Microsoft 365 Certified: Administrator Expert practice questions

217 free questions with answers and explanations.

Practice test
  1. 101.A Microsoft 365 administrator is troubleshooting mail flow issues for a custom domain 'contoso.com' after migrating to Exchange Online. Users are able to send emails internally and receive emails from other Exchange Online users, but they are not receiving external emails. The administrator suspects a DNS record issue. Which DNS record should the administrator verify first?Deploy and manage a Microsoft 365 tenant
  2. 102.A Microsoft 365 E3 tenant has a custom domain 'contoso.com'. The administrator wants to ensure that all internal email communication sent from users in 'contoso.com' to other users in 'contoso.com' is never subject to external spam filtering or routing delays. Which DNS record type, if misconfigured or missing, would most likely cause internal email to be routed externally before being delivered internally?Deploy and manage a Microsoft 365 tenant
  3. 103.A global administrator is setting up a new Microsoft 365 tenant. They want to ensure that all administrative actions performed by other administrators are logged and can be reviewed for auditing purposes. Where should the administrator configure settings to enable comprehensive logging of administrative activities across Microsoft 365 services?Deploy and manage a Microsoft 365 tenant
  4. 104.An organization is implementing Microsoft 365 and plans to use Microsoft Teams for collaboration. The security team requires that all data at rest within Microsoft Teams must be encrypted using customer-managed encryption keys (CMEK). Which Microsoft 365 feature is required to enable CMEK for Microsoft Teams data?Deploy and manage a Microsoft 365 tenant
  5. 105.A client is migrating its on-premises Active Directory Domain Services (AD DS) users to Microsoft Entra ID. The client wants to ensure that all user objects are synchronized, but only specific attributes (e.g., mail, sAMAccountName, userPrincipalName, displayName) should be synchronized to Microsoft Entra ID for privacy and compliance reasons. Other attributes, such as employeeID or personal details, must be excluded. Which Microsoft Entra Connect feature should be used to achieve this?Implement and manage Microsoft Entra ID
  6. 106.A Microsoft 365 administrator is planning to migrate a large number of user mailboxes from an on-premises Exchange Server to Exchange Online. During the migration, users must be able to seamlessly access their mailboxes without interruption. After the migration, all mail flow should be directed to Exchange Online. Which type of migration should the administrator choose?Deploy and manage a Microsoft 365 tenant
  7. 107.A company is managing external guest users in Microsoft Entra ID. They want to ensure that guest users automatically lose access to all company resources after 90 days, unless their access is explicitly renewed. Which Microsoft Entra ID governance feature should be configured?Implement and manage Microsoft Entra ID
  8. 108.A Microsoft 365 administrator is experiencing issues with user authentication. Users are reporting that they are intermittently unable to sign in to Microsoft 365 services, and some are receiving 'Access Denied' messages even with correct credentials. The administrator suspects a problem with the federation service. Which PowerShell cmdlet should the administrator use to diagnose the health of the federation service in their Microsoft 365 tenant?Deploy and manage a Microsoft 365 tenant
  9. 109.A global enterprise uses Microsoft Entra ID to manage identities. They have several highly sensitive applications that require an additional layer of security. You need to implement a solution that ensures users accessing these applications are consistently prompted for a second verification factor, even if they have recently satisfied MFA for another application. Which Microsoft Entra Conditional Access session control should you configure?Implement and manage Microsoft Entra ID
  10. 110.A Microsoft 365 administrator is configuring email routing for a new custom domain, 'contoso.net'. The organization requires that all incoming emails for 'contoso.net' be directed to Exchange Online. Which type of DNS record must the administrator create and configure with the correct value provided by Microsoft 365 for proper email delivery?Deploy and manage a Microsoft 365 tenant
  11. 111.A consultant is helping a client migrate user identities to Microsoft Entra ID. The client has an existing on-premises Active Directory Domain Services (AD DS) environment. They want to ensure that if the internet connection to their on-premises network fails, users can still sign in to Microsoft 365 services using their cached credentials. Which Microsoft Entra Connect authentication method provides this capability?Implement and manage Microsoft Entra ID
  12. 112.A consultant is assisting a small business with implementing Microsoft Entra Connect. The business has a single domain Active Directory forest with fewer than 50,000 objects. They need a simple, cloud-managed synchronization solution that minimizes on-premises infrastructure and administrative overhead. Which deployment option should the consultant recommend?Implement and manage Microsoft Entra ID
  13. 113.A company is planning to deploy Microsoft Entra Connect to synchronize identities from its on-premises Active Directory Domain Services (AD DS) to Microsoft Entra ID. The on-premises environment consists of two separate, non-trusted Active Directory forests, ForestA.local and ForestB.local. Users in both forests need to be synchronized to a single Microsoft Entra tenant. Each forest has its own DNS infrastructure and network segments. You need to design the Microsoft Entra Connect deployment. Which deployment topology is most suitable for this scenario?Implement and manage Microsoft Entra ID
