Microsoft 365 Certified: Administrator Expert practice questions

217 free questions with answers and explanations.

Practice test
  1. 151.A Microsoft 365 administrator is responsible for managing user licenses. A new department has been created, and 50 new employees need to be assigned F3 licenses. The administrator wants to automate the license assignment process for these new users and ensure that any future users added to this department's security group automatically receive an F3 license. Which method should the administrator use?Deploy and manage a Microsoft 365 tenant
  2. 152.A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a large enterprise with thousands of devices. The organization has a strict policy that prevents users from downloading and executing unsigned scripts from the internet. The administrator needs to ensure that all unapproved or unsigned applications and scripts are automatically blocked from running on endpoints. Which Defender for Endpoint capability should be implemented to achieve this?Implement and manage Microsoft Defender XDR
  3. 153.A Microsoft 365 administrator is configuring a custom alert rule in Microsoft Defender XDR to detect anomalous activities. The rule needs to trigger an alert if a user successfully logs in from a country that is not part of the organization's approved list of operational countries, and then, within 30 minutes, attempts to access sensitive SharePoint Online data. The administrator plans to use Kusto Query Language (KQL) for this. Which KQL operator is essential for correlating these two distinct events (login and data access) based on a common user and within a specified time window?Implement and manage Microsoft Defender XDR
  4. 154.A security operations center (SOC) analyst is investigating a suspicious activity detected by Microsoft Defender for Endpoint. The alert indicates that a PowerShell script executed on a workstation attempted to communicate with a known malicious IP address. The analyst needs to quickly block all future communication from this workstation to that specific IP address across the entire organization. Which action should the analyst take within Microsoft Defender for Endpoint?Implement and manage Microsoft Defender XDR
  5. 155.A company is planning to implement Microsoft Entra ID for identity management. They have an existing on-premises Active Directory Domain Services (AD DS) environment. The security team has a strict requirement that no user passwords should ever be stored or synchronized to the cloud, even in hashed form. They also require that users authenticate directly against the on-premises AD DS environment for all cloud services. Which Microsoft Entra Connect authentication method should you recommend to meet these requirements?Implement and manage Microsoft Entra ID
  6. 156.A security analyst is performing an Advanced Hunting query in Microsoft Defender XDR. They need to identify all unique IP addresses that have attempted to connect to a specific internal server (IP: 10.0.0.10) on port 3389 (RDP) over the last 7 days. Which KQL query correctly retrieves this information?Implement and manage Microsoft Defender XDR
  7. 157.A company is planning to deploy Microsoft Entra Connect Cloud Sync to synchronize users from an on-premises Active Directory domain to Microsoft Entra ID. The domain controller is running Windows Server 2012 R2. Which of the following is a prerequisite for deploying Microsoft Entra Connect Cloud Sync agents?Implement and manage Microsoft Entra ID
  8. 158.A security team is using Microsoft Defender XDR and wants to integrate security alerts and incidents with their existing Security Information and Event Management (SIEM) system. They require near real-time streaming of all high-severity alerts. Which capability within Microsoft Defender XDR should the administrator configure?Implement and manage Microsoft Defender XDR
  9. 159.A Microsoft 365 administrator is implementing a new security policy that requires all highly sensitive documents stored in SharePoint Online and OneDrive for Business to be automatically encrypted and restricted from external sharing if they contain specific financial data patterns. The organization uses Microsoft Defender for Cloud Apps and Microsoft Purview Information Protection. Which type of policy in Defender for Cloud Apps should the administrator configure to enforce this requirement?Implement and manage Microsoft Defender XDR
  10. 160.A Microsoft 365 administrator is investigating a series of alerts in Microsoft Defender XDR related to a compromised user account. The alerts indicate that the account was used to access multiple cloud applications from unusual geographic locations and that large volumes of data were downloaded shortly after. The administrator needs to review a unified timeline of all activities related to this user account across various Microsoft 365 services (Azure AD, Exchange Online, SharePoint Online, etc.) to understand the full scope of the compromise. Which feature within Microsoft Defender XDR provides this comprehensive, cross-domain activity timeline for a user account?Implement and manage Microsoft Defender XDR
