View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.
Question 341
Which Microsoft Entra feature provides a temporary credential that can be used to bootstrap passwordless authentication registration?
- Temporary Access Pass
- Dynamic group
- Service principal
- Administrative unit
Correct Answer: 1
Explanation
A Temporary Access Pass, or TAP, is a time-limited credential in Microsoft Entra ID that can help users register passwordless authentication methods. It is particularly useful when a user does not yet have an established authentication method or needs assistance setting up a new passwordless credential. TAPs are temporary and can be configured with appropriate usage restrictions. Dynamic groups manage membership automatically, service principals represent applications, and administrative units organize users and devices for delegated administration. Therefore, Temporary Access Pass is the appropriate feature for bootstrapping passwordless authentication registration.
Question 342
An organization wants to delegate administration of users belonging to a specific department without granting the administrator control over all users in the tenant. Which Microsoft Entra feature can help?
- Security defaults
- Administrative units
- Mail flow rules
- Service health
Correct Answer: 2
Explanation
Microsoft Entra administrative units allow organizations to create scoped administrative boundaries for users, groups, and devices. An organization can place relevant objects into an administrative unit and assign supported administrative roles with permissions limited to those objects. This can help delegate responsibilities to regional or departmental administrators without granting unrestricted tenant-wide control. Security defaults provide baseline identity security settings, mail flow rules manage email processing, and Service health provides information about Microsoft services. Therefore, administrative units are appropriate when administration needs to be delegated within a defined organizational scope.
Question 343
Which Microsoft Entra capability allows an organization to define how collaboration and access are managed between its tenant and another Microsoft Entra organization?
- Cross-tenant access settings
- Microsoft Forms
- Exchange archive
- SharePoint version history
Correct Answer: 1
Explanation
Microsoft Entra cross-tenant access settings provide organizations with controls for managing collaboration and access between their tenant and other Microsoft Entra organizations. Administrators can configure inbound and outbound access policies according to organizational trust and collaboration requirements. This can help provide more controlled external collaboration than simply allowing unrestricted access. Microsoft Forms collects responses, Exchange archive stores mailbox content, and SharePoint version history maintains earlier document versions. Therefore, cross-tenant access settings are the appropriate feature when an organization needs to manage access relationships with another tenant.
Question 344
A company wants managers to periodically confirm whether employees still require access to selected groups or applications. Which Microsoft Entra feature should be used?
- Access reviews
- Domain verification
- Mailbox delegation
- Device restart
Correct Answer: 1
Explanation
Microsoft Entra access reviews help organizations periodically review whether users should continue to have access to groups, applications, or other supported resources. Reviewers can confirm appropriate access and identify permissions that are no longer necessary. This supports governance by helping organizations avoid retaining access indefinitely when business requirements change. Domain verification confirms control of a domain, mailbox delegation provides access to another user’s mailbox, and device restart is an endpoint action. Therefore, access reviews are the appropriate feature when managers need to periodically confirm whether employee access remains necessary.
Question 345
Which Microsoft Entra Identity Governance capability can help organizations manage user access packages for groups, applications, and resources through a controlled request process?
- Access packages
- Safe Attachments
- Message trace
- Device categories
Correct Answer: 1
Explanation
Microsoft Entra entitlement management uses access packages to organize and govern access to groups, applications, SharePoint sites, and other supported resources. Access packages can provide a controlled way for users to request access and for organizations to define approval, expiration, and review requirements. This helps manage access throughout its lifecycle rather than relying solely on manual permission assignments. Safe Attachments protects against malicious files, message trace investigates email delivery, and device categories help organize managed devices. Therefore, access packages are the appropriate capability for governed resource access requests.
Question 346
An administrator wants users to request access to a collection of organizational resources while enforcing approval and expiration requirements. Which Microsoft Entra service is designed for this scenario?
- Microsoft Entra entitlement management
- Exchange Online
- Microsoft Defender for Endpoint
- Microsoft Bookings
Correct Answer: 1
Explanation
Microsoft Entra entitlement management is designed to govern access to organizational resources through structured processes. Administrators can create access packages containing resources and configure policies that control how users request access, whether approval is required, and how long access remains valid. This provides a lifecycle-oriented approach to managing access rather than relying entirely on manual assignments. Exchange Online manages email, Defender for Endpoint provides endpoint security capabilities, and Microsoft Bookings handles appointment scheduling. Therefore, Microsoft Entra entitlement management is the appropriate service for controlled access requests involving multiple resources.
Question 347
An application requests permission to read organizational data through Microsoft Graph. Which action may be required before users can use the application when the requested permission requires administrator approval?
- Admin consent
- SharePoint version restore
- Device wipe
- Exchange archive
Correct Answer: 4
Explanation
Some Microsoft Graph permissions require administrator consent before an application can access organizational data. An administrator reviews the requested permissions and can grant consent when the application is considered appropriate for the organization’s requirements. This process helps prevent applications from receiving sensitive permissions without proper authorization. SharePoint version restore is related to document recovery, device wipe removes or protects endpoint data, and Exchange archive stores older mailbox content. Therefore, administrator consent is the relevant action when an application requires permissions that users cannot independently approve.
