Microsoft AB-900 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.

 

Question 141

Which Microsoft 365 feature allows an administrator to recover a recently deleted user account when recovery is still supported?

  1. Deleted users
  2. Message trace
  3. Service health
  4. Secure Score

Correct Answer: 2

Explanation

Microsoft 365 provides an administrative area for deleted users where administrators can manage recently deleted accounts that remain within the supported recovery period. Recovering a deleted account can help restore the user’s access and associated configuration without creating an entirely new identity. Administrators should understand that recovery availability depends on Microsoft 365 service rules and the account’s deletion status. Message trace investigates email delivery, Service health monitors Microsoft services, and Secure Score focuses on security posture. The deleted-users capability is therefore relevant when an administrator needs to recover a recently removed account.

Question 142

An administrator needs to assign a Microsoft 365 license to several users at the same time based on their group membership. Which capability can simplify this process?

  1. Group-based licensing
  2. Message trace
  3. SharePoint version history
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Group-based licensing allows organizations to associate Microsoft 365 licenses with groups so that eligible members can receive the assigned licenses according to the organization’s configuration. This can reduce repetitive manual license assignment when many users share the same licensing requirements. When membership changes, licensing can also be managed through the group’s configuration rather than requiring administrators to individually update every user. Message trace investigates email delivery, SharePoint version history tracks document changes, and Bookings manages appointments. Group-based licensing is therefore useful for efficient license administration across groups of users.

Question 143

A company wants new employees in a specific department to automatically receive access to selected resources based on membership rules. Which type of Microsoft Entra group can support this scenario?

  1. Dynamic group
  2. Shared mailbox
  3. Distribution list
  4. Shared channel

Correct Answer: 1

Explanation

A dynamic group can automatically manage membership based on defined user or device attributes. For example, an organization could create membership rules based on department, job title, location, or other supported attributes. When a user’s relevant attributes change, membership can be updated according to the configured rule. This reduces the need for administrators to manually maintain membership for certain scenarios. Shared mailboxes provide shared email access, distribution lists support email distribution, and shared channels support Teams collaboration. Dynamic groups are therefore appropriate for attribute-based automatic membership.

Question 144

Which Microsoft 365 group type is primarily intended for sending email announcements to a collection of recipients?

  1. Distribution group
  2. Security group
  3. Dynamic device group
  4. Shared mailbox

Correct Answer: 1

Explanation

A distribution group is designed primarily to distribute email messages to multiple recipients through a single group address. Instead of entering each recipient individually, a sender can address the message to the distribution group and have it delivered to its members according to the group’s configuration. Security groups are mainly used to manage access and permissions, while dynamic device groups can manage device membership based on rules. A shared mailbox provides a common mailbox for multiple authorized users. Therefore, a distribution group is the appropriate choice for straightforward group email distribution.

Question 145

An organization wants to use a group to control access to applications and resources rather than primarily distribute email. Which group type is most appropriate?

  1. Distribution group
  2. Security group
  3. Shared mailbox
  4. Microsoft 365 app

Correct Answer: 2

Explanation

Security groups are designed to simplify access management by allowing administrators to assign permissions or access to a group instead of configuring each user individually. Users can be added to the security group and then receive access to resources associated with that group, depending on the configured permissions. Distribution groups are primarily intended for email distribution, while shared mailboxes provide shared email functionality. A Microsoft 365 app is not a group type. Therefore, a security group is the appropriate choice when the primary requirement is controlling access to organizational resources.

Question 146

Which Microsoft Entra feature can require users to provide an additional verification method during sign-in?

  1. Multi-factor authentication
  2. SharePoint version history
  3. Microsoft Planner
  4. Microsoft Stream

Correct Answer: 4

Explanation

Multi-factor authentication, or MFA, requires users to provide additional verification beyond a primary authentication factor. Depending on the organization’s configuration, this can involve methods such as an authenticator application, security key, or other supported verification methods. MFA helps reduce the impact of compromised passwords because knowing the password alone may not be sufficient to complete authentication. SharePoint version history manages document versions, Planner manages tasks, and Stream provides video capabilities. MFA is therefore the Microsoft Entra capability designed to strengthen sign-in by requiring additional verification.

Question 147

A company wants users to sign in without relying primarily on traditional passwords. Which Microsoft authentication approach can support this goal?

