Q1.The department you manage runs a Microsoft 365 subscription that includes Microsoft SharePoint sites and Microsoft Teams teams.
During an audit, you discovered that some of these sites and teams are shared with external users outside your organization.
What should you use to identify the sites and teams that are shared with external users?
Show answer
The SharePoint admin center lets you understand which sites and files are shared externally through its sharing reports.
Because files stored in a standard Teams channel are kept in the underlying SharePoint site, you can also review the sharing status related to Teams here.
Therefore, the SharePoint admin center is best suited for identifying external sharing targets.
The Microsoft Teams admin center focuses on Teams policies and operational management, and is not well suited to enumerating external sharing targets.
On the exam, it is important to remember that Teams uses SharePoint as its underlying file store.
Reports on sharing files and folders in SharePoint sites
Q2.Your company is running a pilot deployment of Microsoft 365 Copilot and has already secured 100 licenses.
You need to review a report that provides detailed insight into Copilot usage in Microsoft Teams, such as the amount of meeting time summarized by Copilot and the meeting actions performed through Copilot.
What should you use?
Show answer
The Microsoft 365 Copilot dashboard in Microsoft Viva Insights lets you review Copilot adoption and impact in detail, and it can also track metrics related to Teams.
Detailed usage such as summarized meeting time and Copilot meeting actions falls within what this dashboard captures.
The readiness report is intended for pre-deployment assessment, and the usage report in the admin center is for understanding overall trends, so neither is suited to reviewing granular Teams metrics.
On the exam, it is important that you choose Viva Insights for detailed Teams-related metrics.
Connect to the Microsoft Copilot Dashboard for Microsoft 365 customers | Microsoft Learn
Q3.Your organization uses a Microsoft 365 subscription and has assigned Microsoft 365 Copilot licenses to all users.
You need to identify where sensitive content is being handled in interactions with Copilot, analyze usage trends, and provide recommendations for applying appropriate protection.
What should you use?
Show answer
DSPM for AI in Microsoft Purview is a capability that centrally manages data protection when generative AI, including Copilot, is used.
It can identify where sensitive data is being used, analyze prompts and responses, and understand usage patterns, and it recommends assessing oversharing risk and applying protection through sensitivity labels and DLP.
Viva Insights is for productivity analytics, Security Copilot is for supporting security operations, and Insider Risk Management is for detecting insider threats, so none of them meet this requirement.
On the exam, it is important to understand that Purview handles data protection when AI is used.
Microsoft Purview Data Security Posture Management for AI | Microsoft Learn
Q4.Your organization has a Microsoft 365 subscription.
You discover that files in Microsoft SharePoint are shared with users outside your organization.
You need to identify the files that are shared with external users.
Which report should you use in the SharePoint admin center?
Show answer
The Data access governance report is a report for analyzing the state of external sharing and access in SharePoint.
It can surface sharing link usage and make external sharing visible, and it lets you identify which files and sites are shared with external users.
Agent insights and App insights analyze app usage, and Change history reviews the change log, so all of them serve other purposes and are not suited to this requirement.
On the exam, it is important to remember that you use Data access governance to investigate external sharing.
Reports on sharing files and folders in SharePoint sites
Q5.Your organization has a Microsoft 365 subscription.
You need to evaluate your organization’s Identity Secure Score.
Which factors affect the score?
Each correct answer presents part of the solution.
Show answer
Identity Secure Score is evaluated based on how well your configuration aligns with the identity security recommendations from Microsoft Entra.
The number of global administrators is directly tied to excessive privilege, and the fewer there are, the higher the security.
In addition, not making passwords non-expiring is also an important recommendation and affects the score.
On the other hand, SharePoint permissions and users’ locations are not direct evaluation factors of Identity Secure Score.
On the exam, it is important to choose the items related to recommended identity protection settings.
Protect identities and secrets – Microsoft Entra
Q6.Your organization has a Microsoft 365 subscription and a user named User1.
User1 is scheduled to leave the company in two weeks.
To confirm whether User1 is exfiltrating data, you need to record their activity.
Which Microsoft Purview solution should you use?
Show answer
Insider Risk Management is a Microsoft Purview capability that detects and analyzes risky behavior such as data exfiltration by internal users.
In particular, it provides policies aimed at departing users and can track behaviors such as downloading files or forwarding them externally.
Communication Compliance is for monitoring communications, DSPM is for gaining visibility across data as a whole, and Data Lifecycle Management is for managing retention.
For monitoring data leakage risk as in this question, Insider Risk Management is the best fit.
Microsoft Purview Insider Risk Management
Q7.Your company has a Microsoft SharePoint site named Site1.
Site1 stores all of the HR department’s policies as Microsoft Word documents.
All users have read access to Site1.
The HR manager reports that responding to policy inquiries falls behind, especially during major holiday periods.
You need to recommend a solution that lets users find HR policies on their own.
The solution must present a list of common inquiries and must guarantee that answers are based only on the content of Site1.
What should you include in your recommendation?
Show answer
A custom Microsoft 365 Copilot agent is a capability that can generate answers based on a specific data source, such as a SharePoint site.
This question requires that answers be limited to the content of Site1 only, and you can meet the requirement by creating an agent grounded on the target site.
Furthermore, by configuring starter prompts, you can also present a list of frequently asked questions.
The other options center on personal use or general-purpose analysis, and are not suited to providing knowledge limited to a specific site.
Overview of agents for Microsoft 365 Copilot
Q8.Your organization has a Microsoft 365 subscription.
You need to assign licenses to users.
What should you use?
Show answer
In the Microsoft 365 admin center, you can assign and remove licenses from a user’s details page or the Licenses page.
Microsoft Learn also guides you to manage them on the Active users page or the Licenses page.
The Microsoft Purview portal is for compliance and data protection, and the Teams admin center is for Teams settings and policy management.
Therefore, to grant product licenses to users, the correct choice is to use the license management features of the admin center.
Assign or unassign licenses for users in the Microsoft 365 admin center
Q9.For each of the following statements, select Yes if the statement is true, or No if it is false.
| Statement | Yes | No | |
|---|---|---|---|
| Microsoft Purview Communication Compliance can detect inappropriate text within images stored in SharePoint | |||
| Microsoft Purview Communication Compliance anonymizes users by default during investigations | |||
| Microsoft Purview Communication Compliance appends a disclaimer to all monitored communications |
Show answer
Microsoft Purview Communication Compliance is a capability that detects and investigates inappropriate language, harassment, and the sharing of sensitive information across communications such as email, Teams, Viva Engage, and Microsoft 365 Copilot.
Detection of text within images targets embedded or attached images in email and Teams messages, and it does not directly monitor images stored in SharePoint, so the first statement is false.
During investigations, usernames are pseudonymized by default, allowing investigations while preserving privacy, so the second statement is a true statement.
On the other hand, there is no feature that automatically adds a disclaimer to monitored communications, so the third statement is false.
Microsoft Purview Communication Compliance
Q10.Your company uses a Microsoft 365 subscription.
A user named John is assigned an administrator role as shown in the figure below.
Based on the information shown in the figure, select the option that completes the statement using the drop-down menu.

Show answer
In the figure, John is assigned the Global Reader role.
This role grants read-only permission to view the admin center features and settings that a Global Administrator can access.
Therefore, John can view user information in the Microsoft Entra tenant.
On the other hand, viewing all content in SharePoint, reading the contents of Exchange mailboxes, and performing eDiscovery on Copilot prompts require different permissions.
On the exam, it is important to categorize Global Reader as a view-only administrative role.
About admin roles in the Microsoft 365 admin center – Microsoft 365 admin | Microsoft Learn
