Skip to main content

AB-900 Real Exam Questions

Microsoft 365 Copilot and Agent Administration Fundamentals

107 questions available · Page 1 of 11

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Your organization has a Microsoft 365 subscription. You need to review the impact of a recent phishing incident that targeted email users.

What should you use?

  1. A

    the Microsoft Defender portal

  2. B

    the Microsoft 365 admin center

  3. C

    the Microsoft Entra admin center

  4. D

    the Microsoft Exchange admin center

Show answer and explanation

Correct answer: A

Explanation

The Microsoft Defender portal is used to review security incidents, alerts, and threat protection information, including phishing impact for email users. The Microsoft 365 admin center handles tenant administration, Entra focuses on identity, and Exchange admin center handles mail configuration. The requirement is security incident review, so Defender is the best fit.

Question 2 Single choice

Which statement accurately describes authorization in Microsoft 365?

  1. A

    a process to verify whether an identity is who or what they claim to be

  2. B

    a process to require additional authentication methods before an identity can access resources

  3. C

    a process to verify whether an identity is allowed to access a resource

  4. D

    a process to validate an identity from an external system

Show answer and explanation

Correct answer: C

Explanation

Authorization determines what an authenticated identity is allowed to access or perform. Authentication verifies who or what the identity is, and MFA strengthens authentication rather than authorization. The requirement asks for the meaning of authorization in Microsoft 365, so the permission decision definition is correct.

Question 3 Hotspot

HOTSPOT

Your legal department is conducting an internal investigation. They need to find all content related to a confidential project named Project Falcon in email messages exchanged between two specific users. The solution must support searching, preserving, and reviewing relevant Microsoft 365 content for investigation purposes.

Select the answer that correctly completes the sentence.

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

Microsoft Purview eDiscovery is used to search and collect content such as emails and files for investigations or legal matters. Audit reviews activity records, Data Catalog is not the search tool here, and Insider Risk Management detects risky behavior. The requirement is content search for a legal investigation.

Question 4 Hotspot

HOTSPOT

Your organization uses Microsoft 365 Copilot Chat and work-grounded agents. You are reviewing the Copilot credits report in the Microsoft 365 admin center to understand how pay-as-you-go Copilot usage is calculated. You need to identify which users are included in the Credits used metric when they interact with work-grounded agents in Microsoft 365 Copilot Chat.

Select the answer that correctly completes the sentence.

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

The Credits used metric applies to pay-as-you-go metered usage. Microsoft states that this metric shows credits used from interactions by users in the organization who do not have a Microsoft 365 Copilot license and who interact with agents in Copilot Chat that trigger the Copilot Studio meter.

Therefore, the report is focused on unlicensed Microsoft 365 Copilot users whose agent interactions are billed through Copilot credits. It is not based on whether users use Teams, whether they are external users, or whether they already have a Microsoft 365 Copilot license. Microsoft also confirms that if pay-as-you-go is configured and users without a Microsoft 365 Copilot license use metered agents in Copilot Chat, that data appears in the Copilot Credits report.

Question 5 Single choice

A security administrator needs to investigate a sign-in failure that may have been blocked by Conditional Access and multifactor authentication requirements.

Which Microsoft Entra evidence should the administrator review?

  1. A

    Sign-in logs

  2. B

    Data Explorer

  3. C

    Content search

  4. D

    Copilot Analytics

Show answer and explanation

Correct answer: A

Explanation

Sign-in logs in Microsoft Entra record authentication attempts, MFA status, Conditional Access decisions, and related failure details. Data Explorer, Content search, and Copilot Analytics serve compliance discovery, eDiscovery, or adoption reporting. The requirement is sign-in troubleshooting evidence.

Question 6 Hotspot

HOTSPOT

Your company is evaluating Zero Trust as part of its Microsoft security strategy. The security team wants to understand whether Zero Trust is a product, a subscription requirement, or a security model that can guide access decisions across Microsoft 365 and cloud environments.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

No; Yes; No

Zero Trust is a security strategy and operating model, not a specific Microsoft 365 product or a feature that is simply enabled from one admin center. It does not require an Azure subscription as a principle. The rule is to apply Zero Trust practices across identity, device, access, and data controls.

Question 7 Single choice

A Microsoft 365 administrator assigns a Microsoft 365 license to a security group. A new user does not have access to the licensed features.

What should the administrator do to grant the user access through the existing group-based assignment?

  1. A

    Add the user to the licensed group

  2. B

    Create a Microsoft Purview DLP policy

  3. C

    Create an app registration for the user

  4. D

    Enable Privileged Identity Management for the user

Show answer and explanation

Correct answer: A

Explanation

When a license is assigned to a group, the user must be a member of that group to receive the service entitlement. DLP policies, app registrations, and PIM activation do not apply the existing license assignment. The requirement is to grant access through group-based licensing.

Question 8 Single choice

You need to create a Microsoft 365 Copilot agent that can create charts and visualizations based on a Microsoft Excel workbook.

What should you configure for the agent?

  1. A

    the image generator capability

  2. B

    the Scrum Assistant template

  3. C

    the Customer Insights Assistant template

  4. D

    the code interpreter capability

Show answer and explanation

Correct answer: D

Explanation

An agent that can create charts and visualizations from an Excel workbook needs access to the workbook as a knowledge or data source and the ability to use that content for responses. Other choices that only control licensing, retention, or identity do not provide the agent with the business data needed for chart generation.

Question 9 Hotspot

HOTSPOT

Your company is evaluating Microsoft Purview Compliance Manager to improve its compliance posture.
The compliance team wants to know whether Compliance Manager can provide a risk-based compliance score, offer improvement actions, and whether it belongs to the Microsoft Defender product family.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

Yes; Yes; No

Microsoft Purview Compliance Manager provides a risk-based compliance score and improvement actions with guidance for remediation. It does not automatically make an organization compliant with all regulations. The requirement tests posture measurement and guidance rather than a guarantee of legal compliance.

Question 10 Single choice

An administrator must reduce standing privileged access for Microsoft 365 administrator roles and require eligible administrators to activate roles only when needed.

What should the administrator use?

  1. A

    Privileged Identity Management

  2. B

    Communication Compliance

  3. C

    Microsoft Defender XDR incidents

  4. D

    SharePoint Advanced Management

Show answer and explanation

Correct answer: A

Explanation

Privileged Identity Management reduces standing administrative access by requiring eligible administrators to activate roles when needed. Communication Compliance detects risky messages, Defender XDR investigates threats, and SharePoint Advanced Management governs SharePoint. The requirement is just-in-time privileged role activation.