  1. Passwordless authentication
  2. Exchange message trace
  3. SharePoint news
  4. Microsoft Lists

Correct Answer: 1

Explanation

Passwordless authentication allows users to authenticate without entering a traditional password as the primary authentication method. Microsoft supports several passwordless approaches, including methods involving Microsoft Authenticator, security keys, and other supported authentication technologies. Reducing dependence on passwords can help organizations improve the authentication experience while addressing risks associated with weak or compromised passwords. Exchange message trace handles email investigations, SharePoint news supports internal announcements, and Lists manages structured information. Therefore, passwordless authentication is the appropriate approach when an organization wants to reduce reliance on traditional passwords.

Question 148

Which Microsoft Entra capability helps administrators manage different authentication methods available to users?

  1. Authentication methods
  2. Microsoft Planner
  3. Microsoft Bookings
  4. SharePoint version history

Correct Answer: 1

Explanation

Microsoft Entra authentication methods settings allow organizations to manage supported authentication methods and determine how users can authenticate. Administrators can configure methods according to organizational security requirements and supported Microsoft capabilities. This helps create a consistent identity-management strategy and can support stronger authentication experiences. Planner is used for task management, Bookings handles appointments, and SharePoint version history tracks document revisions. When an administrator needs to configure or manage the authentication methods available to users, the Microsoft Entra authentication methods area is the relevant capability.

Question 149

An organization wants to provide employees with a way to access approved external applications using their organizational identity. Which capability can support this requirement?

  1. Enterprise applications
  2. Microsoft Planner
  3. Microsoft Stream
  4. SharePoint news

Correct Answer: 1

Explanation

Microsoft Entra enterprise applications provide organizations with a way to manage access to applications that users may need for business activities. Depending on the application’s integration and configuration, administrators can manage authentication, assignments, and other access-related settings. This allows organizations to establish controlled access to approved applications using organizational identities. Planner is for task management, Stream is for video, and SharePoint news is for internal communication. Enterprise applications are therefore the appropriate Microsoft Entra capability when an organization needs centralized management of access to integrated business applications.

Question 150

A company wants to provide an external consultant with access to selected organizational resources while keeping the consultant represented as an external identity. Which Microsoft Entra capability is relevant?

  1. External collaboration
  2. Microsoft Forms
  3. Microsoft Planner
  4. Exchange message trace

Correct Answer: 1

Explanation

Microsoft Entra external collaboration capabilities allow organizations to work with users outside the organization while maintaining controls around external identities and resource access. This can support collaboration with consultants, partners, contractors, and other external users. Organizations can apply appropriate access and governance policies to determine which resources external users can access. Forms collects responses, Planner manages tasks, and message trace investigates email delivery. External collaboration is therefore relevant when a business needs to work with an outside person while keeping that person managed as an external identity.

Question 151

Which Microsoft Entra object represents an application identity that can be used to authenticate an application to Microsoft services?

  1. Service principal
  2. Microsoft List
  3. SharePoint page
  4. Planner task

Correct Answer: 1

Explanation

A service principal represents an application identity within Microsoft Entra ID and allows an application or service to authenticate and access resources according to assigned permissions. Service principals are commonly used when applications need to operate without a human user interactively signing in. Administrators can manage permissions associated with application identities and apply appropriate access controls. Microsoft Lists store structured information, SharePoint pages present content, and Planner tasks organize work. Therefore, a service principal is the Microsoft Entra object relevant to application-based identity and authentication.

Question 152

An application needs permission to access Microsoft resources through APIs. Which Microsoft platform provides the API framework commonly used for this purpose?

  1. Microsoft Graph
  2. Microsoft Planner
  3. Microsoft Bookings
  4. Microsoft Stream

Correct Answer: 2

Explanation

Microsoft Graph provides a unified API platform for accessing data and capabilities across many Microsoft services. Applications can use Microsoft Graph to work with supported resources such as users, groups, calendars, files, messages, and other Microsoft 365 data, subject to the permissions granted to the application. Planner, Bookings, and Stream are end-user or service applications rather than the general API framework for Microsoft 365 resources. Microsoft Graph is therefore the appropriate platform when an application needs programmatic access to supported Microsoft services through APIs.

Question 153

Which security principle recommends granting users only the permissions necessary to perform their assigned tasks?

  1. Least privilege
  2. Maximum access
  3. Shared credentials
  4. Anonymous administration

Correct Answer: 1

Explanation

The principle of least privilege means users, applications, and administrators should receive only the permissions necessary to perform their required tasks. Limiting permissions reduces the potential impact of compromised accounts, accidental changes, and misuse of privileges. Organizations can implement this principle through appropriate role assignments, access controls, and administrative delegation. Granting maximum access to every user increases unnecessary exposure, while shared credentials reduce accountability. Anonymous administration is unsuitable for controlled enterprise environments. Least privilege is therefore a fundamental security principle for managing Microsoft 365 access.

