Microsoft AB-900 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.

 

Question 281

Which Microsoft 365 feature allows an administrator to create a policy that automatically applies a sensitivity label when specific types of sensitive information are detected?

  1. Device enrollment
  2. Auto-labeling
  3. Service health
  4. Mail flow connector

Correct Answer: 2

Explanation

Microsoft Purview auto-labeling can automatically apply sensitivity labels when configured conditions are met, such as detecting specific sensitive information or content patterns. This can reduce reliance on users to manually classify every document or email. Administrators can configure rules that determine when particular labels should be applied, helping organizations apply consistent information protection policies. Mail flow connectors handle email routing, device enrollment manages device registration, and Service health provides information about Microsoft service conditions. Therefore, auto-labeling is the appropriate capability when sensitivity labels need to be applied automatically based on content.

Question 282

A user receives a notification explaining that an email may violate an organization’s data protection policy and may be blocked or require an action. Which DLP capability provides this type of guidance directly to the user?

  1. Service plan
  2. Site template
  3. Policy tip
  4. Device category

Correct Answer: 3

Explanation

Microsoft Purview Data Loss Prevention policy tips can provide users with contextual notifications when their actions may violate an organization’s DLP policies. For example, a user may receive a message explaining that a document contains sensitive information and that sharing it may violate company rules. Policy tips can help users understand organizational requirements while they work with protected information. Device categories organize Intune-managed devices, site templates provide predefined SharePoint structures, and service plans define available licensed services. Therefore, a DLP policy tip is the appropriate capability for providing this type of user guidance.

Question 283

An organization wants users to request an exception when a DLP rule blocks an action that has a legitimate business purpose. Which DLP capability can support this scenario?

  1. User override
  2. Device sync
  3. SharePoint hub association
  4. Domain verification

Correct Answer: 1

Explanation

A DLP policy can be configured to allow users to override certain policy actions when organizational rules permit it. When a legitimate business need exists, an authorized user may be able to provide a justification or otherwise follow the configured exception process. Administrators can use reporting and auditing capabilities to monitor such events. Domain verification confirms ownership of a domain, device synchronization retrieves updated management information, and SharePoint hub association connects related sites. Therefore, a user override is the relevant DLP capability when controlled exceptions are allowed for legitimate business scenarios.

Question 284

Which Microsoft Purview capability allows administrators to define how long specific records should be retained and how they should be managed as organizational records?

  1. Intune enrollment
  2. Safe Links
  3. Microsoft Search
  4. Records management

Correct Answer: 4

Explanation

Microsoft Purview Records Management provides capabilities for managing information as organizational records. It supports policies and labels that can help organizations determine how long records should be retained and what actions should occur during their lifecycle. This is useful for organizations that must manage information according to legal, regulatory, or business requirements. Microsoft Search helps users find information, Safe Links protects against malicious URLs, and Intune enrollment registers devices for management. Therefore, Records Management is the appropriate Purview capability for governing information as formal organizational records.

Question 285

An organization needs to preserve relevant electronic information because of an ongoing legal matter. Which Microsoft Purview capability can place information on hold so it is not removed according to normal retention or deletion processes?

  1. Device configuration
  2. Service health
  3. eDiscovery hold
  4. Microsoft Search

Correct Answer: 3

Explanation

An eDiscovery hold can preserve relevant electronic information when an organization needs to protect content for a legal matter or investigation. Placing content on hold can prevent it from being permanently deleted according to ordinary retention or deletion processes, depending on the workload and configuration. This helps organizations preserve potentially relevant information while legal or investigative activities are underway. Microsoft Search is designed for information discovery, device configuration manages endpoint settings, and Service health reports Microsoft service conditions. Therefore, an eDiscovery hold is the appropriate capability for preserving information required for a legal matter.

Question 286

A compliance administrator needs to find only specific audit activities performed by users during a defined period. Which approach provides the most targeted search?

  1. Open the Exchange archive
  2. Configure audit search filters
  3. Check Teams app permissions
  4. Review the OneDrive recycle bin

Correct Answer: 2

Explanation

Microsoft Purview audit search supports filtering activities by relevant criteria such as users, dates, workloads, and activity types. Applying targeted filters makes it easier for administrators to locate the specific audit events required for an investigation instead of reviewing a large volume of unrelated activity. The OneDrive recycle bin contains deleted files, Teams app permissions control application availability, and Exchange archive stores older mailbox content. Therefore, configuring appropriate audit search filters is the most efficient approach when a compliance administrator needs to locate specific activities during a defined period.

Question 287

Which Microsoft 365 capability helps an organization determine whether its current Microsoft 365 environment is prepared for a planned Copilot deployment?

  1. DNS MX record
  2. Exchange Online Archive
  3. Device category
  4. Copilot readiness assessment

Correct Answer: 4

Explanation

A Copilot readiness assessment can help an organization evaluate factors that may affect a Microsoft 365 Copilot deployment. Readiness activities can include reviewing identity configuration, permissions, data governance, licensing considerations, and organizational preparation. This helps administrators identify areas that may require attention before broader adoption. Exchange Online Archive manages mailbox storage, device categories organize managed endpoints, and DNS MX records control email routing. Therefore, a Copilot readiness assessment is the relevant approach when an organization wants to evaluate whether its environment is prepared for a Copilot deployment.

