Microsoft 365 Certified: Administrator Expert practice questions

217 free questions with answers and explanations.

Practice test
  1. 51.A company is deploying Microsoft Entra Connect to synchronize identities from its on-premises Active Directory Domain Services (AD DS). The security team has mandated that user passwords should not be stored in Microsoft Entra ID, but users should still be able to sign in using their on-premises credentials. Additionally, the company already has an existing Active Directory Federation Services (AD FS) farm deployed and wants to leverage it for single sign-on (SSO) to Microsoft 365 and other Microsoft Entra ID-connected applications. Which Microsoft Entra Connect authentication method should you configure?Implement and manage Microsoft Entra ID
  2. 52.A Microsoft 365 administrator is implementing a new policy for Microsoft 365 Groups. They need to ensure that all new groups created adhere to a specific naming convention, such as 'Dept_Groupname_Region', and that certain words, like 'HR' or 'Finance', are blocked from being used in group names unless specifically approved. Which Microsoft 365 feature should the administrator configure?Deploy and manage a Microsoft 365 tenant
  3. 53.A company is onboarding 5,000 new Windows 11 devices to Microsoft Defender for Endpoint. The security team requires that these devices are onboarded using a method that is scalable, automated, and integrates seamlessly with their existing Microsoft Intune environment for device management. Which onboarding method should the administrator choose?Implement and manage Microsoft Defender XDR
  4. 54.A healthcare organization is using Microsoft Defender for Identity to protect its on-premises Active Directory. Due to strict compliance requirements, they need to ensure that all domain controllers are monitored for suspicious activities, including potential Pass-the-Hash attacks and other credential theft attempts. They also need to minimize the performance impact on the domain controllers. Which component of Microsoft Defender for Identity should be deployed directly on each domain controller?Implement and manage Microsoft Defender XDR
  5. 55.A Microsoft 365 administrator is investigating an alert in Microsoft Defender XDR that indicates a potential supply chain attack. The alert shows that a digitally signed application, which is typically trusted, has exhibited highly suspicious behavior, including attempting to inject code into another process and making unusual network connections. The organization wants to ensure that even trusted applications are monitored for anomalous behavior. Which Defender for Endpoint capability would be most effective in detecting this type of post-execution suspicious behavior from a seemingly legitimate application?Implement and manage Microsoft Defender XDR
  6. 56.An organization is setting up Microsoft Entra Connect to synchronize identities from its on-premises Active Directory to Microsoft Entra ID. The organization has several organizational units (OUs) that contain service accounts and disabled user accounts that should NOT be synchronized to Microsoft Entra ID. How can you prevent these specific OUs from synchronizing?Implement and manage Microsoft Entra ID
  7. 57.A Microsoft 365 administrator is preparing to deploy Microsoft Teams for a large organization. The organization wants to ensure that all Teams meetings, including recordings and chat messages, are automatically retained for a minimum of five years to comply with regulatory requirements. Which Microsoft 365 compliance feature should the administrator configure?Deploy and manage a Microsoft 365 tenant
  8. 58.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint. The organization wants to block specific applications from launching on all Windows 10 and 11 devices across the organization. These applications are known to be used for non-business purposes and pose a security risk. Which feature should the administrator configure to achieve this?Implement and manage Microsoft Defender XDR
  9. 59.A Microsoft 365 administrator is investigating a complex attack scenario where an attacker attempted to gain unauthorized access to an on-premises application server. The attacker used a compromised service account to perform multiple reconnaissance activities, followed by an attempt to escalate privileges. The administrator needs to query the authentication activities specifically involving service accounts over the past 7 days to identify all logon attempts, source IPs, and success/failure statuses. Which Advanced Hunting table in Microsoft Defender XDR should be primarily queried to gather this information efficiently?Implement and manage Microsoft Defender XDR