  14. 114.A global administrator needs to delegate the ability to manage Exchange Online recipient properties (e.g., mailboxes, distribution lists) to a junior administrator, but without granting them full control over all Exchange Online settings or other Microsoft 365 services. Which built-in Azure AD role provides the LEAST privilege required for this task?Deploy and manage a Microsoft 365 tenant
  15. 115.A company uses Microsoft Entra ID for identity management. They have a custom line-of-business application that needs to access user profiles and group memberships in Microsoft Entra ID. The application runs as a background service and does not have a signed-in user. You need to grant the application the necessary permissions to access Microsoft Entra ID resources securely. What type of identity should you create and configure for this application?Implement and manage Microsoft Entra ID
  16. 116.A Microsoft 365 administrator needs to delegate the ability to reset passwords for all users in the 'Sales' department without granting them broader administrative privileges. The Sales department users are organized into a specific Azure AD administrative unit. Which role and scope should the administrator assign?Deploy and manage a Microsoft 365 tenant
  17. 117.A Microsoft 365 administrator is preparing for a large-scale migration of user mailboxes from an on-premises Exchange Server 2016 environment to Exchange Online. The company requires a staged migration approach to minimize disruption and maintain seamless coexistence during the transition. Users must be able to access their mailboxes regardless of whether they are on-premises or in the cloud, and free/busy information must be shared between both environments. Which type of Exchange deployment should the administrator implement?Deploy and manage a Microsoft 365 tenant
  18. 118.A Microsoft 365 administrator needs to integrate security alerts from Microsoft Defender XDR into their existing Security Information and Event Management (SIEM) system for centralized logging and analysis. The SIEM system supports ingesting data via an API endpoint that requires a continuous stream of security incidents and alerts. Which Microsoft Defender XDR integration method should the administrator choose?Implement and manage Microsoft Defender XDR
  19. 119.A Microsoft 365 administrator needs to create a new group that automatically includes all users located in 'London' and excludes any users with a job title containing 'Contractor'. This group will be used to assign licenses and access to specific SharePoint sites. Which type of group should the administrator create?Deploy and manage a Microsoft 365 tenant
  20. 120.A Microsoft 365 administrator is tasked with integrating Microsoft Defender for Endpoint with a third-party Security Information and Event Management (SIEM) system. The security operations center (SOC) team requires real-time streaming of all security alerts, incidents, and raw event data from Defender for Endpoint into their SIEM for centralized monitoring and analysis. Which integration method should the administrator implement?Implement and manage Microsoft Defender XDR
  21. 121.A company requires that all Global Administrators and other highly privileged roles in Microsoft Entra ID must use multi-factor authentication (MFA) every time they sign in, regardless of their location or device compliance. Additionally, these users should be prompted for MFA even if they are already signed into another Microsoft 365 service within the same session. Which type of policy should be configured to enforce this strict security requirement?Implement and manage Microsoft Entra ID
  22. 122.A Microsoft 365 administrator is reviewing the service health of their tenant. They notice a yellow warning icon next to 'Exchange Online' in the Microsoft 365 admin center's Service health dashboard. Upon clicking the incident, they see a message indicating 'Performance degradation for Mailbox access' with a recommended action to 'Monitor for resolution'. Which of the following statements is true regarding this situation?Deploy and manage a Microsoft 365 tenant
  23. 123.A company is using Microsoft Entra ID for identity management and has deployed Microsoft Entra Connect to synchronize users from their on-premises Active Directory. The security team has identified a need to enforce Multi-Factor Authentication (MFA) for all users accessing sensitive cloud applications, but only when they are outside the corporate network. Users should not be prompted for MFA when connecting from trusted corporate IP ranges. Which Microsoft Entra feature should you configure?Implement and manage Microsoft Entra ID
  24. 124.A Microsoft 365 administrator is configuring a new tenant and needs to ensure that all user accounts created in the tenant are assigned a specific country/region to enable access to certain Microsoft 365 services and features that are region-specific. Which user attribute must be configured for each user?Deploy and manage a Microsoft 365 tenant
  25. 125.A Microsoft 365 administrator is managing a tenant where users are currently authenticating directly to Azure AD. The company has a large on-premises Active Directory infrastructure and wants to implement single sign-on (SSO) for all Microsoft 365 services without synchronizing password hashes to Azure AD. The solution must also support advanced authentication policies from the on-premises environment. Which authentication method should the administrator choose?Deploy and manage a Microsoft 365 tenant
  26. 126.A multinational corporation uses Microsoft Entra ID and has implemented Microsoft Entra Connect to synchronize identities from its on-premises Active Directory. They have a requirement to ensure that all user objects synchronized from a specific on-premises domain, 'europe.contoso.com', are provisioned to Microsoft Entra ID. However, users from another domain, 'asia.contoso.com', should be completely excluded from synchronization. Which filtering method should be configured in Microsoft Entra Connect?Implement and manage Microsoft Entra ID
