MS-900 Security, Compliance, & Privacy in Microsoft 365 — Questions and Answers
Question 1: Which feature helps protect Microsoft 365 from malware and phishing attacks?
- Azure AD Connect
- Microsoft Defender (Correct answer)
- OneDrive
- Yammer
Correct answer: Microsoft Defender
Microsoft Defender, specifically Microsoft Defender for Office 365, is a robust security solution that helps protect Microsoft 365 environments from advanced threats like malware, phishing attacks, and ransomware. It provides advanced threat protection capabilities, including safe attachments and safe links, to safeguard users and data. This ensures a secure email and collaboration experience.
Question 2: What is the role of Microsoft Purview Compliance Manager?
- Runs Excel macros
- Monitors compliance posture and risks (Correct answer)
- Manages email signatures
- Edits videos
Correct answer: Monitors compliance posture and risks
Microsoft Purview Compliance Manager is a tool within Microsoft 365 designed to help organizations manage and improve their compliance posture. It provides a dashboard to assess compliance risks, track progress on compliance activities, and generate reports against various regulatory standards. This helps organizations meet their legal and industry-specific compliance obligations.
Question 3: What is multi-factor authentication (MFA)?
- Single password login
- Access using a username only
- Multiple verification steps for secure access (Correct answer)
- Disable login protection
Correct answer: Multiple verification steps for secure access
Multi-factor authentication (MFA) is a security measure that requires users to provide two or more verification factors to gain access to an account or system. Instead of just a password, it might also require a code from a mobile app, a fingerprint, or a physical token. This significantly enhances security by making it much harder for unauthorized users to access accounts, even if they know a password.
Question 4: Which policy helps prevent data leaks in Microsoft 365?
- AutoSave
- Data Loss Prevention (DLP) (Correct answer)
- Archive policy
- Bookmark sync
Correct answer: Data Loss Prevention (DLP)
Data Loss Prevention (DLP) policies in Microsoft 365 are designed to prevent sensitive information from being accidentally or intentionally shared outside the organization. DLP identifies, monitors, and protects sensitive data across various Microsoft 365 services, such as email and SharePoint. By enforcing rules, DLP helps organizations comply with regulations and protect proprietary information.
Question 5: What is the benefit of Microsoft 365 Information Protection?
- Stores YouTube links
- Protects and labels sensitive content (Correct answer)
- Manages Excel sheets
- Uploads TikTok videos
Correct answer: Protects and labels sensitive content
Microsoft 365 Information Protection (MIP) provides tools to discover, classify, label, and protect sensitive content across an organization. It allows users to apply sensitivity labels to documents and emails, which then enforce specific protection actions like encryption or access restrictions. This ensures that sensitive data remains secure and compliant, regardless of where it is stored or shared.
Question 6: Which portal allows admins to configure and manage security settings?
- Billing Portal
- Security Center (Correct answer)
- Design Studio
- Whiteboard
Correct answer: Security Center
The Microsoft 365 Security Center (now part of the Microsoft 365 Defender portal) is the centralized portal where administrators can configure, monitor, and manage security settings and policies for their Microsoft 365 environment. It provides a comprehensive view of security posture, threat protection, and compliance features. This allows admins to effectively safeguard their organization's data and users.
Question 7: Which compliance standard does Microsoft 365 help customers align with?
- HTML5
- GDPR and ISO 27001 (Correct answer)
- Flash
- CSS
Correct answer: GDPR and ISO 27001
Microsoft 365 is designed with robust compliance capabilities to help customers align with various global and industry-specific regulatory standards. Notably, it supports compliance with regulations like the General Data Protection Regulation (GDPR) and international standards such as ISO 27001. Microsoft provides tools and certifications to assist organizations in meeting these stringent requirements.
Question 8: What is the purpose of audit logs in Microsoft 365?
- Create PowerPoint slides
- Track and record actions for review (Correct answer)
- Sync bookmarks
- Design templates
Correct answer: Track and record actions for review
Audit logs in Microsoft 365 are crucial for tracking and recording user and admin activities across various services. These logs capture details such as who performed an action, what action was taken, and when it occurred. This functionality is essential for security investigations, compliance auditing, and troubleshooting, providing a verifiable record of events within the environment.
Question 9: What is the Microsoft Trust Center?
- Customer support center
- Blog for developers
- Official resource for security and compliance transparency (Correct answer)
- Marketing hub
Correct answer: Official resource for security and compliance transparency
The Microsoft Trust Center is a public-facing website that serves as an official resource for information regarding Microsoft's security, privacy, compliance, and transparency practices. It provides detailed documentation, whitepapers, and reports on how Microsoft protects customer data and adheres to various industry standards and regulations. It is a key resource for customers to understand Microsoft's commitment to trust.
Which feature helps protect Microsoft 365 from malware and phishing attacks?