Microsoft AB-900 Practice Test Questions and Exam Dumps Part5 Q81-100

View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.

 

Question 81

Which Microsoft 365 capability allows an organization to control how users access organizational resources based on conditions such as device state or sign-in risk?

  1. Retention labels
  2. Conditional Access
  3. SharePoint version history
  4. Exchange message trace

Correct Answer: 2

Explanation

Conditional Access allows organizations to make access decisions based on signals and conditions associated with a sign-in request. Policies can evaluate factors such as user identity, device state, location, application, and sign-in risk. Based on these conditions, an organization can require multifactor authentication, require a compliant device, or block access. Retention labels manage information governance, SharePoint version history tracks document changes, and message trace investigates email delivery. AB-900 includes Conditional Access as an important Microsoft Entra security capability for implementing identity-based access controls.

Question 82

Which Microsoft Entra capability can require administrators to provide additional verification before accessing privileged resources?

  1. Privileged Identity Management
  2. Microsoft Forms
  3. Microsoft Planner
  4. SharePoint version history

Correct Answer: 1

Explanation

Microsoft Entra Privileged Identity Management, or PIM, helps organizations manage, control, and monitor privileged access. It can require eligible administrators to activate roles when needed and can apply controls such as multifactor authentication, approval, and time-limited access. This reduces the need for permanent privileged assignments and supports the principle of least privilege. Microsoft Forms and Planner are productivity applications, while SharePoint version history manages document versions. AB-900 includes PIM as a key identity-management capability for controlling privileged administrative access.

Question 83

Which Microsoft Entra feature can automatically add or remove users from a group based on user attributes?

  1. Dynamic membership
  2. Manual permissions
  3. Mailbox delegation
  4. Retention configuration

Correct Answer: 1

Explanation

Dynamic membership allows Microsoft Entra groups to determine membership automatically using defined rules based on user or device attributes. For example, an organization can create a rule that includes users based on department, job title, or another supported attribute. When the relevant attribute changes, membership can be updated automatically. Manual permissions require administrators to make changes directly, mailbox delegation controls access to Exchange mailboxes, and retention configuration manages information lifecycle requirements. AB-900 includes dynamic groups and automated administration concepts, making dynamic membership an important feature to understand.

Question 84

An organization needs to provide external partners with controlled access to selected Microsoft 365 resources. Which identity capability is most relevant?

  1. External identities
  2. Exchange transport rules
  3. SharePoint version history
  4. Microsoft Lists

Correct Answer: 1

Explanation

Microsoft Entra External ID capabilities support scenarios where organizations need to collaborate with people outside their internal workforce. External identities can be used to provide controlled access to supported organizational resources while maintaining identity and access management through Microsoft Entra. Exchange transport rules control email processing, SharePoint version history tracks document changes, and Microsoft Lists manages structured information. AB-900 includes external identities as part of Microsoft Entra administration, so candidates should recognize this capability when a business requirement involves secure collaboration with external users.

Question 85

Which Microsoft 365 security capability helps protect an organization by identifying potentially malicious activity across multiple Microsoft security products?

  1. Microsoft Defender XDR
  2. Microsoft Bookings
  3. Microsoft Forms
  4. Microsoft Lists

Correct Answer: 1

Explanation

Microsoft Defender XDR provides an integrated security experience that can correlate threat signals across multiple Microsoft Defender products. This helps security teams investigate incidents from a broader perspective rather than examining each workload independently. Defender XDR can support detection, investigation, and response to threats affecting areas such as identities, endpoints, email, and applications. Bookings, Forms, and Lists are productivity applications and do not provide cross-workload threat detection. AB-900 includes Microsoft Defender capabilities, so understanding the purpose of Defender XDR is important for recognizing integrated security operations.

Question 86

Which Microsoft Defender product focuses specifically on protecting Microsoft 365 email from phishing and malware?

  1. Microsoft Defender for Office 365
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Cloud Apps

Correct Answer: 1

Explanation

Microsoft Defender for Office 365 provides security capabilities designed to protect Microsoft 365 communication and collaboration workloads, particularly Exchange Online email. It helps protect users against threats such as phishing, malicious attachments, malicious links, and other email-based attacks. Defender for Endpoint focuses on devices, Defender for Identity focuses on identity threats, and Defender for Cloud Apps provides cloud application security and visibility. AB-900 includes Microsoft Defender products and their purposes, so candidates should understand why Defender for Office 365 is the appropriate solution for Microsoft 365 email protection.

Question 87

Which Microsoft security capability can help identify applications that employees are using without formal organizational approval?