  27. 127.A Microsoft 365 administrator needs to delegate the ability to manage user mailboxes, including setting mailbox permissions and managing distribution lists, to a junior administrator named Sarah. Sarah should NOT be able to manage other aspects of the tenant, such as security settings or global configurations. Which built-in role in Exchange Online should the administrator assign to Sarah?Deploy and manage a Microsoft 365 tenant
  28. 128.A Microsoft 365 administrator is reviewing the security posture of their organization. They notice that several Windows Server 2019 machines are reporting vulnerabilities but are not fully onboarded to Microsoft Defender for Endpoint's unified solution for servers. The administrator needs to ensure these servers are fully protected and contribute to the overall security posture. What is the recommended method to onboard these servers to the unified solution?Implement and manage Microsoft Defender XDR
  29. 129.A company uses Microsoft 365 and has recently integrated Microsoft Defender for Endpoint. The security team wants to ensure that all devices, including servers, are fully protected against the latest threats. They also need to implement device isolation capabilities for rapid incident response. Which of the following components of Microsoft Defender for Endpoint should be deployed on their Windows Server 2019 machines to meet these requirements?Implement and manage Microsoft Defender XDR
  30. 130.A company is deploying Microsoft Entra Connect to synchronize identities from its on-premises Active Directory to Microsoft Entra ID. They have a strict security policy requiring that user passwords are NOT stored in the cloud in any form, including hashed versions. However, users must be able to use their on-premises Active Directory credentials to sign in to Microsoft 365 services. Which authentication method should you configure in Microsoft Entra Connect?Implement and manage Microsoft Entra ID
  31. 131.A company uses Microsoft Entra ID for identity management. They have a custom line-of-business application that needs to retrieve user profile information from Microsoft Entra ID. The application should only have read access to user attributes and should not be able to modify any user data. Which type of identity should you create for the application to access Microsoft Entra ID?Implement and manage Microsoft Entra ID
  32. 132.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a new organization. The organization has a strict policy that all security events from endpoints must be retained for at least 180 days for forensic analysis and compliance purposes. The default retention period is insufficient. Which setting must the administrator modify to meet this requirement?Implement and manage Microsoft Defender XDR
  33. 133.A global organization uses Microsoft Defender for Identity to protect its on-premises Active Directory infrastructure. Due to network segmentation, some domain controllers are in isolated network segments and cannot directly reach the internet to communicate with the Defender for Identity cloud service. How can the administrator ensure these isolated domain controllers are still protected by Defender for Identity?Implement and manage Microsoft Defender XDR
  34. 134.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint to protect client devices. The organization requires a solution that can automatically block known malicious files and processes based on behavioral analysis and cloud-delivered protection, even when devices are offline. Which Defender for Endpoint capability should the administrator enable to meet this requirement?Implement and manage Microsoft Defender XDR
  35. 135.An organization is setting up Microsoft Entra Connect to synchronize identities from its on-premises Active Directory Domain Services (AD DS) to Microsoft Entra ID. They have several Organizational Units (OUs) that contain service accounts and legacy users which should *not* be synchronized to the cloud. You need to configure Microsoft Entra Connect to exclude these specific OUs from synchronization. What is the most efficient way to achieve this?Implement and manage Microsoft Entra ID
  36. 136.A large enterprise with multiple Active Directory forests needs to synchronize user identities from all forests to a single Microsoft Entra ID tenant. Each forest has its own distinct schema extensions and attribute definitions. The company requires a robust and flexible synchronization solution that can handle these complexities and provide advanced attribute flow customization. Which component of Microsoft Entra Connect is best suited for this requirement?Implement and manage Microsoft Entra ID
  37. 137.A Microsoft 365 administrator is planning to implement a new policy for Microsoft 365 Groups. The policy requires that all new groups created must have a specific prefix ('PROJ-') and suffix ('-GR') to ensure consistency and easy identification. Additionally, a list of specific words (e.g., 'Confidential', 'HR') must be blocked from being used in group names. Which feature should the administrator configure?Deploy and manage a Microsoft 365 tenant
  38. 138.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint to monitor critical servers within the organization. These servers host sensitive applications and require a high level of security monitoring. The administrator wants to ensure that all process creations, network connections, file modifications, and registry changes on these servers are comprehensively logged and available for advanced hunting. Which type of data collection should be explicitly enabled or verified for these servers in Defender for Endpoint?Implement and manage Microsoft Defender XDR
