Microsoft AB-900 Practice Test Questions and Exam Dumps Part1 Q1-20

View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.

 

Question 1

Which Microsoft 365 service is primarily used to manage users, groups, licenses, and organization settings from a centralized administration interface?

  1. Microsoft 365 admin center
  2. SharePoint admin center
  3. Teams admin center
  4. Exchange admin center

Correct Answer: 1

Explanation

The Microsoft 365 admin center provides a centralized location for administrators to manage many organization-wide settings and Microsoft 365 services. Administrators can manage users, groups, licenses, domains, and various organizational configurations from this portal. The SharePoint, Teams, and Exchange admin centers focus more specifically on their respective workloads. For AB-900, it is important to understand which administration center should be used for a particular task because Microsoft 365 contains several specialized management portals. The Microsoft 365 admin center is the primary starting point for many organization-level administrative operations.

Question 2

An administrator needs to configure a mailbox for a specific user. Which Microsoft 365 administration center should the administrator primarily use?

  1. Microsoft Purview portal
  2. Exchange admin center
  3. Microsoft 365 admin center
  4. Teams admin center

Correct Answer: 2

Explanation

The Exchange admin center is designed to manage Exchange Online objects and settings, including user mailboxes and distribution groups. When an administrator needs to perform mailbox-related configuration, Exchange-specific administration tools are appropriate. The Microsoft 365 admin center can handle broader user and license management, but it is not the primary specialized interface for detailed Exchange mailbox administration. Microsoft Purview focuses on compliance, governance, and data protection, while the Teams admin center manages Teams-related settings. Knowing which administration center manages particular Microsoft 365 objects is an important AB-900 skill.

Question 3

Which SharePoint object is primarily used to organize and store files so that users can collaborate on documents?

  1. Distribution group
  2. Channel
  3. Document library
  4. Mailbox

Correct Answer: 3

Explanation

A SharePoint document library is designed to store, organize, and manage files while supporting collaboration and access control. Libraries can contain folders and documents and can be associated with SharePoint sites used by teams or departments. Distribution groups are Exchange objects used for email communication, channels are Teams collaboration spaces, and mailboxes are Exchange objects used for email and related messaging. In AB-900, administrators should understand the basic objects used across Microsoft 365 services and recognize the appropriate object based on the task being performed.

Question 4

A company wants to control which Microsoft Teams features users can access based on organizational requirements. Which Teams object is most appropriate for applying these settings?

  1. SharePoint library
  2. Teams policy
  3. Exchange mailbox
  4. Microsoft Purview label

Correct Answer: 2

Explanation

Teams policies allow administrators to control various Teams capabilities and experiences for users. Depending on the policy type, administrators can manage features related to meetings, messaging, calling, and other Teams functionality. A SharePoint library is used for file storage, an Exchange mailbox handles email, and a Microsoft Purview label is associated with information protection and governance. AB-900 includes identifying the appropriate objects in Microsoft Teams administration. Understanding the difference between Teams policies and objects from other Microsoft 365 workloads helps administrators configure services correctly.

Question 5

Which principle of Zero Trust requires users and devices to be verified before access to organizational resources is granted?

  1. Assume breach
  2. Verify explicitly
  3. Trust internal networks
  4. Disable authentication

Correct Answer: 2

Explanation

The Zero Trust principle of “verify explicitly” requires organizations to authenticate and authorize access using relevant signals before granting access to resources. Instead of automatically trusting users or devices because they are inside a corporate network, Zero Trust assumes that access should be continuously evaluated. “Assume breach” is another important Zero Trust principle, but it focuses on operating as though compromise may already have occurred. AB-900 expects candidates to understand core Zero Trust concepts and how authentication, authorization, and security controls contribute to protecting Microsoft 365 resources.

Question 6

Which Microsoft Entra feature can require multifactor authentication when specific access conditions are met?

  1. Conditional Access
  2. SharePoint permissions
  3. Exchange transport rules
  4. Teams channels

Correct Answer: 1

Explanation

Microsoft Entra Conditional Access allows administrators to create policies that evaluate conditions before allowing access to organizational resources. A policy can require multifactor authentication based on factors such as user, application, location, device state, or risk. This helps organizations implement Zero Trust access controls instead of relying only on passwords. SharePoint permissions control access to SharePoint resources, Exchange transport rules manage mail flow, and Teams channels organize collaboration. For AB-900, recognizing Conditional Access as a central Microsoft Entra security capability is essential.

Question 7

A user wants to access several Microsoft 365 applications after signing in once rather than entering credentials repeatedly. Which capability supports this experience?

  1. Data Loss Prevention
  2. Privileged Identity Management
  3. Single sign-on
  4. Insider Risk Management

Correct Answer: 3

Explanation

Single sign-on, or SSO, allows users to authenticate once and then access multiple supported applications without repeatedly providing their credentials. Microsoft Entra ID can provide authentication and SSO capabilities for Microsoft 365 and other applications. This improves the user experience while allowing organizations to centrally manage authentication. Data Loss Prevention focuses on protecting sensitive information, Privileged Identity Management manages elevated administrative access, and Insider Risk Management helps identify potential risky activities. AB-900 candidates should understand SSO as an identity and access capability rather than a data protection feature.