  11. 161.A global enterprise uses Microsoft Entra ID to manage identities. They have several highly sensitive applications that process confidential financial data. The security team requires that users accessing these applications re-authenticate every 30 minutes, regardless of their previous sign-in activity, even if they have an active session. All other applications can use the default session duration. Which Conditional Access control should be configured to meet this requirement?Implement and manage Microsoft Entra ID
  12. 162.A Microsoft 365 administrator is reviewing security recommendations from Microsoft Defender Vulnerability Management. They notice a recommendation to 'Update web browsers to the latest version' on several devices. The administrator wants to identify all devices that currently have an outdated version of Google Chrome installed. Which KQL query in Advanced Hunting would achieve this?Implement and manage Microsoft Defender XDR
  13. 163.A global administrator in a Microsoft 365 tenant wants to delegate the ability to manage user mailboxes, including creating new mailboxes, assigning licenses, and setting mailbox permissions, to a junior administrator. The junior administrator should NOT be able to manage any other Microsoft 365 services or global settings. Which built-in role should the global administrator assign to the junior administrator?Deploy and manage a Microsoft 365 tenant
  14. 164.A Microsoft 365 administrator is investigating a potential insider threat where an employee might be exfiltrating sensitive data by uploading it to an unsanctioned cloud storage service. The administrator needs to identify which specific files were uploaded and by whom. Which Microsoft Defender for Cloud Apps policy type should be configured to detect and log these activities?Implement and manage Microsoft Defender XDR
  15. 165.A Microsoft 365 administrator is setting up a new tenant and needs to ensure that users can only access Microsoft 365 services from trusted devices and approved network locations. Users attempting to access from untrusted devices or unknown locations should be blocked. The company has a Microsoft 365 E5 subscription. Which Azure AD feature should the administrator implement to achieve this granular access control?Deploy and manage a Microsoft 365 tenant
  16. 166.A company is implementing Microsoft Purview and needs to ensure that sensitive financial data, such as credit card numbers and bank account details, is automatically identified and protected across Microsoft 365 services. The company requires a solution that can detect these data types without manual tagging by users and apply appropriate compliance actions. Which Microsoft Purview component should be used to achieve this goal?Implement and manage Microsoft Purview compliance
  17. 167.A legal department requires the ability to quickly and comprehensively search for and preserve all emails, documents, and Teams chat messages related to a specific project code ('PROJ-FIN-2024') across the entire organization for an ongoing litigation case. The solution must allow for deduplication, near-duplicate detection, and the ability to export data in a reviewable format. Which Microsoft Purview feature should be utilized?Implement and manage Microsoft Purview compliance
  18. 168.A Human Resources department uses Microsoft 365 and needs to ensure that all documents containing employee performance reviews are automatically assigned a sensitivity label that encrypts the document and restricts access to only HR personnel. These documents are created in various SharePoint Online sites and OneDrive accounts. The identification of these documents should be based on a combination of keywords such as 'performance review' and 'employee ID'. Which method should the administrator use to achieve this automated labeling?Implement and manage Microsoft Purview compliance
  19. 169.A global company needs to ensure that specific sensitive information types (SITs) are consistently detected and protected across all Microsoft 365 services, including Exchange, SharePoint, OneDrive, and Teams. They also require that these SITs are recognized in their custom line-of-business applications. Which method allows for the creation of custom sensitive information types that can be deployed across both Microsoft 365 and external applications?Implement and manage Microsoft Purview compliance
  20. 170.A Microsoft 365 administrator is configuring a retention policy for all SharePoint sites to ensure that documents are kept for at least five years, regardless of user actions. After five years, the documents should be automatically deleted. The administrator wants to ensure that users cannot circumvent this policy by manually deleting items before the retention period expires. Which type of retention label or policy should be applied?Implement and manage Microsoft Purview compliance
