You are configuring custom domain verification for a new secondary domain, hr-contoso.com, in your Microsoft 365 tenant. The production web services for this domain are active on third-party servers. Which DNS record should you add at the registrar to verify domain ownership without interrupting web or existing mail traffic?
- A TXT record containing the MS=ms verification code (Correct)
- An MX record pointing directly to mail.protection.outlook.com
- A CNAME record for autodiscover.contoso.com
- An SRV record for SIP federation
Explanation: Adding a TXT record with the MS=ms verification string verifies ownership directly without altering IP routing, MX priorities, or existing web traffic.
You need to assign an administrative role to a helpdesk engineer who only needs to reset passwords for standard users and monitor Microsoft 365 service health. Following the principle of least privilege, which role should you assign?
- Helpdesk Administrator (Correct)
- Global Administrator
- User Administrator
- Security Administrator
Explanation: The Helpdesk Administrator role allows resetting passwords for non-administrators and monitoring service health without granting global directory permissions.
Your organization is enabling Microsoft 365 Backup for high-speed recovery against ransomware. Which workloads can be natively backed up using the Microsoft 365 Backup service in the admin center?
- SharePoint Online, OneDrive, and Exchange Online (Correct)
- Azure SQL databases and on-premises Hyper-V hosts
- Endpoint physical hard drives and BIOS firmware
- Third-party Salesforce databases only
Explanation: Microsoft 365 Backup natively protects SharePoint Online document libraries, OneDrive user accounts, and Exchange Online mailboxes within the tenant boundary.
You need to automate the assignment of Microsoft 365 E5 and Copilot licenses to all employees whose Active Directory department attribute is "Finance". Which mechanism should you implement?
- Group-based licensing assigned to a dynamic user security group (Correct)
- Manually assigning licenses to each user via CSV import daily
- Exchange mail flow transport rules
- Defender for Endpoint automated remediation scripts
Explanation: Group-based licensing combined with dynamic user membership groups automatically provisions and deprovisions licenses based on Entra ID user attributes.
You are configuring tenant-wide release preferences to allow the IT pilot group to test new Microsoft 365 features early, while all other employees remain on standard general releases. What should you configure in the Microsoft 365 admin center?
- Targeted release for selected users under Release preferences (Correct)
- Semi-Annual Enterprise Channel via GPO
- Security Defaults toggle in Entra ID
- Disabling Exchange Online transport rules
Explanation: Under Settings > Org settings > Organization profile > Release preferences, administrators can configure "Targeted release for selected users" and assign the pilot group.
An administrator needs to deploy Microsoft 365 Apps with monthly feature updates rolled out on Patch Tuesday. Which update channel must be selected in the Office Deployment Tool configuration?
- Monthly Enterprise Channel (Correct)
- Beta Channel
- Semi-Annual Enterprise Channel
- Current Channel (Preview)
Explanation: Monthly Enterprise Channel delivers feature updates on a predictable schedule once a month on the second Tuesday (Patch Tuesday), balancing features with stability.
You must configure external email routing so that unresolved recipient addresses for fabrikam.com are forwarded back to an on-premises mail server rather than producing an immediate NDR. How should the domain be configured in Exchange Online?
- Internal Relay (Correct)
- Authoritative
- External Relay
- Client Access Proxy
Explanation: An Internal Relay accepted domain forwards messages for unresolvable cloud recipients to an on-premises mail system via outbound connectors instead of bouncing them.
You are auditing tenant admin roles. You want to see all users who have an active or eligible Global Administrator assignment. Which portal section provides this direct consolidation?
- Microsoft 365 admin center under Roles > Role assignments (Correct)
- Exchange Admin Center under Mail flow
- SharePoint site collection settings
- Microsoft Endpoint Manager under Devices
Explanation: In the Microsoft 365 admin center, Roles > Role assignments provides a centralized list of both active assignees and Privileged Identity Management (PIM) eligible roles.
A remote branch office has low bandwidth. When users receive Microsoft 365 Apps Click-to-Run updates, you want devices to share downloaded chunks locally across peer devices on the same subnet. What technology should you enable?
- Delivery Optimization (DO) (Correct)
- BranchCache in hosted mode only
- DirectAccess network tunnels
- Network Load Balancing (NLB) clusters
Explanation: Delivery Optimization (DO) uses peer-to-peer cloud-managed caching to distribute Office and Windows update binaries across local network peers.
You want to receive instant email notifications whenever an Exchange Online or Teams service advisory or major incident is opened by Microsoft. Where do you configure this notification destination?
