Microsoft AB-900 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps.

 

Question 61

Which Microsoft 365 service provides a centralized location for administrators to review recommendations related to the organization’s security posture?

  1. Microsoft Bookings
  2. Microsoft Forms
  3. Microsoft Secure Score
  4. Microsoft Lists

Correct Answer: 3

Explanation

Microsoft Secure Score helps organizations evaluate and improve their security posture by providing recommendations for security-related actions. Administrators can review available improvement actions and determine which changes are appropriate for their environment. The score can help organizations prioritize security improvements rather than simply reporting individual incidents. Microsoft Bookings manages appointments, Forms collects information, and Lists organizes structured data. AB-900 includes security posture concepts and Secure Score, so candidates should recognize it as a resource for improving security configurations across Microsoft 365 rather than as a service for productivity or collaboration.

Question 62

Which Microsoft Defender capability is designed to protect users from malicious links and attachments delivered through email?

  1. Microsoft Defender for Office 365
  2. Microsoft Defender for Cloud
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Endpoint

Correct Answer: 1

Explanation

Microsoft Defender for Office 365 provides protection for Microsoft 365 collaboration and communication workloads, including email. Its capabilities can help protect users against threats such as malicious links, harmful attachments, phishing attempts, and other email-based attacks. Defender for Endpoint focuses on devices, Defender for Identity focuses on identity-related signals and on-premises identities, and Defender for Cloud provides cloud security capabilities. AB-900 includes Microsoft Defender capabilities, so understanding which Defender product protects Microsoft 365 communication workloads is important when selecting the appropriate security solution.

Question 63

Which Microsoft Defender product is primarily focused on protecting organizational devices such as Windows computers?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender for Office 365
  4. Microsoft Defender for Cloud Apps

Correct Answer: 2

Explanation

Microsoft Defender for Endpoint is designed to provide security capabilities for endpoints such as computers and other supported devices. It helps organizations detect, investigate, and respond to endpoint threats and provides visibility into device-related security activity. Defender for Identity focuses on identity signals, Defender for Office 365 protects Microsoft 365 email and collaboration workloads, and Defender for Cloud Apps provides visibility and control for cloud applications. AB-900 includes foundational Defender concepts, so recognizing Defender for Endpoint as the product focused on endpoint protection is essential.

Question 64

Which Microsoft Defender product helps organizations detect identity-based threats involving on-premises Active Directory identities?

  1. Microsoft Defender for Cloud
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Office 365

Correct Answer: 3

Explanation

Microsoft Defender for Identity is designed to help organizations detect and investigate identity-based threats involving on-premises Active Directory environments. It uses signals from identity activity to help security teams identify suspicious behavior and potential attacks. Defender for Endpoint protects devices, Defender for Office 365 focuses on email and collaboration threats, and Defender for Cloud provides cloud security capabilities. AB-900 includes Microsoft security products and their primary purposes, so candidates should understand which Defender solution addresses identity-related threats and distinguish it from endpoint and email protection.

Question 65

Which Microsoft Defender capability provides visibility into cloud applications and can help organizations identify and control the use of unsanctioned cloud services?

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Defender for Identity
  3. Microsoft Defender for Endpoint
  4. Microsoft Defender for Office 365

Correct Answer: 1

Explanation

Microsoft Defender for Cloud Apps provides visibility and security controls for cloud applications. Organizations can use it to discover cloud application usage, assess risks, and apply controls to improve the security of cloud-based services. This can help administrators identify applications that employees may be using without formal organizational approval. Defender for Identity focuses on identity threats, Defender for Endpoint protects devices, and Defender for Office 365 protects Microsoft 365 communication workloads. AB-900 includes understanding Microsoft Defender products and selecting the appropriate capability for cloud application security.

Question 66

An organization wants to protect employee devices by ensuring that only approved security configurations are maintained. Which Microsoft service is designed for centralized device management?

  1. Microsoft Intune
  2. Microsoft Forms
  3. Microsoft Planner
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Microsoft Intune provides cloud-based endpoint management capabilities that allow organizations to manage devices, applications, configuration policies, and compliance requirements. Administrators can use Intune to establish organizational settings and help ensure that managed devices meet defined requirements. Forms, Planner, and Bookings are productivity applications and do not provide centralized device-management capabilities. AB-900 includes Microsoft Intune fundamentals and its relationship with device management and compliance. Understanding the purpose of Intune helps administrators distinguish endpoint-management responsibilities from Microsoft 365 productivity and collaboration services.

Question 67

What is the primary purpose of a device compliance policy in Microsoft Intune?