  10. 60.A Microsoft 365 administrator is investigating a series of suspicious login attempts originating from unusual geographic locations for several executive accounts. These attempts did not result in successful logins, but the administrator wants to enhance protection specifically for these high-value accounts against future brute-force or credential stuffing attacks. Which Microsoft Defender for Identity capability should the administrator configure?Implement and manage Microsoft Defender XDR
  11. 61.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a new organization. The administrator needs to ensure that all devices onboarding to Defender for Endpoint automatically receive the latest security updates and are configured with recommended security settings based on Microsoft's best practices. Which component of Defender for Endpoint should the administrator leverage to achieve this goal?Implement and manage Microsoft Defender XDR
  12. 62.A large enterprise uses Microsoft Entra ID and has implemented Microsoft Entra Connect for hybrid identity. They have a strict security policy that requires all Global Administrators to re-authenticate every hour when accessing sensitive resources, regardless of other Conditional Access policies. Other users should have a normal sign-in frequency. You need to configure this requirement. Which Conditional Access control should you use?Implement and manage Microsoft Entra ID
  13. 63.A company uses Microsoft Defender for Office 365. Users report receiving phishing emails that contain malicious URLs, even though Safe Links is enabled. Upon investigation, the administrator discovers that the URLs are within attachments (e.g., PDF documents) and are not being rewritten by Safe Links. What is the most likely reason for this behavior?Implement and manage Microsoft Defender XDR
  14. 64.A Microsoft 365 administrator is planning to migrate a large number of user mailboxes from an on-premises Exchange Server 2016 environment to Exchange Online. The organization requires a seamless co-existence during the migration, allowing users to remain on-premises or in the cloud without disruption, and for mail flow to function bi-directionally. Which deployment model should the administrator choose?Deploy and manage a Microsoft 365 tenant
  15. 65.A Microsoft 365 administrator is configuring email routing for a new custom domain, 'example.com', in their tenant. They have added the domain and verified ownership. What specific DNS record type must be configured in the public DNS records for 'example.com' to ensure that all incoming emails are correctly delivered to the Exchange Online mailboxes?Deploy and manage a Microsoft 365 tenant
  16. 66.A Microsoft 365 administrator is configuring a new tenant for a global organization. The organization has a strict policy that requires all user data for employees in the European Union to be stored within the EU data residency boundaries. Which Microsoft 365 feature should the administrator configure to meet this requirement?Deploy and manage a Microsoft 365 tenant
  17. 67.A company is planning to deploy Microsoft Entra Connect. They have two on-premises Active Directory forests, Forest A and Forest B, both with separate Active Directory schemas. Users in Forest A need to access resources in Microsoft 365, and users in Forest B need to access different resources in Microsoft 365. You need to synchronize users from both forests into a single Microsoft Entra ID tenant. Which deployment topology should you use for Microsoft Entra Connect?Implement and manage Microsoft Entra ID
  18. 68.A Microsoft 365 administrator is implementing a new security policy that requires all administrative actions in the tenant to be logged and auditable for a period of one year. This includes actions performed by global administrators, user administrators, and other privileged roles. Which feature must the administrator enable to ensure this logging occurs across all relevant Microsoft 365 services?Deploy and manage a Microsoft 365 tenant
  19. 69.A Microsoft 365 administrator is configuring a new tenant for a legal firm. The firm requires that all communications, including emails and Microsoft Teams chats, be retained for seven years for compliance purposes, even if users delete them. Which Microsoft 365 feature should the administrator implement to meet this requirement?Deploy and manage a Microsoft 365 tenant
  20. 70.A company is using Microsoft Entra ID to manage identities and has deployed Microsoft Entra Connect to synchronize users from its on-premises Active Directory. They have a specific requirement to ensure that users can only access sensitive cloud applications when they are physically present in one of the company's designated office locations. Access from any other location, including remote work or personal networks, should be blocked. Which Microsoft Entra Conditional Access component should be configured to enforce this policy?Implement and manage Microsoft Entra ID
