MS-900 - Microsoft 365 Fundamentals Microsoft 365 Security Solutions Questions and Answers — Questions and Answers
Question 1: An organization wants to proactively protect its users from malicious URLs in emails and Microsoft Teams chats. When a user clicks a link, the service should check it in real-time against a list of known malicious sites and block access if a threat is detected. Which Microsoft 365 Defender feature provides this capability?
- Safe Attachments
- Safe Links (Correct answer)
- Anti-phishing policies
- Microsoft Defender for Endpoint
Correct answer: Safe Links
Microsoft Defender for Office 365 includes the Safe Links feature, which provides time-of-click verification of URLs in emails and Office documents. It proactively protects users from malicious links by dynamically blocking them while allowing access to safe links.
Question 2: A company's security team wants a single, bird's-eye view of security events across their entire digital estate, including Microsoft 365, Azure, and on-premises resources. They need a solution that can collect data from all these sources, perform intelligent analysis to detect complex threats, and orchestrate automated responses. Which Microsoft security solution is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) tool designed for this purpose?
- Microsoft Defender XDR
- Microsoft Purview
- Microsoft Sentinel (Correct answer)
- Microsoft Entra ID
Correct answer: Microsoft Sentinel
Microsoft Sentinel is a cloud-native SIEM and SOAR solution that provides intelligent security analytics and threat intelligence across the enterprise. It collects data from various sources, including Microsoft 365 and Azure, to detect, investigate, and respond to threats.
Question 3: An administrator is looking for a way to measure the organization's security posture and get actionable recommendations for improvement. They want a centralized dashboard that provides a numerical score based on the implementation of security controls across identities, devices, and apps. Which feature within the Microsoft 365 Defender portal serves this function?
- Compliance Manager
- Service Trust Portal
- Microsoft Secure Score (Correct answer)
- Threat Analytics
Correct answer: Microsoft Secure Score
Microsoft Secure Score is a measurement of an organization's security posture, with a higher number indicating more recommended actions have been taken. It provides a centralized dashboard in the Microsoft 365 Defender portal to monitor and improve the security of Microsoft 365 identities, apps, and devices.
Question 4: A financial services firm needs to automatically discover, classify, and protect sensitive information, such as credit card numbers and financial reports, wherever it resides. They want to apply sensitivity labels to documents and emails to enforce protection policies like encryption and access restrictions. Which Microsoft 365 solution provides these information protection and data governance capabilities?
- Microsoft Defender for Identity
- Microsoft Sentinel
- Microsoft Entra Conditional Access
- Microsoft Purview Information Protection (Correct answer)
Correct answer: Microsoft Purview Information Protection
Microsoft Purview Information Protection (formerly Microsoft Information Protection) helps you discover, classify, and protect sensitive information wherever it lives or travels. It uses capabilities like sensitivity labels to apply protection actions, including encryption and access restrictions.
Question 5: Which of the following provides organizations with access to audit reports, compliance documentation, and trust-related information about Microsoft's cloud services, demonstrating how Microsoft meets various regulatory standards?
- Microsoft Secure Score
- Service Trust Portal (Correct answer)
- Microsoft Purview Compliance Manager
- Microsoft Defender Portal
Correct answer: Service Trust Portal
The Microsoft Service Trust Portal is the central location for accessing documentation about Microsoft's compliance with international standards and regulations. It provides access to third-party audit reports, white papers, and information about how Microsoft cloud services protect customer data.
Question 6: An organization is concerned about phishing attacks and zero-day malware being delivered through email attachments. They need a security solution that scans attachments in a sandboxed environment to analyze their behavior and block them before they reach the user's mailbox if they are found to be malicious. Which Microsoft Defender for Office 365 feature addresses this specific requirement?
- Safe Links
- Threat Explorer
- Safe Attachments (Correct answer)
- Attack simulation training
Correct answer: Safe Attachments
Safe Attachments in Microsoft Defender for Office 365 protects against unknown malware and viruses by routing all email attachments without a known signature to a special 'detonation' chamber. This sandboxed environment uses machine learning and analysis to detect malicious intent before the email is delivered.
An organization wants to proactively protect its users from malicious URLs in emails and Microsoft Teams chats.
When a user clicks a link, the service should check it in real-time against a list of known malicious sites and block access if a threat is detected.
Which Microsoft 365 Defender feature provides this capability?