- Health > Service health > Preferences > Email in the admin center (Correct)
- Exchange message trace queries
- Windows Event Viewer alerts
- Azure Cost Management budgeting notifications
Explanation: In the Microsoft 365 admin center under Health > Service health > Preferences > Email, admins can enter up to two dedicated alert email addresses.
You are creating an Administrative Unit (AU) for the Dallas regional office. What objects can be placed inside an Administrative Unit in Microsoft Entra ID?
- Users, groups, and devices (Correct)
- Azure subscriptions and resource groups only
- On-premises domain controller objects only
- Exchange transport rules only
Explanation: Administrative Units in Microsoft Entra ID support users, groups, and devices as members, allowing delegated administrative scopes over those exact assets.
You need to run a diagnostic on an executive mailbox that cannot send outbound emails. Which self-service capability inside the Microsoft 365 admin center provides instant automated tests?
- Integrated "Need Help?" diagnostics in the admin center (Correct)
- Manual ping tests to 127.0.0.1
- Third-party port scanner utility
- Reviewing local client registry hives
Explanation: The "Need Help?" self-service support pane in the Microsoft 365 admin center executes automated backend diagnostics when queried with shortcut diagnostic strings.
Your organization plans to customize the Microsoft 365 web sign-in page with a corporate background, banner logo, and sign-in hints. Where is this branding configured?
- Microsoft Entra admin center under Company branding (Correct)
- SharePoint Modern Team site themes
- Exchange ActiveSync mobile policies
- Microsoft Defender for Endpoint portal settings
Explanation: Microsoft Entra admin center under Identity > User experiences > Company branding enables custom background imagery, logos, and custom sign-in text.
You need to delegate authority to manage Microsoft Teams app permission policies without granting full Teams Administrator permissions. Which role should you assign?
- Teams Administrator (Correct)
- Compliance Manager Reader
- Exchange Recipient Administrator
- Directory Writers
Explanation: Teams Communications Administrator or scoped Application Administrator roles delegate app management, but Teams Administrator manages full workload configurations.
You need to verify the geographic region where your tenant's Exchange mailboxes and SharePoint documents are stored at rest. Where can you confirm this in the admin center?
- Settings > Org settings > Organization profile > Data location (Correct)
- Compliance > Audit log export
- Billing > Invoices history
- Azure Monitor metric charts
Explanation: In the Microsoft 365 admin center under Settings > Org settings > Organization profile > Data location, administrators can view customer data residency.
What is the primary function of Microsoft Entra Connect Health when deployed in a hybrid environment?
- Monitoring synchronization health, latency, and operational alerts (Correct)
- Encrypting local domain controller hard drives
- Blocking outbound internet traffic on client workstations
- Assigning Office licenses automatically via GPO
Explanation: Entra Connect Health monitors the health, synchronization performance, latency, and operational alerts of on-premises AD FS, AD DS, and sync engines.
You need to connect to Microsoft Graph via PowerShell to automate user licensing without storing hardcoded credentials. Which authentication method should you configure for an automated background runbook?
- Managed identity or certificate-based service principal authentication (Correct)
- Storing cleartext Global Admin credentials in a script file
- Interactive web login with SMS codes for background jobs
- Basic Authentication with NTLM
Explanation: A managed identity or certificate-based service principal authentication in Microsoft Graph PowerShell allows secure non-interactive administration without client secrets.
You are configuring external sharing for OneDrive. Your security policy dictates that files can be shared with existing external guests only, not anonymous links. Which sharing level must you set?
- Existing guests (Correct)
- Anyone links
- Public web access
- Anonymous dropboxes
Explanation: Setting the external sharing level to "Existing guests" prevents creating new guest invitations and disables "Anyone" links, allowing sharing only with verified directory guests.
What DNS record must you publish to authenticate outbound emails originating from Microsoft 365 on behalf of your custom domain?
- v=spf1 include:spf.protection.outlook.com -all (Correct)
- v=dmarc1 p=reject
- cname=smtp.office365.com
- srv=_sip._tls.contoso.com
Explanation: A Sender Policy Framework (SPF) TXT record specifying "v=spf1 include:spf.protection.outlook.com -all" designates Microsoft 365 as an authorized outbound mail source.
An administrator needs to create a shared mailbox for incoming sales inquiries. What license assignment is required for a shared mailbox with less than 50 GB of storage?
- No license is required if under 50 GB storage and without hold (Correct)
- Requires a standalone Microsoft 365 E5 license
- Requires an Entra ID P2 license
- Requires an Intune Suite license
Explanation: Shared mailboxes under 50 GB do not require an active standalone license provided they do not have an archive mailbox or litigation hold enabled.
