MS-900 Microsoft 365 Fundamentals Microsoft 365 Security Solutions 2 — Questions and Answers
Question 1: Which Microsoft 365 feature uses machine learning to detect unusual sign-in patterns and automatically block suspicious access attempts?
- Azure AD Identity Protection (Correct answer)
- Microsoft Defender for Office 365
- Microsoft Purview Compliance Portal
- Microsoft Endpoint Manager
Correct answer: Azure AD Identity Protection
Azure AD Identity Protection uses machine learning to detect risky sign-ins and can automatically block or require MFA for suspicious access.
Question 2: A company wants to prevent users from forwarding sensitive emails outside the organization. Which Microsoft 365 security feature should they use?
- Safe Attachments
- Information Rights Management (IRM) (Correct answer)
- Secure Score
- Attack Simulator
Correct answer: Information Rights Management (IRM)
Information Rights Management (IRM) allows organizations to restrict email actions like forwarding, copying, or printing sensitive messages.
Question 3: What does Microsoft Secure Score measure in a Microsoft 365 environment?
- Network bandwidth usage across all Microsoft 365 services
- The organization's security posture based on implemented security controls (Correct answer)
- Number of active user licenses in the tenant
- Performance benchmarks for Microsoft 365 applications
Correct answer: The organization's security posture based on implemented security controls
Microsoft Secure Score measures an organization's security posture by assigning points for implemented security controls and configurations.
Question 4: Which type of attack does Microsoft Defender for Office 365 Safe Links protect against?
- Brute force password attacks
- Malicious URLs embedded in emails and documents (Correct answer)
- Unauthorized device enrollment
- Data exfiltration via USB drives
Correct answer: Malicious URLs embedded in emails and documents
Safe Links rewrites and checks URLs at the time of click to protect users from malicious links in emails and Office documents.
Question 5: An administrator needs to enforce that all mobile devices accessing company email meet minimum security requirements. Which Microsoft 365 solution provides this capability?
- Microsoft Teams
- Microsoft Intune (Correct answer)
- Microsoft Forms
- Microsoft Viva
Correct answer: Microsoft Intune
Microsoft Intune provides mobile device management (MDM) and mobile application management (MAM) to enforce compliance policies on devices.
Question 6: What is the primary purpose of Conditional Access policies in Microsoft 365?
- To schedule automatic software updates for all tenant users
- To grant or block access based on signals like user location, device health, and risk level (Correct answer)
- To manage email retention schedules and archiving rules
- To configure bandwidth throttling for Microsoft Teams meetings
Correct answer: To grant or block access based on signals like user location, device health, and risk level
Conditional Access policies evaluate signals such as user identity, location, device compliance, and risk level to make real-time access decisions.
Question 7: Which Microsoft 365 security feature provides a simulated phishing attack capability so administrators can train employees?
- Microsoft Defender for Endpoint
- Attack Simulation Training in Microsoft Defender for Office 365 (Correct answer)
- Azure AD Privileged Identity Management
- Microsoft Purview Insider Risk Management
Correct answer: Attack Simulation Training in Microsoft Defender for Office 365
Attack Simulation Training lets administrators send simulated phishing emails to employees to measure susceptibility and deliver targeted security training.
Which Microsoft 365 feature uses machine learning to detect unusual sign-in patterns and automatically block suspicious access attempts?