MS-900 Microsoft 365 Fundamentals Microsoft 365 Security Solutions 4 — Questions and Answers
Question 1: A healthcare organization using Microsoft 365 needs to ensure patient data is classified and labeled appropriately before sharing. Which Microsoft Purview feature should they configure?
- Sensitivity labels (Correct answer)
- Retention labels
- Communication compliance policies
- eDiscovery holds
Correct answer: Sensitivity labels
Sensitivity labels classify and optionally protect content by applying encryption, access restrictions, and visual markings based on the data's sensitivity level.
Question 2: Which Microsoft 365 security concept involves granting users only the minimum permissions required to perform their job functions?
- Defense in depth
- Principle of least privilege (Correct answer)
- Zero Trust networking
- Identity federation
Correct answer: Principle of least privilege
The principle of least privilege limits user access rights to only what is necessary, reducing the attack surface if an account is compromised.
Question 3: What is Microsoft Cloud App Security (now Microsoft Defender for Cloud Apps) primarily used for?
- Providing antivirus protection for Windows endpoints in the organization
- Gaining visibility into and control over cloud app usage, including shadow IT detection (Correct answer)
- Managing SharePoint storage quotas and document library permissions
- Configuring email flow rules and connectors in Exchange Online
Correct answer: Gaining visibility into and control over cloud app usage, including shadow IT detection
Microsoft Defender for Cloud Apps provides visibility into cloud app usage, detects shadow IT, and enforces security policies across sanctioned and unsanctioned apps.
Question 4: An employee is about to share a file containing credit card numbers via OneDrive. Which Microsoft 365 capability can automatically detect and block this sensitive data from being shared externally?
- Azure AD Conditional Access
- Data Loss Prevention (DLP) policy (Correct answer)
- Microsoft Intune app protection policy
- Microsoft Teams communication compliance
Correct answer: Data Loss Prevention (DLP) policy
DLP policies can detect sensitive information types like credit card numbers and automatically block, warn, or notify users when they attempt to share such data.
Question 5: Which Microsoft 365 security feature provides just-in-time privileged access for administrators to reduce standing administrator permissions?
- Azure AD Self-Service Password Reset
- Azure AD Privileged Identity Management (PIM) (Correct answer)
- Microsoft Endpoint Manager enrollment
- Microsoft Secure Score recommendations
Correct answer: Azure AD Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) enables just-in-time privileged access, requiring admins to activate elevated permissions only when needed.
Question 6: What distinguishes Microsoft Defender for Endpoint from Microsoft Defender for Office 365?
- Defender for Endpoint protects email and collaboration tools; Defender for Office 365 protects devices
- Defender for Endpoint protects Windows/macOS/mobile devices; Defender for Office 365 protects email and collaboration services (Correct answer)
- Both products provide identical protection but for different Microsoft 365 licensing tiers
- Defender for Endpoint is a legacy product replaced by Defender for Office 365
Correct answer: Defender for Endpoint protects Windows/macOS/mobile devices; Defender for Office 365 protects email and collaboration services
Defender for Endpoint focuses on endpoint device security (EDR), while Defender for Office 365 focuses on email, Teams, SharePoint, and OneDrive protection.
Question 7: Which element of the Zero Trust security model assumes that threats exist both inside and outside the traditional network perimeter?
- Verify explicitly — always authenticate and authorize based on all available data points
- Never trust, always verify — assume breach and treat all network traffic as potentially hostile
- Use least privilege access — limit user access to only what is needed
- All of the above principles are foundational to Zero Trust (Correct answer)
Correct answer: All of the above principles are foundational to Zero Trust
Zero Trust is built on three principles: verify explicitly, use least privilege access, and assume breach — all are equally foundational to the model.
A healthcare organization using Microsoft 365 needs to ensure patient data is classified and labeled appropriately before sharing.
Which Microsoft Purview feature should they configure?