MS-900 Exam (microsoft 365 cert)

Pataasin ang iyong marka sa homework at exams ngayon gamit ang Quizwiz!

The Nutex Corporation has recently acquired a company that develops CRM software. The CRM software is hosted at the company's in-house data center. You are tasked with improving the security posture of the company's in-house data center. Your initial analysis reveals that the data center is not well equipped to deal with cyber-attacks and insider threats. You want to implement Microsoft Advanced Threat Analytics in the data center. Which of the following statements about Microsoft Advanced Threat Analytics are TRUE? (Choose two.) A)Advanced Threat Analytics can detect malicious attacks and abnormal behavior but cannot detect protocol vulnerabilities. B)Advanced Threat Analytics can forward notifications to a third-party SIEM tool. C)All types of detections done by Advanced Threat Analytics provide the possibility of adding exclusions. D)Suppressing an alert permanently excludes that type of alert until it is manually included. E)Advanced Threat Analytics integrates with all third-party VPN solutions that use RADIUS accounting.

-Advanced Threat Analytics can detect malicious attacks and abnormal behavior but cannot detect protocol vulnerabilities. -All types of detections done by Advanced Threat Analytics provide the possibility of adding exclusions.

You are an IT manager for the Nutex Corporation. The company currently hosts its own Exchange server for email. You are considering migrating the company email to Microsoft 365. What are the two cost advantages of Microsoft 365 versus the current solution? A)Reduction of power and cooling costs B)Less reliance on capital expenditures C)Greater predictability of a static cost model D)Reduced storage costs due to unlimited mailbox sizes E)Elimination of the operational cost model

-Reduction of power and cooling costs -Less reliance on capital expenditures -Greater predictability of a static cost model

Due to regulatory restrictions, Dreamsuites Inc. has some reservations about moving their physical datacenter to the cloud. They want the economies of the cloud but need high security. As a consultant, you suggest that a hybrid cloud may be the best solution. What are some features and benefits of a hybrid cloud solution for Dreamsuites? (Choose all that apply.) A)Control B)Scalability for increased demand C)Data security D)All physical hardware controlled by Dreamsuites E)Cost efficiency

-Scalability for increased demand -Data security

Which of the following statements about the architecture to extend AD FS to Azure are true? (Choose three.) A) The AD DS servers provide federated authorization and authentication. B) The AD FS proxy subnet is exposed to the Internet. C) AD DS and AD FS use NSG rules to restrict traffic. D) The AD FS servers authenticate local on-premises identities. E) The AD FS WAP servers shield the AD FS servers from direct access to the Internet.

-The AD FS WAP servers shield the AD FS servers from direct access to the Internet. -The AD FS servers authenticate local on-premises identities.

You manage content at the Nutex Corporation on local servers by using an open-source app. With Microsoft 365 in use, the management expects you to use the content management capabilities available with Microsoft 365. You are to come up with a plan to adopt and advocate the use of SharePoint Online for content management purposes. Which of the following statements about SharePoint Online are TRUE? (Choose three.) A)The Message Center posts display Microsoft's announcements about new and changed SharePoint Online features. B)By design, users with the SharePoint admin role have access to all SharePoint sites and OneDrive libraries. C)Sites can only be permanently deleted. D)Content can be targeted to appear only to members of specific Microsoft 365 groups. E)Sharing content with people outside your organization is enabled by default.

-The Message Center posts display Microsoft's announcements about new and changed SharePoint Online features. -By design, users with the SharePoint admin role have access to all SharePoint sites and OneDrive libraries.

You are an IT manager for the Nutex Corporation. You are evaluating various support options for Microsoft 365. Because the company cannot tolerate disruptions, you are considering Professional Direct. What are the two benefits that are unique to Professional Direct? A)The company is assigned a cloud solution provider. B)Support is available on a 24/7 basis for critical issues. C)The company has access to Microsoft's volume licensing program. D)Additional advisory services are available for on-premises technologies. E)The company is assigned a technical account manager.

-The company has access to Microsoft's volume licensing program. -Support is available on a 24/7 basis for critical issues.