Question 288

Which Microsoft 365 Copilot principle ensures that Copilot does not provide a user with information they are not already authorized to access?

  1. License inheritance
  2. Permission-aware access
  3. Anonymous discovery
  4. Automatic administrator elevation

Correct Answer: 2

Explanation

Microsoft 365 Copilot is designed to respect existing user permissions when retrieving and presenting organizational information. Permission-aware access means that Copilot does not simply grant users access to content they could not otherwise access. If a user does not have permission to a document, message, or other protected resource, Copilot should not bypass those permissions to provide the content. This principle is important because Copilot operates within the organization’s existing security and access framework. Automatic administrator elevation, anonymous discovery, and license inheritance do not describe this permission behavior.

Question 289

An organization wants to make a Copilot agent available only to a selected group of employees instead of everyone in the tenant. What should the administrator configure?

  1. Agent access permissions
  2. DNS TXT verification
  3. SharePoint list view
  4. Exchange message trace

Correct Answer: 1

Explanation

Agent access permissions can be configured to control which users or groups are allowed to use a Copilot agent. Restricting access can help organizations roll out agents gradually or limit specialized functionality to employees who need it. This approach can also support governance by ensuring that only approved users can interact with particular agents or organizational resources. Exchange message trace investigates email delivery, SharePoint list views change how list information is displayed, and DNS TXT records are commonly used for domain verification. Therefore, agent access permissions are the appropriate control for restricting an agent to selected employees.

Question 290

Which Microsoft 365 Copilot capability is intended to help users analyze information and generate insights from data?

  1. Intune Sync
  2. Exchange Archive
  3. Copilot Analyst
  4. Copilot Reader

Correct Answer: 3

Explanation

Copilot Analyst is designed to assist users with analyzing information and producing insights from available data. It can help users examine data, identify patterns, and work through analytical tasks using natural-language interactions and supported capabilities. This differs from administrative services such as Exchange Archive or Intune Sync, which serve mailbox and device-management purposes. When the primary requirement is assistance with data analysis rather than email storage or endpoint management, Copilot Analyst is the relevant capability. Its usefulness also depends on the user’s permissions, available data, and organizational configuration.

Question 291

An organization wants employees to use Copilot to investigate a topic and gather information from relevant sources. Which Copilot capability is designed for research-oriented tasks?

  1. Microsoft Intune
  2. Copilot Researcher
  3. SharePoint recycle bin
  4. Exchange Online

Correct Answer: 2

Explanation

Copilot Researcher is designed for research-oriented tasks in which users need assistance investigating topics and synthesizing information from relevant sources. It can help organize information and produce research-oriented results while operating within the user’s available access and organizational controls. Microsoft Intune manages devices and applications, Exchange Online provides email and calendaring, and the SharePoint recycle bin contains deleted content. Therefore, Copilot Researcher is the capability most directly associated with research and information-gathering tasks.

Question 292

Which Microsoft 365 security principle requires an administrator to verify a request before granting access rather than automatically trusting the request because it comes from inside the organization?

  1. Perimeter-only security
  2. Open access
  3. Zero Trust
  4. Anonymous access

Correct Answer: 3

Explanation

The Zero Trust security model is based on the principle of not automatically trusting access requests simply because they originate from an internal network or organizational account. Access should be verified using appropriate identity, device, application, and contextual information before authorization is granted. This approach helps reduce the risks associated with compromised accounts and unauthorized movement within an environment. Open access and anonymous access provide weaker security controls, while perimeter-only security relies heavily on the assumption that internal activity is trustworthy. Zero Trust therefore represents the appropriate security principle for this scenario.

Question 293

A company wants to identify whether users are accessing cloud applications that have not been centrally approved or managed by IT. Which Microsoft security capability can provide visibility into cloud application usage?

  1. Windows Autopilot
  2. SharePoint site template
  3. Cloud Discovery
  4. Exchange Online Archive

Correct Answer: 3

Explanation

Microsoft Defender for Cloud Apps Cloud Discovery helps organizations identify cloud applications being used within their environment. This visibility can reveal applications that may not have been formally approved or managed by IT, sometimes referred to as shadow IT. Administrators can use discovery information to better understand application usage and evaluate security or governance requirements. Exchange Online Archive manages older mailbox content, SharePoint site templates provide predefined site structures, and Windows Autopilot supports device provisioning. Therefore, Cloud Discovery is the appropriate capability for identifying unapproved cloud application usage.

Question 294

Which Microsoft Defender capability focuses on identifying security weaknesses and vulnerabilities across an organization’s endpoints?