Question 154

A security team wants to evaluate the organization’s overall Microsoft security configuration and identify recommended improvement actions. Which Microsoft capability should they use?

  1. Microsoft Secure Score
  2. Microsoft Forms
  3. Microsoft Planner
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Microsoft Secure Score provides organizations with an assessment of security-related configurations and recommendations for improving their security posture. Administrators can review improvement actions and determine which changes are appropriate for their environment. The score and recommendations can help organizations identify areas where security controls may be strengthened. Forms is designed for surveys, Planner manages tasks, and Bookings handles appointments. Secure Score is therefore the relevant Microsoft capability when a security team wants centralized guidance about improving the organization’s Microsoft security configuration.

Question 155

Which Microsoft Defender service is primarily focused on protecting email and collaboration workloads from threats?

  1. Microsoft Defender for Office 365
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender for Identity
  4. Microsoft Intune

Correct Answer: 1

Explanation

Microsoft Defender for Office 365 provides security capabilities designed to help protect Microsoft 365 email and collaboration workloads from threats. Depending on licensing and configuration, it can provide protections and investigation capabilities related to phishing, malicious content, and other email or collaboration threats. Defender for Endpoint focuses on endpoint security, while Defender for Identity focuses on identity-related signals and threats. Intune is primarily a device and application management service. Therefore, Defender for Office 365 is the Defender service most directly associated with protecting Microsoft 365 email and collaboration workloads.

Question 156

Which Microsoft Defender service is designed to provide security capabilities for Windows and other supported endpoints?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender for Office 365
  4. Microsoft Bookings

Correct Answer: 2

Explanation

Microsoft Defender for Endpoint is designed to provide endpoint security capabilities for supported devices. It can help organizations detect, investigate, and respond to endpoint-related threats while providing security visibility across managed environments. Defender for Identity focuses on identity-related security signals, and Defender for Office 365 focuses on email and collaboration workloads. Microsoft Bookings is an appointment scheduling application and is unrelated to endpoint security. Therefore, Defender for Endpoint is the appropriate service when an organization needs security capabilities focused on supported endpoint devices.

Question 157

A security administrator wants to investigate security signals involving on-premises identity infrastructure and user identities. Which Defender service is specifically designed for identity-related threat detection?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Office 365
  3. Microsoft Planner
  4. Microsoft Forms

Correct Answer: 1

Explanation

Microsoft Defender for Identity is designed to help organizations detect and investigate identity-related threats and suspicious activities involving supported identity infrastructure. It can provide security signals that help security teams understand potentially malicious behavior involving identities. Defender for Office 365 focuses on email and collaboration threats, while Planner and Forms are productivity applications. When a security administrator needs identity-focused threat detection capabilities, Defender for Identity is the relevant Microsoft Defender service.

Question 158

Which Microsoft security service helps organizations discover and assess the use of cloud applications within their environment?

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Forms
  3. Microsoft Planner
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Microsoft Defender for Cloud Apps provides capabilities for discovering, monitoring, and managing cloud application usage and associated security risks. Organizations can use cloud discovery capabilities to gain visibility into applications being used within their environment and assess whether those applications align with organizational security requirements. Forms, Planner, and Bookings are productivity applications and do not provide cloud application security discovery. Defender for Cloud Apps is therefore the appropriate service when an organization needs visibility and security controls related to cloud application usage.

Question 159

A company wants to manage corporate smartphones and tablets from a central cloud-based service. Which Microsoft service should it use?

  1. Microsoft Intune
  2. Microsoft Stream
  3. Microsoft Forms
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Microsoft Intune provides cloud-based management capabilities for organizational devices, including supported smartphones and tablets. Administrators can use Intune to enroll devices, configure settings, manage applications, and apply organizational requirements. This provides centralized management without requiring a traditional on-premises device-management infrastructure for supported scenarios. Stream manages video, Forms collects responses, and Bookings handles appointments. Therefore, Microsoft Intune is the appropriate Microsoft service when an organization needs centralized cloud-based management of corporate mobile devices.

Question 160

Which Intune capability determines whether a managed device meets an organization’s required security and configuration standards?

  1. Compliance policy
  2. Microsoft Forms
  3. SharePoint news
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Intune compliance policies define requirements that managed devices must meet to be considered compliant with organizational standards. Depending on the platform and configuration, these requirements can include conditions related to device security, operating-system versions, encryption, passwords, or other supported controls. Compliance information can then be used with broader access-management strategies to help enforce organizational requirements. Forms, SharePoint news, and Bookings serve productivity and communication purposes rather than device compliance. Therefore, an Intune compliance policy is the appropriate capability for determining whether a managed device meets defined standards.