Preview real exam questions, verified answers and available explanations before choosing a study plan.
Question 1
Single choice
You use Microsoft 365 Copilot.
What does Copilot use to generate responses based on corporate data stored in Microsoft SharePoint?
A
Microsoft Intune
B
Microsoft Defender
C
Microsoft Graph
D
Microsoft Purview
Reveal answer detailsClose answer details
Correct answerC
Explanation
Microsoft 365 Copilot uses Microsoft Graph to ground responses in organizational data from services such as SharePoint while respecting permissions. Intune manages devices, Defender protects against threats, and Purview governs compliance. The requirement asks how Copilot accesses corporate SharePoint data for responses.
Question 2
Single choice
Your organization has a Microsoft 365 subscription.
All users are assigned Microsoft 365 Copilot licenses.
Some users report receiving Copilot responses that contain information from a Microsoft SharePoint site named Finance.
The users report that the information is commercially sensitive.
You need to prevent Copilot from providing responses that contain information from the Finance site.
What should you do?
A
From Microsoft Purview, create an Information Barrier (IB) policy.
B
From Microsoft Defender, create a data connector.
C
From Microsoft Entra, create a Conditional Access policy.
D
From the Finance site, configure permissions.
Reveal answer detailsClose answer details
Correct answerA
Explanation
Microsoft 365 Copilot respects existing Microsoft 365 permissions, so users may receive responses from SharePoint content they can already access. If results include Finance site content, the first step is to review and remediate permissions or oversharing. Other actions that only adjust prompts or licenses do not address the data access root cause.
Question 3
Single choice
A Microsoft Purview administrator creates a sensitivity label. Users must be able to apply the label to files in Microsoft 365 apps.
What should the administrator configure next?
A
A sensitivity label policy
B
A retention event
C
A Microsoft Entra app registration
D
A SharePoint data access governance report
Reveal answer detailsClose answer details
Correct answerA
Explanation
A sensitivity label policy publishes a sensitivity label to the intended users or groups so it appears in Microsoft 365 apps. Retention events, app registrations, and SharePoint governance reports solve different administrative problems. The requirement is making a created label available to users.
Question 4
Hotspot
HOTSPOT
Your organization uses Microsoft Teams for meetings, collaboration, and conference room experiences. The IT department manages Teams settings centrally and needs to perform administrative tasks from the Microsoft Teams admin center.
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
The Microsoft Teams admin center is used to manage Teams settings and Teams devices, including Teams Rooms devices. User license assignment is generally done in the Microsoft 365 admin center, client deployment is managed separately, and team creation controls are policy settings rather than the task described.
Question 5
Single choice
You need to identify files and emails that contain social security numbers (SSNs) and credit card numbers.
What should you use in the Microsoft Purview portal?
A
Data explorer
B
Information Protection reports
C
Information Protection policies
D
Activity explorer
Reveal answer detailsClose answer details
Correct answerC
Explanation
Information Protection policies and sensitivity labeling capabilities help identify and classify files and emails that contain sensitive information types such as SSNs and credit card numbers. Data explorer can help view discovered sensitive information, but the policy capability is used to identify and protect matching content. The requirement is sensitive information identification.
Question 6
Hotspot
HOTSPOT
Your organization allows users to create and use Microsoft 365 Copilot agents. Administrators need to manage agent availability across the organization, including removing agents, controlling deployment to users, and understanding which agent settings can be configured from the Microsoft 365 admin center.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Yes; No; Yes
Administrators can remove or block Copilot agents from users and can deploy agents to specific users or groups. The Microsoft 365 admin center is used for availability and deployment governance, not for configuring the internal prompt design of an individual agent. Authoring belongs to agent creation tools.
Question 7
Hotspot
HOTSPOT
Your organization has a Microsoft 365 subscription.
The HR department at your company asks for a copy of all the recent files that were modified by a user named User1.
You need to search for relevant content across Microsoft 365 and collect the files in a way that supports investigation and review.
What should you use in the Microsoft Purview portal? To answer, select the appropriate solutions in the answer area.
