Your organization is preparing a corporate network for Microsoft Teams media traffic. You need to ensure real-time audio, video, and screen sharing receive prioritized routing across network routers. Which mechanism should you configure?
- Configure Quality of Service (QoS) with DSCP markings on network endpoints (Correct)
- Disable IPv6 on all corporate network switches
- Route all Teams traffic through an on-premises VPN concentrator
- Configure static NAT port forwards on port 80
Explanation: Quality of Service (QoS) uses Differentiated Services Code Point (DSCP) markings on IP packet headers (such as DSCP 46 for audio and DSCP 34 for video) to enable routers and switches to prioritize real-time delay-sensitive traffic over standard bulk data traffic.
In the Microsoft Teams admin center, what is the primary purpose of defining Network Topology by mapping physical subnets to network sites and regions?
- Enabling Location-Based Routing, Emergency Calling, and Call Admission Control (Correct)
- Assigning Microsoft 365 E5 licenses automatically
- Setting Outlook email forwarding rules
- Backing up user desktop wallpaper files
Explanation: Defining network topology maps physical subnets to specific geographic network sites. This enables advanced capabilities like Location-Based Routing (LBR), Network-based Location services, and Call Admission Control (CAC).
You are configuring External Access in Microsoft Teams. You want employees to be able to communicate with federated users at contoso.com, but block communications with all other external Teams organizations. Which setting should you apply?
- Set external access to "Allow only specific external domains" and add contoso.com (Correct)
- Block TCP port 5061 on the external firewall
- Delete all external guest users from Microsoft Entra ID
- Disable federation in Skype for Business Server hybrid config
Explanation: Under Users > External access in the Teams admin center, you can set the domain access configuration to "Allow only specific external domains" and explicitly add contoso.com to the allow list.
What is the key architectural difference between External Access (Federation) and Guest Access in Microsoft Teams?
- External access allows federated chat without directory accounts; Guest access uses Entra B2B identities (Correct)
- External access provides full access to internal SharePoint files
- Guest access cannot be used to invite external email addresses
- There is no difference between the two configurations
Explanation: External access (federation) allows users to chat, call, and find users in other domains without those external users joining the tenant. Guest access provisions a B2B guest account in Microsoft Entra ID, giving the external user membership in teams, channels, and access to files.
You want external contractors to collaborate in your Teams tenant as Guests, but you must prevent them from deleting their sent chat messages. Where is this permission configured?
- Teams admin center under Org-wide settings > Guest access (Correct)
- Azure Active Directory Domain Services GPO
- Exchange Online recipient mailflow rules
- Intune device compliance baseline
Explanation: Guest permissions (such as allowing guests to edit or delete sent messages) are managed tenant-wide in the Microsoft Teams admin center under Org-wide settings > Guest access.
You need to enable collaboration via Teams shared channels with an external business partner. Both tenants must trust each other without inviting external accounts as directory guests. What must be configured in Microsoft Entra External ID?
- Mutual B2B direct connect configured in Cross-Tenant Access Settings (Correct)
- Active Directory Federation Services (AD FS) claims provider trust
- Point-to-Site VPN with SSTP authentication
- Creating matching user accounts in both active directory forests
Explanation: Teams shared channels rely on Microsoft Entra B2B direct connect, which requires both organizations to configure mutual inbound and outbound trust within Cross-Tenant Access Settings.
You are configuring Teams upgrade coexistence modes during an on-premises Skype for Business migration. You want users to receive incoming chats and calls only in Teams, and all new meetings must be scheduled in Teams. Which coexistence mode should be set?
- TeamsOnly (Correct)
- Islands
- SkypeForBusinessOnly
- SkypeForBusinessWithTeamsCollab
Explanation: TeamsOnly mode routes all chats and calls directly to Microsoft Teams, uses Teams for all meeting scheduling, and disables Skype for Business client functionality.
You are deploying Microsoft Teams Rooms (MTR) on Windows. Which license should you assign to dedicated Teams Room console accounts for enterprise management, conditional access, and Intune enrollment?
- Microsoft Teams Rooms Pro (Correct)
- Microsoft 365 F1
- Microsoft 365 Business Basic
- Exchange Online Plan 1
Explanation: Microsoft Teams Rooms Pro delivers advanced management, intelligent audio/video, device conditional access, Intune enrollment, and advanced analytics for meeting space devices.
You want to deploy configuration updates and reboot multiple certified Teams SIP IP phone devices remotely. Where in the admin center can you manage firmware and device configurations?