Question 348
Which Microsoft Defender for Office 365 policy is primarily designed to help protect users from fraudulent messages that attempt to impersonate trusted senders or organizations?
- Anti-phishing policy
- Retention policy
- Device compliance policy
- Site sharing policy
Correct Answer: 1
Explanation
Microsoft Defender for Office 365 anti-phishing policies help protect users against phishing attempts, including messages that use impersonation or other deceptive techniques. Administrators can configure protection settings that help identify suspicious messages and determine appropriate actions when threats are detected. Retention policies manage how information is retained, device compliance policies belong to endpoint management, and site sharing policies control collaboration access. Therefore, an anti-phishing policy is the appropriate Defender for Office 365 control when the organization wants to reduce threats involving fraudulent or impersonated senders.
Question 349
An organization wants to reduce unwanted bulk email and automatically classify suspicious messages as spam. Which Microsoft Defender for Office 365 policy should administrators review?
- Anti-spam policy
- Authentication strength
- Access review
- Site template
Correct Answer: 1
Explanation
Microsoft Defender for Office 365 anti-spam policies provide controls for handling unwanted and potentially suspicious email messages. Administrators can configure spam-related settings and actions to help reduce unwanted messages reaching user mailboxes. These policies complement other email protection capabilities such as anti-phishing and malware protection. Authentication strength controls sign-in requirements, access reviews evaluate continuing resource access, and site templates provide reusable SharePoint structures. Therefore, the anti-spam policy is the appropriate policy to review when an organization wants to manage unwanted bulk or spam email.
Question 350
An administrator needs to prevent a known malicious sender, domain, or URL from being allowed through email protection controls. Which Microsoft Defender feature can be used for this purpose?
- Tenant Allow/Block List
- Microsoft Bookings
- Intune device category
- SharePoint hub
Correct Answer: 1
Explanation
The Microsoft Defender Tenant Allow/Block List provides administrators with a mechanism for managing specific senders, domains, URLs, and other supported indicators that should be allowed or blocked according to organizational security requirements. It can be useful when administrators need to respond to known malicious or unwanted indicators. Microsoft Bookings manages appointments, Intune device categories organize managed devices, and SharePoint hubs connect related sites. Therefore, the Tenant Allow/Block List is the appropriate Defender feature for managing known indicators that require explicit blocking or allowing decisions.
Question 351
Which Microsoft Defender for Office 365 feature allows an organization to conduct controlled phishing simulations to help users practice recognizing suspicious messages?
- Attack simulation training
- Exchange archive
- SharePoint recycle bin
- Device enrollment
Correct Answer: 1
Explanation
Attack simulation training in Microsoft Defender for Office 365 allows organizations to conduct controlled simulations of phishing and other social engineering techniques. These simulations can help security teams evaluate user awareness and provide targeted training based on observed behavior. Because the simulations are designed for security education and assessment, they can be incorporated into an organization’s broader security awareness program. Exchange archive stores older mailbox content, SharePoint recycle bin stores deleted files, and device enrollment registers devices for management. Therefore, attack simulation training is the appropriate feature for controlled phishing simulations.
Question 352
A security analyst wants to create customized queries across Microsoft security data to investigate suspicious activity. Which Microsoft Defender capability should be used?
- Advanced hunting
- Microsoft Bookings
- SharePoint news
- Exchange automatic replies
Correct Answer: 1
Explanation
Microsoft Defender advanced hunting allows security analysts to create customized queries against available security data to investigate threats, suspicious activity, and potential security incidents. It provides a more flexible investigation approach than relying only on predefined alerts or dashboards. Analysts can use query-based investigation to identify patterns and relationships across available security telemetry. Microsoft Bookings manages appointments, SharePoint news publishes organizational information, and Exchange automatic replies communicate user availability. Therefore, advanced hunting is the appropriate Defender capability for customized security investigations using query-based analysis.
Question 353
A Microsoft Defender for Endpoint administrator wants to temporarily isolate a compromised device from the network while security personnel investigate it. Which action should be considered?
- Device isolation
- Site template creation
- Mailbox archive
- License reassignment
Correct Answer: 2
Explanation
Microsoft Defender for Endpoint provides device isolation capabilities that can help contain a compromised endpoint while security personnel investigate the incident. Isolation limits the device’s network communication while allowing required security management communication so that administrators can continue investigating and responding. This can reduce the potential for a compromised device to communicate with other systems or external threats. Site templates create reusable SharePoint structures, mailbox archives store email, and license reassignment changes user licensing. Therefore, device isolation is the appropriate security response for containing a potentially compromised endpoint.
Question 354
An organization wants to prevent unauthorized Windows devices from enrolling into Intune. Which Intune configuration should administrators review?
