{"id":15222,"date":"2026-09-17T11:08:01","date_gmt":"2026-09-17T11:08:01","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15222"},"modified":"2026-09-17T11:08:01","modified_gmt":"2026-09-17T11:08:01","slug":"microsoft-ab-900-practice-test-questions-and-exam-dumps-part1-q1-20","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ab-900-practice-test-questions-and-exam-dumps-part1-q1-20\/","title":{"rendered":"Microsoft AB-900 Practice Test Questions and Exam Dumps Part1 Q1-20"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ab-900-exam-dumps\"><b>Microsoft AB-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 1<\/b><\/h3>\n<p><b>Which Microsoft 365 service is primarily used to manage users, groups, licenses, and organization settings from a centralized administration interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 admin center provides a centralized location for administrators to manage many organization-wide settings and Microsoft 365 services. Administrators can manage users, groups, licenses, domains, and various organizational configurations from this portal. The SharePoint, Teams, and Exchange admin centers focus more specifically on their respective workloads. For AB-900, it is important to understand which administration center should be used for a particular task because Microsoft 365 contains several specialized management portals. The Microsoft 365 admin center is the primary starting point for many organization-level administrative operations.<\/span><\/p>\n<h3><b>Question 2<\/b><\/h3>\n<p><b>An administrator needs to configure a mailbox for a specific user. Which Microsoft 365 administration center should the administrator primarily use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Exchange admin center is designed to manage Exchange Online objects and settings, including user mailboxes and distribution groups. When an administrator needs to perform mailbox-related configuration, Exchange-specific administration tools are appropriate. The Microsoft 365 admin center can handle broader user and license management, but it is not the primary specialized interface for detailed Exchange mailbox administration. Microsoft Purview focuses on compliance, governance, and data protection, while the Teams admin center manages Teams-related settings. Knowing which administration center manages particular Microsoft 365 objects is an important AB-900 skill.<\/span><\/p>\n<h3><b>Question 3<\/b><\/h3>\n<p><b>Which SharePoint object is primarily used to organize and store files so that users can collaborate on documents?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distribution group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Channel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Document library<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mailbox<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A SharePoint document library is designed to store, organize, and manage files while supporting collaboration and access control. Libraries can contain folders and documents and can be associated with SharePoint sites used by teams or departments. Distribution groups are Exchange objects used for email communication, channels are Teams collaboration spaces, and mailboxes are Exchange objects used for email and related messaging. In AB-900, administrators should understand the basic objects used across Microsoft 365 services and recognize the appropriate object based on the task being performed.<\/span><\/p>\n<h3><b>Question 4<\/b><\/h3>\n<p><b>A company wants to control which Microsoft Teams features users can access based on organizational requirements. Which Teams object is most appropriate for applying these settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint library<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mailbox<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview label<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Teams policies allow administrators to control various Teams capabilities and experiences for users. Depending on the policy type, administrators can manage features related to meetings, messaging, calling, and other Teams functionality. A SharePoint library is used for file storage, an Exchange mailbox handles email, and a Microsoft Purview label is associated with information protection and governance. AB-900 includes identifying the appropriate objects in Microsoft Teams administration. Understanding the difference between Teams policies and objects from other Microsoft 365 workloads helps administrators configure services correctly.<\/span><\/p>\n<h3><b>Question 5<\/b><\/h3>\n<p><b>Which principle of Zero Trust requires users and devices to be verified before access to organizational resources is granted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assume breach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Verify explicitly<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trust internal networks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Zero Trust principle of \u201cverify explicitly\u201d requires organizations to authenticate and authorize access using relevant signals before granting access to resources. Instead of automatically trusting users or devices because they are inside a corporate network, Zero Trust assumes that access should be continuously evaluated. \u201cAssume breach\u201d is another important Zero Trust principle, but it focuses on operating as though compromise may already have occurred. AB-900 expects candidates to understand core Zero Trust concepts and how authentication, authorization, and security controls contribute to protecting Microsoft 365 resources.<\/span><\/p>\n<h3><b>Question 6<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can require multifactor authentication when specific access conditions are met?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange transport rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams channels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access allows administrators to create policies that evaluate conditions before allowing access to organizational resources. A policy can require multifactor authentication based on factors such as user, application, location, device state, or risk. This helps organizations implement Zero Trust access controls instead of relying only on passwords. SharePoint permissions control access to SharePoint resources, Exchange transport rules manage mail flow, and Teams channels organize collaboration. For AB-900, recognizing Conditional Access as a central Microsoft Entra security capability is essential.<\/span><\/p>\n<h3><b>Question 7<\/b><\/h3>\n<p><b>A user wants to access several Microsoft 365 applications after signing in once rather than entering credentials repeatedly. Which capability supports this experience?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Insider Risk Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Single sign-on, or SSO, allows users to authenticate once and then access multiple supported applications without repeatedly providing their credentials. Microsoft Entra ID can provide authentication and SSO capabilities for Microsoft 365 and other applications. This improves the user experience while allowing organizations to centrally manage authentication. Data Loss Prevention focuses on protecting sensitive information, Privileged Identity Management manages elevated administrative access, and Insider Risk Management helps identify potential risky activities. AB-900 candidates should understand SSO as an identity and access capability rather than a data protection feature.