Microsoft 365 Certified: Administrator Expert practice questions
217 free questions with answers and explanations.
- 1.A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team wants to enable a seamless single sign-on experience for users accessing cloud applications, without exposing any on-premises domain controllers directly to the internet. They also prefer a solution that minimizes infrastructure overhead compared to a full federation solution. Which authentication method, combined with Seamless SSO, should be implemented?Implement and manage Microsoft Entra ID
- 2.A global manufacturing company uses Microsoft Entra ID for identity management. The company has several highly privileged roles, such as Global Administrator and Exchange Administrator. They want to implement a solution that ensures these roles are assigned with just-in-time (JIT) access and are automatically revoked after a set period, requiring re-activation for future use. Which Microsoft Entra ID governance feature should you implement?Implement and manage Microsoft Entra ID
- 3.A Microsoft 365 administrator needs to assign a custom domain, 'contoso.com', to their tenant. After adding the domain in the Microsoft 365 admin center, the system prompts the administrator to add a specific DNS record to verify ownership. Which type of DNS record is typically used for domain ownership verification during the initial setup of a custom domain in Microsoft 365?Deploy and manage a Microsoft 365 tenant
- 4.A Microsoft 365 administrator is setting up a new tenant and needs to ensure that users can only access Microsoft 365 resources from trusted devices. They also want to prevent users from downloading sensitive company data to unmanaged devices. Which feature should the administrator implement?Deploy and manage a Microsoft 365 tenant
- 5.A security analyst is investigating an incident where a user's machine was compromised. The analyst needs to quickly gather detailed information about network connections established by a malicious process, including remote IP addresses and ports, to understand the extent of the breach. Which table in Advanced Hunting in Microsoft Defender XDR should the analyst query to retrieve this information?Implement and manage Microsoft Defender XDR
- 6.A Microsoft 365 administrator is configuring a new tenant. They need to ensure that all user identities are managed by their on-premises Active Directory and synchronized to Azure AD. Users should authenticate against the on-premises directory when accessing Microsoft 365 services. Which identity model should the administrator implement?Deploy and manage a Microsoft 365 tenant
- 7.A company is implementing Microsoft Entra ID governance. They want to ensure that all new users are automatically assigned to appropriate groups and have the necessary licenses based on their department. This assignment should be dynamic and update automatically if a user's department changes. Which Microsoft Entra ID governance feature should you use?Implement and manage Microsoft Entra ID
- 8.A Microsoft 365 administrator is configuring a new tenant and needs to ensure that all user accounts created in the tenant are assigned a default usage location. This is critical for compliance with regional service availability and feature enablement. Which setting in Azure AD should the administrator configure to achieve this?Deploy and manage a Microsoft 365 tenant
- 9.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a new set of Windows 11 client devices. The organization has a strict security posture that requires limiting the execution of unsigned scripts and potentially malicious macros in Office applications. The administrator wants to implement a proactive defense mechanism that blocks these types of activities without relying solely on signature-based detection. Which Defender for Endpoint capability should be used to achieve this goal?Implement and manage Microsoft Defender XDR
- 10.A Microsoft 365 administrator is required to implement a security policy that automatically blocks access to Microsoft 365 applications if a user's sign-in is detected as 'high risk' by Azure AD Identity Protection. Which type of policy in Azure AD should the administrator configure?Deploy and manage a Microsoft 365 tenant
- 11.A global manufacturing company uses Microsoft 365 and has recently experienced several sophisticated phishing attacks targeting their supply chain partners. These attacks often involve highly personalized emails with malicious URLs embedded. The security team wants to implement a robust solution within Microsoft Defender for Office 365 that specifically protects users from clicking on unsafe links in emails, even if the links are initially deemed safe but later become malicious. Which feature should the administrator configure?Implement and manage Microsoft Defender XDR
- 12.A company is implementing Microsoft 365 and needs to ensure that all administrative actions performed by global administrators, user administrators, and Exchange administrators are logged and available for auditing for at least one year. Which Microsoft 365 feature should the administrator configure to meet this requirement?Deploy and manage a Microsoft 365 tenant
- 13.A Microsoft 365 administrator notices that some users are experiencing delays when accessing SharePoint Online sites and OneDrive files, particularly during peak hours. The tenant's overall service health appears green, and network diagnostics show no local issues. The administrator suspects a potential bottleneck within the Microsoft 365 service infrastructure itself. Which tool should the administrator use to investigate more granular performance metrics and potential service-side issues impacting their tenant?Deploy and manage a Microsoft 365 tenant
