Which two cards are available in the Microsoft 365 Defender portal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Devices at risk
B. Compliance Score
C. Service Health
D. User Management
E. Users at risk
Show Answer
Correct Answer: A, E
Explanation: The Microsoft 365 Defender portal Home page includes cards that summarize security posture and active threats. Among the listed options, **Devices at risk** and **Users at risk** are standard cards shown to highlight affected endpoints and user accounts. Compliance Score, Service Health, and User Management are accessed in other portals or sections, not as Defender Home cards.
Question 115
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: incidents
Explanation: In Microsoft 365 Defender, alerts are grouped into incidents, which show the impacted entities such as affected devices, allowing identification of devices related to an alert.
Question 116
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
Yes
No
Explanation: • Windows Hello for Business does not use the Microsoft Authenticator app; it uses device-bound credentials.
• A PIN is a supported authentication method in Windows Hello for Business.
• Windows Hello for Business credentials are device-specific and do not sync across a user’s devices.
Question 117
In a hybrid identity model, what can you use to sync identities between Active Directory Domain Services (AD DS) and Azure Active Directory (Azure AD)?
A. Active Directory Federation Services (AD FS)
B. Microsoft Sentinel
C. Azure AD Connect
D. Azure AD Privileged Identity Management (PIM)
Show Answer
Correct Answer: C
Explanation: In a hybrid identity model, Azure AD Connect (now called Microsoft Entra Connect) is the tool designed to synchronize identities between on-premises Active Directory Domain Services (AD DS) and Azure Active Directory. AD FS provides federation, Sentinel is a SIEM, and PIM manages privileged access, not identity synchronization.
Question 118
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
No
Yes
Explanation: NSG rules require unique names within an NSG. Default NSG rules are built-in and cannot be deleted, only overridden by higher-priority rules. NSG rules support protocol filtering for TCP, UDP, and ICMP.
Question 119
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: Identity Protection creates risk detections during sign-in after authentication context is established. Each risk event is classified with a risk level (Low, Medium, or High). User risk reflects the likelihood that an identity or account has been compromised based on aggregated risk signals.
Question 120
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: playbooks.
Explanation: In Microsoft Sentinel, playbooks automate common tasks and incident responses using workflows (Azure Logic Apps).
Question 121
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: playbooks
Explanation: In Microsoft Sentinel, playbooks use Azure Logic Apps to automate and orchestrate responses to alerts and incidents.
Question 122
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: A security information and event management (SIEM)
Explanation: A SIEM collects and analyzes data from multiple systems, correlates events to detect anomalies, and generates alerts and incidents.
Question 123
You need to keep a copy of all files in a Microsoft SharePoint site for one year, even if users delete the files from the site.
What should you apply to the site?
A. a retention policy
B. an insider risk policy
C. a data loss prevention (DLP) policy
D. a sensitivity label policy
Show Answer
Correct Answer: A
Explanation: A retention policy in Microsoft Purview can be applied to a SharePoint site to retain copies of files for a specified period. Even if users delete files, the content is preserved in the preservation hold library for the duration (one year), meeting the requirement. Insider risk, DLP, and sensitivity labels do not retain deleted content.
$19
Get all 224 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.