Describe security, compliance, privacy, and trust in Microsoft 365
MS-900 · 87 questions
- A city needs a cloud directory for Microsoft 365 sign-in and groups. Which Microsoft 365 identity solution provides that cloud identity and access management?
- City hall staff sign in once and then open Outlook, Teams, and SharePoint without entering credentials again. Which Microsoft Entra ID capability does that describe?
- A township runs only cloud identities and has no on-premises Active Directory. Which identity model does that describe?
- A legacy municipal utility still authenticates line-of-business apps against on-premises Active Directory. Which identity concept does that describe?
- A county syncs on-premises Active Directory accounts into Microsoft Entra ID so staff can use Microsoft 365. Which identity model is that?
- A city council mandates that staff must approve a second factor when signing in to email. Which identity protection method does that mandate describe?
- Municipal employees reset forgotten Microsoft 365 passwords themselves without opening help-desk tickets. Which Entra ID capability enables that?
- A city’s payroll apps should be reachable only from compliant devices or trusted locations. Which Microsoft Entra capability is designed for that kind of adaptive access rule?
- A vendor tells a municipal IT lead that passwords alone are enough for Microsoft 365 admin accounts. What should the candidate recommend instead as the foundational identity control?
- A county help desk is flooded every Monday with password-reset tickets. Which Microsoft Entra capability most directly reduces that ticket volume at fundamentals depth?
- Remote municipal staff signing in from unusual countries should face stronger checks before reaching Microsoft 365. Which capability is meant to apply those context-based controls?
- A new civic IT hire says Microsoft Entra ID is only another name for on-premises Active Directory Domain Services. What clarification is accurate for Microsoft 365?
- A city keeps file servers that need on-premises Active Directory while mail has already moved to Exchange Online. Why is hybrid identity often chosen in that situation?
- A smart-city lab startup has no on-premises Active Directory and uses only Microsoft 365. Which identity approach fits that environment?
- Guest auditors need temporary access to a municipal SharePoint site. Which Microsoft Entra ID capability area covers collaborating with those external identities at fundamentals depth?
- A county wants stronger protection for privileged Microsoft 365 roles by combining a second sign-in factor with adaptive access rules. Which pairing best matches that fundamentals goal?
- A city enables self-service password reset, but many employees still call the help desk because they never set up recovery methods. What readiness requirement does that highlight?
- A municipal security program’s phishing-resistant roadmap starts by requiring stronger sign-in for all Microsoft 365 users. Which foundational control should come first in that identity story?
- A township network engineer assumes Conditional Access is simply another perimeter firewall rule set. What is the more accurate description for Microsoft 365?
- A civic CIO asks whether on-premises Active Directory alone can natively authenticate users to Microsoft 365 cloud services with no cloud identity integration. What is the correct fundamentals answer?
- During MS-900 study, a city analyst must explain hybrid identity without configuring sync tools. Which statement stays at the correct fundamentals depth?
- A municipal IT team uses Microsoft Entra ID groups to assign Microsoft 365 licenses and control who can access Teams. Which Entra ID capability does that illustrate?
- After password-spray attempts against municipal Microsoft 365 accounts, leadership asks for a control that reduces success of password-only attacks. Which method fits?
- After several failed logons, a city employee’s Microsoft 365 account is locked. Which Entra ID capability can let that employee unlock or reset access without calling the help desk?
- A county wants to stop risky legacy authentication clients from signing in to Microsoft 365. Which identity capability is commonly described for restricting those pathways?
- A city moves from treating cloud identity as optional to requiring Microsoft Entra ID for every Microsoft 365 workload. What fundamentals conclusion does that adoption reflect?
- A police department keeps a few legacy apps on on-premises Active Directory while Microsoft 365 users sign in with hybrid identities. Which identity pattern does this describe?
- A city security charter lists Microsoft Entra ID as the control plane for Microsoft 365 access. What purpose does Entra ID serve in that charter?
- During a county onboarding day, staff register an authenticator app once so they can complete multifactor authentication and reset forgotten passwords later. What does that registration primarily support?