  1. To determine whether a device meets defined organizational requirements
  2. To create Exchange mailboxes
  3. To classify SharePoint documents
  4. To create Microsoft Teams channels

Correct Answer: 1

Explanation

An Intune device compliance policy evaluates whether a device meets organizational requirements. These requirements can include conditions related to operating system versions, security settings, encryption, passwords, or other supported compliance criteria. Compliance information can then be used with other Microsoft security and access capabilities to help control access to organizational resources. Exchange mailboxes, SharePoint documents, and Teams channels are separate workloads. AB-900 includes device management and compliance concepts, so candidates should understand that a compliance policy assesses device state rather than directly managing email, files, or Teams collaboration spaces.

Question 68

Which Microsoft Intune capability allows administrators to configure organizational settings on managed devices without manually configuring each device?

  1. Configuration policies
  2. Audit searches
  3. Retention labels
  4. Distribution groups

Correct Answer: 1

Explanation

Intune configuration policies allow administrators to define and deploy device settings centrally. Instead of configuring every managed device manually, administrators can create policies containing appropriate settings and assign them to users or devices. Audit searches are associated with activity investigation, retention labels support information governance, and distribution groups facilitate email communication. AB-900 includes Intune configuration and device-management concepts, so understanding how policies simplify administration is important. Centralized configuration can help organizations maintain consistent device settings while reducing repetitive administrative tasks.

Question 69

A company wants to deploy a business application automatically to managed employee devices. Which Microsoft Intune capability can support this requirement?

  1. Application management
  2. Communication Compliance
  3. Data Lifecycle Management
  4. Sensitivity labeling

Correct Answer: 1

Explanation

Microsoft Intune application management allows administrators to deploy and manage applications on supported devices. Administrators can configure applications and assignments so that required software is made available or installed according to organizational policies. Communication Compliance focuses on communications, Data Lifecycle Management manages information retention and disposition, and sensitivity labels classify and protect content. AB-900 includes application management within Microsoft Intune, making it important to understand that Intune is not limited to device configuration; it can also help organizations centrally manage applications on managed endpoints.

Question 70

Which Microsoft 365 capability can help an administrator determine whether a user has the appropriate license for a particular service?

  1. License assignment information
  2. SharePoint version history
  3. Teams chat history
  4. Purview Activity Explorer

Correct Answer: 1

Explanation

License assignment information in the Microsoft 365 administration environment allows administrators to review which licenses are assigned to users and what services those licenses provide. When a user cannot access a Microsoft 365 capability, checking licensing can be an important troubleshooting step. SharePoint version history tracks changes to files, Teams chat history relates to collaboration content, and Purview Activity Explorer provides visibility into certain data-related activities. AB-900 includes licensing and service access concepts, so administrators should consider licensing when investigating why a user cannot access a particular Microsoft 365 service.

Question 71

Which Microsoft 365 administration capability allows an administrator to assign an administrative role to a user while limiting the permissions available to that user?

  1. Role-based access control
  2. Data classification
  3. Retention management
  4. Message tracing

Correct Answer: 1

Explanation

Role-based access control, or RBAC, assigns permissions based on defined administrative roles. Instead of giving every administrator unrestricted access, organizations can assign roles that provide only the permissions required for specific responsibilities. This supports the principle of least privilege and can reduce unnecessary administrative access. Data classification concerns information categorization, retention management controls information lifecycle requirements, and message tracing investigates email delivery. AB-900 includes Microsoft 365 administrative roles and role-based access, so candidates should understand why assigning appropriate roles is preferable to granting excessive privileges.

Question 72

Which Microsoft Entra concept represents the process of proving that a user is who they claim to be?

  1. Authorization
  2. Authentication
  3. Retention
  4. Classification

Correct Answer: 2

Explanation

Authentication is the process of verifying the identity of a user, device, or other security principal. Common authentication methods include passwords, multifactor authentication, passwordless methods, and other supported identity technologies. Authorization occurs after authentication and determines what the authenticated identity is allowed to access or perform. Retention and classification relate to information governance rather than identity verification. AB-900 includes authentication fundamentals, so understanding the distinction between authentication and authorization is essential when working with Microsoft Entra ID and Microsoft 365 access controls.

Question 73

Which security principle recommends granting users only the permissions required to perform their assigned responsibilities?

  1. Least privilege
  2. Open access
  3. Anonymous administration
  4. Unlimited delegation

Correct Answer: 1

Explanation

The principle of least privilege recommends providing users and administrators with only the permissions necessary to perform their required tasks. Limiting permissions can reduce the potential impact of compromised accounts or accidental administrative actions. It is an important security principle used across Microsoft 365 and Microsoft Entra environments. Open access, anonymous administration, and unlimited delegation do not represent secure permission-management approaches. AB-900 includes identity and security fundamentals, so understanding least privilege helps candidates recognize why organizations should avoid granting excessive permissions to users or administrators.

Question 74

Which Microsoft 365 capability allows administrators to delegate selected administrative tasks without making a user a Global Administrator?