Reveal answer detailsClose answer details
Explanation
Microsoft Purview eDiscovery is used to search for and collect content, including files modified by a specific user when performing an investigation or legal request. Other solutions such as DLP or Compliance Manager serve prevention or posture management rather than producing the requested content copy.
Question 8
Hotspot
HOTSPOT
Your organization is preparing to deploy Microsoft 365 Copilot. Some SharePoint sites contain content that users are allowed to access directly, but the organization does not want Copilot to include all of those sites in its search and grounding experience. You need a solution that limits Copilot access to selected
SharePoint content without changing the users' direct permissions to files and sites.
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
Restricted SharePoint Search limits which SharePoint sites Microsoft 365 Copilot can use for grounding, without removing users' direct permissions to files they can access. It is not a general eDiscovery or guest access control. The requirement is narrowing Copilot's SharePoint grounding scope.
Question 9
Multiple choice
Your organization has a Microsoft 365 subscription.
You create a security group named Group1 and assign a Microsoft 365 E3 license to the group.
You discover that a user named User1 does NOT have access to the Microsoft 365 E3 features.
You need to ensure that User1 can access all the Microsoft 365 E3 features.
Which two actions can you perform? (Choose two.)
A
Add User1 to Group1.
B
Assign a Conditional Access policy to Group1.
C
Assign a Conditional Access policy to User1.
D
Assign a license to User1.
Reveal answer detailsClose answer details
Correct answersA, D
Explanation
A user can receive Microsoft 365 features either by being added to the licensed group or by receiving the license directly. Conditional Access policies control access conditions but do not assign product licenses. The requirement is feature entitlement, so group membership or direct license assignment are the relevant actions.
Question 10
Single choice
Your organization has a Microsoft 365 E5 subscription.
You need to prevent users from sharing corporate financial data to external users.
What should you use?
A
role groups
B
data loss prevention (DLP) policies
C
insider risk management policies
D
retention labels
Reveal answer detailsClose answer details
Correct answerB
Explanation
Microsoft Purview Data Loss Prevention policies can detect sensitive information and prevent users from sharing corporate financial data externally. Role groups assign administrative permissions, insider risk policies detect risky behavior, and retention labels manage content lifecycle. The requirement is preventing sensitive data sharing.
Question 11
Hotspot
HOTSPOT
Your company wants to reduce the risk of standing administrative privileges in Microsoft Entra ID. Administrators should not have permanent elevated access. Instead, they should request or activate privileged roles only when needed and only for a limited period of time.
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
Microsoft Entra Privileged Identity Management provides just-in-time, time-bound activation for privileged roles so administrators do not keep permanent elevated access. The other choices describe identity lifecycle or application management areas, but they do not address the requirement to reduce standing administrative privilege.
Question 12
Single choice
A compliance team wants to prevent users from sharing credit card numbers in Microsoft Teams chats with external users.
Which Microsoft Purview capability should the team configure?
A
Data Loss Prevention policies
B
Retention labels
C
Copilot Analytics
D
Identity Secure Score
Reveal answer detailsClose answer details
Correct answerA
Explanation
Microsoft Purview Data Loss Prevention policies can detect sensitive information such as credit card numbers and help prevent improper sharing in Teams chats. Retention labels control content lifecycle, Copilot Analytics reports usage, and Identity Secure Score evaluates identity posture. The requirement is sensitive data sharing prevention.
Question 13
Single choice
Your organization has a Microsoft 365 subscription that contains a Microsoft SharePoint site named Site1. You need to prevent users from sharing the content of Site1 to external users.
What should you use?
A
the Site1 content
B
the SharePoint admin center
C
the Microsoft 365 admin center
D
the Microsoft Entra admin center
Reveal answer detailsClose answer details
Correct answerB
Explanation
SharePoint site sharing settings and permissions control whether site content can be shared externally. The other choices relate to different Microsoft 365 administration areas and do not directly prevent external sharing for one SharePoint site. The requirement is site-level content sharing control, so SharePoint administration is the relevant path.
Question 14
Single choice
Your organization has a Microsoft 365 subscription. Your company recently purchased Microsoft 365 Copilot licenses for some users.
You need to identify how many unlicensed users have used Copilot in Microsoft Teams.
Which usage report should you use in the Microsoft 365 admin center?