<\/span><\/p>\n<h3><b>Question 8<\/b><\/h3>\n<p><b>Which Microsoft Entra object is commonly used to represent an individual person who needs access to Microsoft 365 resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Document library<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitivity label<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A user account in Microsoft Entra ID represents an individual identity that can be authenticated and assigned access to Microsoft 365 resources. Administrators can manage users, assign licenses, place users into groups, and apply appropriate access policies. A document library is a SharePoint storage object, while sensitivity labels and retention policies are Microsoft Purview capabilities used for information protection and governance. AB-900 requires knowledge of core Microsoft 365 objects, including users and groups, and how these objects support identity, access, and administration across Microsoft 365 services.<\/span><\/p>\n<h3><b>Question 9<\/b><\/h3>\n<p><b>Which Microsoft security capability is designed to help detect, investigate, and respond to threats across multiple Microsoft security products?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint document library<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Planner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR provides capabilities for detecting, investigating, and responding to threats across supported Microsoft security products. It can correlate signals from different security workloads to provide a broader view of incidents and threats. This cross-workload approach can help security teams investigate suspicious activity more efficiently. SharePoint is primarily a collaboration and content-management service, Exchange Online provides email and calendaring capabilities, and Planner supports task management. AB-900 includes foundational knowledge of threat protection and intelligence, including the role of Microsoft Defender XDR in Microsoft 365 security.<\/span><\/p>\n<h3><b>Question 10<\/b><\/h3>\n<p><b>An administrator wants to review records showing actions performed by users and administrators in Microsoft 365. Which capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams channels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint libraries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange contacts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 audit logs provide records of activities performed by users and administrators across supported services. Administrators and security personnel can use audit information to investigate events, review administrative changes, and support compliance investigations. Audit logs are different from ordinary service objects such as Teams channels or SharePoint libraries. Exchange contacts are used for contact information and do not provide centralized activity auditing. For AB-900, understanding how audit logs help organizations review user and administrator activity is important because auditing supports security investigations, governance, and compliance requirements.<\/span><\/p>\n<h3><b>Question 11<\/b><\/h3>\n<p><b>Which Microsoft Purview capability is primarily intended to help prevent sensitive information from being improperly shared or transmitted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra SSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mailbox delegation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention, commonly called DLP, helps organizations identify and protect sensitive information and reduce the risk of inappropriate sharing or transmission. DLP policies can evaluate activities involving sensitive data and apply organizational rules to help prevent unwanted data exposure. Microsoft Entra SSO addresses authentication, Teams policies manage Teams functionality, and mailbox delegation controls access to Exchange mailboxes. AB-900 covers Microsoft Purview as an important part of Microsoft 365 data protection and governance, so candidates should understand the primary purpose of DLP.<\/span><\/p>\n<h3><b>Question 12<\/b><\/h3>\n<p><b>A company wants to classify sensitive documents and apply protection settings based on their sensitivity. Which Microsoft Purview feature should administrators consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitivity labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams channels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels allow organizations to classify and protect information according to its sensitivity. Labels can be configured to apply protection settings, such as encryption or access restrictions, depending on organizational requirements. They help users and administrators identify how information should be handled while supporting broader information protection strategies. Conditional Access is an identity and access control capability, Teams channels support collaboration, and user accounts represent identities. AB-900 candidates should understand the distinction between information protection features and identity-based security controls.<\/span><\/p>\n<h3><b>Question 13<\/b><\/h3>\n<p><b>Which Microsoft Purview capability helps organizations manage how long certain types of information should be retained or disposed of?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Lifecycle Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Identity Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Lifecycle Management provides capabilities for managing the retention and disposition of organizational information. Organizations can use retention settings to help ensure that certain content is retained for required periods and can establish processes for disposing of information when appropriate. Defender XDR focuses on security detection and response, Conditional Access controls access decisions, and Privileged Identity Management manages privileged roles. AB-900 includes data protection and governance tasks, making it important to understand how retention and lifecycle capabilities support organizational information-management requirements.<\/span><\/p>\n<h3><b>Question 14<\/b><\/h3>\n<p><b>Which Microsoft Entra capability is designed to provide just-in-time access to privileged roles and reduce unnecessary standing administrative permissions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint version history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management, or PIM, helps organizations manage privileged access by allowing eligible users to activate administrative roles when needed rather than maintaining permanent elevated permissions. Organizations can use controls such as approval requirements, time limits, and auditing to help manage privileged role activation. Microsoft Purview DLP protects sensitive information, Teams policies manage Teams functionality, and SharePoint version history helps track document changes. AB-900 includes the role of PIM as part of Microsoft 365 identity and security administration.