MS-900 Security, Compliance, & Privacy in Microsoft 2 — Questions and Answers
Question 1: Which Microsoft 365 feature provides a centralized hub for monitoring your organization's security posture and recommending improvement actions?
- Microsoft Secure Score (Correct answer)
- Compliance Manager
- Azure Security Center
- Microsoft Defender for Endpoint
Correct answer: Microsoft Secure Score
Microsoft Secure Score is a measurement of an organization's security posture that provides recommended improvement actions to strengthen security.
Question 2: What is the primary purpose of Microsoft Purview Compliance Manager?
- Blocking malware in email
- Assessing and managing compliance risks against regulatory requirements (Correct answer)
- Encrypting files stored in SharePoint
- Monitoring user sign-in activity
Correct answer: Assessing and managing compliance risks against regulatory requirements
Compliance Manager helps organizations assess compliance risks, manage compliance activities, and track progress against regulatory standards.
Question 3: Which Microsoft service uses AI to detect unusual patterns in user behavior that may indicate a compromised account?
- Microsoft Defender for Office 365
- Azure AD Identity Protection (Correct answer)
- Microsoft Intune
- Microsoft Sentinel
Correct answer: Azure AD Identity Protection
Azure AD Identity Protection uses machine learning to detect risky sign-ins and user behaviors that may indicate identity compromise.
Question 4: A user in your organization accidentally shares a confidential document externally. Which Microsoft 365 feature would have prevented this based on the document's content?
- Multi-Factor Authentication
- Data Loss Prevention (DLP) policy (Correct answer)
- Conditional Access
- Microsoft Defender Antivirus
Correct answer: Data Loss Prevention (DLP) policy
DLP policies detect sensitive content and prevent it from being shared externally based on predefined rules and conditions.
Question 5: What does the principle of 'Zero Trust' assume about network traffic inside a corporate network?
- Internal traffic is always safe and trusted
- No traffic should be trusted by default, even internal traffic (Correct answer)
- Only external traffic needs verification
- Trust is granted automatically after first login
Correct answer: No traffic should be trusted by default, even internal traffic
Zero Trust assumes breach and verifies every request explicitly, regardless of whether it originates inside or outside the network perimeter.
Question 6: Which Microsoft 365 plan tier is required to access Microsoft Defender for Office 365 Plan 2 features like Attack Simulator?
- Microsoft 365 Business Basic
- Microsoft 365 F3
- Microsoft 365 E5 or Defender for Office 365 Plan 2 add-on (Correct answer)
- Microsoft 365 Business Standard
Correct answer: Microsoft 365 E5 or Defender for Office 365 Plan 2 add-on
Advanced Defender for Office 365 Plan 2 features including Attack Simulator require Microsoft 365 E5 or purchasing it as an add-on.
Question 7: Which concept describes Microsoft's commitment to giving customers control over their own data stored in Microsoft cloud services?
- Data residency
- Customer data ownership and privacy (Correct answer)
- Data classification
- Shared responsibility model
Correct answer: Customer data ownership and privacy
Microsoft's privacy commitment ensures customers own their data, Microsoft does not mine it for advertising, and customers control how it is used.
Which Microsoft 365 feature provides a centralized hub for monitoring your organization's security posture and recommending improvement actions?