Question 8

Which Microsoft Entra object is commonly used to represent an individual person who needs access to Microsoft 365 resources?

  1. User account
  2. Document library
  3. Sensitivity label
  4. Retention policy

Correct Answer: 1

Explanation

A user account in Microsoft Entra ID represents an individual identity that can be authenticated and assigned access to Microsoft 365 resources. Administrators can manage users, assign licenses, place users into groups, and apply appropriate access policies. A document library is a SharePoint storage object, while sensitivity labels and retention policies are Microsoft Purview capabilities used for information protection and governance. AB-900 requires knowledge of core Microsoft 365 objects, including users and groups, and how these objects support identity, access, and administration across Microsoft 365 services.

Question 9

Which Microsoft security capability is designed to help detect, investigate, and respond to threats across multiple Microsoft security products?

  1. Microsoft Defender XDR
  2. SharePoint document library
  3. Exchange Online
  4. Microsoft Planner

Correct Answer: 1

Explanation

Microsoft Defender XDR provides capabilities for detecting, investigating, and responding to threats across supported Microsoft security products. It can correlate signals from different security workloads to provide a broader view of incidents and threats. This cross-workload approach can help security teams investigate suspicious activity more efficiently. SharePoint is primarily a collaboration and content-management service, Exchange Online provides email and calendaring capabilities, and Planner supports task management. AB-900 includes foundational knowledge of threat protection and intelligence, including the role of Microsoft Defender XDR in Microsoft 365 security.

Question 10

An administrator wants to review records showing actions performed by users and administrators in Microsoft 365. Which capability should be used?

  1. Microsoft Teams channels
  2. Audit logs
  3. SharePoint libraries
  4. Exchange contacts

Correct Answer: 2

Explanation

Microsoft 365 audit logs provide records of activities performed by users and administrators across supported services. Administrators and security personnel can use audit information to investigate events, review administrative changes, and support compliance investigations. Audit logs are different from ordinary service objects such as Teams channels or SharePoint libraries. Exchange contacts are used for contact information and do not provide centralized activity auditing. For AB-900, understanding how audit logs help organizations review user and administrator activity is important because auditing supports security investigations, governance, and compliance requirements.

Question 11

Which Microsoft Purview capability is primarily intended to help prevent sensitive information from being improperly shared or transmitted?

  1. Microsoft Purview Data Loss Prevention
  2. Microsoft Entra SSO
  3. Microsoft Teams policy
  4. Exchange mailbox delegation

Correct Answer: 1

Explanation

Microsoft Purview Data Loss Prevention, commonly called DLP, helps organizations identify and protect sensitive information and reduce the risk of inappropriate sharing or transmission. DLP policies can evaluate activities involving sensitive data and apply organizational rules to help prevent unwanted data exposure. Microsoft Entra SSO addresses authentication, Teams policies manage Teams functionality, and mailbox delegation controls access to Exchange mailboxes. AB-900 covers Microsoft Purview as an important part of Microsoft 365 data protection and governance, so candidates should understand the primary purpose of DLP.

Question 12

A company wants to classify sensitive documents and apply protection settings based on their sensitivity. Which Microsoft Purview feature should administrators consider?

  1. Conditional Access
  2. Sensitivity labels
  3. Teams channels
  4. User accounts

Correct Answer: 2

Explanation

Microsoft Purview sensitivity labels allow organizations to classify and protect information according to its sensitivity. Labels can be configured to apply protection settings, such as encryption or access restrictions, depending on organizational requirements. They help users and administrators identify how information should be handled while supporting broader information protection strategies. Conditional Access is an identity and access control capability, Teams channels support collaboration, and user accounts represent identities. AB-900 candidates should understand the distinction between information protection features and identity-based security controls.

Question 13

Which Microsoft Purview capability helps organizations manage how long certain types of information should be retained or disposed of?

  1. Microsoft Defender XDR
  2. Conditional Access
  3. Data Lifecycle Management
  4. Privileged Identity Management

Correct Answer: 3

Explanation

Microsoft Purview Data Lifecycle Management provides capabilities for managing the retention and disposition of organizational information. Organizations can use retention settings to help ensure that certain content is retained for required periods and can establish processes for disposing of information when appropriate. Defender XDR focuses on security detection and response, Conditional Access controls access decisions, and Privileged Identity Management manages privileged roles. AB-900 includes data protection and governance tasks, making it important to understand how retention and lifecycle capabilities support organizational information-management requirements.