  1. SharePoint hub site
  2. Defender Vulnerability Management
  3. Exchange Online Archive
  4. Microsoft Search

Correct Answer: 2

Explanation

Microsoft Defender Vulnerability Management helps organizations identify and manage security weaknesses affecting their devices and endpoints. It can provide visibility into vulnerabilities, misconfigurations, and other security exposure so administrators can prioritize remediation activities. This supports a proactive approach to endpoint security by helping organizations understand where weaknesses exist before they are exploited. Microsoft Search is an information discovery service, Exchange Online Archive provides additional mailbox storage, and SharePoint hub sites organize related sites. Defender Vulnerability Management is therefore the capability specifically focused on identifying endpoint vulnerabilities and security exposure.

Question 295

An administrator wants to investigate a security alert and determine which related alerts belong to the same security event. Which Microsoft Defender XDR concept groups related security signals for investigation?

  1. Service plan
  2. SharePoint view
  3. Incident
  4. Device category

Correct Answer: 3

Explanation

A Microsoft Defender XDR incident groups related alerts and security signals into a broader security event that can be investigated as a connected case. Instead of reviewing every alert independently, security teams can examine an incident to understand related activity, affected entities, and the potential scope of an attack. Service plans relate to licensing, device categories organize managed devices, and SharePoint views organize list information. Therefore, an incident is the appropriate Defender XDR concept when administrators need to investigate related alerts together as part of a security event.

Question 296

Which Microsoft Defender XDR capability can help security analysts investigate an alert by showing related users, devices, files, and other entities involved in the event?

  1. Exchange archive
  2. Domain verification
  3. OneDrive Files On-Demand
  4. Incident investigation

Correct Answer: 4

Explanation

Defender XDR incident investigation provides security analysts with contextual information about entities associated with a security event. Depending on the incident, investigators can review affected users, devices, files, processes, and other related signals to understand what occurred and determine appropriate response actions. Domain verification is used when establishing control of a domain, OneDrive Files On-Demand manages cloud file availability, and Exchange archive provides additional mailbox storage. Therefore, incident investigation is the relevant capability when analysts need contextual information about entities connected to a security alert.

Question 297

An administrator needs to determine which Microsoft 365 changes require preparation by the organization before a new feature is introduced. Which Message center information should receive attention?

  1. Device inventory
  2. Mailbox archive items
  3. Deleted files
  4. Planned changes

Correct Answer: 4

Explanation

Message center planned-change notifications provide administrators with information about upcoming Microsoft 365 changes that may affect users or services. Reviewing these messages allows organizations to understand what is changing, when changes may occur, and whether administrative preparation or communication is required. Deleted files, mailbox archive items, and device inventory do not provide information about upcoming Microsoft 365 service changes. Administrators can use Message center information as part of change management and preparation activities. Therefore, planned changes are the relevant information when preparing the organization for upcoming Microsoft 365 feature updates.

Question 298

A Microsoft 365 administrator wants to reduce unnecessary notifications by choosing which Message center communications are most relevant to the organization. Which feature can help?

  1. Intune device sync
  2. Message center preferences
  3. Exchange mailbox delegation
  4. SharePoint list views

Correct Answer: 2

Explanation

Message center preferences allow administrators to configure aspects of how Microsoft 365 change communications are presented and managed. By tailoring notification or preference settings, administrators can focus attention on information that is most relevant to their organization’s environment and responsibilities. SharePoint list views control how list data is displayed, Exchange mailbox delegation provides mailbox access permissions, and Intune device sync requests updated management information from devices. Therefore, Message center preferences are the appropriate feature when administrators want to manage how they receive or review Microsoft 365 change communications.

Question 299

Which Microsoft 365 capability provides employees with a social networking experience for sharing posts, discussions, and organizational conversations?

  1. Microsoft Intune
  2. Viva Engage
  3. Windows Autopilot
  4. Exchange Online Archive

Correct Answer: 2

Explanation

Viva Engage provides a social and community-oriented experience within Microsoft 365. Employees can use it to participate in conversations, share posts, ask questions, exchange knowledge, and engage with communities across an organization. It is designed to support employee communication and knowledge sharing rather than device management or mailbox storage. Exchange Online Archive manages older email, Windows Autopilot supports device provisioning, and Microsoft Intune manages devices and applications. Therefore, Viva Engage is the Microsoft 365 capability designed for organizational social interaction and community conversations.

Question 300

An organization wants users to collaborate on a project by combining structured information, pages, and content in a flexible Microsoft 365 workspace. Which tool is designed for this type of collaborative workspace?

  1. Microsoft Loop
  2. DNS MX record
  3. Defender Quarantine
  4. Exchange Online Archive

Correct Answer: 1

Explanation

Microsoft Loop provides a flexible collaborative workspace where users can organize information and work together using components, pages, and workspaces. It is designed for dynamic collaboration in which project information can be brought together and updated by multiple participants. Exchange Online Archive is used for older mailbox content, Defender Quarantine isolates potentially unsafe content, and DNS MX records direct email delivery. Therefore, Microsoft Loop is the appropriate Microsoft 365 tool when users need a flexible workspace for organizing and collaborating on project information.