View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.
Question 221
Which DNS record is primarily used to verify ownership of a custom domain when adding it to Microsoft 365?
- MX record
- TXT record
- CNAME record
- SRV record
Correct Answer: 2
Explanation
A TXT record can be added to a domain’s DNS configuration to verify that an organization controls the domain. During Microsoft 365 domain setup, the administrator is provided with a unique TXT value that must be published by the domain’s DNS provider. Microsoft 365 checks the record to confirm ownership before allowing the domain to be configured for organizational services. This verification process helps prevent unauthorized organizations from claiming domains they do not control and is an important step when connecting a custom domain to Microsoft 365.
Question 222
An organization wants incoming email for its custom domain to be delivered to Exchange Online. Which DNS record should the administrator configure?
- CNAME
- TXT
- MX
- SRV
Correct Answer: 3
Explanation
An MX, or Mail Exchange, record identifies the mail server responsible for receiving email for a domain. When an organization uses Exchange Online, its domain’s MX record is configured to point email delivery toward Microsoft’s Exchange Online infrastructure. Mail systems on the internet use MX records to determine where messages should be sent. TXT records are commonly used for verification and email security information, while CNAME records provide aliases. Therefore, the MX record is the appropriate DNS record for directing incoming mail to Exchange Online.
Question 223
A Microsoft 365 administrator needs to automatically create an Exchange Online connection between Microsoft 365 and an external email system. Which feature should the administrator investigate?
- Mail flow connector
- Sensitivity label
- Retention label
- Device configuration profile
Correct Answer: 1
Explanation
Exchange Online mail flow connectors control how email messages move between Microsoft 365 and external or on-premises email systems. Organizations can configure connectors to establish trusted mail-flow paths and apply specific routing requirements. For example, a company transitioning from an on-premises messaging environment to Exchange Online may need a connector to support communication between the two environments. Sensitivity and retention labels are designed for information governance, while device configuration profiles belong to Intune. A mail flow connector is therefore the relevant feature for this scenario.
Question 224
Which Microsoft Defender for Office 365 feature helps protect users from malicious URLs by checking links when users click them?
- Safe Attachments
- Quarantine
- Safe Links
- Anti-spam policy
Correct Answer: 3
Explanation
Safe Links is a Microsoft Defender for Office 365 feature designed to help protect users from malicious web links. When a user interacts with a URL in a supported Microsoft 365 workload, Safe Links can analyze the destination and determine whether it is considered unsafe. This protection can help reduce the risk of phishing and other web-based threats. Safe Attachments focuses on potentially malicious files, while quarantine stores suspicious messages or content. Anti-spam policies primarily address unwanted email rather than performing the specific URL protection provided by Safe Links.
Question 225
A security administrator wants Microsoft 365 to scan email attachments for malicious content before users open them. Which feature should be configured?
- Safe Links
- Safe Attachments
- SharePoint hub site
- Microsoft Search
Correct Answer: 2
Explanation
Safe Attachments is designed to help protect users against malicious files delivered through email and other supported Microsoft 365 services. It analyzes attachments to identify potentially harmful content before the content reaches or is accessed by the user. This capability is particularly useful against threats that rely on malicious documents or files. Safe Links instead focuses on URLs, while SharePoint hub sites organize related SharePoint sites and Microsoft Search helps users locate information. Therefore, Safe Attachments is the appropriate feature when the primary security concern is malicious email attachments.
Question 226
A user reports that a legitimate email has been isolated by Microsoft 365 because it was considered suspicious. Where can an administrator review the isolated message?
- Microsoft Purview Data Explorer
- Microsoft Defender quarantine
- Microsoft Intune devices
- SharePoint recycle bin
Correct Answer: 2
Explanation
Microsoft Defender quarantine provides administrators with a central location to review messages and other content that Microsoft security controls have isolated. Depending on the detection and organizational policies, administrators may be able to release legitimate messages, delete unwanted content, or investigate why an item was quarantined. Purview Data Explorer is associated with data classification and governance, while Intune devices focuses on endpoint management. The SharePoint recycle bin is unrelated to email security. For a suspicious or incorrectly isolated email, the Defender quarantine is the appropriate administrative location.
Question 227
Which Microsoft Entra feature allows users to reset their own forgotten passwords without contacting the help desk?
- Self-service password reset
- Privileged Identity Management
- Enterprise applications
- Dynamic group membership
Correct Answer: 1
Explanation
Microsoft Entra self-service password reset allows users to reset their own passwords when they forget them or become unable to sign in. Organizations can configure authentication methods and policies that determine how users verify their identity during the reset process. This reduces the number of password-related support requests handled manually by help-desk staff. Privileged Identity Management is intended for managing privileged access, enterprise applications manage application access, and dynamic groups automatically maintain membership based on defined rules. Therefore, self-service password reset is the feature designed specifically for user-initiated password recovery.