  21. 171.A global enterprise needs to ensure that specific sensitive information types (SITs) unique to their industry, such as 'Proprietary Project ID' (e.g., 'PROJ-XYZ-2023-001') or 'Client Confidential Code' (e.g., 'CLNT-ABC-SECURE'), are consistently identified across all Microsoft 365 workloads. These SITs are not covered by the default Microsoft Purview SITs. What should an administrator implement?Implement and manage Microsoft Purview compliance
  22. 172.A global company needs to ensure that specific sensitive information types (SITs) unique to their industry, such as 'Pharmaceutical Batch ID' (e.g., 'BATCH-PHARMA-XYZ-12345') or 'Clinical Trial Protocol Number' (e.g., 'CTP-2023-007'), are consistently identified across all Microsoft 365 services. These SITs must be detectable by Data Loss Prevention (DLP) policies and trigger auto-labeling for documents containing them. Which Microsoft Purview feature should the administrator use to define and deploy these industry-specific identifiers?Implement and manage Microsoft Purview compliance
  23. 173.A financial services company needs to ensure that all internal communications related to trading activities are reviewed and archived for seven years to meet regulatory requirements. The solution must automatically identify and flag communications containing specific keywords related to financial transactions. Which Microsoft Purview feature should be implemented?Implement and manage Microsoft Purview compliance
  24. 174.A research institution collaborates with external partners on highly sensitive projects. They need to ensure that project-specific SharePoint sites are only accessible by authorized internal staff and specific external guest users who have signed NDAs. Furthermore, all content within these sites must be encrypted, and external sharing must be restricted to only the authorized guest users. Which combination of Microsoft Purview features is most effective for this scenario?Implement and manage Microsoft Purview compliance
  25. 175.A global engineering firm uses Microsoft 365 and needs to ensure that all project-related communications and documents are retained for seven years after the project's completion, regardless of where they are stored within Microsoft 365. The company has thousands of projects, each with a unique project ID (e.g., 'ENG-PROJ-2023-001'). The solution must dynamically identify content related to a specific project and apply the retention policy. Which Microsoft Purview feature should the administrator configure?Implement and manage Microsoft Purview compliance
  26. 176.A multinational financial organization uses Microsoft 365. Due to strict data residency laws, all data generated by employees in Germany must be stored and processed exclusively within Microsoft 365 data centers in the EU. This applies to Exchange mailboxes, SharePoint sites, and OneDrive accounts. Which Microsoft 365 feature is essential to ensure compliance with this requirement?Implement and manage Microsoft Purview compliance
  27. 177.A company is conducting an internal investigation into potential fraud. The legal team requires the ability to quickly and comprehensively search for, preserve, and analyze all relevant data across Exchange mailboxes, SharePoint sites, OneDrive accounts, and Microsoft Teams. They also need to identify patterns and relationships within the identified data, and redact sensitive information before producing content for external review. Which Microsoft Purview feature should the legal team utilize?Implement and manage Microsoft Purview compliance
  28. 178.A healthcare provider needs to implement a system to monitor and detect potential data exfiltration attempts by employees who have access to patient health information (PHI). Specifically, they are concerned about unusual downloading of large volumes of PHI, sharing PHI with unauthorized external parties, and emailing PHI to personal accounts. The solution must provide alerts and allow for investigation. Which Microsoft Purview solution is best suited for this scenario?Implement and manage Microsoft Purview compliance
  29. 179.A financial institution needs to implement a policy to ensure that no sensitive client financial data (e.g., account numbers, credit card numbers) can be copied from their internal SharePoint sites to unmanaged personal devices or shared with unauthorized external cloud storage services. The policy should also prevent printing of such data. Which Microsoft Purview feature is specifically designed to prevent these types of data exfiltration scenarios?Implement and manage Microsoft Purview compliance
  30. 180.A company is implementing Microsoft Purview to manage compliance. They need to ensure that all audit logs related to administrative activities across Exchange Online, SharePoint Online, and Azure Active Directory are retained for a minimum of one year for forensic investigations. Which type of retention policy should be configured?Implement and manage Microsoft Purview compliance