<\/span><\/p>\n<h3><b>Question 15<\/b><\/h3>\n<p><b>Which Microsoft 365 object is designed to distribute email messages to multiple recipients using a common address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distribution group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams channel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitivity label<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Exchange distribution group provides a common email address that can be used to send messages to multiple members. Instead of entering each recipient individually, a sender can address the distribution group and Exchange delivers the message to its members according to the group&#8217;s configuration. SharePoint sites are collaboration and content-management locations, Teams channels organize conversations and collaboration, and sensitivity labels classify or protect information. AB-900 expects candidates to recognize Exchange objects such as mailboxes and distribution groups and understand which administration center is used to manage them.<\/span><\/p>\n<h3><b>Question 16<\/b><\/h3>\n<p><b>A Microsoft 365 administrator needs to determine whether a user has permission to perform a particular operation on a resource. Which security concept is most directly involved?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authorization determines what an authenticated user or identity is allowed to access or perform within a system. Authentication establishes that a user or identity is who they claim to be, while authorization determines the permissions granted after authentication. Data retention concerns how long information is kept, threat intelligence provides information about potential threats, and data classification helps categorize information. AB-900 distinguishes authentication from authorization because both are fundamental security concepts. Understanding this difference helps administrators correctly interpret Microsoft 365 identity and access controls.<\/span><\/p>\n<h3><b>Question 17<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can help administrators investigate sign-in activity that may indicate a compromised account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint version history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams meeting policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risky sign-ins<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange distribution groups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra risky sign-ins can help identify authentication events that Microsoft considers potentially suspicious based on available risk signals. Administrators can investigate these events and use appropriate identity security controls, including Conditional Access policies, to respond to risky authentication activity. SharePoint version history tracks document changes, Teams meeting policies control meeting behavior, and distribution groups manage email distribution. AB-900 includes troubleshooting common sign-in issues involving multifactor authentication, Conditional Access, and risky sign-ins, so recognizing risky sign-ins as an identity security signal is important.<\/span><\/p>\n<h3><b>Question 18<\/b><\/h3>\n<p><b>Which Microsoft 365 security capability is intended to help identify potentially risky behavior by users within an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Insider Risk Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online mailbox<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint document library<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams channel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Insider Risk Management helps organizations identify and investigate potentially risky activities associated with users. It can use signals and policies to help security and compliance teams identify behaviors that may present organizational risk while supporting appropriate investigation processes. Exchange mailboxes provide email functionality, SharePoint libraries store and manage documents, and Teams channels support collaboration. AB-900 includes Insider Risk Management as part of Microsoft Purview&#8217;s data protection and governance capabilities, so candidates should understand its purpose and distinguish it from general Microsoft 365 collaboration services.<\/span><\/p>\n<h3><b>Question 19<\/b><\/h3>\n<p><b>A company wants to register an application so that it can integrate with Microsoft identity and access services. Which Microsoft Entra object should the administrator use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention label<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App registration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distribution group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint library<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An app registration in Microsoft Entra ID provides an identity configuration for an application and enables integration with Microsoft identity services. Administrators can configure application settings, permissions, authentication methods, and other identity-related properties depending on the application&#8217;s requirements. Retention labels are used for information governance, distribution groups support email distribution, and SharePoint libraries store documents. AB-900 includes app registrations and enterprise applications among its core Microsoft Entra topics. Understanding their purpose helps administrators identify the correct identity object when applications need to authenticate or access resources.<\/span><\/p>\n<h3><b>Question 20<\/b><\/h3>\n<p><b>Which Microsoft 365 capability provides a numerical measurement intended to help organizations understand and improve their security posture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint storage metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mailbox quota<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity Secure Score in Microsoft Entra provides an assessment of an organization&#8217;s identity security posture and can help administrators identify recommended improvements. It gives organizations a way to review security-related configurations and prioritize actions that can strengthen identity protection. Teams analytics, SharePoint storage metrics, and Exchange mailbox quotas serve different operational purposes and are not designed to provide an identity security posture measurement. AB-900 specifically includes interpreting Identity Secure Score, making it important to understand that it is intended to guide identity security improvements rather than measure general productivity.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps. &nbsp; Question 1 Which Microsoft 365 service is primarily used to manage users, groups, licenses, and organization settings from a centralized administration interface? Microsoft 365 admin center SharePoint admin center Teams admin center Exchange admin center Correct Answer: 1 Explanation The Microsoft 365 admin center [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15222"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15222"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15222\/revisions"}],"predecessor-version":[{"id":15268,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15222\/revisions\/15268"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}