Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware.
Solution: You create an anti-malware policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: A balanced baseline protection profile in Microsoft Defender for Office 365 is implemented using the Standard protection preset security policy, which provides balanced protection across spam, phishing, and malware. Creating only an anti-malware policy addresses malware but does not provide the full balanced baseline profile.
Question 84
You have a Microsoft 365 E5 subscription.
You plan to implement a data loss prevention (DLP) strategy by using Microsoft Purview.
You need to recommend a classification method for a DLP condition. The classification method must automatically recognize document types based on existing documents in Microsoft SharePoint Online.
What should you recommend?
A. sensitive information types (SITs)
B. sensitivity labels
C. trainable classifiers
D. exact data match (EDM) classifiers
Show Answer
Correct Answer: C
Explanation: Trainable classifiers are designed to automatically recognize and classify document types by learning from examples of existing content, including documents stored in SharePoint Online. They are appropriate for DLP conditions that need to identify document categories based on learned patterns rather than predefined sensitive data types. Sensitive information types detect specific data patterns (such as credit card numbers), sensitivity labels classify/protect content but do not learn document types, and exact data match compares against hashed structured datasets rather than recognizing document types.
Question 85
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware.
Solution: You create a Strict preset security policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: The goal is to apply a balanced baseline protection profile against spam, phishing, and malware. In Microsoft Defender for Office 365, the Standard preset security policy provides the baseline profile suitable for most users, while the Strict preset security policy applies more aggressive protections intended for high-value or higher-risk users. Therefore, creating a Strict preset security policy does not meet the stated goal of a balanced baseline profile.
Question 86
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You need to create a file policy named Policy1 that meets the following requirements:
• Inspects files in connected software as a service (SaaS) apps
• Inspects protected files
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Information Protection: Microsoft Information Protection
Conditional Access App Control: Files
Explanation: To inspect files in connected SaaS apps, enable Files settings for file monitoring. To inspect protected (encrypted/labeled) files, enable Microsoft Information Protection integration and the Inspect protected files option.
Question 87
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You plan to create a Conditional Access policy named Policy1.
You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal. Azure PowerShell, or Azure Command-Line Interface (CLI).
How should you configure Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Access controls: Set Grant to Require authentication strength.
Target resources: Windows Azure Service Management API.
Explanation: To enforce only Passwordless MFA, Conditional Access must use the 'Require authentication strength' grant control and select the built-in Passwordless MFA strength. The Azure portal, Azure PowerShell, and Azure CLI are covered by the Windows Azure Service Management API target resource.
Question 88
HOTSPOT
-
You have a hybrid deployment of Microsoft Entra that contains the users shown in the following table.
You need to identify which users can perform the following tasks:
• View sync errors in Microsoft Entra Connect Health.
• Configure Microsoft Entra Connect Health settings.
Which user should you identify for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: View sync errors: User2
Configure Microsoft Entra Connect Health settings: User2
Explanation: The Microsoft Entra Connect Health Contributor role can view sync errors and manage Microsoft Entra Connect Health settings. The sync account is not an administrative role, and Application Administrator does not grant Connect Health administration permissions.
Question 89
You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1.
You enable Microsoft Entra ID Protection.
You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege.
To which role should you add User1?
A. Security Reader
B. Reports Reader
C. Compliance Administrator
D. Owner
Show Answer
Correct Answer: A
Explanation: The Security Reader role has read-only access to security-related information, including Microsoft Entra ID Protection risk data such as risky users. Reports Reader can view some reports but does not provide the appropriate access to Identity Protection risk data. Compliance Administrator and Owner grant unnecessary permissions, violating least privilege.
Question 90
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User objects: User2 only
Microsoft 365 groups: User1, User2, and User3
Explanation: User Administrator can create user objects and manage/create groups. Groups Administrator can create/manage Microsoft 365 groups but not users. Teams Administrator also has permission to create/manage Microsoft 365 groups, but not user objects.
Question 91
DRAG DROP
-
You have a Microsoft 365 E5 subscription that contains two security groups named Group1 and Group2.
You need to recommend an authentication solution that meets the following requirements:
• Members of Group1 must be able to authenticate by using a hardware token.
• Members of Group2 must be able to authenticate by using a public key infrastructure (PKI).
Which authentication method should you recommend for each group? To answer, drag the appropriate methods to the correct groups. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Explanation: Hardware token authentication is provided by FIDO2 security keys. PKI-based authentication in Microsoft Entra ID uses certificate-based authentication (CBA), which relies on X.509 certificates.
Question 92
You have a Microsoft 365 E5 subscription.
You plan to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra.
You need to ensure that a user can make a role assignment request for the User Administrator role only during the next six months.
How should you configure the assignment?
A. Set Assignment type to Eligible.
B. Set Assignment type to Active.
C. Set Allow permanent active to assignment Yes.
D. Set Allow permanent eligible assignment to Yes.
Show Answer
Correct Answer: A
Explanation: Use an Eligible assignment. Eligible assignments require the user to request/activate the role through PIM. By configuring the assignment with a defined start/end period (the next six months), the user can make role activation requests only during that window. Active assignments are already assigned and do not require requests, while permanent active/eligible settings remove the time limit rather than restricting it to six months.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.