  31. 181.A multinational financial organization uses Microsoft 365. Due to strict data residency laws, all data generated by its European subsidiary must be stored exclusively within the European Union, while data from its North American subsidiary must remain in North America. The organization uses a single Microsoft 365 tenant. Which Microsoft Purview capability, in conjunction with Microsoft 365 Multi-Geo, should be configured to ensure data residency compliance for content in Exchange Online, SharePoint Online, and OneDrive?Implement and manage Microsoft Purview compliance
  32. 182.A healthcare provider is implementing Microsoft Purview to ensure compliance with HIPAA regulations. They need to categorize and protect all documents containing Protected Health Information (PHI) within SharePoint Online and Exchange Online. The protection must include encryption and visual markings (header/footer). Additionally, the company requires that these documents cannot be shared with external users, even if the external user has an Azure AD account. Which Microsoft Purview feature should be used to achieve this comprehensive protection?Implement and manage Microsoft Purview compliance
  33. 183.A legal department needs to ensure that all audit logs generated by Microsoft 365 services, particularly those related to administrator activities and eDiscovery searches, are retained for a minimum of 7 years for regulatory compliance. They also require the ability to search these logs for investigative purposes. Which Microsoft Purview feature should be configured?Implement and manage Microsoft Purview compliance
  34. 184.An organization is deploying an adaptive scope for retention policies. They have a dynamic group of employees working on 'Project Alpha' who have different retention requirements than the rest of the company. The 'Project Alpha' group is managed in Azure AD and is frequently updated. The organization wants to ensure that as employees join or leave 'Project Alpha', their associated data automatically falls under or is removed from the specific retention policy without manual intervention. Which query type should be used for the adaptive scope?Implement and manage Microsoft Purview compliance
  35. 185.A global pharmaceutical company uses Microsoft 365. Due to strict clinical trial regulations, all documents related to ongoing drug development must be retained for 15 years from their creation date, and then permanently deleted. This applies to all SharePoint Online sites and Exchange mailboxes used by the Research & Development department. How should an administrator configure this requirement?Implement and manage Microsoft Purview compliance
  36. 186.A global consulting firm needs to ensure that all internal communications between consultants and clients for specific projects are monitored for ethical conduct and compliance with client confidentiality agreements. The firm has identified certain keywords and phrases that, if used, should trigger an alert for review by the compliance team. The solution must support monitoring across Exchange Online, Microsoft Teams, and Yammer. Which Microsoft Purview feature should be configured?Implement and manage Microsoft Purview compliance
  37. 187.A company is conducting an internal investigation into potential fraud. The legal team has identified several key custodians and needs to preserve all their Exchange mailbox content, OneDrive files, and SharePoint site documents, ensuring that this content cannot be altered or deleted by users. The preserved content must be easily searchable for review. Which Microsoft Purview feature should be used?Implement and manage Microsoft Purview compliance
  38. 188.A large pharmaceutical company needs to ensure that no documents containing patient health information (PHI) are ever shared outside the organization. This policy must apply to all email, SharePoint, OneDrive, and Teams communications. Additionally, the policy should alert security administrators and block the sharing attempt. Which Microsoft Purview feature is best suited for this requirement?Implement and manage Microsoft Purview compliance
  39. 189.A construction company uses Microsoft 365 and needs to ensure that sensitive project blueprints, identified by a unique 'Project Code' (e.g., 'BLU-2023-001'), are always encrypted and watermarked when shared externally. These blueprints are stored in SharePoint Online. The company wants to automate the application of sensitivity labels based on the presence of these project codes within the documents. Which combination of features should be configured?Implement and manage Microsoft Purview compliance
  40. 190.A manufacturing company needs to manage access to highly confidential design documents stored in SharePoint Online. These documents should only be accessible by members of the 'Design Team' and 'Management' groups. Furthermore, members of the 'Contractors' group, even if they are part of the 'Design Team', should never be able to access these specific documents. Which Microsoft Purview feature would allow the administrator to implement these granular access controls and exclusions?Implement and manage Microsoft Purview compliance