  21. 71.A Microsoft 365 administrator is configuring Microsoft Defender for Office 365. The organization wants to ensure that all email messages containing specific sensitive keywords (e.g., 'Confidential Project X', 'Patent Application Y') are quarantined before delivery to user inboxes. Which type of policy should the administrator create?Implement and manage Microsoft Defender XDR
  22. 72.A global manufacturing company uses Microsoft Entra ID for identity management. The company has several highly privileged roles, such as Global Administrator and Exchange Administrator, which are frequently assigned to IT personnel for short-term tasks. The security team wants to ensure that these privileged roles are only active when absolutely necessary and that their usage is audited. Which Microsoft Entra ID governance feature should you implement?Implement and manage Microsoft Entra ID
  23. 73.A Microsoft 365 administrator is onboarding a new user, John Doe. John needs access to specific SharePoint sites, Microsoft Teams, and an email inbox. The administrator assigns John a Microsoft 365 E3 license. After a few hours, John reports that he cannot access Teams or his email, although he can log in to the Microsoft 365 portal. The administrator verifies the license is assigned correctly. What is the MOST likely reason for John's inability to access these services?Deploy and manage a Microsoft 365 tenant
  24. 74.A Microsoft 365 administrator is managing user accounts. The organization has a policy that all user accounts must have a 'Usage Location' attribute set to 'United States' to ensure proper licensing and service availability. The administrator needs to automate the setting of this attribute for all new user accounts created directly in Azure AD. Which method should the administrator use?Deploy and manage a Microsoft 365 tenant
  25. 75.A global administrator has enabled Azure AD Privileged Identity Management (PIM) for their Microsoft 365 tenant. They want to ensure that all users assigned to the 'Global Administrator' role must provide a justification and multi-factor authentication (MFA) when activating the role. Additionally, the activation period for this role should be limited to a maximum of four hours. Which PIM role setting should the administrator configure to meet these requirements?Deploy and manage a Microsoft 365 tenant
  26. 76.A Microsoft 365 administrator is investigating a series of sophisticated phishing attacks where users are tricked into clicking malicious links that lead to credential harvesting sites. The organization uses Microsoft Defender for Office 365. To prevent future attacks, the administrator needs to ensure that all email links are rewritten and scanned at the time of click, even if a link was initially deemed safe. Additionally, a custom block list of known malicious URLs must be applied globally. Which Defender for Office 365 policy should the administrator configure to achieve these requirements?Implement and manage Microsoft Defender XDR
  27. 77.A Microsoft 365 administrator is implementing a new security policy that requires all sensitive documents shared externally via SharePoint Online or OneDrive for Business to be automatically encrypted and restricted from further sharing or downloading by unauthorized recipients. Which Microsoft Defender XDR component, in conjunction with Microsoft Purview Information Protection, should the administrator leverage?Implement and manage Microsoft Defender XDR
  28. 78.A Microsoft 365 administrator is preparing to decommission an old custom domain, 'olddomain.com', from their tenant. This domain was previously used for email and SharePoint site addresses. Before removing the domain, the administrator needs to ensure that no users, groups, or services are still associated with 'olddomain.com'. What is the MOST critical initial step to identify all remaining dependencies on this domain?Deploy and manage a Microsoft 365 tenant
  29. 79.A company is implementing Microsoft Entra Connect to synchronize users from a single on-premises Active Directory forest to Microsoft Entra ID. They need to ensure that only users whose 'department' attribute is set to 'Sales' or 'Marketing' are synchronized. Which filtering method should be used?Implement and manage Microsoft Entra ID
  30. 80.A company is migrating its email services to Exchange Online. They have an existing on-premises Active Directory and want to synchronize user accounts to Azure AD, allowing users to use their existing on-premises credentials to access Microsoft 365 services. The company does NOT want to deploy additional servers for identity federation. Which authentication method should the administrator implement?Deploy and manage a Microsoft 365 tenant