Question 228
An organization wants to prevent users from choosing commonly used or weak passwords in Microsoft Entra ID. Which capability should be used?
- Authentication strengths
- Password protection
- Conditional Access
- Windows Autopilot
Correct Answer: 2
Explanation
Microsoft Entra password protection helps organizations reduce the use of weak or commonly known passwords. Administrators can use Microsoft-provided banned password lists and add organization-specific words or patterns that should not be used. This provides an additional layer of protection against password guessing and credential-based attacks. Authentication strengths determine which authentication methods are acceptable in particular access scenarios, while Conditional Access evaluates access conditions and Windows Autopilot focuses on device deployment. Password protection is therefore the capability directly associated with preventing users from selecting weak passwords.
Question 229
A company wants to require phishing-resistant authentication for access to a sensitive application. Which Microsoft Entra capability can define the required authentication method strength?
- Authentication strengths
- Microsoft Search
- OneDrive Files On-Demand
- Mail flow connectors
Correct Answer: 1
Explanation
Microsoft Entra authentication strengths allow administrators to specify which authentication methods must be used for particular access scenarios. An organization can configure an authentication strength that requires stronger methods, including phishing-resistant authentication, and then apply it through appropriate access policies. This helps organizations match authentication requirements to the sensitivity of applications and resources. Microsoft Search is used to find organizational information, OneDrive Files On-Demand manages local availability of cloud files, and mail flow connectors control email routing. Authentication strengths are therefore the relevant capability for enforcing stronger authentication requirements.
Question 230
A company provides employees with Windows devices and wants to automatically move known user folders such as Desktop and Documents into OneDrive. Which feature supports this requirement?
- SharePoint hub sites
- OneDrive Known Folder Move
- Exchange Online archive
- Microsoft Forms
Correct Answer: 2
Explanation
OneDrive Known Folder Move helps organizations redirect supported Windows user folders, such as Desktop, Documents, and Pictures, into OneDrive. Once configured, files stored in these folders can be synchronized with the user’s OneDrive account, helping protect data and make it available across supported devices. This approach can also simplify device replacement because important user files remain associated with the user’s cloud storage. SharePoint hub sites are used for site organization, Exchange Online archive manages mailbox data, and Microsoft Forms collects responses. Known Folder Move is specifically designed for this file-management scenario.
Question 231
Which SharePoint sharing option allows a user to share a file with only the specific people explicitly selected by the file owner?
- Anyone with the link
- People in the organization
- Specific people
- Public anonymous access
Correct Answer: 3
Explanation
The Specific people sharing option allows a SharePoint or OneDrive file to be shared with explicitly selected individuals. Access is limited to the people identified through the sharing process rather than being generally available to anyone who receives a link. This provides more controlled sharing when a document contains information intended for a defined group of recipients. An Anyone link provides broader access, while an organizational sharing option generally allows people within the organization to access the content. Specific people is therefore the appropriate option when access must be restricted to named recipients.
Question 232
An administrator wants related SharePoint sites to share navigation and organizational structure under a common central site. Which SharePoint feature should be considered?
- SharePoint hub site
- OneDrive recycle bin
- Exchange mailbox delegation
- Microsoft Lists
Correct Answer: 1
Explanation
A SharePoint hub site provides a way to connect related SharePoint sites under a common organizational structure. Sites associated with a hub can share navigation and other common elements, helping users discover related resources more easily. Hub sites are useful when an organization has multiple sites supporting departments, projects, or business functions that should remain separate while still being connected. OneDrive recycle bin handles deleted files, Exchange mailbox delegation manages mailbox permissions, and Microsoft Lists is used for structured information. The SharePoint hub site is the feature designed for connected site organization.
Question 233
A manager needs an assistant to send messages from a mailbox while making it clear that the message was sent on behalf of the manager. Which Exchange permission should be used?
- Send As
- Send on Behalf
- Full Access
- Receive As
Correct Answer: 2
Explanation
The Send on Behalf permission allows a user to send email representing another mailbox while indicating that the message was sent on behalf of that mailbox owner. This differs from Send As, where the recipient generally sees the message as being sent directly by the mailbox owner. Full Access provides access to mailbox contents but does not by itself grant the ability to send messages as or on behalf of another user. Therefore, when transparency about the sender is required and the message should identify the manager as the represented person, Send on Behalf is the appropriate permission.
Question 234
Which Exchange permission allows a delegate to send an email that appears to have been sent directly by the mailbox owner?