- Teams admin center under Teams devices > Phones (Correct)
- SharePoint site settings
- Microsoft Entra Company branding page
- Exchange Admin Center mobile access
Explanation: In the Microsoft Teams admin center under Teams devices > Phones, administrators can update firmware, change configuration profiles, restart devices, and monitor operational status.
Your compliance department requires that all file uploads inside Teams standard channels be encrypted at rest and protected by Data Loss Prevention (DLP). Where are files uploaded to a Teams standard channel physically stored?
- SharePoint Online site collection document library for the team (Correct)
- Local hard drive of the user who created the team
- On-premises Exchange 2013 public folder
- Azure Blob Storage cold archive tier
Explanation: Files uploaded to standard channels in Microsoft Teams are stored in the underlying SharePoint Online team site collection document library created for that team.
Where are files stored when a user shares a document during a private one-on-one or group chat in Microsoft Teams?
- The sender's personal OneDrive for Business in "Microsoft Teams Chat Files" (Correct)
- The recipient's Outlook Inbox folder
- The primary domain controller root drive
- A temporary local browser cache folder only
Explanation: Files shared in private 1:1 or group chats are uploaded to the sender's personal Microsoft OneDrive for Business account in a folder named "Microsoft Teams Chat Files".
You need to configure retention rules so that Teams 1:1 chat messages are deleted permanently after 90 days across the entire company. Which portal should you use?
- Microsoft Purview compliance portal under Data Lifecycle Management (Correct)
- Teams admin center under Messaging policies
- Exchange admin center under Retention tags
- Azure Portal under Virtual Networks
Explanation: Microsoft Purview compliance portal under Data Lifecycle Management is where retention policies specifically targeting Teams chats and Teams channel messages are configured.
You want to prevent employees from sending credit card numbers and passport details inside Teams channel posts and private chats. What should you configure?
- Microsoft Purview Data Loss Prevention (DLP) policies (Correct)
- Windows Firewall outbound port filtering
- Exchange Online connection filtering
- Teams App Setup policies
Explanation: Data Loss Prevention (DLP) policies configured in Microsoft Purview can target Teams chat and channel messages, blocking messages containing sensitive info and displaying policy tips.
A legal department requires immediate preservation of all chat messages and channel posts of a specific custodian involved in litigation. What should you create in Microsoft Purview?
- An eDiscovery case with a Custodian Hold (Correct)
- A Call Admission Control policy
- A static DNS pointer record
- An Intune device wipe command
Explanation: An eDiscovery case with a Custodian Hold targeting the user's mailbox ensures all Teams chat messages (stored in the user's mailbox) and associated files are immutably preserved.
You need to block communication and file sharing in Microsoft Teams between the Investment Banking department and the Equity Research department. Which compliance feature must be configured?
- Microsoft Purview Information Barriers (Correct)
- Exchange Online anti-spam whitelist
- Active Directory Sites and Services subnets
- Azure Application Gateway rules
Explanation: Microsoft Purview Information Barriers defines boundary policies that restrict specific segments of users from communicating or collaborating with each other in Microsoft Teams.
What is the default TCP/UDP port range recommended by Microsoft for real-time audio media traffic when configuring Quality of Service (QoS) for Teams clients?
- UDP ports 50000 to 50019 (Correct)
- TCP port 25 to 80
- UDP ports 1000 to 1010
- TCP port 443 only
Explanation: The default port range for Teams audio media traffic is UDP ports 50000-50019, while video typically uses UDP 50020-50039, and screen sharing uses UDP 50040-50059.
You need to ensure that users working on unmanaged personal computers cannot access Microsoft Teams on the web unless their session is monitored and file downloads are blocked. What should you configure?
- Conditional Access policy with Session controls and Defender for Cloud Apps (Correct)
- Uninstalling the web browser on corporate laptops
- Blocking port 443 at the network perimeter
- Disabling the user account in Active Directory
Explanation: A Microsoft Entra Conditional Access policy using Session controls with Conditional Access App Control (Defender for Cloud Apps) monitors web sessions and blocks downloads on unmanaged devices.
In the Teams admin center, what is the impact of enabling "Email integration" in Teams Settings?
- Users can send an email to a channel address and post it directly to the channel (Correct)
- All emails in Outlook are forwarded to personal Gmail addresses
- Teams completely replaces the user Outlook mailbox database
- Users can no longer send messages inside Teams
Explanation: When email integration is enabled, users can send an email directly to a channel by using the channel's unique email address, and the message and attachments appear as a channel post.
You are configuring security policies in Microsoft Defender for Office 365. You want to ensure that malicious links sent inside Teams 1:1 chats are detonated and verified at the moment of click. Which feature must be enabled?
