What is a function of Conditional Access session controls?
A. enforcing device compliance
B. enforcing client app compliance
C. enable limited experiences, such as blocking download of sensitive information
D. prompting multi-factor authentication (MFA)
Show Answer
Correct Answer: C
Explanation: Conditional Access session controls are used after authentication to govern what users can do during an active session, such as restricting downloads or providing limited access within cloud apps. Device compliance, client app compliance, and MFA are Conditional Access policy conditions or grant controls rather than session controls.
Question 104
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Authorization determines what level of access a user has to a resource. Authentication verifies a user's identity. Permissions such as reading and writing files are part of authorization, not authentication.
Question 105
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: authentication
Explanation: Signing in involves verifying a user's credentials to prove identity, which is authentication. Authorization determines what an authenticated user can access.
Question 106
What can be created in Active Directory Domain Services (AD DS)?
A. line-of-business (LOB) applications that require modern authentication
B. computer accounts
C. software as a service (SaaS) applications that require modern authentication
D. mobile devices
Show Answer
Correct Answer: B
Explanation: Active Directory Domain Services (AD DS) stores and manages directory objects such as users, groups, and computer accounts. Modern authentication application registrations (LOB or SaaS apps) and mobile device objects are associated with Microsoft Entra ID rather than AD DS.
Question 107
DRAG DROP
-
Match the types of compliance score actions to the appropriate tasks.
To answer, drag the appropriate action type from the column on the left to its task on the right. Each type may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Show Answer
Correct Answer: Use encryption to protect data at rest. → Preventative
Actively monitor systems to identify irregularities that might represent risks. → Detective
Explanation: Preventative actions reduce the likelihood of incidents (for example, encryption). Detective actions identify potential issues through monitoring.
Question 108
Which pillar of identity relates to tracking the resources accessed by a user?
A. authorization
B. auditing
C. administration
D. authentication
Show Answer
Correct Answer: B
Explanation: Auditing is the identity pillar concerned with tracking and logging user activity, including which resources a user accesses. Authorization determines what a user is allowed to access, authentication verifies identity, and administration manages identity systems.
Question 109
DRAG DROP
-
Match the pillars of Zero Trust to the appropriate requirements.
To answer, drag the appropriate pillar from the column on the left to its requirement on the right. Each pillar may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Show Answer
Correct Answer: Networks → Must be segmented
Identities → Must be verified by using strong authentication
Data → Must be classified, labeled, and encrypted based on its attributes
Explanation: In the Zero Trust model, networks are segmented to limit lateral movement, identities are continuously verified with strong authentication, and data is protected through classification, labeling, and encryption.
Question 110
Which compliance feature should you use to identify documents that are employee resumes?
A. pre-trained classifiers
B. Activity explorer
C. eDiscovery
D. Content explorer
Show Answer
Correct Answer: A
Explanation: Pre-trained classifiers in Microsoft Purview are designed to automatically identify specific document categories, including employee resumes. Activity explorer monitors user activities, eDiscovery is for legal discovery, and Content explorer displays classified content but is not the feature used to identify resumes.
Question 111
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
Yes
Yes
Explanation: Microsoft Sentinel supports many third-party and Microsoft data connectors, Azure Monitor workbooks can visualize Sentinel data, and hunting enables proactive threat identification before alerts are triggered.
Question 112
What are three uses of Microsoft Cloud App Security? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. to discover and control the use of shadow IT
B. to provide secure connections to Azure virtual machines
C. to protect sensitive information hosted anywhere in the cloud
D. to provide pass-through authentication to on-premises applications
E. to prevent data leaks to noncompliant apps and limit access to regulated data
Show Answer
Correct Answer: A, C, E
Explanation: Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) is used to discover and manage shadow IT, protect sensitive information across cloud services through visibility and governance, and enforce policies that prevent data leakage and restrict access to regulated data. It does not provide secure VM connections (Azure Bastion does that) or pass-through authentication for on-premises applications (handled by Microsoft Entra ID features).
$19
Get all 230 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.