Microsoft 365 Fundamentals practice questions
238 free questions with answers and explanations.
- 201.A multinational corporation uses Microsoft 365 and needs to ensure that internal communications, especially those involving financial transactions, comply with industry regulations by detecting and preventing potential conflicts of interest or inappropriate information sharing between specific groups of employees. The company's legal department requires a solution that can monitor and flag such interactions. Which Microsoft 365 compliance solution should they implement?Describe security, compliance, privacy, and trust in Microsoft 365
- 202.A company is migrating its on-premises user identities to Microsoft 365. They need to ensure that user passwords and other sensitive identity information are not stored directly in the cloud in a readable format, aligning with the principle of least privilege and data minimization. Which Azure AD authentication method achieves this by maintaining password hashes on-premises while allowing cloud authentication?Describe security, compliance, privacy, and trust in Microsoft 365
- 203.A Microsoft 365 administrator needs to ensure that specific sensitive data, such as credit card numbers or social security numbers, is not shared accidentally or maliciously outside the organization's control. This includes preventing sharing through email, Teams messages, and SharePoint documents. Which Microsoft 365 capability should the administrator configure to achieve this goal?Describe security, compliance, privacy, and trust in Microsoft 365
- 204.A global pharmaceutical company uses Microsoft 365. Due to strict industry regulations, they must ensure that certain sensitive documents, such as clinical trial results, are permanently deleted after a specific period (e.g., 7 years) and cannot be recovered by anyone, including administrators. Which Microsoft Purview capability is most effective for ensuring this irreversible deletion and managing the document lifecycle?Describe security, compliance, privacy, and trust in Microsoft 365
- 205.Which Microsoft 365 capability helps organizations meet regulatory requirements by providing predefined compliance templates and risk assessments?Describe security, compliance, privacy, and trust in Microsoft 365
- 206.A financial services company uses Microsoft 365 and is subject to stringent regulatory requirements like GDPR and HIPAA. They need to demonstrate to auditors that they have controls in place to protect sensitive customer data and can provide evidence of compliance. Which Microsoft 365 compliance management capability is specifically designed to centralize and simplify this process?Describe security, compliance, privacy, and trust in Microsoft 365
- 207.A Microsoft 365 administrator is implementing a new security policy where users attempting to log in from 'risky' IP addresses (known to be associated with cyber threats) must be challenged with multi-factor authentication, even if they are internal employees. This policy should also automatically block sign-ins from extremely high-risk locations. Which Azure AD feature is best suited for this granular, risk-based access control?Describe security, compliance, privacy, and trust in Microsoft 365
- 208.A Microsoft 365 administrator is investigating a potential data breach where sensitive company documents were accessed from an unusual location. The administrator suspects that the user's account might be compromised. To prevent further unauthorized access and protect the organization's data, the administrator needs to ensure that if a user's sign-in activity is deemed risky, immediate action is taken, such as blocking the sign-in or forcing a password reset. Which Azure AD feature is specifically designed to detect and respond to identity-based risks in real-time?Describe security, compliance, privacy, and trust in Microsoft 365
- 209.A Microsoft 365 administrator is tasked with ensuring that all administrative actions performed within the Microsoft 365 environment, such as changing user permissions, configuring tenant settings, or creating new sites, are recorded and immutable. This is critical for forensic investigations and demonstrating accountability during security audits. Which Microsoft Purview feature provides a comprehensive and tamper-proof record of these administrative activities?Describe security, compliance, privacy, and trust in Microsoft 365
- 210.A Microsoft 365 global administrator is investigating a potential data breach where sensitive customer information might have been accessed by an unauthorized individual. The administrator needs to identify exactly which files were accessed, when, and by whom, across SharePoint Online and OneDrive for Business. Which Microsoft 365 compliance tool is specifically designed for these types of detailed forensic investigations?Describe security, compliance, privacy, and trust in Microsoft 365
- 211.A global corporation needs to ensure that all data stored in Microsoft 365 services, regardless of its location, complies with the General Data Protection Regulation (GDPR). Which Microsoft 365 capability is primarily responsible for helping to identify, classify, and protect sensitive personal data to meet such regulatory requirements?Describe security, compliance, privacy, and trust in Microsoft 365
- 212.A company is concerned about its employees accidentally or maliciously sharing sensitive customer data, such as credit card numbers or personally identifiable information (PII), outside the organization through email or cloud storage. They need a proactive solution that can identify, monitor, and automatically prevent this type of data exfiltration. Which Microsoft 365 security capability should be implemented?Describe security, compliance, privacy, and trust in Microsoft 365