- Safe Links for Microsoft Teams in Defender for Office 365 (Correct)
- Connection Filtering IP allow list
- DKIM outbound signing
- Customer Lockbox approvals
Explanation: Safe Links in Microsoft Defender for Office 365 can be extended to Microsoft Teams to provide time-of-click verification for URLs shared in chats and channels.
You want to monitor the health and peripheral connectivity (microphones, cameras, touch consoles) of Microsoft Teams Rooms from a centralized portal. What should you use?
- Microsoft Teams Rooms Pro Management portal (Correct)
- Local Device Manager on each Windows PC
- SharePoint Storage Quotas tab
- Azure Cost Management analysis blade
Explanation: The Microsoft Teams Rooms Pro Management portal provides cloud-based monitoring, automated incident remediation, peripheral health tracking, and firmware update distribution.
You need to configure a custom banner notification across the top of Microsoft Teams for all users informing them of scheduled weekend maintenance. Where can this be configured?
- Organizational messages in Microsoft 365 admin center / Intune (Correct)
- Editing the default desktop shortcut name
- Configuring an MX DNS priority record
- Deploying a local host file script
Explanation: Organization-wide alert banners or organizational messages in Microsoft 365 admin center / Intune allow administrators to dispatch in-product notification banners directly into Teams.
When configuring external access, you want to allow users to communicate with people outside your organization who are using personal Microsoft accounts (Skype consumer). Which setting controls this?
- People in my organization can communicate with Skype users (Correct)
- Allow anonymous users to join meetings
- Require encryption for all internal network traffic
- Enable PSTN audio conferencing
Explanation: In Teams admin center under External access, administrators can toggle "People in my organization can communicate with Skype users" to permit federation with consumer Skype.
You need to assign telephone numbers and manage auto attendants in Teams. Which built-in role provides the administrative scope to manage voice settings without providing full Global Admin access?
- Teams Telephony Administrator (Correct)
- Billing Administrator
- Helpdesk Administrator
- Security Reader
Explanation: The Teams Telephony Administrator role provides permissions to configure voice routing, assign phone numbers, manage auto attendants and call queues, and review device health.
Your organization requires sensitivity labels to be applied when new teams are provisioned to automatically enforce privacy (Public vs Private) and guest access. Which service enables this integration?
- Microsoft Purview Information Protection sensitivity labels (Correct)
- Windows Defender Firewall rules
- Exchange Online address book policies
- Intune Wi-Fi profiles
Explanation: Microsoft Purview Information Protection sensitivity labels can be integrated with Microsoft 365 Groups and Teams to automatically govern container-level privacy and external sharing.
What happens to a Microsoft Teams team when its underlying Microsoft 365 Group expires due to an inactivity expiration policy and is not renewed?
- The team and associated resources are soft-deleted for 30 days (Correct)
- The team is permanently erased with zero chance of recovery
- All team members are converted into external guests
- The team continues operating forever without any prompt
Explanation: When the Microsoft 365 Group expires, the group and all its associated resources (including the team, channels, chat history, and SharePoint document library) are soft-deleted for 30 days.
You need to recover a team that was deleted 10 days ago by its owner. Which console or cmdlet allows you to restore the soft-deleted team?
- Restore via Microsoft Entra admin center (Deleted groups) within 30 days (Correct)
- Rebuilding the entire team and re-adding users manually
- Restoring an offline tape backup from 5 years ago
Explanation: Administrators can restore soft-deleted Microsoft 365 Groups and Teams within 30 days via the Microsoft Entra admin center (Deleted groups) or using the Restore-MgDirectoryDeletedItem cmdlet.
Which component of Microsoft 365 is responsible for storing Teams meeting transcripts and meeting video recordings for standard channel meetings?
- The SharePoint Online document library for that channel (Correct)
- Local Windows client desktop folder
- The organizer personal Gmail inbox
- An on-premises SAN volume
Explanation: Teams meeting recordings and transcripts for channel meetings are automatically stored in the SharePoint Online document library of that specific channel.
Where are meeting recordings stored when a scheduled meeting is not held in a channel (e.g., an ad-hoc or calendar invite meeting)?
- OneDrive for Business of the user who initiated the recording (Correct)
- A public YouTube channel
- The primary domain controller SYSVOL share
- An unencrypted USB flash drive
Explanation: Non-channel meeting recordings are stored in the OneDrive for Business account of the user who initiated or scheduled the recording.
You need to automate Teams provisioning using the Microsoft Graph API. Which permission is required to create teams on behalf of the application without an interactive user login?