Question 14

Which Microsoft Entra capability is designed to provide just-in-time access to privileged roles and reduce unnecessary standing administrative permissions?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Purview DLP
  3. Microsoft Teams policy
  4. SharePoint version history

Correct Answer: 1

Explanation

Microsoft Entra Privileged Identity Management, or PIM, helps organizations manage privileged access by allowing eligible users to activate administrative roles when needed rather than maintaining permanent elevated permissions. Organizations can use controls such as approval requirements, time limits, and auditing to help manage privileged role activation. Microsoft Purview DLP protects sensitive information, Teams policies manage Teams functionality, and SharePoint version history helps track document changes. AB-900 includes the role of PIM as part of Microsoft 365 identity and security administration.

Question 15

Which Microsoft 365 object is designed to distribute email messages to multiple recipients using a common address?

  1. SharePoint site
  2. Distribution group
  3. Teams channel
  4. Sensitivity label

Correct Answer: 2

Explanation

An Exchange distribution group provides a common email address that can be used to send messages to multiple members. Instead of entering each recipient individually, a sender can address the distribution group and Exchange delivers the message to its members according to the group’s configuration. SharePoint sites are collaboration and content-management locations, Teams channels organize conversations and collaboration, and sensitivity labels classify or protect information. AB-900 expects candidates to recognize Exchange objects such as mailboxes and distribution groups and understand which administration center is used to manage them.

Question 16

A Microsoft 365 administrator needs to determine whether a user has permission to perform a particular operation on a resource. Which security concept is most directly involved?

  1. Authorization
  2. Data retention
  3. Threat intelligence
  4. Data classification

Correct Answer: 1

Explanation

Authorization determines what an authenticated user or identity is allowed to access or perform within a system. Authentication establishes that a user or identity is who they claim to be, while authorization determines the permissions granted after authentication. Data retention concerns how long information is kept, threat intelligence provides information about potential threats, and data classification helps categorize information. AB-900 distinguishes authentication from authorization because both are fundamental security concepts. Understanding this difference helps administrators correctly interpret Microsoft 365 identity and access controls.

Question 17

Which Microsoft Entra capability can help administrators investigate sign-in activity that may indicate a compromised account?

  1. SharePoint version history
  2. Teams meeting policy
  3. Risky sign-ins
  4. Exchange distribution groups

Correct Answer: 3

Explanation

Microsoft Entra risky sign-ins can help identify authentication events that Microsoft considers potentially suspicious based on available risk signals. Administrators can investigate these events and use appropriate identity security controls, including Conditional Access policies, to respond to risky authentication activity. SharePoint version history tracks document changes, Teams meeting policies control meeting behavior, and distribution groups manage email distribution. AB-900 includes troubleshooting common sign-in issues involving multifactor authentication, Conditional Access, and risky sign-ins, so recognizing risky sign-ins as an identity security signal is important.

Question 18

Which Microsoft 365 security capability is intended to help identify potentially risky behavior by users within an organization?

  1. Microsoft Purview Insider Risk Management
  2. Exchange Online mailbox
  3. SharePoint document library
  4. Teams channel

Correct Answer: 1

Explanation

Microsoft Purview Insider Risk Management helps organizations identify and investigate potentially risky activities associated with users. It can use signals and policies to help security and compliance teams identify behaviors that may present organizational risk while supporting appropriate investigation processes. Exchange mailboxes provide email functionality, SharePoint libraries store and manage documents, and Teams channels support collaboration. AB-900 includes Insider Risk Management as part of Microsoft Purview’s data protection and governance capabilities, so candidates should understand its purpose and distinguish it from general Microsoft 365 collaboration services.

Question 19

A company wants to register an application so that it can integrate with Microsoft identity and access services. Which Microsoft Entra object should the administrator use?

  1. Retention label
  2. App registration
  3. Distribution group
  4. SharePoint library

Correct Answer: 2

Explanation

An app registration in Microsoft Entra ID provides an identity configuration for an application and enables integration with Microsoft identity services. Administrators can configure application settings, permissions, authentication methods, and other identity-related properties depending on the application’s requirements. Retention labels are used for information governance, distribution groups support email distribution, and SharePoint libraries store documents. AB-900 includes app registrations and enterprise applications among its core Microsoft Entra topics. Understanding their purpose helps administrators identify the correct identity object when applications need to authenticate or access resources.

Question 20

Which Microsoft 365 capability provides a numerical measurement intended to help organizations understand and improve their security posture?

  1. Microsoft Teams analytics
  2. SharePoint storage metrics
  3. Identity Secure Score
  4. Exchange mailbox quota

Correct Answer: 3

Explanation

Identity Secure Score in Microsoft Entra provides an assessment of an organization’s identity security posture and can help administrators identify recommended improvements. It gives organizations a way to review security-related configurations and prioritize actions that can strengthen identity protection. Teams analytics, SharePoint storage metrics, and Exchange mailbox quotas serve different operational purposes and are not designed to provide an identity security posture measurement. AB-900 specifically includes interpreting Identity Secure Score, making it important to understand that it is intended to guide identity security improvements rather than measure general productivity.