MS-900 Security, Compliance, & Privacy in Microsoft 4 — Questions and Answers
Question 1: What capability does Microsoft Sentinel provide in the context of Microsoft 365 security?
- Endpoint antivirus scanning
- Cloud-native SIEM and SOAR for threat detection and response across the organization (Correct answer)
- Email filtering for spam and phishing
- Identity governance and access reviews
Correct answer: Cloud-native SIEM and SOAR for threat detection and response across the organization
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.
Question 2: Which Microsoft 365 feature enables administrators to review and certify that users still need the access rights they currently have?
- Conditional Access policies
- Azure AD Access Reviews (Correct answer)
- Privileged Identity Management (PIM)
- Identity Protection risk policies
Correct answer: Azure AD Access Reviews
Azure AD Access Reviews allow administrators to periodically review and certify that group memberships and application access assignments are still appropriate.
Question 3: What does Microsoft Defender for Identity primarily protect against?
- Malware on managed devices
- On-premises Active Directory identity-based attacks such as pass-the-hash and lateral movement (Correct answer)
- Phishing emails in Exchange Online
- Data exfiltration from SharePoint
Correct answer: On-premises Active Directory identity-based attacks such as pass-the-hash and lateral movement
Microsoft Defender for Identity monitors on-premises Active Directory signals to detect and investigate advanced threats like credential theft and lateral movement attacks.
Question 4: What is the purpose of Microsoft Purview Audit (formerly called Office 365 Audit Log)?
- To encrypt sensitive files automatically
- To record user and administrator activity across Microsoft 365 services for investigation and compliance (Correct answer)
- To block access from risky locations
- To classify documents by sensitivity
Correct answer: To record user and administrator activity across Microsoft 365 services for investigation and compliance
The Purview Audit log captures thousands of activities across Microsoft 365 services, allowing security and compliance teams to investigate incidents and meet audit requirements.
Question 5: An organization wants to prevent users from accessing Microsoft 365 from countries where it does not operate. Which feature should they configure?
- Data Loss Prevention policy
- Conditional Access with named location restrictions (Correct answer)
- Microsoft Defender for Cloud Apps session policy
- Azure AD Password Protection
Correct answer: Conditional Access with named location restrictions
Conditional Access named locations allow administrators to define geographic regions and block or require additional verification for sign-ins from those areas.
Question 6: What is the key difference between Microsoft Defender for Office 365 Plan 1 and Plan 2?
- Plan 1 includes anti-spam; Plan 2 does not
- Plan 2 adds advanced hunting, Attack Simulator, and automated investigation and response (AIR) (Correct answer)
- Plan 1 protects SharePoint; Plan 2 only protects email
- Plan 2 is only available for government tenants
Correct answer: Plan 2 adds advanced hunting, Attack Simulator, and automated investigation and response (AIR)
Defender for Office 365 Plan 2 builds on Plan 1 by adding Threat Explorer, automated investigation and response, Attack Simulator, and advanced threat hunting capabilities.
Question 7: Which Microsoft concept refers to the built-in privacy principles ensuring that data collected is used only for specified purposes and not retained longer than necessary?
- Data sovereignty
- Privacy by design and data minimization (Correct answer)
- Compliance boundary
- Trust Center commitments
Correct answer: Privacy by design and data minimization
Privacy by design and data minimization are core Microsoft privacy principles ensuring data is collected for explicit purposes and not kept beyond its intended use.
What capability does Microsoft Sentinel provide in the context of Microsoft 365 security?