  31. 81.A Microsoft 365 administrator is onboarding a new employee, Alex. Alex will be part of the Sales department and requires access to specific applications and resources. The company uses Azure AD group-based licensing and dynamic groups for resource access. Which attribute should the administrator configure for Alex's user account to ensure automatic assignment to the correct Sales department groups and licenses?Deploy and manage a Microsoft 365 tenant
  32. 82.A global administrator has enabled Azure AD Privileged Identity Management (PIM) in their Microsoft 365 tenant. They want to ensure that users assigned to the 'Global Administrator' role must always justify their elevated access and have it automatically revoked after a maximum of 4 hours. Which PIM setting should be configured for the Global Administrator role?Deploy and manage a Microsoft 365 tenant
  33. 83.A Microsoft 365 administrator is managing a new tenant for a startup company. The company wants to ensure that all administrative actions performed by global administrators are logged and available for review for compliance purposes. Which Microsoft 365 service should the administrator configure to meet this requirement?Deploy and manage a Microsoft 365 tenant
  34. 84.A Microsoft 365 administrator is auditing the roles assigned to users in their tenant. They discover that several users have been assigned the 'Global Administrator' role for an extended period, which violates the company's least privilege policy. The administrator wants to ensure that these highly privileged roles are assigned only when needed and for a limited duration, requiring explicit activation and approval. Which Azure AD feature should the administrator implement?Deploy and manage a Microsoft 365 tenant
  35. 85.A company is migrating its on-premises Active Directory users to Microsoft Entra ID. The company requires that users continue to use their existing on-premises credentials to access cloud resources, and password hashes must not be synchronized to Microsoft Entra ID for security reasons. Users should experience a seamless sign-on experience from corporate-joined devices. Which authentication method should you implement?Implement and manage Microsoft Entra ID
  36. 86.A Microsoft 365 administrator is implementing a new security policy that requires all users to authenticate using multi-factor authentication (MFA) when accessing SharePoint Online from outside the corporate network. Additionally, if the sign-in is detected as high risk by Azure AD Identity Protection, access should be blocked entirely. Which type of policy should the administrator configure?Deploy and manage a Microsoft 365 tenant
  37. 87.A Microsoft 365 administrator is configuring a new tenant. The organization requires that all user mailboxes and SharePoint Online sites reside in a specific geographical region (e.g., European Union) due to data residency regulations. The administrator has already purchased the necessary licenses. What is the NEXT step the administrator must take to meet this requirement for newly provisioned services?Deploy and manage a Microsoft 365 tenant
  38. 88.A Microsoft 365 administrator is reviewing the tenant's security posture. They discover that a Global Administrator account was compromised and used to create several new user accounts. The administrator needs to identify when the Global Administrator account was activated via Privileged Identity Management (PIM) before the compromise occurred and what actions were performed. Which tool should the administrator use to gather this information?Deploy and manage a Microsoft 365 tenant
  39. 89.A Microsoft 365 administrator is configuring Microsoft Defender for Identity in a hybrid environment. The organization has several domain controllers (DCs) running Windows Server 2016 and a mix of Windows Server 2019 and 2022. To ensure comprehensive identity threat detection, the administrator needs to deploy Defender for Identity sensors. Which type of sensor should be installed directly on all domain controllers?Implement and manage Microsoft Defender XDR
  40. 90.A company uses Microsoft Entra ID and has implemented Microsoft Entra Connect to synchronize user identities from their on-premises Active Directory. They have a group of highly privileged administrators who need temporary, just-in-time access to specific Microsoft Entra roles (e.g., Global Administrator) only when performing specific tasks. This access should be time-bound and require approval. Which Microsoft Entra ID governance feature should you implement?Implement and manage Microsoft Entra ID
