Free MS-900 Module 02 Questions and Answers — Questions and Answers
Question 1: Signals are combined, choices are made, and organizational policies are enforced through conditional access. One of the features of ______________ is conditional access.
- Cloud App security
- Privileged Identity Management
- AAD Premium 1 (Correct answer)
- AD
Correct answer: AAD Premium 1
Conditional Access is a feature of Azure Active Directory (AAD) Premium P1 that allows organizations to enforce policies based on various signals, such as user location, device compliance, and application sensitivity. It enables granular control over resource access, ensuring that users can only access resources when specific conditions are met. This capability is crucial for implementing a robust Zero Trust security model.
Question 2: Users recently complained that they were unable to access specific SharePoint sites. You are required to rate Microsoft 365's current state of health. Which option from the list would you pick to satisfy the requirement?
- Threat management dashboard
- Service health page (Correct answer)
- Service request history page
- SharePoint product page
Correct answer: Service health page
The Microsoft 365 Service health page provides real-time information about the status and availability of Microsoft 365 services, including SharePoint Online. When users report issues like being unable to access sites, checking this page is the first step to determine if there's a known service incident or outage affecting the platform. It offers transparent updates on service disruptions and planned maintenance.
Question 3: Administrators can turn on the ______________ option for Microsoft 365 Activity Reports to lessen the risk associated with personally identifiable information.
- Anonymization (Correct answer)
- Exfiltration
- Randomization
- Obfuscation
Correct answer: Anonymization
Anonymization is the process of removing or modifying personally identifiable information (PII) from data so that individuals cannot be identified. Enabling this option in Microsoft 365 Activity Reports allows administrators to analyze usage patterns and trends without exposing sensitive user data, thereby significantly reducing privacy risks and enhancing compliance.
Question 4: PTG Ltd. is getting ready to switch to Microsoft Azure and Office 365. Peter has been tasked with finding a cloud provider that offers website hosting as part of the process. Which choice from the list below should he pick in order to fulfill the requirement?
- Software as a Service (SaaS)
- Platform as a Service (PaaS) (Correct answer)
- Infrastructure as a Service (IaaS)
- Container as a Service (CaaS)
Correct answer: Platform as a Service (PaaS)
Platform as a Service (PaaS) provides a complete development and deployment environment in the cloud, including infrastructure, operating systems, and tools, making it ideal for hosting web applications. With PaaS, users can deploy their websites without managing the underlying servers or network infrastructure, which is typically handled by the cloud provider.
Question 5: Marlon is employed by PTG Ltd. as a Compliance Administrator. He has been requested to look for users who have visited particular SharePoint sites. What instrument should Marlon use in this situation?
- Microsoft 365 admin center
- SharePoint Report Server
- Audit log search (Correct answer)
- SharePoint admin center
Correct answer: Audit log search
The audit log search in Microsoft 365 allows administrators to track user and admin activities across various services, including SharePoint Online. By searching the audit log, Marlon can identify specific user actions, such as visiting SharePoint sites, which is essential for compliance, security investigations, and understanding user engagement.
Question 6: For PTG Ltd., Maurice serves as the Office 365 administrator. Before sending any updates to the entire firm, he has been instructed to complete security and compliance reviews. Which choice from the list below ought to George use to fulfill the requirement?
- Targeted Releases (Correct answer)
- FastTrack
- Microsoft 365 Enterprise Test Lab
- Standard Releases
Correct answer: Targeted Releases
Targeted Release (formerly First Release) in Microsoft 365 allows organizations to receive updates and new features early, before the standard worldwide release. This enables administrators like Maurice to test and review changes, including security and compliance implications, in a controlled environment with a subset of users before they are rolled out to the entire organization.
Question 7: Microsoft 365 has been installed by PTG Ltd. Dan pointed out places where several Microsoft 365 services may be enhanced. Dan has been invited to formally submit his enhancement recommendations to Microsoft. He should submit a feature request using which of the following tools.
- Microsoft Office Support site
- UserVoice site (Correct answer)
- Security & Compliance Center
- Microsoft 365 Roadmap site
- Feedback Hub app
Correct answer: UserVoice site
The UserVoice site (now often integrated into Microsoft Feedback Portal) was historically the primary platform for Microsoft 365 users to submit feature requests and provide feedback directly to Microsoft product teams. It allowed users to suggest enhancements, vote on existing ideas, and engage with the development process, ensuring their input could influence future product development.
Question 8: When a user accesses a federated third-party application, PTG Ltd., which makes use of Microsoft 365, wants to ask them for extra verification. Additionally, it's vital to refrain from asking users for more authentication when they enter Microsoft Outlook. You've been tasked with coming up with a workable solution that satisfies these demands. What choice from the list should be used to fulfill the requirement?
- Active Directory Federation Services (AD FS)
- Conditional Access (Correct answer)
- Self-service password reset (SSPR)
- Multi-factor authentication (MFA)
Correct answer: Conditional Access
Conditional Access policies in Azure Active Directory allow administrators to enforce specific access requirements based on various conditions, such as user location, device state, or application being accessed. This enables PTG Ltd. to require extra verification (like MFA) for federated third-party applications while exempting trusted applications like Microsoft Outlook, providing granular control over access.