You need to delegate permissions so that an auditor can view billing reports, invoice histories, and license quantities without being able to modify subscriptions. Which role is best?
- Global Reader (Correct)
- Global Administrator
- Security Operator
- Billing Administrator with write access
Explanation: The Global Reader role provides read-only visibility into tenant configuration and billing information without allowing any administrative edits.
You are configuring Microsoft 365 Apps deployment. Which tool is used to generate the XML configuration file visually using a web interface?
- Office Customization Tool (config.office.com) (Correct)
- Active Directory Users and Computers
- IIS Web Manager
- Windows PowerShell ISE default script
Explanation: The Office Customization Tool (config.office.com) provides a web-based wizard to generate XML configuration files consumed by Click-to-Run and ODT.
Where in the Microsoft 365 admin center can you verify the synchronization status and last sync time of Microsoft Entra Connect?
- Settings > Directory sync status in the Microsoft 365 admin center (Correct)
- Billing > Invoices blade
- Security > Secure Score actions
- Intune device compliance blade
Explanation: On the Microsoft 365 admin center Home page dashboard or under Settings > Directory sync status, admins can verify directory sync state.
You are deploying Microsoft Entra Connect. You want to enable dark-web leaked credential detection in Microsoft Entra Identity Protection while keeping directory infrastructure simple. Which synchronization method should you select?
- Password Hash Synchronization (PHS) (Correct)
- Active Directory Federation Services (AD FS) with federation farm
- Pass-through Authentication without PHS backup
- LDAP relay over unencrypted port 389
Explanation: Password Hash Synchronization (PHS) syncs password hashes to Microsoft Entra ID, enabling Identity Protection to match user hashes against known breached credentials.
You are creating a Conditional Access policy. You want to require Multi-Factor Authentication whenever a user signs in from outside corporate network boundaries. What must you configure as the condition?
- Named Locations defined by trusted IP ranges (Correct)
- Active Directory Sites and Services configuration
- DNS forward lookup zone files
- Local client subnet masks
Explanation: Named Locations defined by trusted IP address ranges allow Conditional Access policies to trigger MFA whenever sign-in traffic originates outside those ranges.
Your organization is experiencing MFA fatigue attacks where attackers repeatedly trigger MFA push notifications. Which Microsoft Authenticator feature blocks this by requiring users to enter digits displayed on the sign-in screen?
- Number Matching in Microsoft Authenticator (Correct)
- SMS one-time passcode fallback
- Automated voice calls to desk phones
- Disabling MFA tenant-wide
Explanation: Number Matching prompts the user to enter the specific two-digit number displayed on the sign-in portal into the Authenticator application before granting access.
You need to ensure that when a user's risk level reaches "High" in Microsoft Entra Identity Protection, the account is not locked out, but the user is forced to perform a secure self-service password reset using MFA. Which policy should you configure?
- User Risk Policy requiring MFA and password change (Correct)
- Sign-in Risk Policy blocking domain controllers
- Exchange anti-spam notification policy
- Intune remote wipe policy
Explanation: A User Risk Policy configured with a Grant control requiring MFA and a password reset allows compromised users to securely remediate their risk independently.
You are deploying Self-Service Password Reset (SSPR) for synchronized hybrid Active Directory users. Which feature must be enabled in Microsoft Entra Connect to ensure password changes apply on-premises immediately?
- Password Writeback in Microsoft Entra Connect (Correct)
- Kerberos Constrained Delegation
- AD FS Relying Party trust claims rules
- Azure ExpressRoute private peering
Explanation: Password Writeback securely synchronizes cloud-initiated password resets back to on-premises Active Directory in real time.
You configure Privileged Identity Management (PIM) for the Security Administrator role. What is the effect of making an admin "Eligible" rather than "Active"?
- The admin must manually activate the role via PIM when needed (Correct)
- The admin possesses permanent 24/7 Global Admin rights
- The admin cannot access the Azure portal under any circumstances
- The admin account is deleted automatically after 30 days
Explanation: An eligible admin does not hold the permissions permanently; they must explicitly activate the role via the PIM portal, undergo approvals or MFA, and access is time-limited.
You need to prevent unmanaged, personal mobile devices from downloading corporate attachments from Outlook Web Access (OWA) while still allowing web-based reading. Which Conditional Access control should you use?