  41. 191.A legal department requests that all existing emails and documents related to a specific legal case, identified by a unique case ID in their subject lines or document properties, be preserved indefinitely and made searchable for eDiscovery. New content matching this criteria must also be preserved. What is the most efficient way to achieve this using Microsoft Purview?Implement and manage Microsoft Purview compliance
  42. 192.A global pharmaceutical company uses Microsoft 365. Due to strict clinical trial regulations, all research data must be retained for 15 years from the date the associated clinical trial concludes, not from the date the data was created. The legal department requires that the retention period for this data only begins after a specific 'Trial Concluded' event is formally logged. Which Microsoft Purview feature should the administrator configure to meet this requirement?Implement and manage Microsoft Purview compliance
  43. 193.A large pharmaceutical company uses Microsoft 365. They have a strict requirement to manage the lifecycle of clinical trial documents, which must be retained for 15 years from the 'Study Completion Date' property in SharePoint, then automatically deleted. These documents are stored in specific SharePoint Online sites. Which Microsoft Purview feature is best suited to automate this process?Implement and manage Microsoft Purview compliance
  44. 194.A global enterprise needs to ensure that all communications containing specific project code names (e.g., 'Project Chimera', 'Project Phoenix') are monitored for potential policy violations related to intellectual property and insider trading. The company requires a solution that can automatically detect these code names within emails and Teams chats, flag them for review, and allow designated compliance officers to investigate without impacting user productivity. Which Microsoft Purview feature would best address this requirement?Implement and manage Microsoft Purview compliance
  45. 195.A global manufacturing company uses Microsoft 365 and has a strict policy against sharing intellectual property outside the organization. They need to implement an information protection solution that automatically encrypts and applies specific usage restrictions (e.g., 'Do Not Forward', 'Do Not Print') to documents containing proprietary designs, even when shared with external partners. The solution must integrate seamlessly with Microsoft Office applications. Which Microsoft Purview technology should be employed?Implement and manage Microsoft Purview compliance
  46. 196.A company operating in the healthcare sector needs to implement a solution to prevent its employees from communicating with patients through unofficial channels (e.g., personal email, unapproved chat apps) while still allowing internal communication among healthcare professionals. They also need to ensure that any attempts to share patient information outside approved channels are flagged for review. Which Microsoft Purview feature should be configured?Implement and manage Microsoft Purview compliance
  47. 197.A multinational corporation has a strict requirement to keep all data generated by its German subsidiary exclusively within the German geographical boundaries for compliance with local data residency laws. This includes emails, documents, and chat messages. Which Microsoft 365 feature, when combined with appropriate Purview policies, is essential to meet this data residency requirement?Implement and manage Microsoft Purview compliance
  48. 198.A compliance officer needs to implement a solution that prevents specific user groups, such as the Research & Development (R&D) team, from communicating or sharing files with the Sales team within Microsoft Teams and Exchange Online. This restriction must be enforced at the organizational level to avoid information leakage between competing departments. Which Microsoft Purview feature should be configured?Implement and manage Microsoft Purview compliance
  49. 199.An organization uses Microsoft Purview to manage compliance. They have a requirement to apply a specific retention label, 'Contract-7Years', to all documents uploaded to a particular SharePoint Online library, regardless of their content. This label must be applied automatically upon upload. What is the most efficient way to achieve this?Implement and manage Microsoft Purview compliance
  50. 200.A company is concerned about employees accidentally or maliciously sharing sensitive customer data, such as Social Security Numbers (SSNs) and credit card numbers, with external parties via email and Microsoft Teams. They want to prevent this data from leaving the organization. Which Microsoft Purview solution should be implemented?Implement and manage Microsoft Purview compliance