation.
Question 76
You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1.
You enable Microsoft Entra ID Protection.
You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Security Reader
B. Reports Reader
C. Compliance Administrator
D. Owner
Show Answer
Correct Answer: A
Explanation: Reviewing users flagged for risk in Microsoft Entra ID Protection requires read access to security data. The Security Reader role can view Identity Protection risky users and reports without making changes, which satisfies the principle of least privilege. The other roles either lack Identity Protection access or are overly privileged.
Question 77
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User objects:
User2 only
Microsoft 365 groups:
User1, User2, and User3
Explanation: Only the User Administrator role can create user objects. Groups Administrator, User Administrator, and Teams Administrator roles all have permissions to create and manage Microsoft 365 groups.
$19
Get all 417 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.