MS-900 Microsoft 365 Fundamentals Microsoft 365 Security Solutions 3 — Questions and Answers
Question 1: Which Microsoft 365 service provides data loss prevention (DLP) policies that can detect and protect sensitive information across Exchange, SharePoint, and Teams?
- Microsoft Purview (Correct answer)
- Microsoft Defender for Identity
- Azure Sentinel
- Microsoft Endpoint Configuration Manager
Correct answer: Microsoft Purview
Microsoft Purview (formerly Microsoft 365 Compliance) includes DLP policies that identify and protect sensitive information across multiple Microsoft 365 workloads.
Question 2: What is the role of Azure Active Directory (Azure AD) in Microsoft 365 security?
- It provides cloud storage for all Microsoft 365 documents and files
- It serves as the identity and access management foundation for Microsoft 365 services (Correct answer)
- It manages billing and subscription licensing for Microsoft 365 tenants
- It provides real-time collaboration features in Microsoft Teams
Correct answer: It serves as the identity and access management foundation for Microsoft 365 services
Azure AD is the identity provider for Microsoft 365, handling authentication, authorization, and user management across all Microsoft 365 services.
Question 3: A user receives an email with a malicious attachment that has not yet been identified by antivirus signatures. Which Microsoft Defender for Office 365 feature would detonate this attachment in a sandbox environment?
- Safe Links
- Safe Attachments (Correct answer)
- Anti-phishing policies
- Quarantine policies
Correct answer: Safe Attachments
Safe Attachments opens suspicious files in a virtual environment (sandbox) to observe behavior before delivering them to the recipient.
Question 4: Which Microsoft 365 feature allows administrators to require users to prove their identity using two or more verification methods before granting access?
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA) (Correct answer)
- Password Hash Synchronization
- Azure AD B2C
Correct answer: Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) requires users to provide two or more verification factors, significantly reducing the risk of compromised credentials.
Question 5: What does the 'shared responsibility model' mean in the context of Microsoft 365 security?
- Microsoft and users share equal administrative rights over all tenant settings
- Security responsibilities are divided between Microsoft (infrastructure) and the customer (data, identities, devices) (Correct answer)
- All security configurations are managed exclusively by Microsoft to ensure compliance
- Customers and Microsoft jointly set retention policies for regulated industries
Correct answer: Security responsibilities are divided between Microsoft (infrastructure) and the customer (data, identities, devices)
In the shared responsibility model, Microsoft secures the underlying cloud infrastructure while customers are responsible for securing their data, identities, and device configurations.
Question 6: Which Microsoft 365 plan tier is required to access Microsoft Defender for Office 365 Plan 2 features like Threat Explorer and Automated Investigation?
- Microsoft 365 Business Basic
- Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 add-on (Correct answer)
- Microsoft 365 Business Standard
- Microsoft 365 F1
Correct answer: Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 add-on
Defender for Office 365 Plan 2 features, including Threat Explorer and AIR, are available with Microsoft 365 E5 or as an add-on subscription.
Question 7: What is the primary function of Microsoft Defender for Identity (formerly Azure ATP)?
- Scanning email attachments for malware before delivery to users
- Detecting advanced threats and compromised identities by monitoring on-premises Active Directory signals (Correct answer)
- Enforcing mobile device compliance policies for BYOD scenarios
- Managing guest user access to SharePoint sites and Teams channels
Correct answer: Detecting advanced threats and compromised identities by monitoring on-premises Active Directory signals
Microsoft Defender for Identity monitors on-premises Active Directory to detect lateral movement, credential theft, and other identity-based attacks.
Which Microsoft 365 service provides data loss prevention (DLP) policies that can detect and protect sensitive information across Exchange, SharePoint, and Teams?