Question 9: Daniel is employed with PTG Ltd. Recently, he was instructed to use Windows Autopilot to deploy Windows 10 devices inside the corporate environment. He has been requested to offer a solution to make sure that users' remote access to data saved in OneDrive for Business is maintained. Solution: Daniel recommends enabling multi-factor authentication for users of Microsoft Azure AD. Does the proposed approach successfully achieve the desired result?
- No (Correct answer)
- Yes
Correct answer: No
While Multi-Factor Authentication (MFA) enhances security for user logins to Azure AD and subsequently OneDrive for Business, it does not *directly* ensure remote access to data. Remote access to OneDrive for Business data is inherently provided by OneDrive's cloud nature and synchronization capabilities, not solely by MFA. Therefore, MFA alone does not fulfill the requirement of *maintaining* remote access, though it secures it.
Question 10: James is employed by TPT Ltd. as a Microsoft 365 administrator. In compliance with the provisions of the General Data Protection Regulation (GDPR), one of the employees seeks personal information. For the employee, he must retrieve the information. Which choice from the list below should he pick in order to fulfill the requirement?
- Create a data subject request case. (Correct answer)
- Create a GDPR assessment.
- Create a data-loss prevention policy.
- Create a retention policy.
Correct answer: Create a data subject request case.
Under GDPR, individuals have the right to request access to their personal data held by an organization, known as a Data Subject Access Request (DSAR). Microsoft 365 provides tools within the compliance center to manage these requests by creating a data subject request case, which helps administrators efficiently search, review, and export an employee's personal information across various services.
Question 11: What does the word "scalable" refer to when discussing cloud services?
- Able to build models.
- Able to resize organizational data structures.
- Able to add or reduce service capacity on demand. (Correct answer)
- Services are deployed in a redundant manner.
Correct answer: Able to add or reduce service capacity on demand.
Scalability in cloud computing refers to the ability of a system to handle a growing amount of work by adding or reducing resources as needed. This means cloud services can dynamically increase or decrease their capacity, such as computing power, storage, or network bandwidth, to meet fluctuating demand without manual intervention or significant downtime.
Question 12: What information is required in order to integrate Microsoft 365 Usage Analytics to Power BI?
- What information is required in order to integrate Microsoft 365 Usage Analytics to Power BI? (Correct answer)
- Activity report ID
- Power BI Template ID
- Global Administrator Object ID
Correct answer: What information is required in order to integrate Microsoft 365 Usage Analytics to Power BI?
The provided correct answer is identical to the question itself, indicating a potential error in the question's options. In a typical scenario, integrating Microsoft 365 Usage Analytics with Power BI requires specific data connection details, such as a tenant ID or access to the Microsoft 365 Usage Analytics content pack, to establish the data flow and visualize usage reports.
Question 13: A Microsoft 365 outage that impacts the entire region is experienced by a business. The service is healthy, as you can see from the Service Health Dashboard. You must locate information in Service Health Dashboard that explains what transpired during the outage after the situation has been fixed. Which should you employ?
- Messenger Center
- Incident closure summary
- Post-Incident Review (PIR) (Correct answer)
- Service request
Correct answer: Post-Incident Review (PIR)
A Post-Incident Review (PIR) is a detailed report provided by Microsoft after a significant service incident or outage has been resolved. It explains the root cause of the outage, the steps taken to mitigate it, and the preventative measures implemented to avoid recurrence. This document is crucial for understanding what transpired and for organizational learning.
Question 14: Which two Intune remote actions are accessible when Configuration Manager and Intune are set up for co-management?
- User reset
- Factory reset (Correct answer)
- Remote control (Correct answer)
- Application reset
Correct answer: Factory reset
When Configuration Manager and Intune are set up for co-management, certain remote actions become available through Intune for Windows 10 devices. 'Factory reset' (also known as Wipe) allows an administrator to reset a device to its factory default settings, while 'Remote control' enables remote assistance for troubleshooting. These actions provide powerful device management capabilities in a co-managed environment.
Question 15: Which of the following is the acronym for GDPR?
- General Data Privacy Regulation
- General Data Protection Regulation (Correct answer)
- General Data Primary Regulation
- General Data Proposed Regulation
Correct answer: General Data Protection Regulation
GDPR stands for General Data Protection Regulation, a comprehensive data privacy law enacted by the European Union. It imposes strict rules on how personal data is collected, stored, processed, and protected, granting individuals greater control over their personal information. Organizations worldwide must comply with GDPR if they process data of EU residents.
Question 16: Which interface is used to obtain Microsoft 365 Activity Reports?
- Security & Compliance Center
- SharePoint Admin Center
- Report Center
- Microsoft 365 Admin Center (Correct answer)
Correct answer: Microsoft 365 Admin Center
The Microsoft 365 Admin Center is the central portal for managing an organization's Microsoft 365 services, including user accounts, licenses, and service health. It also provides access to various reports, such as the Activity Reports, which offer insights into user adoption, usage patterns, and service health across different Microsoft 365 applications.
Signals are combined, choices are made, and organizational policies are enforced through conditional access.
One of the features of ______________ is conditional access.