A
Microsoft 365 Copilot Chat
B
Microsoft 365 Copilot Search
C
Microsoft 365 Apps
D
Microsoft 365 Copilot
Reveal answer detailsClose answer details
Correct answerA
Explanation
The Microsoft 365 admin center provides Copilot-related usage and billing information, including identifying pay-as-you-go or unlicensed usage scenarios where applicable. Other admin experiences do not provide the same Copilot usage visibility. The requirement is to see unlicensed Copilot usage in Teams.
Question 15
Hotspot
HOTSPOT
Your organization uses Microsoft Entra Privileged Identity Management to manage privileged access. An administrator needs access to a user account, but the administrator does not currently have any eligible or active role assignments.
You need to identify the first action the administrator must take before accessing the user account through a privileged role.
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
In Microsoft Entra Privileged Identity Management, eligible administrators must activate the role before they can perform privileged actions such as creating a user account. Installing the Authenticator app or requesting a password reset is not the same as activating an eligible role assignment.
Question 16
Single choice
Users ask Microsoft 365 Copilot questions about organizational files. The security team wants to understand why Copilot only returns information the user is allowed to access.
Which service and control model influence these grounded responses?
A
Microsoft Graph with existing Microsoft 365 permissions
A standalone local document index with no permissions
Reveal answer detailsClose answer details
Correct answerA
Explanation
Microsoft 365 Copilot grounds responses through Microsoft Graph while respecting existing Microsoft 365 permissions and controls. PIM, transport rules, and permissionless local indexes do not describe Copilot grounding across organizational files. The key rule is that Copilot inherits user-accessible Microsoft 365 context.
Question 17
Hotspot
HOTSPOT
Your organization uses Microsoft Purview sensitivity labels to protect content and containers across Microsoft 365. The compliance team is reviewing where sensitivity labels can be applied, including SharePoint sites, Exchange email messages, and Windows devices.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Yes; Yes; No
Sensitivity labels can be applied to SharePoint sites as containers and to email messages in Exchange. They are not applied to Windows 11 devices as device management objects. Device compliance and configuration are handled through endpoint management rather than Purview sensitivity labeling.
MICROSOFT
Microsoft 365 Copilot and Agent Administration Fundamentals
What does Copilot use to generate responses based on corporate data stored in Microsoft SharePoint?
A.
Microsoft Intune
B.
Microsoft Defender
C.
Microsoft Graph
D.
Microsoft Purview
Correct Answer: C
Explanation
Explanation/Reference:
Microsoft 365 Copilot uses Microsoft Graph to ground responses in organizational data from services such as SharePoint while respecting permissions. Intune manages devices, Defender protects against threats, and Purview governs compliance. The requirement asks how Copilot accesses corporate SharePoint data for responses.
QUESTION 2
Your organization has a Microsoft 365 subscription.
All users are assigned Microsoft 365 Copilot licenses.
Some users report receiving Copilot responses that contain information from a Microsoft SharePoint site named Finance.
The users report that the information is commercially sensitive.
You need to prevent Copilot from providing responses that contain information from the Finance site.
What should you do?
A.
From Microsoft Purview, create an Information Barrier (IB) policy.
B.
From Microsoft Defender, create a data connector.
C.
From Microsoft Entra, create a Conditional Access policy.
D.
From the Finance site, configure permissions.
Correct Answer: A
Explanation
Explanation/Reference:
Microsoft 365 Copilot respects existing Microsoft 365 permissions, so users may receive responses from SharePoint content they can already access. If results include Finance site content, the first step is to review and remediate permissions or oversharing. Other actions that only adjust prompts or licenses do not address the data access root cause.
QUESTION 3
A Microsoft Purview administrator creates a sensitivity label. Users must be able to apply the label to files in Microsoft 365 apps.
What should the administrator configure next?
A.
A sensitivity label policy
B.
A retention event
C.
A Microsoft Entra app registration
D.
A SharePoint data access governance report
Correct Answer: A
Explanation
Explanation/Reference:
A sensitivity label policy publishes a sensitivity label to the intended users or groups so it appears in Microsoft 365 apps. Retention events, app registrations, and SharePoint governance reports solve different administrative problems. The requirement is making a created label available to users.
