Free Microsoft AB-900 Exam Questions

Become Microsoft Certified with updated AB-900 exam questions and correct answers

Page:    1 / 88      
Total 437 Questions | Updated On: Jul 03, 2026
Add To Cart
Question 1

A risk analyst is explaining when to use Microsoft Purview Insider Risk Management instead of only relying on DLP and audit logs.Complete the sentence:“Use Microsoft Purview Insider Risk Management when you need to ______.”


Answer: C
Question 2

The HR team at Tailwind Traders has 200 specialists who use Copilot heavily every day across Outlook, Word, Teams, and SharePoint. The CFO wants Copilot costs for this team to be stable and easy to forecast for the next 12 months. Other small project teams will experiment with SharePoint agents, but their usage will be occasional and unpredictable.Which licensing approach best fits the HR specialists?


Answer: D
Question 3

Fabrikam currently assigns permanent Global Administrator and Security Administrator roles to several senior IT engineers. A recent internal audit flags this as a risk and recommends just-in-time access with approvals, alerts when privileged roles are activated, and regular reviews of who can elevate into admin roles.A proposed design is to use Microsoft Entra Privileged Identity Management so that users are eligible for privileged roles but must activate them for a limited time with justification, MFA, and (optionally) approval, while auditors perform access reviews on those eligibilities.Microsoft Entra Privileged Identity Management is specifically intended to reduce standing privileged access by providing just-in-time elevation, access reviews, and auditing for high-privilege roles.


Answer: A
Question 4

A security architect enables Microsoft Entra ID Protection and assumes that, from that moment onward, any sign-in flagged as “high risk” will automatically be blocked or forced to perform multifactor authentication, even if no Conditional Access policies have been configured to act on risk. The architect states, “ID Protection on its own will enforce MFA or block access when risk is detected.” This statement is:


Answer: B
Question 5

A group of high-impact administrators in a Microsoft 365 tenant are repeatedly targeted by modern phishing kits that can proxy sign-in pages and steal MFA codes in real time. The security team wants a sign-in method that is resistant to credential theft and MFA code replay, and that ties authentication to a hardware-backed credential. Which authentication method best meets this requirement?


Answer: C
Page:    1 / 88      
Total 437 Questions | Updated On: Jul 03, 2026
Add To Cart

© Copyrights DumpsCertify 2026. All Rights Reserved

We use cookies to ensure your best experience. So we hope you are happy to receive all cookies on the DumpsCertify.