You need to create a data loss prevention (DLP) policy. What should you use?
Answer : D
In Microsoft's Security, Compliance, and Identity guidance, Data Loss Prevention (DLP) is configured from the compliance portal (formerly called the Microsoft 365 Compliance Center, now Microsoft Purview compliance portal). Microsoft's documentation states that DLP is administered from the compliance experience: ''Use data loss prevention (DLP) policies in the Microsoft Purview compliance portal to help identify, monitor, and automatically protect sensitive items'' across Microsoft 365 workloads. It further specifies where you create policies: ''To create a DLP policy, go to the Microsoft Purview compliance portal > Data loss prevention > Policies and choose Create policy.'' The portal provides policy templates, locations, and rules that ''help prevent the inadvertent sharing of sensitive information'' and enable ''policy tips and automatic remediation actions'' (such as restricting access, auditing, or blocking).
By contrast, the Microsoft 365 admin center is for tenant administration and licensing, not DLP policy authoring. The Microsoft Endpoint Manager admin center (Intune) manages device and app protection policies, not Microsoft 365 DLP policies. The Microsoft 365 Defender portal surfaces security alerts and investigations but does not host the creation workflow for DLP policies. Therefore, when the requirement is to create a DLP policy, Microsoft directs administrators to the Microsoft 365 Compliance center (Microsoft Purview compliance portal) where the DLP solutions and policy creation wizard reside.
What can you use to protect against malicious links sent in email messages, chat messages, and channels?
Answer : D
Microsoft Defender for Office 365 is the Microsoft 365 solution designed to protect users from threats delivered through email and collaboration workloads. SCI training material explains that Defender for Office 365 protects Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive for Business by detecting and blocking malware, phishing, and other advanced attacks that use messages and shared content as the delivery channel.
A key capability is Safe Links, which specifically protects against malicious URLs. When a user receives an email, Teams chat message, or channel post that contains a hyperlink, Safe Links scans and rewrites that URL. At the moment the user clicks, the link is checked again; if it is identified as malicious or leads to a known phishing or malware-hosting site, access is blocked and a warning page is shown. This time-of-click protection is emphasized in Microsoft's security documentation as a primary defense against weaponized links in email and collaborative communications.
You have an Azure subscription.
You need to implement approval-based, tiProme-bound role activation.
What should you use?
Answer : D
In Microsoft's Security, Compliance, and Identity guidance, Azure AD Privileged Identity Management (PIM) is the service used to manage, control, and monitor access to important resources in Azure and Microsoft 365. The documentation explains that PIM enables ''just-in-time'' and ''time-bound'' activation of privileged roles, requiring users to elevate only when needed and for a limited duration. PIM policies can require approval before a role is activated, enforce multifactor authentication, capture business justification, send notifications, and maintain detailed auditing and access review records. These controls are designed to reduce the risk associated with standing administrative privileges by ensuring that elevation is temporary, approved, and tracked.
By contrast, Windows Hello for Business provides strong, device-bound authentication; Azure AD Identity Protection focuses on detecting and remediating risky sign-ins and users; and Azure AD Access Reviews periodically reattest existing assignments but do not provide the on-demand, approval-based, time-limited activation of roles. Therefore, when the requirement is approval-based, time-bound role activation, Microsoft's prescribed capability is Azure AD PIM, which delivers just-in-time elevation with approvers, duration limits, and audit/logging to support least privilege and Zero Trust operational practices.
What Microsoft Purview feature can use machine learning algorithms to detect and automatically protect sensitive items?
Answer : B
Microsoft Purview Data Loss Prevention (DLP) is designed to ''detect and protect sensitive items'' across Microsoft 365 locations, endpoints, and cloud apps. Microsoft explains that Purview DLP policies use sensitive information types, exact data match (EDM), and machine learning--based trainable classifiers to identify content, and then automatically apply protective actions such as blocking or restricting sharing, notifying users with policy tips, auditing, or auto-quarantining/justifying activities. This fulfills the description ''use machine learning algorithms to detect and automatically protect sensitive items.'' While eDiscovery focuses on legal hold and content discovery, and Communication compliance monitors communications for policy violations (ethics/regulatory scenarios), they are not positioned to broadly and automatically protect sensitive data across services. ''Information risks'' is not a distinct Purview solution category. Therefore, the Purview capability that leverages machine learning classifiers and automatically enforces protections on sensitive data is Data loss prevention (DLP).
Which Microsoft Defender for Cloud metric displays the overall security health of an Azure subscription?
Answer : B
In Microsoft Defender for Cloud, the metric that represents the overall security health of your Azure subscription is secure score. Microsoft's documentation explains: ''Secure score provides an aggregated view of your security posture across your subscriptions and resources. It's based on security recommendations; addressing those recommendations improves your score.'' Defender for Cloud calculates secure score by assessing controls and recommendations mapped to standards, then weighting them by risk and importance: ''Each recommendation contributes to the secure score. Completing remediation steps increases the score and reduces risk.'' This single percentage view lets security teams quickly gauge how well current configurations and protections align with Microsoft's security best practices and regulatory mappings. Other elements surfaced in Defender for Cloud---like ''resource health,'' ''status of recommendations,'' or ''completed controls''---are components and statuses that feed into or relate to the scoring model, but the overall subscription security health indicator presented and tracked over time is secure score.
Which three authentication methods can Microsoft Entra users use to reset their password? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Answer : A, C, D
Microsoft Entra self-service password reset (SSPR) supports multiple verification methods that users can register and use to prove their identity during a reset. Microsoft's documentation lists the SSPR methods as: ''Mobile app notification,'' ''Mobile app code,'' ''Email,'' ''Mobile phone (text message or call),'' ''Office phone,'' and ''Security questions.'' Administrators choose which of these are allowed and how many methods are required. During the reset flow, SSPR ''prompts the user to verify with the registered methods'' before permitting a password change. Notably, certificates and picture passwords are not SSPR verification methods in Microsoft Entra ID. Therefore, among the options provided: a text message to a phone (mobile phone), a mobile app notification (Microsoft Authenticator), and security questions are valid SSPR authentication methods; certificate and picture password are not supported for SSPR. This aligns with SCI learning content that positions SSPR as a user-empowering capability to securely restore access using admin-approved methods without help-desk intervention.
What should you use in the Microsoft 365 security center to view security trends and track the protection status of identities?
Answer : B
In the Microsoft 365 security center/Microsoft 365 Defender portal, the Reports area is designed to provide organization-wide visibility into security posture and activity over time. Microsoft describes the Reports experience as enabling you to ''view security trends and track the protection status across identities, endpoints, email & collaboration, and cloud apps.'' Within Reports, the Identity section aggregates signals from Microsoft Entra ID protection and related identity defenses so security teams can monitor trends such as risky sign-ins, user risk, MFA adoption/registration, and other identity protection metrics. These curated, read-only dashboards are aimed at measuring protection status and changes over time, helping you validate the impact of controls and prioritize remediation.
By contrast, Attack simulator is used to run user training simulations (e.g., phishing) and is not intended for posture trend reporting. Hunting (Advanced hunting) lets analysts query raw telemetry for investigations, not to provide summarized trend dashboards. Incidents correlates alerts into incident records for triage and response, rather than showing long-term trends and protection status views. Therefore, to view security trends and track the protection status of identities, the correct place is Reports in the Microsoft 365 security center/Microsoft 365 Defender portal.