Microsoft 365 (Reading) — Questions and Answers
Question 1: What is the purpose of reading message trace logs in Microsoft 365?
- To monitor user login attempts
- To trace email delivery paths (Correct answer)
- To analyze disk usage
- To reset passwords
Correct answer: To trace email delivery paths
Message trace logs in Microsoft 365 are essential diagnostic tools for administrators. Their primary purpose is to track the journey of an email message as it travels through the Exchange Online service, from sender to recipient. These logs provide detailed information about the message's delivery status, including whether it was delivered, deferred, or failed, and any actions taken on it, such as being quarantined or marked as spam.
Question 2: Which component in Microsoft 365 lets you read reports about message hygiene?
- Azure Portal
- Outlook Web
- Security & Compliance Center (Correct answer)
- Teams Dashboard
Correct answer: Security & Compliance Center
The Microsoft 365 Security & Compliance Center (now often referred to as the Microsoft Purview compliance portal or Microsoft 365 Defender portal for security aspects) is the central hub for managing an organization's security and compliance needs. It provides various reports and dashboards related to message hygiene, including anti-malware, anti-spam, and data loss prevention policies, allowing administrators to monitor and analyze the effectiveness of their messaging security.
Question 3: Where can administrators read the delivery status of an email?
- Power BI
- Azure DevOps
- Exchange admin center (Correct answer)
- OneDrive dashboard
Correct answer: Exchange admin center
The Exchange admin center (EAC) is the web-based management console for Exchange Online in Microsoft 365. Administrators can use the EAC to perform various messaging-related tasks, including managing mailboxes, mail flow rules, and critically, running message traces. The message trace feature within the EAC allows administrators to check the delivery status of specific emails, providing details on whether a message was delivered, rejected, or quarantined.
Question 4: What type of information can be read from an email header?
- Calendar events
- Routing and security data (Correct answer)
- Chat history
- Files shared
Correct answer: Routing and security data
An email header contains crucial metadata about an email message, providing a detailed history of its journey from sender to recipient. This information includes routing details like the mail servers it passed through, sender and recipient IP addresses, and timestamps. It also contains security-related data such as authentication results (SPF, DKIM, DMARC), spam scores, and anti-malware scan results, which are vital for troubleshooting delivery issues and investigating security incidents.
Question 5: What should be read to understand why an email was quarantined?
- Blocked sender list
- Message center feed
- Quarantine message details (Correct answer)
- Azure Active Directory logs
Correct answer: Quarantine message details
When an email is quarantined in Microsoft 365, it is held in a secure location because it was identified as spam, malware, or violated a mail flow rule. To understand why a specific email was quarantined, administrators should access the quarantine message details within the Microsoft 365 Defender portal or Exchange admin center. These details provide the specific reason for quarantine, such as the detected threat, the policy it violated, and options for releasing or deleting the message.
Question 6: Where can you read about current service health for Microsoft 365?
- Security & Compliance Center
- Microsoft 365 Admin Center (Correct answer)
- Microsoft Learn
- Exchange message trace
Correct answer: Microsoft 365 Admin Center
The Microsoft 365 Admin Center is the central portal for administrators to manage their Microsoft 365 services. It provides a dedicated "Service health" dashboard where administrators can view the current status, incidents, and planned maintenance for all their subscribed Microsoft 365 services. This allows them to stay informed about potential service disruptions and communicate effectively with users.
Question 7: Why is it important to read retention policy settings?
- To adjust antivirus settings
- To track login failures
- To manage data lifecycle (Correct answer)
- To send group invites
Correct answer: To manage data lifecycle
Retention policies are crucial for managing the lifecycle of data within an organization. They define how long specific types of data, such as emails or documents, should be kept or deleted. This helps organizations comply with legal and regulatory requirements, reduce storage costs, and ensure that only necessary data is retained, thereby managing information governance effectively.
Question 8: Which Microsoft 365 feature allows reading user mailbox access logs?
- Mailbox insights
- Audit logging (Correct answer)
- Exchange connectors
- Yammer history
Correct answer: Audit logging
Audit logging in Microsoft 365 allows administrators to track and review activities performed on user mailboxes, including who accessed a mailbox, when, and what actions were taken. This feature is vital for security, compliance, and forensic investigations, as it provides a detailed record of mailbox access, helping to identify unauthorized activity or investigate data breaches.
Question 9: How can you read threat detection information in Microsoft 365?
- Yammer posts
- Threat Explorer (Correct answer)
- PowerPoint reports
- Microsoft Planner
Correct answer: Threat Explorer
Threat Explorer, part of Microsoft Defender for Office 365, is a powerful security tool that allows administrators to investigate and analyze threats like malware, phishing, and spam. It provides detailed insights into email-borne threats, including sender information, delivery status, and detection details, enabling proactive threat hunting and incident response.
What is the purpose of reading message trace logs in Microsoft 365?