Microsoft 365 Copilot AB-900 Threat Protection Intelligence And Microsoft Defender XDR Practice Test

 

Skills 1.2 • 20 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on threat protection intelligence and microsoft defender xdr through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Northwind Traders has validated the surrounding services. The remaining requirement is to use threat intelligence context to prioritize an investigation. Which choice is correct? No unrelated tenant settings should be changed.

  1. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  2. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  3. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement

Correct answer: D

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

B: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

C: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

E: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 2

An administrator reviewing admin-center audit for Fourth Coffee must correlate signals from multiple Microsoft security products into one incident. Which Microsoft 365 control or object should be used? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  2. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  3. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  4. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  5. Use Identity Secure Score to review identity-security recommendations and track posture improvements

Correct answer: B

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

B: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

C: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

D: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

E: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 3

A design review at Alpine Ski House identifies one specific goal: identify the security capability focused on detecting and responding to threats rather than assigning licenses. Which option best matches that goal? The choice should follow normal Microsoft 365 administrative practice.

  1. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  4. Use the Exchange admin center to configure the required mailbox or distribution group
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: C

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

C: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

D: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 4

Which statement best explains how Microsoft 365 should address this requirement at Contoso: use a unified security operations experience for incidents and alerts? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  3. Use Microsoft Entra ID for cloud identity, authentication, and access management
  4. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  5. Evaluate authorization after authentication to determine what the identity is allowed to access or do

Correct answer: B

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

B: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

C: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

D: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

E: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 5

While handling a pilot rollout, the security administrator needs to use threat information to understand malicious activity affecting the organization. Which answer most directly addresses the stated need? The team needs a direct administrative answer, not a broad redesign.

  1. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  2. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  3. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  4. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  5. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity

Correct answer: E

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

B: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

C: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

D: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

E: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 6

During a tenant cleanup at Trey Research, the service desk lead must investigate an attack across identities, endpoints, email, and cloud apps. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  2. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  3. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  4. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: A

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

B: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

C: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

D: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 7

Consolidated Messenger is preparing a Copilot adoption project. The team needs to use threat intelligence context to prioritize an investigation. What should the Copilot administrator choose? The solution should preserve least privilege and existing governance where possible.

  1. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  2. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  3. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Use Microsoft Entra ID for cloud identity, authentication, and access management

Correct answer: C

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

B: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

C: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

E: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 8

Which statement best explains how Microsoft 365 should address this requirement at Woodgrove Bank: correlate signals from multiple Microsoft security products into one incident? The team wants the smallest change that directly addresses the requirement.

  1. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  2. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  3. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  4. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  5. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control

Correct answer: D

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

B: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

C: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

D: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

E: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 9

For a new-user onboarding at Wide World Importers, which Microsoft 365 approach correctly addresses the need to identify the security capability focused on detecting and responding to threats rather than assigning licenses? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use Microsoft Entra ID for cloud identity, authentication, and access management

Correct answer: A

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

E: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 10

The identity administrator at Southridge Video is asked to use a unified security operations experience for incidents and alerts. What is the most appropriate next step? The team will validate the result immediately after the change.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads

Correct answer: E

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

C: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

E: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 11

Fabrikam has validated the surrounding services. The remaining requirement is to use threat information to understand malicious activity affecting the organization. Which choice is correct? No unrelated tenant settings should be changed.

  1. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  2. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  3. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Evaluate authorization after authentication to determine what the identity is allowed to access or do

Correct answer: C

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

B: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

C: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

E: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 12

Which statement best explains how Microsoft 365 should address this requirement at Wingtip Toys: investigate an attack across identities, endpoints, email, and cloud apps? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  2. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  3. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads

Correct answer: E

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

B: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

C: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

E: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 13

A design review at VanArsdel identifies one specific goal: use threat intelligence context to prioritize an investigation. Which option best matches that goal? The choice should follow normal Microsoft 365 administrative practice.

  1. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  4. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  5. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity

Correct answer: E

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

C: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

D: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

E: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 14

The IT team at Bellows College wants to correlate signals from multiple Microsoft security products into one incident. Which Microsoft 365 capability should it use? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  4. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  5. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation

Correct answer: D

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

C: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

D: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

E: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 15

While handling a agent governance review, the Copilot administrator needs to identify the security capability focused on detecting and responding to threats rather than assigning licenses. Which answer most directly addresses the stated need? The team needs a direct administrative answer, not a broad redesign.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  3. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  4. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  5. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials

Correct answer: B

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

B: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

C: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

D: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

E: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify the security capability focused on detecting and responding to threats rather than assigning licenses.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 16

Which statement best explains how Microsoft 365 should address this requirement at Coho Winery: use a unified security operations experience for incidents and alerts? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Entra ID for cloud identity, authentication, and access management
  2. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  3. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: B

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

B: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

C: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a unified security operations experience for incidents and alerts.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 17

Humongous Insurance is preparing a admin-center audit. The team needs to use threat information to understand malicious activity affecting the organization. What should the IT administrator choose? The solution should preserve least privilege and existing governance where possible.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  3. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  4. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  5. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach

Correct answer: C

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

B: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

C: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

D: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

E: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat information to understand malicious activity affecting the organization.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 18

A support case at Adventure Works says administrators must investigate an attack across identities, endpoints, email, and cloud apps. Which option is the best fit? The team wants the smallest change that directly addresses the requirement.

  1. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  2. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  3. Use the Exchange admin center to configure the required mailbox or distribution group
  4. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  5. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation

Correct answer: D

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

B: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

C: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

D: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

E: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate an attack across identities, endpoints, email, and cloud apps.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Question 19

For a governance workshop at Blue Yonder Airlines, which Microsoft 365 approach correctly addresses the need to use threat intelligence context to prioritize an investigation? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  2. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  3. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use the Teams admin center and configure the relevant team, channel, or Teams policy

Correct answer: A

Why: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

Option review:

A: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This directly addresses the stated requirement.

B: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

C: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

E: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use threat intelligence context to prioritize an investigation.

Learning point: Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity. Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks.

Question 20

Which statement best explains how Microsoft 365 should address this requirement at Relecloud: correlate signals from multiple Microsoft security products into one incident? The team will validate the result immediately after the change.

  1. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  2. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  3. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  4. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  5. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature

Correct answer: C

Why: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

Option review:

A: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

B: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

C: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This directly addresses the stated requirement.

D: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

E: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to correlate signals from multiple Microsoft security products into one incident.

Learning point: Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads. Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals.

Popular posts

img