You are an IT manager for the Verigon Corporation. Your company utilizes both Exchange Online and SharePoint Online in its Microsoft 365 plan. Last month, Microsoft was not able to deliver on the SLA terms concerning Exchange services the previous calendar month due to Microsoft 365 service outage. What two types of information will you need to provide Microsoft in order to be compensated for the failure to deliver on the benchmarks stated within the SLA? A)The usernames that were affected by the occurrence B)The name and contact information of your company C)The outage incident identifier D)The dates that the planned outage occurred E)Your customer tenant GUID

-The usernames that were affected by the occurrence -The outage incident identifier

Nutex Corporation plans to offer data storage and database management for hospitals. Accordingly, they must meet stringent HIPAA requirements. They want to offer the cloud advantages of scalability while providing strong control and security. What cloud concept can best meet these needs? A)A public cloud B)A hybrid cloud C)A private cloud D)PaaS E)SaaS

A private cloud

You are the enterprise administrator at the Nutex Corporation. You are tasked with identifying an online meeting solution. The management feels that an online meeting solution can improve productivity and track meeting activities. You have identified Microsoft Teams as the solution that you will recommend. Which of the following does Microsoft automatically create when you create a team on Microsoft Teams? (Select all that apply.) A)A OneNote notebook B)An Azure DevOps Services account C)A free GitHub account D)A SharePoint Online site E)An Exchange Online shared mailbox F)A Microsoft 365 group

An Azure DevOps Services account A Microsoft 365 group A SharePoint Online site

In which of the following scenarios are an organization's applications MOST LIKELY to remain in a hybrid environment after migration of on-premises resources to Azure? A)Microsoft 365 Apps B)All applications C)Applications that contain sensitive information D)Apps that require USB tokens E)Legacy applications

Applications that contain sensitive information

You are a system administrator for your organization. Your organization has deployed sensitive on-premises business applications which capture highly confidential information, including personal information and payment card information that is stored inside the company's data center. You have designed security controls based on the Zero Trust model. Under which of the Zero Trust model guiding principles would you encrypt the highly confidential information? A)Network Security B)Assume Breach C)Hardening Principle D)Least Privileged Access

Assume Breach

You need to enable the use of smart cards as an authentication factor in your Azure hybrid environment. Considering this requirement, which authentication method should you choose? A)Azure AD password hash synchronization B)Federated authentication C)Azure AD pass-through synchronization D)Azure AD pass-through authentication

Azure AD pass-through synchronization

A university has a subscription to Microsoft 365 for Education for all students and professors. As an administrator, you want to use the Microsoft 365 admin center to manage the subscription. Which of the following cards is NOT available to add to the Microsoft 365 admin center home page? A)SharePoint B)Azure Active Directory C)Microsoft Teams D)Billing

Azure Active Directory

You are the IT architect at the Nutex Corporation. You are part of a team who must come up with a long-term strategy for the IT, finance, marketing, sales, human resources, and operations divisions. You have analyzed the strategies of other leaders and believe that the identity management part of the solution must meet the following requirements: High-privilege accounts must be validated on-premises. The solution must not have a critical point of failure that halts the authentication service. The on-premises users must ALWAYS be able to authenticate. Which of the following identity management models meets the requirements? A)Federation between AD FS and Azure AD B)Hybrid identity model with password hash synchronization and seamless single sign-on C)Cloud-only identity model D)Hybrid identity model with pass-through authentication and seamless single sign-on

Cloud-only identity model

The Nutex Corporation has been using Microsoft 365 for a few years. Over this period, the workforce has grown from 45 to 250 employees and Nutex has acquired two companies. All employees of Nutex and the acquired companies use the same Microsoft 365 tenant. With increasing demands from customers and governance for compliance to data protection standards, Nutex wants to implement initiatives to protect its data on hundreds of SharePoint sites in the tenant. You must devise a strategy to go through existing sites and create policies to prevent users from sharing privacy and compliance data with users outside your tenant. You doubt that sites contain sensitive data that is not part of the built-in sensitive information types in Microsoft 365. Which of the following should you do to implement the strategy? (Select all that apply.) A)Create DLP queries to scan the sites for sensitive content. B)Create custom sensitive information types to scan content for undefined sensitive data. C)Create DLP policies with All SharePoint Sites as the location. D)Specify DLP policy actions to restrict sharing content that matches the DLP policy rules. E)Create DLP policies with SharePoint Online as the location.

Create DLP queries to scan the sites for sensitive content.

You are implementing a data governance strategy that allows for data classification. You have published the proper labels. What must you do to ensure that matching documents are reviewed? A)Create a data loss prevention policy B)Create an alert policy C)Create a security policy D)Create a retention policy

Create a security policy

Your manager is concerned that Microsoft engineers could access the confidential data your organization stores in SharePoint Online and OneDrive for Business. You must ensure that Microsoft engineers cannot access your content to perform service operations without your explicit approval. Which tool do you need to make use of? A)Microsoft Intune B)Data loss prevention (DLP) policies C)Privileged Identity Management D)Azure Information Protection E)Customer Lockbox

Data loss prevention (DLP) policies

You are preparing a CSV file to deploy Windows devices using Windows AutoPilot. Which of the following is NOT required to be included in the file? A)Device name B)Windows Product ID C)Hardware hash D)Serial number