- Send As
- Send on Behalf
- Read Only
- Mailbox Audit
Correct Answer: 1
Explanation
Send As permission allows a delegate to send messages that appear to come directly from another mailbox. The recipient generally sees the mailbox owner’s address as the sender rather than a message indicating that it was sent on the owner’s behalf. This permission can be useful for shared operational mailboxes or situations where an authorized delegate must communicate using the mailbox identity. Send on Behalf produces a different sender presentation, while Read Only and mailbox auditing do not provide the ability to send messages. Therefore, Send As is the correct permission for this requirement.
Question 235
A company wants to allow users to access Microsoft 365 applications while keeping cloud files available without downloading every file to the device. Which OneDrive capability supports this?
- Safe Links
- Files On-Demand
- Exchange message trace
- Windows Hello for Business
Correct Answer: 2
Explanation
OneDrive Files On-Demand allows users to view and work with files stored in OneDrive without requiring every cloud file to be permanently downloaded to the local device. Files can appear in File Explorer while their actual contents remain in cloud storage until needed. This can reduce local storage requirements, particularly on devices with limited disk capacity. Safe Links protects users from malicious URLs, Exchange message trace investigates email delivery, and Windows Hello for Business provides authentication. Files On-Demand is therefore the capability that addresses cloud file availability without downloading everything locally.
Question 236
Which Microsoft Entra authentication capability allows administrators to define different authentication requirements for different access scenarios?
- Dynamic membership
- Authentication strengths
- Password protection
- Domain verification
Correct Answer: 2
Explanation
Authentication strengths provide administrators with a way to define acceptable authentication methods for specific access scenarios. For example, an organization can require stronger authentication for sensitive applications while allowing different authentication requirements for lower-risk resources. These requirements can then be incorporated into access policies to provide more appropriate protection based on the resource being accessed. Dynamic membership is used to automatically manage group membership, password protection helps block weak passwords, and domain verification confirms control of a domain. Authentication strengths are specifically intended to control the strength of authentication required for access.
Question 237
An administrator wants to find applications installed on managed devices through Microsoft Intune. Which type of information should the administrator review?
- Discovered apps
- Service health
- Message center
- Domain DNS records
Correct Answer: 1
Explanation
Intune discovered apps provides information about applications detected on managed devices. Administrators can use this information to understand which software is present across enrolled devices and identify applications that may require further management or review. This capability can support software inventory and device-management activities without requiring administrators to manually inspect every endpoint. Service health provides information about Microsoft cloud service status, Message center communicates important Microsoft 365 changes, and DNS records are used for domain configuration. Therefore, discovered apps is the appropriate Intune information source for reviewing installed application inventory.
Question 238
A user receives a Microsoft 365 application notification asking them to approve access to organizational information. Which concept determines what data or actions the application is allowed to access?
- Authorization
- Domain verification
- Mail routing
- Device enrollment
Correct Answer: 1
Explanation
Authorization determines what an authenticated user or application is permitted to access or perform. In Microsoft 365 and Microsoft Entra environments, an application may request specific permissions that define the resources or actions it can use. Administrators can review and control these permissions according to organizational requirements. Authentication establishes who or what is requesting access, while authorization determines what that identity is allowed to do. Domain verification is related to domain ownership, mail routing controls message delivery, and device enrollment registers devices with management services. Authorization is therefore the key concept in this scenario.
Question 239
Which Microsoft 365 application feature helps users locate organizational documents, people, and information across Microsoft 365 services?
- Microsoft Search
- Safe Attachments
- Exchange Online archive
- Windows Autopilot
Correct Answer: 1
Explanation
Microsoft Search helps users find relevant information across Microsoft 365 services and organizational content. Depending on permissions and the connected services, users can search for documents, people, sites, messages, and other information from supported Microsoft 365 experiences. Search results respect access permissions, meaning users should only receive content they are authorized to discover. Safe Attachments is a security capability for malicious files, Exchange Online archive manages older mailbox content, and Windows Autopilot supports device deployment. Microsoft Search is therefore the feature designed to help users locate organizational information efficiently.
Question 240
A company wants administrators to receive information about important Microsoft 365 changes that may require preparation or action. Which Microsoft 365 feature provides these announcements?
- Microsoft Search
- Message center
- OneDrive Files On-Demand
- Exchange Online archive
Correct Answer: 2
Explanation
The Microsoft 365 Message center provides administrators with information about planned changes, new features, service updates, and other developments that may affect an organization. Administrators can review messages to understand what is changing and determine whether preparation or administrative action may be necessary. This helps organizations stay informed about Microsoft 365 changes instead of discovering them only after they become visible to users. Microsoft Search helps locate information, Files On-Demand manages cloud file availability, and Exchange Online archive handles mailbox data. Therefore, Message center is the appropriate feature for administrative change announcements.