- Conditional Access Session control: Use app-enforced restrictions (Correct)
- Disabling TLS 1.3 across the tenant
- Local Windows Firewall inbound port blocking
- Uninstalling the Edge browser from corporate laptops
Explanation: Conditional Access Session control using "Use app-enforced restrictions" or Defender for Cloud Apps session policies enforces read-only access and blocks downloads.
You want to automate quarterly reviews to verify that external B2B guests still have a valid business justification to access sensitive project teams. Which feature should you implement?
- Microsoft Entra Access Reviews (Correct)
- Microsoft Defender for Identity honeypots
- Microsoft Purview Information Barriers
- Exchange Online transport rules
Explanation: Microsoft Entra Access Reviews enables recurring certification reviews where resource owners or managers must reaffirm guest access or it will be revoked automatically.
You are configuring phishing-resistant Multi-Factor Authentication for tenant administrators. Which Authentication Strength option in Conditional Access should you select?
- Phishing-resistant MFA (FIDO2, Windows Hello, CBA) (Correct)
- SMS text verification codes
- Email one-time passcodes
- Security questions and answers
Explanation: The Phishing-resistant MFA authentication strength enforces FIDO2 security keys, Windows Hello for Business, or certificate-based authentication exclusively.
What is the primary operational benefit of Continuous Access Evaluation (CAE) in Microsoft Entra ID?
- Near real-time revocation of access tokens upon security events (Correct)
- Extending access token lifetime to 30 continuous days
- Bypassing MFA completely on untrusted guest personal devices
- Disabling conditional access evaluation during office hours
Explanation: Continuous Access Evaluation (CAE) revokes active user access tokens in near real time (within minutes) when critical events like password reset or account disablement occur.
You need to deploy Defender for Endpoint to 500 corporate Windows 11 devices enrolled in Microsoft Intune. What is the most efficient onboarding method?
- Enable the Defender for Endpoint connector in Intune and deploy an EDR policy (Correct)
- Manually run onboarding batch files on each machine via USB
- Emailing scripts to end users to run locally
- Reimaging all machines with Windows Server Datacenter
Explanation: Enabling the Defender for Endpoint connector in Intune and creating an Endpoint Detection and Response (EDR) policy automatically onboard managed endpoints.
Which Microsoft Defender for Office 365 feature detonates unknown email attachments inside a virtual sandbox to inspect behavioral activity before delivery?
- Safe Attachments (Correct)
- Connection Filtering IP allow list
- Outbound spam rules
- DMARC strict reject policy
Explanation: Safe Attachments opens unknown email attachments inside a hypervisor-isolated sandbox environment to analyze behavior for zero-day malware before message delivery.
You want to protect users against malicious URLs embedded in incoming emails and Teams messages by evaluating the link destination at the exact moment the user clicks it. What should you configure?
- Safe Links (Correct)
- Safe Attachments
- DKIM signing
- Customer Lockbox
Explanation: Safe Links provides time-of-click verification and URL rewriting for hyperlinks in email messages, Teams chats, and Office documents.
An attacker creates an external email address with the display name of your company's CEO to trick payroll into wiring funds. Which Defender for Office 365 policy detects this?
- Anti-phishing policies with User Impersonation Protection (Correct)
- Connection Filtering IP whitelist
- Safe Attachments dynamic delivery
- Transport encryption rules
Explanation: Anti-phishing policies with User Impersonation Protection flag messages where the sender display name matches protected high-profile executives.
You need to isolate a malware-infected Windows workstation from the local network while still allowing the security team to run remote commands via Microsoft Defender. Which action should you execute?
- Execute the "Isolate device" response action (Correct)
- Delete the device object from Microsoft Entra ID
- Disable the local network switch port physically
- Perform a BitLocker cryptographic hard drive erase
Explanation: The "Isolate device" action in Defender for Endpoint cuts off all IP connectivity except for communication with the Defender cloud management plane.
What is the function of Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint?
- Blocking typical malware behaviors and attack vectors on endpoints (Correct)
- Compressing local hard drive volume capacity
- Routing web browsing traffic through satellite relays
- Managing Exchange Online shared mailbox quotas
Explanation: ASR rules block typical malware attack vectors, such as Office apps creating child processes, credential stealing from LSASS, and malicious scripts launching executables.
You are configuring Attack Simulation Training in Defender for Office 365. What happens when an employee enters credentials into a simulated phishing landing page?
- The event is logged and targeted training modules are automatically assigned (Correct)
- The user account is permanently terminated in the company HR system
- The user computer is automatically reformatted
- All incoming emails to the user are blocked for 30 days
Explanation: Attack Simulation Training flags the user attempt, logs simulation telemetry, and can automatically assign interactive micro-training modules to the employee.