  39. 139.A company is migrating its on-premises Active Directory Domain Services (AD DS) users to Microsoft Entra ID. They want to ensure that user accounts synchronize correctly and that their UPNs (User Principal Names) match the format 'user@contoso.com' in Microsoft Entra ID. Currently, some on-premises UPNs are 'user@contoso.local'. Which step should be taken BEFORE deploying Microsoft Entra Connect to achieve the desired UPN format?Implement and manage Microsoft Entra ID
  40. 140.A Microsoft 365 administrator is configuring Microsoft Defender for Office 365. The organization wants to create a custom policy that specifically targets emails containing a highly sensitive keyword related to a new product launch, ensuring these emails are quarantined if received from external senders. Which type of Defender for Office 365 policy should the administrator configure?Implement and manage Microsoft Defender XDR
  41. 141.A large multinational corporation is implementing Microsoft Defender for Cloud Apps to gain visibility and control over its cloud application usage. The security team needs to identify all unsanctioned cloud applications currently being used by employees across the organization's network, including those accessed from unmanaged devices. This discovery process must be comprehensive and provide risk assessment for each discovered app. Which method for cloud app discovery should the administrator prioritize to achieve this goal?Implement and manage Microsoft Defender XDR
  42. 142.A Microsoft 365 administrator is investigating a series of failed login attempts against cloud applications. The administrator suspects a credential stuffing attack. To gain deeper insights into the source IPs, user agents, and success/failure rates, the administrator needs to query activity logs. Which KQL table in Microsoft Defender for Cloud Apps should the administrator query?Implement and manage Microsoft Defender XDR
  43. 143.A Microsoft 365 administrator is implementing a new security policy that requires all users accessing SharePoint Online from unmanaged devices to use a session with restricted capabilities, such as preventing downloads and requiring web-only access. Which Azure AD feature should the administrator configure to enforce this policy?Deploy and manage a Microsoft 365 tenant
  44. 144.A company is implementing Microsoft Defender for Office 365. They frequently exchange sensitive information via email with external partners. The security team wants to ensure that any email containing specific keywords (e.g., 'Confidential Project X') or classified as 'Highly Confidential' by a sensitivity label is automatically quarantined if sent outside the organization. Which Defender for Office 365 policy should the administrator configure to meet this requirement?Implement and manage Microsoft Defender XDR
  45. 145.A company is performing a phased rollout of Microsoft Entra Connect. They have installed the Microsoft Entra Connect software on a server and configured it to synchronize objects from their on-premises Active Directory to Microsoft Entra ID. Currently, no objects are being exported to Microsoft Entra ID, but the synchronization service shows that imports and synchronizations are completing successfully. What is the most likely reason for this behavior?Implement and manage Microsoft Entra ID
  46. 146.A Microsoft 365 administrator is investigating a sophisticated attack where an attacker managed to compromise a user account and then attempted to escalate privileges by exploiting a known vulnerability in an outdated operating system component. The administrator needs to identify the specific vulnerability exploited and understand its potential impact across the organization's endpoints. Which Microsoft Defender XDR capability provides the most comprehensive information for this investigation, including vulnerability details, affected devices, and remediation steps?Implement and manage Microsoft Defender XDR
  47. 147.A company is using Microsoft Entra ID to manage identities and has deployed Microsoft Entra Connect to synchronize users from their on-premises Active Directory. They want to implement a Conditional Access policy that requires multi-factor authentication (MFA) *only* when users sign in from outside the corporate network. All sign-ins originating from the company's main office IP ranges should not prompt for MFA. You need to configure this Conditional Access policy. What should you define in the policy's conditions?Implement and manage Microsoft Entra ID
  48. 148.A Microsoft 365 administrator is setting up a new tenant for a global organization. They need to ensure that all user data, including Exchange mailboxes and SharePoint sites, for users located in specific geographical regions, is stored within those regions to comply with data residency regulations. Which Microsoft 365 feature should the administrator configure?Deploy and manage a Microsoft 365 tenant
  49. 149.A global financial institution uses Microsoft 365 and Microsoft Defender for Identity. They have a strict compliance requirement to ensure that all sensitive on-premises Active Directory objects (e.g., domain controllers, privileged user accounts) are continuously monitored for suspicious activities and potential compromise. The institution wants to ensure the highest fidelity of alerts and comprehensive coverage without requiring direct access to domain controllers for sensor installation. Which component of Defender for Identity should be deployed and configured to meet this requirement effectively?Implement and manage Microsoft Defender XDR
  50. 150.A Microsoft 365 administrator wants to implement a policy where all new Microsoft 365 Groups created in the tenant must have a specific naming convention (e.g., 'GRP_DepartmentName_Project'). They also need to ensure that certain words (e.g., 'Confidential', 'HR') are blocked from being used in group names. Which feature should the administrator configure?Deploy and manage a Microsoft 365 tenant