QUESTION 4
HOTSPOT
Your organization uses Microsoft Teams for meetings, collaboration, and conference room experiences. The IT department manages Teams settings centrally and needs to perform administrative tasks from the Microsoft Teams admin center.
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
The Microsoft Teams admin center is used to manage Teams settings and Teams devices, including Teams Rooms devices. User license assignment is generally done in the Microsoft 365 admin center, client deployment is managed separately, and team creation controls are policy settings rather than the task described.
QUESTION 5
You need to identify files and emails that contain social security numbers (SSNs) and credit card numbers.
What should you use in the Microsoft Purview portal?
A.
Data explorer
B.
Information Protection reports
C.
Information Protection policies
D.
Activity explorer
Correct Answer: C
Explanation
Explanation/Reference:
Information Protection policies and sensitivity labeling capabilities help identify and classify files and emails that contain sensitive information types such as SSNs and credit card numbers. Data explorer can help view discovered sensitive information, but the policy capability is used to identify and protect matching content. The requirement is sensitive information identification.
QUESTION 6
HOTSPOT
Your organization allows users to create and use Microsoft 365 Copilot agents. Administrators need to manage agent availability across the organization, including removing agents, controlling deployment to users, and understanding which agent settings can be configured from the Microsoft 365 admin center.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Yes; No; Yes
Administrators can remove or block Copilot agents from users and can deploy agents to specific users or groups. The Microsoft 365 admin center is used for availability and deployment governance, not for configuring the internal prompt design of an individual agent. Authoring belongs to agent creation tools.
QUESTION 7
HOTSPOT
Your organization has a Microsoft 365 subscription.
The HR department at your company asks for a copy of all the recent files that were modified by a user named User1.
You need to search for relevant content across Microsoft 365 and collect the files in a way that supports investigation and review.
What should you use in the Microsoft Purview portal? To answer, select the appropriate solutions in the answer area.
Correct Answer:
Explanation
Explanation/Reference:
Microsoft Purview eDiscovery is used to search for and collect content, including files modified by a specific user when performing an investigation or legal request. Other solutions such as DLP or Compliance Manager serve prevention or posture management rather than producing the requested content copy.
QUESTION 8
HOTSPOT
Your organization is preparing to deploy Microsoft 365 Copilot. Some SharePoint sites contain content that users are allowed to access directly, but the organization does not want Copilot to include all of those sites in its search and grounding experience. You need a solution that limits Copilot access to selected
SharePoint content without changing the users' direct permissions to files and sites.
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
Restricted SharePoint Search limits which SharePoint sites Microsoft 365 Copilot can use for grounding, without removing users' direct permissions to files they can access. It is not a general eDiscovery or guest access control. The requirement is narrowing Copilot's SharePoint grounding scope.
QUESTION 9
Your organization has a Microsoft 365 subscription.
You create a security group named Group1 and assign a Microsoft 365 E3 license to the group.
You discover that a user named User1 does NOT have access to the Microsoft 365 E3 features.
You need to ensure that User1 can access all the Microsoft 365 E3 features.
Which two actions can you perform? (Choose two.)
A.
Add User1 to Group1.
B.
Assign a Conditional Access policy to Group1.
C.
Assign a Conditional Access policy to User1.
D.
Assign a license to User1.
Correct Answer: AD
Explanation
Explanation/Reference:
A user can receive Microsoft 365 features either by being added to the licensed group or by receiving the license directly. Conditional Access policies control access conditions but do not assign product licenses. The requirement is feature entitlement, so group membership or direct license assignment are the relevant actions.
QUESTION 10
Your organization has a Microsoft 365 E5 subscription.
You need to prevent users from sharing corporate financial data to external users.
What should you use?
A.
role groups
B.
data loss prevention (DLP) policies
C.
insider risk management policies
D.
retention labels
Correct Answer: B
Explanation
Explanation/Reference:
Microsoft Purview Data Loss Prevention policies can detect sensitive information and prevent users from sharing corporate financial data externally. Role groups assign administrative permissions, insider risk policies detect risky behavior, and retention labels manage content lifecycle. The requirement is preventing sensitive data sharing.