  1. Cloud discovery
  2. Retention management
  3. SharePoint version history
  4. Exchange calendar sharing

Correct Answer: 1

Explanation

Cloud discovery capabilities associated with Microsoft Defender for Cloud Apps can help organizations identify cloud applications being used within their environment. This can reveal applications that may not have been formally approved or reviewed by the organization. Administrators can use this information to assess application risk and determine appropriate security or governance actions. Retention management deals with information lifecycle, SharePoint version history tracks document changes, and Exchange calendar sharing manages calendar access. AB-900 includes cloud application discovery as an important security and governance concept.

Question 88

Which Microsoft Intune feature allows an organization to define requirements that devices must satisfy before they are considered compliant?

  1. Compliance policies
  2. Distribution groups
  3. Retention policies
  4. Mail flow rules

Correct Answer: 1

Explanation

Microsoft Intune compliance policies define requirements that managed devices must meet to be considered compliant. Requirements can include supported operating system versions, encryption, password settings, device security conditions, and other organizational criteria. Compliance information can then be used with access controls to help determine whether a device should be permitted to access protected resources. Distribution groups manage email recipients, retention policies govern information lifecycle, and mail flow rules process email. AB-900 includes Intune compliance policies as a core device-management concept.

Question 89

Which Microsoft Intune capability is used to deploy applications to managed devices?

  1. App deployment
  2. Audit search
  3. Data classification
  4. Sensitivity labeling

Correct Answer: 1

Explanation

Microsoft Intune supports application deployment and management for enrolled and supported devices. Administrators can add applications to Intune, configure appropriate settings, and assign them to users or devices according to organizational requirements. This makes it possible to centrally distribute required applications without manually installing them on every endpoint. Audit search is used for investigating activity, data classification organizes information, and sensitivity labels protect sensitive content. AB-900 includes application deployment as part of Intune administration, so candidates should recognize Intune as both a device-management and application-management platform.

Question 90

Which Microsoft Intune capability can help organizations remove corporate data from a managed device without necessarily removing all personal data?

  1. Selective wipe
  2. Message trace
  3. Sensitivity labeling
  4. Conditional formatting

Correct Answer: 1

Explanation

A selective wipe can remove organizational data from a managed device while preserving appropriate personal information, depending on the application and management scenario. This can be particularly useful when an employee leaves an organization or when a device is lost and corporate information needs to be protected. Message trace is used for Exchange troubleshooting, sensitivity labels protect and classify information, and conditional formatting is unrelated to device data removal. AB-900 includes Intune data-protection concepts, including the ability to manage organizational information on user devices.

Question 91

Which Microsoft 365 feature helps administrators review recommendations for improving an organization’s identity security configuration?

  1. Identity Secure Score
  2. Microsoft Forms
  3. Microsoft Bookings
  4. SharePoint document sets

Correct Answer: 1

Explanation

Identity Secure Score provides information about an organization’s identity security posture and can identify recommended actions that may improve security. Administrators can use the recommendations to review identity-related configurations and prioritize improvements. Forms is used for surveys and quizzes, Bookings supports appointment scheduling, and SharePoint document sets organize related documents. AB-900 includes Identity Secure Score as part of Microsoft Entra administration and security. Candidates should understand that Identity Secure Score focuses specifically on identity-related security improvements rather than general productivity or document management.

Question 92

An administrator needs to investigate suspicious authentication attempts involving a user account. Which Microsoft Entra log should be reviewed first?

  1. Sign-in logs
  2. SharePoint audit logs
  3. Exchange message trace
  4. Teams usage reports

Correct Answer: 1

Explanation

Microsoft Entra sign-in logs provide detailed information about authentication attempts and are an appropriate starting point when investigating suspicious sign-in activity. Administrators can review information about the user, application, authentication result, location, device, and other available signals. SharePoint audit logs focus on SharePoint-related activities, Exchange message trace investigates email delivery, and Teams usage reports provide collaboration-related usage information. AB-900 includes identity monitoring and troubleshooting, making sign-in logs an important source for investigating unusual or failed authentication attempts.

Question 93

Which Microsoft Purview capability can help identify sensitive information types within organizational content?

  1. Sensitive information types
  2. Teams channels
  3. Security groups
  4. App registrations

Correct Answer: 1

Explanation

Sensitive information types are Microsoft Purview components that help identify content containing particular kinds of sensitive data. Organizations can use them as conditions in information-protection and Data Loss Prevention policies to detect information such as financial or personal data according to configured definitions. Teams channels are collaboration spaces, security groups organize identities, and app registrations provide application identity configurations. AB-900 includes sensitive information types as a foundation for data protection, so understanding their role helps administrators create policies that respond appropriately when sensitive data is detected.

Question 94

Which Microsoft Purview feature can apply protection settings to content based on how sensitive the information is?