Hardware hash

Nutex Corporation plans to move many of its IT services, such as web and database, to Microsoft Azure. The web administrators are concerned that the cloud servers may not be able to keep up with the fluctuating demand. What cloud concept allows Nutex to add more power (CPU and RAM) to an individual VM as needed? A)Hyper-V B)Rolling upgrade C)Horizontal scaling D)Vertical scaling E)Automatic failover

Horizontal scaling

You are the IT manager of a company with over 2,500 employees. You want to purchase a subscription for Microsoft 365 that includes Microsoft Defender for Identity, formerly Azure Advanced Threat Protection. Which Microsoft 365 subscription will meet the criteria out of the box? A)Office 365 Business Premium B)Microsoft 365 E5 C)Microsoft 365 F1 D)Microsoft 365 E3

Microsoft 365 E5

Microsoft 365 empowers users with many tools and productivity services. Which of the following services is not part of the capabilities of security and compliance? A)Microsoft Authenticator B)Microsoft Purview Information Protection C)Conditional Access D)Power Platform

Microsoft Purview Information Protection

You want to improve the personal productivity of your employers using Microsoft 365. The productivity should be improved by focusing on high priority tasks, leveraged by using AI to provide better insights. Which Microsoft product is most suitable? A)Microsoft Teams B)Project Online C)Microsoft Viva D)Outlook

Microsoft Viva

You are an IT manager for a small company that is currently licensed for Microsoft 365 Standard Support. Which of the following options is not a support feature for the company's subscription plan? A)The company's Tier 1 Cloud Solution Provider must be contacted first. B)Monthly service reviews. C)Web chat support is not available for any Microsoft 365 components. D)Telephone support is not available for any Microsoft 365 components. E)Response time for critical issues is one-hour.

Monthly service reviews.

Verigon Corporation spends a large portion of their IT budget maintaining their local data center. They run many Hyper-V virtual machines on an array of physical servers. The CIO would like to move the operation to Microsoft Azure. Verigon wants to maintain control of the virtual machines because they want to be able to choose when and how any OS updates are applied. What cloud computing model would meet their specific requirements? A)PaaS B)IaaS C)Hybrid cloud D)Serverless computing E)SaaS

PaaS

You would like to sandbox the damage that could occur if someone learns the password of the global administrator for your Microsoft 365 subscription. Which component of Microsoft 365 can be used to enable on-demand, just-in-time assignment of the global administrator role ONLY when it is needed, and then revoke it? A) Microsoft Intune B)Privileged Identity Management C)OneDrive D)Azure Virtual Desktop

Privileged Identity Management

Which of the following Microsoft Purview eDiscovery solutions included with Microsoft 365 E5 will allow you to send legal hold notifications? A) Purview eDiscovery (Premium) B) Purview eDiscovery (Standard) C) In-place eDiscovery D) Content Search

Purview eDiscovery (premium)

You just completed a data subject request on behalf of a user. Which of the following regulations make this request possible? A)GPDR B)SOX C)HIPAA D)GLBA

SOX

Auditors are asking you about Microsoft's practices for their processes of protection and control. Which of the following information can you NOT find in the Trust Center of the Microsoft Service Trust portal? A)Privacy B)Data protection C)Security D)Compliance

Security

You manage the Office 365 Enterprise license for your organization. A few power users want to preview upcoming Office 365 features before they are released. No other users should have this capability. How can you meet this goal with the least administrative effort? A)Tell the power users to join Office Insider from their Office 365 account settings. B)Go to Settings > Org settings > Services in the 365 admin center. Select What's new in Office and choose Show to users. Add the power users. C)Go to Settings > Org settings > Organization profile > Release preferences in the 365 admin center. Choose Targeted release for all users. Add the power users. D)Go to Settings > Org settings > Organization profile > Release preferences in the 365 admin center. Choose Targeted release for selected users. Add the power users.

Tell the power users to join Office Insider from their Office 365 account settings.

Which of the following is a relevant use case for Azure Virtual Desktop? A)To create a private company social network B)To restore OneDrive files to an earlier date and time C)To use legacy applications on Windows 10 devices D)To provide access to Microsoft 365 Apps from devices running legacy operating systems such as Windows 7 or Windows 8

To use legacy applications on Windows 10 devices

Nutex Corporation has many experienced administrators for Microsoft 365. Where can they share ideas with Microsoft about improvements for Microsoft Teams? A)Communicate with the cloud service provider B)Use the Feedback web portal for Microsoft Teams C)Submit a support ticket using the Microsoft 365 portal D)Submit a support ticket using the Azure portal

Use the Feedback web portal for Microsoft Teams

Which of the following scenarios is appropriate for using PaaS? A)Developing customized cloud-based applications B)Using a CSP-managed email service C)Using hosted applications and hosted websites D)Deploying a Linux VM E)Running legacy applications