QUESTION 11
HOTSPOT
Your company wants to reduce the risk of standing administrative privileges in Microsoft Entra ID. Administrators should not have permanent elevated access. Instead, they should request or activate privileged roles only when needed and only for a limited period of time.
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
Microsoft Entra Privileged Identity Management provides just-in-time, time-bound activation for privileged roles so administrators do not keep permanent elevated access. The other choices describe identity lifecycle or application management areas, but they do not address the requirement to reduce standing administrative privilege.
QUESTION 12
A compliance team wants to prevent users from sharing credit card numbers in Microsoft Teams chats with external users.
Which Microsoft Purview capability should the team configure?
A.
Data Loss Prevention policies
B.
Retention labels
C.
Copilot Analytics
D.
Identity Secure Score
Correct Answer: A
Explanation
Explanation/Reference:
Microsoft Purview Data Loss Prevention policies can detect sensitive information such as credit card numbers and help prevent improper sharing in Teams chats. Retention labels control content lifecycle, Copilot Analytics reports usage, and Identity Secure Score evaluates identity posture. The requirement is sensitive data sharing prevention.
QUESTION 13
Your organization has a Microsoft 365 subscription that contains a Microsoft SharePoint site named Site1. You need to prevent users from sharing the content of Site1 to external users.
What should you use?
A.
the Site1 content
B.
the SharePoint admin center
C.
the Microsoft 365 admin center
D.
the Microsoft Entra admin center
Correct Answer: B
Explanation
Explanation/Reference:
SharePoint site sharing settings and permissions control whether site content can be shared externally. The other choices relate to different Microsoft 365 administration areas and do not directly prevent external sharing for one SharePoint site. The requirement is site-level content sharing control, so SharePoint administration is the relevant path.
QUESTION 14
Your organization has a Microsoft 365 subscription. Your company recently purchased Microsoft 365 Copilot licenses for some users.
You need to identify how many unlicensed users have used Copilot in Microsoft Teams.
Which usage report should you use in the Microsoft 365 admin center?
A.
Microsoft 365 Copilot Chat
B.
Microsoft 365 Copilot Search
C.
Microsoft 365 Apps
D.
Microsoft 365 Copilot
Correct Answer: A
Explanation
Explanation/Reference:
The Microsoft 365 admin center provides Copilot-related usage and billing information, including identifying pay-as-you-go or unlicensed usage scenarios where applicable. Other admin experiences do not provide the same Copilot usage visibility. The requirement is to see unlicensed Copilot usage in Teams.
QUESTION 15
HOTSPOT
Your organization uses Microsoft Entra Privileged Identity Management to manage privileged access. An administrator needs access to a user account, but the administrator does not currently have any eligible or active role assignments.
You need to identify the first action the administrator must take before accessing the user account through a privileged role.
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
In Microsoft Entra Privileged Identity Management, eligible administrators must activate the role before they can perform privileged actions such as creating a user account. Installing the Authenticator app or requesting a password reset is not the same as activating an eligible role assignment.
QUESTION 16
Users ask Microsoft 365 Copilot questions about organizational files. The security team wants to understand why Copilot only returns information the user is allowed to access.
Which service and control model influence these grounded responses?
A.
Microsoft Graph with existing Microsoft 365 permissions
A standalone local document index with no permissions
Correct Answer: A
Explanation
Explanation/Reference:
Microsoft 365 Copilot grounds responses through Microsoft Graph while respecting existing Microsoft 365 permissions and controls. PIM, transport rules, and permissionless local indexes do not describe Copilot grounding across organizational files. The key rule is that Copilot inherits user-accessible Microsoft 365 context.
QUESTION 17
HOTSPOT
Your organization uses Microsoft Purview sensitivity labels to protect content and containers across Microsoft 365. The compliance team is reviewing where sensitivity labels can be applied, including SharePoint sites, Exchange email messages, and Windows devices.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Yes; Yes; No
Sensitivity labels can be applied to SharePoint sites as containers and to email messages in Exchange. They are not applied to Windows 11 devices as device management objects. Device compliance and configuration are handled through endpoint management rather than Purview sensitivity labeling.