- A municipal Conditional Access policy requires multifactor authentication whenever Global Administrators and other privileged admins sign in. What describe-level idea does that policy illustrate?
- A city SOC wants correlated security incidents that span email, identity, endpoints, and cloud apps instead of siloed alerts. Which Microsoft capability fits that goal?
- County laptops need endpoint detection and response style protection against device threats. Which Microsoft Defender product is designed for that endpoint role?
- A parks department sees phishing and malware arriving in email and Teams collaboration payloads. Which Defender product primarily protects those collaboration content threats?
- Analysts notice suspicious lateral movement signals around identities and domain controllers on a hybrid city estate. Which Defender product focuses on identity-based threat detection?
- A municipal CIO worries about shadow IT SaaS that staff adopt without approval and wants visibility into those cloud app risks. Which Defender product addresses that CASB-style need?
- County security analysts open one console to investigate Microsoft Defender alerts and incidents. Which experience is that console?
- A city CIO wants a score that shows Microsoft 365 security posture and where improvement actions would help most. Which capability provides that measurement and guidance?
- Secure Score recommendations for a townships tenant highlight enabling multifactor authentication as a high-impact improvement. What Secure Score benefit does that illustrate?
- Credential phishing against staff email is the most common threat the city help desk reports. How does Microsoft 365 typically address that threat at fundamentals depth?
- Ransomware encrypts files on a clerk's city laptop. Which Microsoft Defender product should the fundamentals candidate name for endpoint threat protection in that scenario?
- Finance staff report business email compromise attempts that try to hijack municipal payment conversations. Which Microsoft 365 approach best addresses that email account compromise threat at describe depth?
- On a hybrid municipal estate, security leads worry about pass-the-hash style identity attacks. Which Defender product should they associate with identity threat awareness?
- IT discovers an unsanctioned file-sharing SaaS that city staff use to move building-permit PDFs. Which Defender product is designed for that cloud app risk scenario?
- A council briefing claims XDR is 'just antivirus on each PC.' What correction best describes Microsoft Defender XDR at fundamentals depth?
- The municipal help desk reviews Microsoft Secure Score each month in the security steering meeting. What governance use does that practice illustrate?
- A malware attachment is blocked before it reaches a clerk's mailbox. Which Microsoft Defender product primarily delivers that email content protection?
- Endpoint detection flags suspicious PowerShell activity on a licensing clerk's PC. Which Defender product is designed to detect and respond to that endpoint threat?
- An alert shows an identity exploring sensitive security groups in abnormal ways on the city's hybrid directory. Which Defender product detects that kind of anomalous identity behavior?
- Security wants policy-based monitoring of risky OAuth app consent in municipal SaaS. Which Defender product supports visibility and control for that cloud application activity?
- Analysts investigating one incident pivot in the Microsoft Defender portal across related email and device alerts. What does that experience demonstrate?
- Staff laptops pick up malware from USB drives and risky websites. Which Microsoft 365 threat protection product addresses those common endpoint malware threats?
- A city clerk opens an email that looks like a parking-ticket notice and almost clicks a link that would steal credentials. Which Microsoft 365 capability is specifically meant to help protect against phishing in email and collaboration content?
- A county help desk sees repeated sign-in failures and stolen-password reports against municipal accounts. Which approach best matches how Microsoft 365 addresses common identity compromise threats at fundamentals depth?
- A municipal CIO presents Microsoft Secure Score to the council and a council member asks whether the score is a legal compliance certification. What is the accurate description?
- A township security lead wants threat protection specifically for email and Microsoft 365 collaboration content beyond basic mail filtering talking points. Which product should they name from the Microsoft 365 threat protection family?
- A parks IT analyst says Microsoft Defender XDR is basically the same thing as Azure Firewall. How should a fundamentals candidate correct that?
- A city shadow-IT review needs visibility into unsanctioned SaaS usage, while device enrollment remains a separate endpoint program. Which pairing is correct?
- After a county raises its Microsoft Secure Score, a manager claims phishing simulations and user vigilance are no longer needed. What is the right takeaway?