  41. 91.A Microsoft 365 administrator wants to implement a policy to automatically block access to Microsoft 365 services for any user account that exhibits a high sign-in risk. The company has a Microsoft 365 E5 subscription. Which Azure AD feature should the administrator configure to achieve this automated remediation?Deploy and manage a Microsoft 365 tenant
  42. 92.A Microsoft 365 administrator is responsible for managing user accounts and licenses in a large organization. A new department, 'Research & Development', has been created, and all 150 employees in this department require a Microsoft 365 E5 license. These employees are already members of an on-premises Active Directory security group named 'SG-R&D'. The administrator wants to automate license assignment for current and future members of this group. Which method should the administrator use?Deploy and manage a Microsoft 365 tenant
  43. 93.A Microsoft 365 administrator is planning to implement multi-factor authentication (MFA) for all users in the tenant. They want to ensure that users are prompted for MFA when accessing Microsoft 365 services from outside the corporate network, but not when they are on the trusted corporate network. Which Azure AD feature should the administrator use to achieve this requirement?Deploy and manage a Microsoft 365 tenant
  44. 94.A Microsoft 365 administrator is investigating a compromised user account. The investigation requires gathering detailed information about all logon attempts to the user's account, including source IP addresses, client applications, and authentication methods, over the past 30 days. Which KQL table should the administrator query in Advanced Hunting?Implement and manage Microsoft Defender XDR
  45. 95.A company uses Microsoft Entra ID and has implemented Microsoft Entra Connect for hybrid identity. Users report that they are frequently prompted for credentials when accessing cloud applications, even after successfully signing in to their domain-joined machines. The company wants to eliminate these prompts for a smoother user experience. Which feature should you enable?Implement and manage Microsoft Entra ID
  46. 96.A Microsoft 365 administrator is configuring custom detection rules in Microsoft Defender XDR using advanced hunting. The security team wants to be alerted whenever a specific PowerShell script, known to be used by a persistent threat actor, is executed on any endpoint in the organization. The script uses a unique command-line argument that can be identified. Which Kusto Query Language (KQL) operator should the administrator use to search for this specific command-line argument within the `CommandLine` field of `DeviceProcessEvents` table, ensuring case-insensitive matching?Implement and manage Microsoft Defender XDR
  47. 97.A Microsoft 365 administrator is managing Microsoft Defender for Endpoint. The organization's security policy dictates that all unmanaged devices attempting to connect to the corporate network must be identified and blocked from accessing sensitive resources until they are properly onboarded and compliant. Which Defender for Endpoint capability, when integrated with network access control solutions, is primarily responsible for discovering these unmanaged devices?Implement and manage Microsoft Defender XDR
  48. 98.A company is implementing Microsoft Entra Connect Cloud Sync to synchronize users from a subset of organizational units (OUs) in their on-premises Active Directory to Microsoft Entra ID. They need to ensure that only users from the 'Sales' and 'Marketing' OUs are synchronized. Which component of Cloud Sync allows you to define these specific OUs for synchronization?Implement and manage Microsoft Entra ID
  49. 99.A Microsoft 365 administrator is configuring custom detection rules in Microsoft Defender XDR's Advanced Hunting. They need to create a rule that identifies attempts to disable security services on endpoints. The rule should trigger whenever a service named 'MsSense' (Microsoft Defender for Endpoint sensor) has its status changed to 'disabled' or 'stopped'. Which Kusto Query Language (KQL) operator should the administrator use to check if the 'ServiceState' field contains either 'disabled' or 'stopped'?Implement and manage Microsoft Defender XDR
  50. 100.A consulting company frequently collaborates with external partners. They want to streamline the process of granting and revoking access to specific SharePoint Online sites and Microsoft 365 Groups for these partners. The access should be time-limited and automatically reviewed. The company also wants to delegate the access request and approval process to business owners instead of IT. Which Microsoft Entra ID governance feature should you implement?Implement and manage Microsoft Entra ID