- Team.Create or Group.ReadWrite.All (Application permissions) (Correct)
- User.Read (Delegated permission)
- Mail.Send
- Device.Command
Explanation: Application permissions such as Team.Create or Group.ReadWrite.All granted to an Entra ID App Registration allow automated backend creation of teams via Microsoft Graph.
You want to deploy a common area phone in a lobby that can make internal calls but requires no user login credentials. Which configuration should you use?
- A certified Teams phone with a Teams Shared Device license (Correct)
- A personal smartphone with an Exchange Kiosk license
- An unmanaged analog landline without licenses
- A virtual machine running Windows Server
Explanation: Deploy a certified Teams phone configured with a Microsoft Teams Shared Device license and assign a common area phone profile.
You are configuring meeting customization in Teams Premium. You want all corporate meetings to feature corporate logos and brand colors in the pre-join screen. Which feature configures this?
- Custom meeting branding in Teams Premium (Correct)
- SharePoint modern theme designer
- Microsoft Entra Company branding for web sign-in
- Exchange Outlook Web App mailbox policy
Explanation: Custom meeting branding in Teams Premium allows administrators to create meeting themes featuring custom brand logos, background images, and company colors.
You need to ensure that only approved corporate Android and iOS mobile devices can access Microsoft Teams. Which technology enforces this compliance check?
- Microsoft Intune Device Compliance with Conditional Access (Correct)
- Disabling Wi-Fi on user smartphones
- Configuring IMAP4 client access
- Deleting device drivers from Windows
Explanation: Microsoft Intune Device Compliance policies paired with Microsoft Entra Conditional Access require mobile devices to be marked compliant before granting access to Teams.
You want to restrict users from installing uncertified third-party USB headsets with Microsoft Teams. Which administrative mechanism controls certified audio device peripherals?
- Teams device management in Teams admin center (Correct)
- Exchange ActiveSync device access rules
- Local PC sound control panel
- DNS zone SRV records
Explanation: Teams device management policies in the Teams admin center allow admins to view connected certified peripherals and monitor peripheral firmware compatibility.
In a hybrid environment, which DNS record must point to sipdir.online.lync.com to support Teams and Skype for Business online federation discovery?
- _sipfederationtls._tcp.<domain> pointing to sipdir.online.lync.com (Correct)
- autodiscover.outlook.com CNAME
- mail.protection.outlook.com MX record
- A record pointing to 127.0.0.1
Explanation: The SRV record _sipfederationtls._tcp.<domain> pointing to sipdir.online.lync.com over port 5061 is required for SIP federation discovery.
You need to configure Microsoft Defender for Cloud Apps to monitor file shares inside Teams for malware in real time. What architecture provides this inspection?
- API connectors connecting Defender for Cloud Apps to Office 365 (Correct)
- On-premises tape backup drives
- Local computer antivirus quarantine folder
- Branch router Access Control Lists
Explanation: API connectors connecting Defender for Cloud Apps directly to Office 365 enable real-time detection of malicious files uploaded to SharePoint and OneDrive via Teams.
You need to delegate authority so a regional administrator can manage Teams devices located strictly in the London branch office. Which feature supports scoping role assignments?
- Administrative Units (AUs) in Microsoft Entra ID (Correct)
- Local Windows Administrator groups
- Exchange address lists
- Active Directory Sites and Services
Explanation: Administrative Units (AUs) in Microsoft Entra ID allow scoping administrative roles (like Teams Device Administrator) over specific scoped users and devices.
You are planning network bandwidth for Teams video calls. What is the recommended minimum bandwidth per endpoint for 1080p HD group video calling?
- 2.0 Mbps to 4.0 Mbps download and 2.5 Mbps upload (Correct)
- 56 Kbps dial-up bandwidth
- 1 Gbps dedicated symmetric fiber only
- 100 Kbps symmetric bandwidth
Explanation: Microsoft recommends approximately 2.0 Mbps to 4.0 Mbps down and 2.5 Mbps up for high-definition 1080p group video calling streams.
You want to ensure that remote workers connect to Microsoft Teams media relays directly rather than hair-pinning through a corporate VPN tunnel. Which VPN configuration is required?
- VPN Split Tunneling bypassing the VPN for Teams media endpoints (Correct)
- Routing all internet traffic through a single proxy server
- Blocking UDP traffic on employee home routers
- Disabling TLS 1.3 across corporate clients
Explanation: VPN Split Tunneling configured to bypass the VPN tunnel for Microsoft 365 Optimize category endpoints (Teams audio, video, and signaling) routes media traffic directly.
Which built-in role can manage all aspects of Microsoft Teams except licensing and user account creation?