- 14.A security operations center (SOC) team uses Microsoft Defender XDR and frequently performs advanced hunting queries to proactively search for threats. They need to create a custom detection rule that identifies any new executable files (EXE) created on critical servers from a remote share, specifically looking for files that have not been observed before within the organization. The rule should trigger an alert if such an event occurs. Which Advanced Hunting table should be the primary source for detecting new file creations on devices?Implement and manage Microsoft Defender XDR
- 15.A company is planning to implement Microsoft Entra ID for identity management. They have an existing on-premises Active Directory Domain Services (AD DS) environment. The security team insists that user passwords must *never* leave the on-premises network and that users should authenticate directly against the on-premises AD DS. Which Microsoft Entra Connect authentication method should you recommend?Implement and manage Microsoft Entra ID
- 16.A Microsoft 365 administrator is configuring a new tenant and needs to set up a group that automatically includes all users from the 'Sales' department whose 'City' attribute is set to 'New York'. The group should update its membership dynamically as user attributes change. Which type of group should the administrator create in Azure AD to meet these requirements?Deploy and manage a Microsoft 365 tenant
- 17.A company is planning to implement Microsoft Entra Connect Cloud Sync to synchronize users from a single on-premises Active Directory Domain Services (AD DS) domain. They have identified several Organizational Units (OUs) within this domain that contain legacy user accounts and service accounts that should *not* be synchronized to Microsoft Entra ID. You need to ensure that only specific OUs are synchronized. How should you configure Cloud Sync to achieve this?Implement and manage Microsoft Entra ID
- 18.A company is using Microsoft 365 and has several departments, each with its own set of SharePoint sites and Microsoft Teams. The IT department wants to create a new administrator role that can manage SharePoint site collections and Teams settings ONLY for the Sales department, without affecting other departments. Which type of administrative unit should be created to delegate this specific scope of administration?Deploy and manage a Microsoft 365 tenant
- 19.A Microsoft 365 administrator is performing an advanced hunting query in Microsoft Defender XDR to investigate a potential data exfiltration incident. The analyst needs to identify all files that were accessed by a specific user account (UserA) on a particular device (DeviceX) within the last 24 hours and were subsequently uploaded to a cloud storage application. The query must correlate file access events with cloud application upload activities. Which KQL operator should the analyst use to combine these two distinct data sets effectively?Implement and manage Microsoft Defender XDR
- 20.A Microsoft 365 tenant administrator is reviewing the tenant's service health. They notice several advisories indicating degraded performance for Exchange Online in their region. Where is the most authoritative and up-to-date information regarding the status of Microsoft 365 services, including any ongoing incidents or planned maintenance, typically found?Deploy and manage a Microsoft 365 tenant
- 21.A Microsoft 365 administrator is reviewing the security posture of their organization using Microsoft Defender XDR. They notice a significant number of alerts related to users accessing cloud applications that are not approved by the company's IT policy. The administrator needs to gain better visibility into all cloud applications being used by employees, sanctioned or unsanctioned, and assess their risk levels. Which component of Microsoft Defender for Cloud Apps provides this capability?Implement and manage Microsoft Defender XDR
- 22.A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team has mandated that user password hashes must be synchronized to Microsoft Entra ID to enable cloud-only authentication scenarios, but also requires that users can sign in using their on-premises credentials. Which authentication method should be configured?Implement and manage Microsoft Entra ID
- 23.A Microsoft 365 administrator is preparing to decommission a custom domain, 'olddomain.com', from their Microsoft 365 tenant. The administrator has already removed all users and groups associated with 'olddomain.com'. Before attempting to remove the domain, what is the next critical prerequisite the administrator must ensure is met?Deploy and manage a Microsoft 365 tenant
- 24.A security operations center (SOC) analyst is investigating an alert generated by Microsoft Defender for Identity concerning a 'Suspicious service creation' on a domain controller. The alert details indicate that an attacker successfully created a new service, potentially for persistence. Which specific type of sensor deployed on the domain controller is responsible for detecting this activity?Implement and manage Microsoft Defender XDR
- 25.A large enterprise with multiple Active Directory forests needs to synchronize user identities to Microsoft Entra ID. They want to maintain a single authoritative source for identity management and ensure that only unique, non-conflicting user objects are provisioned to the cloud. They also require granular control over attribute flow and have complex custom attribute requirements. Which component of Microsoft Entra Connect is primarily responsible for defining how objects and attributes are processed and flowed between connected directories?Implement and manage Microsoft Entra ID