Which component of Microsoft Defender for Identity is deployed directly onto on-premises Domain Controllers to parse network traffic and Windows event logs?
- The Microsoft Defender for Identity sensor (Correct)
- Apache HTTP proxy service
- Exchange Edge Transport agent
- Windows Media Player network sharing service
Explanation: The Defender for Identity sensor installs directly onto domain controllers to monitor authentication traffic and event logs without requiring port mirroring.
In Microsoft Defender for Identity, what is the purpose of configuring "Honeypot" user accounts?
- To detect unauthorized reconnaissance and lateral movement using decoys (Correct)
- To store user passwords in clear text for fast recovery
- To reduce the physical storage size of the NTDS.dit database
- To bypass MFA for executive staff
Explanation: Honeypots are decoy accounts with no business purpose; any authentication attempt or LDAP enumeration against them triggers high-confidence lateral movement alerts.
You are using Advanced Hunting in the Microsoft Defender XDR portal to search raw endpoint event logs for suspicious PowerShell activity. What query language is used?
- Kusto Query Language (KQL) (Correct)
- Transact-SQL (T-SQL)
- GraphQL syntax
- Python scripting only
Explanation: Advanced Hunting queries telemetry data across endpoints, email, and identity using Kusto Query Language (KQL).
You want to prevent local administrators or malicious scripts on Windows 11 machines from turning off Defender real-time antivirus protection. Which feature must be enabled?
- Tamper Protection (Correct)
- Storage Spaces Direct
- DirectAccess wizard
- BitLocker Network Unlock
Explanation: Tamper Protection locks Microsoft Defender Antivirus settings in place and prevents local admins or malware from disabling protection via registry or PowerShell.
Where in the Defender portal can you configure custom Indicators of Compromise (IoCs) to block malicious SHA256 file hashes across all endpoints?
- Settings > Endpoints > Indicators in the Microsoft Defender portal (Correct)
- Active Directory Users and Computers schema
- Exchange admin center mail trace
- Public DNS registrar control panel
Explanation: In the Microsoft Defender portal under Settings > Endpoints > Indicators, administrators can add custom file hashes, IP addresses, and URLs with a Block action.
You need to assess cloud applications accessed by corporate laptop users without routing traffic through a physical corporate proxy. How can Defender for Cloud Apps discover this Shadow IT?
- Integrating Defender for Cloud Apps with Defender for Endpoint (Correct)
- Deploying hardware proxy appliances to every remote home
- Disabling internet access on all remote laptops
- Enabling POP3 mail access protocols
Explanation: By integrating Defender for Cloud Apps with Microsoft Defender for Endpoint, endpoints natively report cloud app connection telemetry directly into Cloud Discovery.
You need to create a Data Loss Prevention (DLP) policy that alerts users when they attempt to share documents containing credit card numbers externally via Teams chat. Which component shows the user an interactive prompt?
- DLP Policy Tips (Correct)
- Exchange transport disclaimer footer
- Windows notification balloon for battery state
- Safe Attachments scan alert
Explanation: DLP Policy Tips display informative banners directly in Teams or Office apps informing users that the content matches corporate compliance policies.
Your organization requires financial records stored in SharePoint to be retained for 7 years, after which they must be deleted automatically. What Purview feature implements this?
- Microsoft Purview Retention Policies (Correct)
- Windows Volume Shadow Copies
- Storage Replica failover
- Manual monthly tape archiving
Explanation: Microsoft Purview Retention Policies applied to SharePoint retain content for the specified duration and automatically delete it once the retention timeframe lapses.
You need to encrypt sensitive legal contracts so that external partners can view and edit them, but cannot copy text or print the document. What technology should you configure?
- Sensitivity labels with custom usage rights encryption (Correct)
- Password-protected zip archive wrappers
- Local NTFS file security permissions
- BitLocker drive encryption
Explanation: Sensitivity labels configured with Azure Information Protection encryption assign custom usage rights (restricting print, copy, and export) to specific recipients.
You want to prevent employees from copying sensitive data containing social security numbers to unauthorized USB flash drives on corporate laptops. Which feature should you deploy?
- Microsoft Purview Endpoint DLP (Correct)
- Disabling USB controllers in computer BIOS
- Exchange transport rules
- Defender for Identity sensor rules
Explanation: Microsoft Purview Endpoint DLP monitors endpoint activities and can audit or block copying sensitive files to removable storage media.