- 213.A Microsoft 365 administrator is investigating unusual activity on a user's account, specifically a login from an unfamiliar location followed by attempts to access sensitive SharePoint sites. The administrator needs to quickly understand the sequence of events and the resources accessed. Which Microsoft 365 feature provides a detailed, searchable record of user and admin activities?Describe security, compliance, privacy, and trust in Microsoft 365
- 214.A small business is using Microsoft 365 and wants to ensure that all sensitive customer data, such as credit card numbers and health information, is not accidentally shared outside the organization via email or other collaboration tools. Which Microsoft 365 security and compliance capability should they implement to prevent this type of data exfiltration?Describe security, compliance, privacy, and trust in Microsoft 365
- 215.A Microsoft 365 administrator is configuring a new tenant for a small business. The business wants to ensure that all user data, including emails and documents, is protected from accidental deletion or malicious attacks, and remains accessible for a specific period, even if users delete items from their mailboxes or OneDrive. Which Microsoft 365 feature should the administrator primarily configure to meet these requirements?Describe security, compliance, privacy, and trust in Microsoft 365
- 216.A Microsoft 365 administrator is configuring a new tenant for a global enterprise. The company's compliance regulations require that data for specific regions must be stored and processed within those geographical boundaries, even for the same tenant. The administrator needs to ensure that user data for employees in Europe resides in European data centers, while data for North American employees remains in North American data centers. Which Microsoft 365 capability addresses this specific data residency requirement?Describe security, compliance, privacy, and trust in Microsoft 365
- 217.A Microsoft 365 administrator is concerned about employees accidentally or maliciously deleting critical business documents from SharePoint Online and OneDrive for Business. The organization needs to ensure that these documents are retained for a specific period, even if users attempt to delete them, to meet legal and regulatory obligations. Which Microsoft Purview feature should the administrator implement?Describe security, compliance, privacy, and trust in Microsoft 365
- 218.A Microsoft 365 administrator is investigating a potential data breach where sensitive company documents might have been exfiltrated from SharePoint Online. The administrator needs to review user activities, file access, and sharing events related to the suspicious activity. Which Microsoft 365 compliance feature should the administrator use first to gather this information?Describe security, compliance, privacy, and trust in Microsoft 365
- 219.A Microsoft 365 administrator is tasked with ensuring that all administrative actions performed within the Microsoft 365 tenant are logged and discoverable for security and compliance audits. This includes changes to user accounts, service settings, and data access. Which Microsoft 365 capability provides a unified log of these activities?Describe security, compliance, privacy, and trust in Microsoft 365
- 220.A healthcare organization stores patient records in Microsoft 365. Due to strict regulatory requirements, these records must be retained for a minimum of 10 years and then permanently deleted. Which Microsoft 365 compliance feature is best suited to automatically enforce both the retention and deletion policies for this sensitive data?Describe security, compliance, privacy, and trust in Microsoft 365
- 221.A global enterprise uses Microsoft 365 and needs to ensure that specific types of sensitive information, such as credit card numbers or social security numbers, are not accidentally shared outside the organization through email, Teams messages, or SharePoint documents. The company also wants to be notified when such incidents occur. Which Microsoft 365 feature is best suited to prevent this data leakage?Describe security, compliance, privacy, and trust in Microsoft 365
- 222.A Microsoft 365 administrator is configuring a new tenant and wants to ensure a baseline level of security for all users without requiring extensive configuration. The organization wants to enforce multi-factor authentication (MFA) for administrative roles, block legacy authentication, and require MFA for risky sign-ins. Which Microsoft 365 feature provides these security controls by default and is recommended for organizations with Azure AD Free or Microsoft 365 Business Basic/Standard licenses?Describe security, compliance, privacy, and trust in Microsoft 365
- 223.A Microsoft 365 administrator is setting up a new tenant for a global financial institution. Due to strict industry regulations, the institution must ensure that all communications between specific groups of employees (e.g., traders and financial analysts) are legally separated to prevent conflicts of interest. No communication should be possible between these groups within any Microsoft 365 service. Which compliance capability should the administrator implement?Describe security, compliance, privacy, and trust in Microsoft 365
- 224.A Microsoft 365 administrator is reviewing the organization's security posture and wants to determine if any user accounts have been compromised or are exhibiting risky behavior, such as sign-ins from unusual locations or attempts to access disabled accounts. The administrator needs a centralized view of these potential identity risks. Which Microsoft 365 capability provides this insight?Describe security, compliance, privacy, and trust in Microsoft 365