- 26.A Microsoft 365 administrator is managing user accounts. They need to create a new user account for a contractor who requires access to specific Microsoft 365 services for a limited period. The contractor's access should automatically expire after 90 days. Which type of user account should the administrator create to meet this requirement efficiently?Deploy and manage a Microsoft 365 tenant
- 27.A Microsoft 365 administrator is onboarding a new employee, Alex. Alex will be part of the Marketing department and requires access to all SharePoint sites and Microsoft Teams associated with Marketing. The administrator wants to automate Alex's access provisioning and ensure that Alex is automatically removed from these resources if they leave the Marketing department. Which feature should the administrator use to achieve this?Deploy and manage a Microsoft 365 tenant
- 28.A consultant is helping a client migrate user identities to Microsoft Entra ID. The client has chosen Password Hash Synchronization (PHS) as the authentication method. The client is concerned about the availability of authentication services during potential outages of the primary Microsoft Entra Connect server. You need to ensure that PHS remains resilient and available even if the primary server fails. What should you recommend?Implement and manage Microsoft Entra ID
- 29.A Microsoft 365 administrator is investigating a potential insider threat. They need to review the activities of a specific user across various Microsoft 365 services, including email, SharePoint, and Teams, to identify any suspicious actions related to data exfiltration. Which feature in Microsoft 365 Defender provides a unified view of a user's activities across these services?Implement and manage Microsoft Defender XDR
- 30.A company is deploying Microsoft Entra Connect and needs to ensure high availability for its synchronization service. They plan to install two Microsoft Entra Connect servers. How should these servers be configured to provide fault tolerance and failover capabilities?Implement and manage Microsoft Entra ID
- 31.A company is implementing Microsoft Entra Identity Protection to enhance security. They want to automatically block sign-ins from IP addresses that are detected as malicious. Additionally, for users signing in from 'risky' locations (e.g., unusual travel), they want to enforce multi-factor authentication (MFA). Which type of policy in Microsoft Entra Identity Protection should be configured to achieve these outcomes?Implement and manage Microsoft Entra ID
- 32.A Microsoft 365 administrator is setting up a new tenant for a company that frequently collaborates with external partners. The company wants to allow external users to access specific SharePoint Online sites and Microsoft Teams channels, but they need to ensure that these external users are only granted access for a limited time and must re-request access after expiration. Which Azure AD feature should the administrator configure to manage this requirement?Deploy and manage a Microsoft 365 tenant
- 33.A company is implementing Microsoft Entra Connect. They have a single on-premises Active Directory forest with 10,000 user accounts. However, due to compliance regulations, only users located in the 'Sales' and 'Marketing' departments should be synchronized to Microsoft Entra ID. All other users, including service accounts and administrative accounts, must remain on-premises and not be replicated to the cloud. You need to configure Microsoft Entra Connect to meet this requirement. Which filtering method should you use?Implement and manage Microsoft Entra ID
- 34.A company is migrating its on-premises user accounts to Microsoft 365. The security team mandates that all user identities must be managed centrally from the on-premises Active Directory and that users should experience a single sign-on experience when accessing Microsoft 365 services. Which synchronization method should be implemented to meet these requirements?Deploy and manage a Microsoft 365 tenant
- 35.A Microsoft 365 administrator needs to integrate security alerts and raw event data from Microsoft Defender XDR with an external Security Information and Event Management (SIEM) system for centralized logging and long-term retention. The integration must provide a continuous, real-time stream of all available security data. Which Defender XDR feature should the administrator configure for this purpose?Implement and manage Microsoft Defender XDR
- 36.A consultant is assisting a small business with implementing Microsoft Entra Connect. The business has a single on-premises Active Directory domain, 'contoso.local', with approximately 300 user objects. They prefer a solution that requires minimal infrastructure, is resilient, and can be deployed quickly without significant changes to their network. They are also concerned about high availability of the synchronization service. Which Microsoft Entra Connect deployment option would best fit these requirements?Implement and manage Microsoft Entra ID
- 37.A Microsoft 365 administrator needs to ensure that all user accounts created in the tenant have a default usage location set to 'United States' to comply with licensing requirements for specific services. Where in the Microsoft 365 admin center can this default setting be configured?Deploy and manage a Microsoft 365 tenant
