A company is evaluating Microsoft 365.
You need to identify concepts of using the principle of least privilege.
Which two concepts should you identify? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Just-in-time access
B. Just-enough-access
C. Azure AD multifactor authentication
D. Blocking legacy authentication
Show Answer
Correct Answer: A, B
Explanation: The principle of least privilege focuses on granting only the minimum permissions required, only when they are needed.
Just-in-time (JIT) access limits privileged access to a short, approved time window, reducing the risk of standing administrative privileges.
Just-enough-access (JEA) ensures users receive only the specific permissions necessary to perform a task, and nothing more.
Multifactor authentication and blocking legacy authentication improve security posture but are not concepts that directly define or implement least-privilege access.
Question 97
HOTSPOT
-
A company is evaluating Microsoft 365.
You need to determine the correct component to secure.
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: endpoints
Explanation: Corporate phones and computers used by workers are endpoint devices, which are secured as endpoints in Microsoft 365.
Question 98
HOTSPOT
-
Instructions: For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
Yes
Explanation: Microsoft Cloud App Security (Defender for Cloud Apps) by itself does not directly block applications; blocking requires integration with tools like Microsoft Defender for Endpoint or Intune.
It includes DLP, information protection, and governance controls that help prevent confidential data from leaking outside the organization.
Microsoft handles legal requests (such as law enforcement or regulatory requests) for customer data stored within Microsoft cloud services, including data governed by Cloud App Security.
Question 99
You need to identify which license to use for BitLocker.
Which license should you identify?
A. Office 365 E3
B. Microsoft 365 E3
C. Windows 365 Standard
D. Microsoft Dynamics 365 Sales Professional
Show Answer
Correct Answer: B
Explanation: BitLocker is a Windows Enterprise feature. Among the options, only Microsoft 365 E3 includes the Windows Enterprise license, which provides BitLocker. Office 365 E3 includes only Office apps, Windows 365 Standard is a Cloud PC service, and Dynamics 365 Sales Professional is unrelated to Windows device security.
Question 100
DRAG DROP -
A company uses Microsoft 365. The company provisions employee user accounts in Active Directory and synchronizes the accounts to Azure Active Directory (Azure AD). The company provisions contractor user accounts in Azure AD.
The company has the following business requirements:
• Employees in the sales department and contractors must be enabled for self-service password reset (SSPR).
• Employees in management must be enabled for conditional access policies.
The company requires a solution that has the least cost.
You need to implement the appropriate Azure AD edition for the users.
What should you use? To answer, drag the appropriate Azure AD editions to the correct users. Each Azure AD edition may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct match is worth one point.
Show Answer
Correct Answer: Sales employees: Azure AD Premium P1
Management employees: Azure AD Premium P1
Contractors: Azure AD Free
Explanation: Sales employees are hybrid users and require SSPR with password writeback, which needs Azure AD Premium P1. Conditional Access for management also requires at least Azure AD Premium P1. Contractors are cloud-only users, and self-service password reset is supported with Azure AD Free, meeting the least-cost requirement.
Question 101
HOTSPOT -
A company is evaluating Microsoft 365.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: 1) No
2) Yes
3) Yes
Explanation: Microsoft Defender for Endpoint is a security/EDR platform, not an application deployment tool.
Microsoft 365 Apps can be deployed from a local network share using tools like the Office Deployment Tool.
Microsoft Endpoint Configuration Manager supports deploying Microsoft 365 Apps.
Question 103
HOTSPOT -
Instructions: For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: Defender for Cloud Apps integrates with Microsoft security services: it leverages the Intelligent Security Graph (now Microsoft 365 Defender signals) for identity-related alerts, contributes to Secure Score by reporting security controls and posture, and integrates with Power BI to generate alerts and enable response workflows tied to suspicious activity.
Question 104
HOTSPOT
-
A company is investigating Microsoft 365.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: • Microsoft To Do integrates with Outlook on desktop (tasks and flagged emails sync).
• Microsoft To Do has official mobile apps for iOS and Android.
• Microsoft Lists is a separate service; To Do tasks are not viewable from the Lists website.
Question 105
HOTSPOT
-
A company is investigating Microsoft 365.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Planner is available as an app within Microsoft Teams. Planner tasks can sync to Outlook (e.g., via Tasks/To Do and calendar views). FindTime integrates with Outlook for scheduling, not directly with Microsoft Planner.
Question 106
A company is evaluating Microsoft 365.
You need to determine the principles of Zero Trust.
Which two principles should you identify? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Identify potential change
B. Assume breach
C. Verify explicitly
D. Implement change
Show Answer
Correct Answer: B, C
Explanation: Microsoft Zero Trust is based on core principles that include verifying explicitly every access request and assuming breach at all times. Options B (Assume breach) and C (Verify explicitly) align directly with Microsoft's Zero Trust framework, whereas the other options are not recognized Zero Trust principles.
$19
Get all 441 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.