- A municipal architecture brief repeats never trust, always verify, and least privilege for Microsoft 365 access. Which model is that describing?
- A council member asks which single Microsoft SKU they should buy to 'get Zero Trust finished.' What should the IT lead explain?
- HR suspects a departing public-works employee may be stealing sensitive files before leaving. Which Microsoft Purview capability is designed for potentially risky insider activities?
- Auditors ask who accessed a specific SharePoint budget file last month for a municipal investigation. Which Purview capability records user and admin activities for that kind of inquiry?
- City legal needs to find and export email and Teams content for a lawsuit. Which Microsoft Purview capability fits that discovery need?
- A finance office marks confidential budget workbooks with a Highly Confidential sensitivity label before sharing. What do Microsoft Purview sensitivity labels primarily do?
- A clerk almost emails a spreadsheet of Social Security numbers to an external recipient. Which Microsoft Purview capability is meant to help prevent inappropriate sharing of that sensitive information?
- A residency policy requires certain citizen records to remain stored in a specific geography. How does Microsoft support that requirement at fundamentals depth?
- A city privacy team needs tooling to assess personal-data handling risks and subject-rights style workflows in Microsoft 365. Which solution should they identify?
- A network slogan poster says Zero Trust, but the city still has no MFA and weak identity verification for Microsoft 365. Why does that miss the model?
- Purview insider risk flags a mass download of department files by an employee who just submitted resignation. What does that scenario illustrate?
- After a privilege change, auditors need proof that an admin altered a role assignment in Microsoft 365. Which capability supports that accountability?
- Investigators open an eDiscovery case that must include Microsoft Teams chat content along with other Microsoft 365 material. What should a fundamentals candidate understand?
- A Word ordinance draft receives a sensitivity label that applies encryption and a visible marking. What capability does that demonstrate?
- Before a staffer sends a sensitive Excel file externally, a DLP policy tip warns about the risky share. What is DLP doing in that moment?
- A sister-city partnership raises EU-style expectations that certain personal data stay in an approved geography. Which Microsoft 365 trust topic addresses that concern?
- Privacy officers want to find personal data that is overexposed inside Microsoft 365. Which product’s privacy-risk capabilities are aimed at that kind of discovery?
- A resident submits a subject-rights style request to export their personal data held by the city in Microsoft 365. Which Microsoft solution supports privacy subject-request workflows at fundamentals depth?
- A municipal cybersecurity tabletop assumes ransomware will eventually get inside the network. Which Zero Trust mindset should the city adopt for that readiness discussion?
- A county compliance officer needs the Microsoft 365 family for sensitivity labels, DLP, insider risk, and eDiscovery—not endpoint threat hunting. Which product family fits?
- A city clerk marks budget drafts Highly Confidential so protection travels with the file beyond the SharePoint folder ACL. What do sensitivity labels add compared with permissions alone?
- A township wants to reduce accidental sharing of Social Security numbers from email, files, and chat. At describe depth, where can Microsoft Purview DLP help protect that sensitive information?
- City legal needs a formal discovery hold across mailboxes and Teams for a lawsuit—not a staffer’s everyday Outlook find. Which capability matches that purpose?
- HR flags unusual mass downloads by a departing public-works employee, while another team only wants to stop Social Security numbers from leaving in email. How should the city distinguish insider risk from DLP?
- After a suspicious admin role change, auditors ask whether Microsoft 365 retained an activity history they can investigate. Which Purview benefit answers that need?
- A sister-city partnership requires citizen records to remain stored in a specific geography. A council member thinks that requirement only means customer-managed encryption keys. What does data residency actually emphasize?
- A privacy officer reviewing citizen personal-data risks keeps calling the work Purview eDiscovery. Which distinction should the team correct?
- A Zero Trust briefing for city endpoints says device health should influence whether a session reaches Microsoft 365. Which pairing matches that model-level idea?
- During a privacy impact discussion for a new citizen-services app, the privacy lead wants the named Microsoft 365 privacy tooling called out on the skills list. Which solution should they mention?