- 38.A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team has mandated that, for disaster recovery purposes, user authentication must remain functional even if the on-premises Active Directory Domain Services (AD DS) becomes temporarily unavailable. Which authentication method should you choose for Microsoft Entra Connect to meet this requirement?Implement and manage Microsoft Entra ID
- 39.An organization is setting up Microsoft Entra Connect to synchronize identities from its on-premises Active Directory to Microsoft Entra ID. They have several Organizational Units (OUs) that contain service accounts and disabled user accounts which should NOT be synchronized to Microsoft Entra ID to reduce clutter and improve security. Which feature of Microsoft Entra Connect should be configured to exclude these specific OUs?Implement and manage Microsoft Entra ID
- 40.A company is performing a phased rollout of Microsoft Entra Connect. They have installed the Microsoft Entra Connect software on a secondary server in their data center but do not want it to actively synchronize any changes to Microsoft Entra ID yet. They need to thoroughly test the synchronization rules and verify the impact of the configuration before enabling full synchronization. Which operational mode should the secondary Microsoft Entra Connect server be configured in?Implement and manage Microsoft Entra ID
- 41.A company has recently acquired another organization. Both companies use Microsoft Entra ID. You need to enable seamless collaboration and resource sharing between users from both organizations without creating duplicate user accounts or synchronizing user data. Which Microsoft Entra ID feature should you implement?Implement and manage Microsoft Entra ID
- 42.A Microsoft 365 administrator is configuring email routing for a new custom domain, 'example.com', which will be used for all user mailboxes in Exchange Online. After adding and verifying the domain, the administrator needs to ensure that all incoming emails for 'example.com' are correctly delivered to the Exchange Online mailboxes. Which type of DNS record must be configured for email to flow correctly to Exchange Online?Deploy and manage a Microsoft 365 tenant
- 43.A Microsoft 365 administrator is notified that users in a specific department are experiencing slow loading times and intermittent disconnections when accessing Microsoft Teams and SharePoint Online. Other departments are not reporting similar issues. The administrator suspects a network performance problem. Which dashboard or tool should the administrator use to investigate this issue?Deploy and manage a Microsoft 365 tenant
- 44.A Microsoft 365 administrator is setting up a new tenant. The organization requires that all user data, including Exchange Online mailboxes and SharePoint Online sites, reside within a specific geographic region to comply with data residency regulations. Which Microsoft 365 feature should the administrator configure to meet this requirement?Deploy and manage a Microsoft 365 tenant
- 45.A Microsoft 365 administrator needs to assign a custom domain, 'contoso.com', to their tenant. The domain is currently registered with a third-party registrar. Which DNS record type is primarily used to verify domain ownership during the custom domain setup process in Microsoft 365?Deploy and manage a Microsoft 365 tenant
- 46.A company has a Microsoft 365 E5 subscription. They want to ensure that all user accounts are protected with multi-factor authentication (MFA) and that access to Microsoft 365 services is blocked if a user signs in from an unfamiliar location or an infected device. Which Azure AD feature should be configured to achieve this comprehensive security posture?Deploy and manage a Microsoft 365 tenant
- 47.A company is planning to deploy Microsoft 365 and wants to ensure that all user data, including email, documents, and chat messages, remains within a specific geographic region (e.g., Europe) to comply with data residency regulations. Which Microsoft 365 feature is designed to address this requirement for data at rest?Deploy and manage a Microsoft 365 tenant
- 48.A Microsoft 365 administrator is setting up a new Microsoft 365 tenant. The organization requires that all new user accounts created for employees automatically include their department name in the user principal name (UPN) and email address, following the format 'firstname.lastname@department.contoso.com'. Additionally, these users should also be members of an Azure AD security group corresponding to their department. Which combination of features should the administrator leverage to automate this user provisioning and management?Deploy and manage a Microsoft 365 tenant
- 49.A global manufacturing company uses Microsoft Entra ID for identity management. The company has a strict policy that administrators should only have elevated permissions for a limited time when performing specific tasks. They also need to ensure that all administrative actions are auditable. Which Microsoft Entra ID governance feature should be implemented to meet these requirements?Implement and manage Microsoft Entra ID
- 50.A Microsoft 365 administrator is implementing a new security policy that requires all sensitive documents shared externally via Microsoft SharePoint Online to be automatically labeled and encrypted. The organization uses Microsoft Information Protection (MIP) sensitivity labels. Which Microsoft Defender for Cloud Apps policy type should the administrator configure to enforce this requirement?Implement and manage Microsoft Defender XDR