Using a CSP-managed email service

You are an IT manager for the Nutex Corporation. Your management team has decided to host all of their Windows 10 desktop computers in Azure Active Directory. It is required that all computers be managed centrally as well as their applications. Which tool will satisfy this requirement? A)Active Directory Users and Computers B)Windows Configuration Manager C)Group Policy D)Intune

Windows Configuration Manager

The Nutex Corporation is expanding its teams and acquiring another company with 100 or more employees. Currently, Nutex is a small 15-member team who are extremely experienced. They handle financial, health, and privacy data for their customers. They also provide services to governmental and defense institutions. With new employees coming in, Nutex wants to protect its customers' data from accidental and intentional sharing with the outside world. You have been appointed as the Microsoft 365 Security Architect. You must ensure that all apps in the Microsoft 365 subscription are protected. You plan to use Microsoft Purview Data Loss Prevention (DLP) policies. Which of the following statements about Microsoft 365 DLP are TRUE? (Choose two.) A)DLP always executes the action when there is at least one occurrence of the specified condition in the content. B)DLP policies must always be created from scratch by specifying the type of sensitive information that must be protected. C)DLP cannot be used to identify and protect sensitive information in the desktop version of the Microsoft 365 apps. D)Retention labels can be used as conditions in a DLP policy. E)The most restrictive rule action is enforced if the content matches multiple DLP rules.

-DLP cannot be used to identify and protect sensitive information in the desktop version of the Microsoft 365 apps. -DLP always executes the action when there is at least one occurrence of the specified condition in the content. -DLP policies must always be created from scratch by specifying the type of sensitive information that must be protected.

The Nutex Corporation is expanding its teams and acquiring another company with 100 or more employees. Currently, Nutex is a small 15-member team who are extremely experienced. They handle financial, health, and private data for their customers. They also provide services to governmental and defense institutions. With new employees coming in, Nutex wants to protect its customers' data from accidental and intentional sharing with the outside world. You have been appointed as the Microsoft 365 Security Architect. You must ensure that all apps in the Microsoft 365 subscription are protected. You plan to use Microsoft Purview Data Loss Prevention (DLP) policies. Which of the following statements about the DLP policy workflows and features in Microsoft 365 are TRUE? (Choose three.) A)A DLP policy can be created to detect and enforce actions for content with multiple types of sensitive information. B)DLP policies offer a Test mode to see the impact of the policies before enforcing them. C)DLP policies can be configured to let users override rules by providing business justifications. D)Locations in the DLP policies workflow refer to the Azure locations where the Microsoft 365 data is stored. E)DLP policies can only be created by using the built-in sensitive information types in Microsoft 365.

-DLP policies offer a Test mode to see the impact of the policies before enforcing them. -A DLP policy can be created to detect and enforce actions for content with multiple types of sensitive information.

The Nutex Corporation has been using a Microsoft 365 subscription for a few months. Recently, Nutex has acquired companies that run multiple B2C apps. The B2C model is new for them. In the B2C model, Nutex now hosts large support teams who use Microsoft 365 apps to support customers. They primarily deal with two B2B apps and have recently moved them to the Azure. With increasing demands from customers and governance for data protection compliance, you are tasked with finding and ensuring that all services on the Microsoft cloud are compliant with data protection and compliance standards. You plan to actively use the Microsoft Service Trust Portal and Purview Compliance Manager to achieve this. Which of the following statements about the Microsoft Service Trust Portal and Purview Compliance Manager are TRUE? (Choose two.) A)The permissions required to access Compliance Manager can only be set in the Microsoft 365 Compliance Center. B)Microsoft Service Trust Portal is accessible only to paid customers with the Microsoft 365, Dynamics 365, or Azure subscriptions. C)Compliance Manager can evaluate the compliance of third-party cloud services. D)Compliance Score is currently available only for Microsoft 365 Assessments. E)Microsoft Service Trust Portal can provide details about how Microsoft cloud services are compliant by industry and by region.

-Microsoft Service Trust Portal is accessible only to paid customers with the Microsoft 365, Dynamics 365, or Azure subscriptions. -The permissions required to access Compliance Manager can only be set in the Microsoft 365 Compliance Center. -Compliance Score is currently available only for Microsoft 365 Assessments.


Kaugnay na mga set ng pag-aaral

Life Insurance basics exam simulator

View Set

Chapter 6 Viruses, Prions, Microbiology

View Set

Psychological Disorders: Study Guide

View Set

Marketing 300 Concept Checks, Assignments, and Video Quizzes Chapter 8, Chapter 10

View Set

Vocabulary Workshop Level F unit 7

View Set

Government Unit 3: Test: United States Government

View Set