- 225.A Microsoft 365 administrator is configuring a new tenant and needs to ensure that users are always prompted for a second form of verification when signing in, regardless of their location or device, to strengthen account security. Which Azure AD identity management capability should the administrator implement to achieve this universal multi-factor authentication (MFA) enforcement?Describe security, compliance, privacy, and trust in Microsoft 365
- 226.A Microsoft 365 global administrator is investigating a security incident where a user's account was compromised. The administrator needs to review all activities performed by that user over the past 30 days, including file access, email sends, and administrative changes. Which Microsoft 365 compliance capability provides a detailed record of these user and admin activities?Describe security, compliance, privacy, and trust in Microsoft 365
- 227.A Microsoft 365 administrator is implementing a security policy that requires all users accessing sensitive data in SharePoint Online from unmanaged devices to use multi-factor authentication (MFA) and to have their session limited to 'view-only' access. Which Microsoft 365 identity and access management capability should the administrator configure to enforce these specific conditions?Describe security, compliance, privacy, and trust in Microsoft 365
- 228.A Microsoft 365 administrator wants to centrally manage security settings and monitor threat protection across all their Microsoft 365 services, including email, endpoints, identities, and cloud apps. Which unified security portal provides this comprehensive view and management?Describe security, compliance, privacy, and trust in Microsoft 365
- 229.A Microsoft 365 customer wants to verify that Microsoft handles their data in a manner consistent with industry-standard security and compliance frameworks, such as ISO 27001. Which aspect of Microsoft's Trust Center and privacy principles should they review to find evidence of these certifications?Describe security, compliance, privacy, and trust in Microsoft 365
- 230.A multinational corporation uses Microsoft 365 for its global operations. They have a strict policy that all user accounts must be automatically disabled after 90 days of inactivity to reduce security risks. Which Microsoft 365 identity protection capability provides this functionality?Describe security, compliance, privacy, and trust in Microsoft 365
- 231.A Microsoft 365 administrator needs to ensure that specific sensitive data, such as credit card numbers or social security numbers, is not accidentally or maliciously shared outside the organization via email, SharePoint, or Teams. The solution must be able to automatically identify this data and prevent its unauthorized transmission. Which Microsoft 365 compliance feature is designed for this purpose?Describe security, compliance, privacy, and trust in Microsoft 365
- 232.A small business is setting up its Microsoft 365 tenant and wants to ensure that all user accounts have a baseline level of security, such as requiring multi-factor authentication for administrative roles and blocking legacy authentication protocols. They have limited IT staff and need a simple, automated solution. Which Microsoft 365 feature should they enable?Describe security, compliance, privacy, and trust in Microsoft 365
- 233.A Microsoft 365 administrator is configuring a new tenant for a global enterprise. The company has a strict data residency requirement that all data for their European subsidiaries must physically reside and be processed within the European Union. Which Microsoft 365 feature ensures that data for specific users or groups is stored in designated geographic locations?Describe security, compliance, privacy, and trust in Microsoft 365
- 234.A compliance officer at a multinational corporation needs to ensure that all data stored within Microsoft 365, regardless of its location or sensitivity, is subject to specific retention and deletion rules based on various global regulations. They also need to ensure that deleted items are irrecoverable after their retention period. Which Microsoft 365 compliance capability is best suited for this comprehensive requirement?Describe security, compliance, privacy, and trust in Microsoft 365
- 235.A Microsoft 365 administrator is configuring the tenant to comply with industry regulations that mandate strict logging of all access to customer data. The administrator needs a way to confirm that Microsoft support engineers, if they ever require access to the customer's data for troubleshooting, must obtain explicit approval from the customer before accessing it. Which Microsoft 365 privacy control addresses this specific requirement?Describe security, compliance, privacy, and trust in Microsoft 365
- 236.A Microsoft 365 administrator is preparing for an upcoming regulatory audit. The auditors require proof that the organization is actively managing and reducing its compliance risk. The administrator needs a tool to assess the current compliance posture, receive actionable recommendations to improve compliance, and generate reports for auditors. Which Microsoft 365 feature provides these capabilities?Describe security, compliance, privacy, and trust in Microsoft 365
- 237.A global non-profit organization is evaluating cloud services. They require a solution that allows them to provision computing resources, such as virtual machines, storage, and networking, programmatically and on-demand without direct human intervention. Which cloud characteristic best describes this requirement?Describe cloud concepts
- 238.A Microsoft 365 administrator is evaluating different Microsoft 365 plans for a company that requires advanced threat protection, identity and access management, and information protection capabilities. The company also needs full desktop versions of Microsoft 365 apps. Which Microsoft 365 Enterprise plan would best meet these requirements?Describe core Microsoft 365 services and concepts