  1. Sensitivity labels
  2. Service health
  3. Sign-in logs
  4. Device compliance

Correct Answer: 1

Explanation

Sensitivity labels allow organizations to classify information and apply protection settings according to the sensitivity of the content. Depending on the configuration, labels can support controls such as encryption, access restrictions, and visual markings. Service health provides information about Microsoft 365 service incidents, sign-in logs record authentication events, and device compliance evaluates endpoint requirements. AB-900 includes information protection and sensitivity labels, so candidates should understand that labels help organizations classify and protect content rather than monitor service availability or authenticate users.

Question 95

Which Microsoft Purview capability can help organizations retain information for a defined period based on organizational or regulatory requirements?

  1. Retention policies
  2. Teams meeting policies
  3. Conditional Access policies
  4. Intune configuration profiles

Correct Answer: 1

Explanation

Microsoft Purview retention policies help organizations manage how long supported information should be retained. Retention requirements can be based on business, legal, regulatory, or organizational needs. Policies can help ensure that information is retained for the required period and can support appropriate disposition when the retention period ends. Teams meeting policies manage Teams meeting behavior, Conditional Access policies control access decisions, and Intune configuration profiles manage device settings. AB-900 includes retention and information governance, so understanding retention policies is essential for managing organizational information throughout its lifecycle.

Question 96

Which Microsoft Purview feature can be used to apply retention or classification settings to specific content based on defined rules or user actions?

  1. Retention labels
  2. Sign-in logs
  3. Secure Score
  4. Application registrations

Correct Answer: 1

Explanation

Retention labels allow organizations to apply specific retention and governance settings to individual items or categories of content. They can be configured to support requirements where information needs a particular retention treatment based on its business or regulatory significance. Sign-in logs monitor authentication activity, Secure Score provides security recommendations, and application registrations manage application identities. AB-900 includes retention labels as part of Microsoft Purview information governance, so candidates should distinguish them from broader retention policies that may apply settings across larger collections of content.

Question 97

Which Microsoft Purview capability can help organizations investigate whether sensitive data is being shared or used in ways that violate organizational policies?

  1. Data Loss Prevention
  2. Microsoft Bookings
  3. Microsoft Planner
  4. Microsoft Forms

Correct Answer: 1

Explanation

Data Loss Prevention helps organizations identify and respond to activities involving sensitive information that may violate organizational policies. DLP policies can detect sensitive information and evaluate activities such as sharing or transmission, depending on the configured workloads and conditions. This allows organizations to apply appropriate actions or generate alerts when potentially risky data-handling behavior occurs. Bookings, Planner, and Forms are productivity applications and do not provide the same sensitive-data protection capabilities. AB-900 includes DLP as a core Microsoft Purview information-protection technology.

Question 98

Which Microsoft 365 capability can help an organization understand how well users are adopting Microsoft 365 applications and services?

  1. Usage reports
  2. Retention labels
  3. Sign-in logs
  4. Sensitivity labels

Correct Answer: 1

Explanation

Microsoft 365 usage reports provide information about how users and organizations are using Microsoft 365 applications and services. Administrators can use these reports to understand adoption patterns, identify usage trends, and determine where additional training or deployment attention may be useful. Retention labels and sensitivity labels support information governance and protection, while sign-in logs focus on authentication activity. AB-900 includes Microsoft 365 reporting and monitoring concepts, so candidates should understand that usage reports are primarily intended to provide visibility into service adoption and user activity.

Question 99

Which Microsoft 365 admin center capability can help administrators review how effectively users are adopting Microsoft 365 Copilot?

  1. Copilot usage reports
  2. Exchange message trace
  3. SharePoint version history
  4. Device compliance reports

Correct Answer: 1

Explanation

Copilot usage reports provide administrators with information that can help them understand Copilot adoption and usage across the organization. These reports can support deployment planning, adoption monitoring, and identification of usage patterns among users. Exchange message trace investigates email delivery, SharePoint version history tracks document changes, and device compliance reports focus on endpoint requirements. AB-900 includes monitoring Copilot adoption through administrative reporting capabilities, so administrators should recognize Copilot usage information as a useful resource when evaluating how users are engaging with the service.

Question 100

Which Microsoft 365 capability provides administrators with information about user activity and service adoption across Microsoft 365 workloads?

  1. Microsoft 365 usage reports
  2. Sensitivity labels
  3. Conditional Access
  4. Privileged Identity Management

Correct Answer: 1

Explanation

Microsoft 365 usage reports provide administrators with information about activity and adoption across supported Microsoft 365 workloads. These reports can help organizations understand how services are being used, identify adoption trends, and support administrative or training decisions. Sensitivity labels protect and classify information, Conditional Access manages access decisions, and Privileged Identity Management controls privileged role activation. AB-900 includes monitoring Microsoft 365 usage and adoption, so candidates should understand that usage reports are designed to provide operational insights rather than directly enforce security or compliance policies.