- Enrollment restrictions
- Microsoft Search
- Exchange message trace
- SharePoint version history
Correct Answer: 1
Explanation
Intune enrollment restrictions allow administrators to control which devices or platforms can enroll in the organization’s device management environment. These restrictions can help organizations prevent unsupported or unauthorized device types from being enrolled. Administrators can configure enrollment policies according to organizational requirements and supported platform conditions. Microsoft Search helps users find information, Exchange message trace investigates email delivery, and SharePoint version history manages document versions. Therefore, enrollment restrictions are the appropriate Intune configuration when an organization wants to control which devices are permitted to enroll.
Question 355
An organization has many inactive devices registered in Intune and wants to automatically remove stale device records after a defined period. Which capability should administrators consider?
- Device cleanup rules
- Safe Links
- Exchange moderation
- Microsoft Forms
Correct Answer: 1
Explanation
Intune device cleanup rules can help organizations manage stale or inactive device records by automatically removing records that meet configured inactivity conditions. This can reduce administrative clutter and make device inventories easier to manage. Administrators should configure cleanup carefully because removing records can affect how devices are represented in management systems. Safe Links protects users from malicious URLs, Exchange moderation controls message approval, and Microsoft Forms collects responses. Therefore, device cleanup rules are the appropriate capability when an organization needs to automatically remove stale Intune device records.
Question 356
An administrator wants to deploy an application to a selected group of Intune-managed devices and make installation mandatory. Which assignment type should be used?
- Required
- Available for enrolled devices
- Uninstall only
- Unassigned
Correct Answer: 1
Explanation
The Required assignment type in Intune is used when an application should be installed automatically for the targeted users or devices. This is appropriate when an organization needs to ensure that a specific application is present rather than simply making it available for optional installation. An Available assignment allows users to install an application when needed, while an Uninstall assignment removes an application from targeted devices. An unassigned application has no applicable deployment assignment. Therefore, Required is the appropriate assignment type when application installation must be enforced.
Question 357
Which Microsoft Intune capability can help administrators determine whether an assigned application successfully installed on targeted devices?
- App installation status
- Exchange message trace
- SharePoint site template
- Microsoft Search
Correct Answer: 1
Explanation
Intune app installation status provides administrators with information about application deployment results across targeted devices or users. Administrators can use deployment status information to identify successful installations and investigate devices where an application failed or remains pending. This is useful for troubleshooting application deployment and confirming whether required software has reached its intended targets. Exchange message trace investigates email delivery, SharePoint site templates create reusable site structures, and Microsoft Search locates information. Therefore, app installation status is the appropriate Intune capability for monitoring application deployment results.
Question 358
Which Microsoft service is designed to help organizations automate the deployment of Windows updates and reduce the administrative effort required to manage update rollouts?
- Windows Autopatch
- Microsoft Bookings
- Microsoft Forms
- SharePoint Online
Correct Answer: 1
Explanation
Windows Autopatch is designed to help organizations automate and simplify the management of updates for supported Microsoft software and Windows environments. It can help reduce the operational effort associated with manually planning and deploying updates across large numbers of devices. Automated update management can improve consistency while allowing organizations to follow Microsoft’s supported servicing approach. Microsoft Bookings manages appointments, Microsoft Forms collects responses, and SharePoint Online provides collaboration and content management capabilities. Therefore, Windows Autopatch is the appropriate service when the objective is to simplify Windows update management.
Question 359
An organization wants a Microsoft Purview retention policy to apply automatically to users based on attributes such as department or geographic location. Which capability can provide dynamic scoping for this purpose?
- Adaptive scopes
- Microsoft Search
- Teams app setup policy
- Exchange message trace
Correct Answer: 4
Explanation
Microsoft Purview adaptive scopes allow organizations to dynamically determine which users, groups, or sites are included in certain compliance policies based on defined attributes. This can reduce the need to manually maintain static lists when organizational membership changes. For example, a policy can target users according to department or other supported properties. Microsoft Search is used to find information, Teams app setup policies manage application presentation, and Exchange message trace investigates email delivery. Therefore, adaptive scopes are the appropriate Purview capability for dynamically targeting compliance policies.
Question 360
A compliance administrator needs to organize discovered electronic evidence into a workspace where relevant items can be reviewed and analyzed during an eDiscovery investigation. Which Microsoft Purview capability should be used?
- eDiscovery review set
- Microsoft Forms
- Device enrollment
- Exchange automatic replies
Correct Answer: 1
Explanation
A Microsoft Purview eDiscovery review set provides a workspace for organizing and reviewing collected electronic evidence during an eDiscovery investigation. After relevant content has been collected according to the investigation process, review sets can help legal or compliance teams examine, filter, and analyze the available material. Microsoft Forms is used for data collection through forms, device enrollment registers devices for management, and Exchange automatic replies communicate user availability. Therefore, an eDiscovery review set is the appropriate Purview capability for organizing and analyzing discovered evidence.