  1. Microsoft Entra built-in roles
  2. SharePoint document libraries
  3. Microsoft Forms
  4. Microsoft Bookings

Correct Answer: 1

Explanation

Microsoft Entra built-in roles allow organizations to delegate administrative responsibilities by assigning predefined roles with specific permissions. This approach supports least privilege because administrators can give users the capabilities required for their responsibilities without automatically granting unrestricted Global Administrator access. SharePoint document libraries manage content, Forms supports surveys and quizzes, and Bookings manages appointments. AB-900 includes Microsoft 365 administrative roles and permissions, so understanding delegated administration is important for organizations that need to distribute administrative responsibilities while maintaining appropriate security controls.

Question 75

Which Microsoft 365 feature can be used to recover a previous version of a document when version history is enabled?

  1. SharePoint version history
  2. Microsoft Entra sign-in logs
  3. Exchange message trace
  4. Conditional Access

Correct Answer: 1

Explanation

SharePoint version history records earlier versions of supported documents and allows users or administrators with appropriate permissions to review or restore previous versions. This can be useful when content is accidentally changed, overwritten, or deleted from a document. Microsoft Entra sign-in logs provide authentication information, Exchange message trace helps investigate email delivery, and Conditional Access controls access decisions. AB-900 includes SharePoint collaboration and document-management concepts, so candidates should understand version history as a content-management feature rather than a security authentication or messaging tool.

Question 76

Which Microsoft 365 feature helps an administrator investigate why an email message was delayed, rejected, or not delivered to a recipient?

  1. Message trace
  2. Secure Score
  3. Data Explorer
  4. App registration

Correct Answer: 1

Explanation

Exchange Online message trace helps administrators investigate the movement and delivery status of email messages. It can provide useful information when troubleshooting problems such as delayed, rejected, or missing messages. Secure Score focuses on security posture, Data Explorer supports investigation of sensitive information, and app registrations provide application identity configuration. AB-900 includes troubleshooting common Microsoft 365 service issues, so administrators should know that message trace is an appropriate Exchange administration tool when investigating email delivery problems.

Question 77

Which Microsoft 365 administration feature allows administrators to review whether Microsoft services are currently experiencing a known outage or advisory?

  1. Service health
  2. Version history
  3. Device compliance
  4. Data classification

Correct Answer: 1

Explanation

Service health in the Microsoft 365 admin center provides information about current service incidents and advisories affecting Microsoft 365 services. Administrators can use this information to determine whether an issue reported by users may be caused by a known Microsoft service problem rather than an organization-specific configuration. Version history tracks document changes, device compliance evaluates endpoint requirements, and data classification categorizes information. AB-900 includes monitoring service health as part of Microsoft 365 administration and troubleshooting, making it an important first step when investigating widespread service problems.

Question 78

An administrator wants to receive notifications when important Microsoft 365 service incidents occur. Which capability can support this requirement?

  1. Service health notifications
  2. SharePoint version history
  3. Sensitivity labels
  4. Teams channels

Correct Answer: 1

Explanation

Service health notifications can help administrators stay informed about important Microsoft 365 incidents and advisories. Configuring appropriate notifications can reduce the need for administrators to repeatedly check the administration center manually and can help them respond more quickly to service-related events. SharePoint version history, sensitivity labels, and Teams channels serve different purposes and do not provide the same centralized service-health notification function. AB-900 includes Microsoft 365 service health and administrative monitoring, so understanding how administrators receive information about service incidents is important for effective operational management.

Question 79

Which Microsoft 365 capability can help administrators manage support requests and communicate with Microsoft regarding service issues?

  1. Service requests in the Microsoft 365 admin center
  2. SharePoint document libraries
  3. Microsoft Forms
  4. Microsoft Lists

Correct Answer: 1

Explanation

The Microsoft 365 admin center provides capabilities for creating and managing service requests when administrators need assistance with Microsoft 365 issues. Administrators can use support functionality to communicate relevant information to Microsoft and track the progress of support cases. SharePoint document libraries, Forms, and Lists provide collaboration or productivity capabilities but are not the primary mechanism for managing Microsoft support requests. AB-900 includes support and troubleshooting concepts, so candidates should recognize the Microsoft 365 admin center as an important starting point when an issue requires assistance from Microsoft.

Question 80

Which Microsoft 365 feature can help an administrator identify whether a recently changed configuration may be responsible for a service problem?

  1. Change history
  2. Microsoft Forms
  3. Microsoft Bookings
  4. Teams reactions

Correct Answer: 1

Explanation

Change history can help administrators review configuration changes made within supported Microsoft 365 administration experiences. When a service begins behaving unexpectedly after a configuration change, reviewing recent changes can help identify what was modified and provide useful information during troubleshooting. Forms, Bookings, and Teams reactions are productivity or collaboration features and do not provide centralized configuration-change tracking. AB-900 includes troubleshooting and administration concepts, so understanding how administrators can use change information to investigate configuration-related issues is important when diagnosing Microsoft 365 service problems.