- Teams Administrator (Correct)
- Helpdesk Administrator
- Compliance Administrator
- Application Administrator
Explanation: The Teams Administrator role has full control over the Microsoft Teams admin center, meeting policies, voice settings, and apps, but cannot assign licenses or manage Entra user objects.
You need to assign a sensitivity label to a team that automatically blocks external guest users from joining. Where do you configure the container settings for the sensitivity label?
- Under Groups & sites protection settings in the Purview portal (Correct)
- In the local Windows Registry
- In the BIOS setup utility
- In public DNS record settings
Explanation: In the Microsoft Purview compliance portal under Information Protection > Labels, configure "Groups & sites" protection settings to control guest access and privacy.
What is the default retention period for soft-deleted teams before permanent deletion occurs?
- 30 days (Correct)
- 24 hours
- 365 days
- Permanently purged immediately
Explanation: Soft-deleted teams and their underlying Microsoft 365 Groups are retained in the Entra ID recycle bin for exactly 30 days before permanent purging.
Which component handles SIP signaling between Teams clients and the Microsoft 365 cloud infrastructure?
- TCP port 5061 (TLS) or HTTPS port 443 (Correct)
- UDP port 67 DHCP
- TCP port 21 FTP
- TCP port 25 SMTP
Explanation: Teams SIP signaling is transmitted securely over TLS using outbound TCP port 5061 or HTTPS port 443 to Microsoft Teams cloud proxies.
You want to restrict team creation across the tenant so that only members of a designated security group named "Team-Creators" can create new Microsoft Teams. What should you configure?
- Restrict Microsoft 365 Group creation to that security group in Entra ID (Correct)
- Disable TCP port 443 for non-authorized users
- Uninstall Microsoft Teams from unauthorized user laptops
- Revoke Exchange Online licenses from non-authorized users
Explanation: Configure Microsoft 365 Group creation permissions in Microsoft Entra ID using PowerShell to restrict group and team creation to members of that specific security group.
You need to create a company-wide team that automatically includes all employees in the organization as members. What type of team should you create?
- An Org-wide team (Correct)
- A private team with manual invitations
- A shared channel team
- A distribution group in Exchange Online
Explanation: An Org-wide team automatically adds all active users in the Microsoft 365 tenant as members and updates membership dynamically as users are provisioned or deleted.
What is the maximum number of members supported in a single standard Microsoft Teams team?
- 25,000 members (Correct)
- 2,500 members
- 100,000 members
- 500 members
Explanation: A standard Microsoft Teams team currently supports up to 25,000 members (including owners, members, and external guests).
You are creating a channel for members of the HR department to discuss confidential salaries. The channel must be accessible only to a subset of the team members. Which channel type should you create?
- A Private channel (Correct)
- A Standard channel
- An Org-wide channel
- A distribution list
Explanation: A Private channel restricts conversation and file access solely to specific members invited from the parent team, backed by its own separate SharePoint site collection.
What is an architectural characteristic of a Microsoft Teams Shared Channel compared to a Private Channel?
- Shared channels allow cross-tenant collaboration without tenant switching (Correct)
- Shared channels do not support file sharing
- Shared channels cannot be used by internal members
- Shared channels store files in personal OneDrive accounts
Explanation: Shared channels can be shared with individual users or entire teams from both inside the home organization and external organizations without requiring external users to switch tenants.
When a Private Channel is created in Microsoft Teams, where are files uploaded into that private channel physically stored?
- A dedicated, separate SharePoint site collection provisioned for that private channel (Correct)
- The parent team's main SharePoint document library in a hidden subfolder
- The personal OneDrive of the user who created the channel
- An Azure Blob storage archive container
Explanation: Each private channel automatically provisions a dedicated, separate SharePoint Online site collection with its own isolated permissions to maintain privacy from the parent team.
You want to enforce a standardized naming scheme for all newly created teams by prefixing the department name to the team name (e.g., HR-ProjectX). What should you configure?
- Microsoft 365 Groups Naming Policy in Microsoft Entra ID (Correct)
- Teams App Setup Policies
- Exchange message routing rules
- DNS zone prefix configurations
Explanation: Microsoft 365 Groups Naming Policy in Microsoft Entra ID enforces prefixes, suffixes, and blocked words on team and group names created across the organization.
You need to ensure that teams that have had no user activity for 180 days prompt the team owner to renew the team, and delete the team if no renewal occurs. Which feature enforces this?
- Microsoft 365 Group Expiration Policies (Correct)
- Intune device retirement threshold
- Continuous Access Evaluation
- Exchange Online litigation holds
Explanation: Microsoft 365 Group Expiration Policies automatically track group activity across Teams, SharePoint, and Outlook, triggering renewal notifications before soft deletion.