AB-900 Practice Questions
Prepare for AB-900 with more than an answer.
- Exam fee
- $99 USD
- Level
- Fundamentals
- Valid for
- Lifetime
Domains covered on the exam 3
- Identify the Core Features and Objects of Microsoft 365 Services32.5%
- Understand Data Protection and Governance Tasks for Microsoft 365 and Copilot37.5%
- Perform Basic Administrative Tasks for Copilot and Agents27.5%
- 1
You are explaining the 'Least Privilege' principle of Zero Trust to a junior administrator. Which Microsoft Entra feature best implements this principle by allowing administrators to request temporary, time-bound access to high-privilege roles?
Show answer details
Correct answer: A
Privileged Identity Management (PIM) provides Just-In-Time (JIT) access to roles, ensuring users only have high privileges when needed and for a limited time, which is the core of Least Privilege.
- 2
Review the state diagram below representing the Agent Lifecycle. What action triggers the transition from 'Draft' to 'Published'?
stateDiagram-v2 [*] --> Draft Draft --> Review: Submit for Approval Review --> Published: Admin Approve Review --> Draft: Admin Reject Published --> [*]: DeleteShow answer details
Correct answer: D
According to the diagram, the transition from 'Review' to 'Published' is triggered by 'Admin Approve'. The path is Draft -> Submit -> Review -> Approve -> Published.
- 3
A developer is using Microsoft Copilot Studio to create an agent that can process travel requests. The developer wants the agent to automatically extract the 'Destination City' and 'Travel Date' from a user's natural language input. Which Copilot Studio feature should be used to define these specific data types for extraction?
Show answer details
Correct answer: B
In Copilot Studio, an entity is a unit of information that represents a real-world type such as a city, date and time, phone number or money. With prebuilt or custom entities, the agent recognizes these values in natural-language input and saves them to variables (slot filling). For example, 'London' becomes the destination city and 'next Tuesday' a date. Topics define conversation paths, variables store the extracted values, and connectors call external systems.
- 4
An administrator is reviewing the 'Activity Explorer' in Microsoft Purview. They see several entries labeled 'Sensitivity label applied'. Which of the following information is available for these entries to help with a security investigation?
Show answer details
Correct answer: D
Activity Explorer provides granular details about data activities, including which user performed the action, what object (file/email) was affected, the date/time, and the specific label or policy involved.
- 5
You are configuring a 'Communication Compliance' policy to monitor for workplace harassment. You want the policy to analyze images sent in Teams chats for inappropriate content. Which feature of Communication Compliance allows for this visual analysis?
Show answer details
Correct answer: B
Communication Compliance supports optical character recognition (OCR) to detect printed and handwritten text in images embedded in or attached to email and Microsoft Teams chat messages, and built-in classifiers, such as those used by the 'Detect inappropriate images' policy template, which detects adult and racy images. Encryption at rest, meeting recordings, and Exchange mail flow rules don't analyze image content.
- 6
A Microsoft 365 Administrator wants a small group of IT power users to receive new Microsoft 365 updates, for example in SharePoint, OneDrive, new Outlook, and Microsoft 365 for the web, before they're rolled out to the rest of the company. Which setting in the Microsoft 365 Admin Center should they use to target this specific group for early feature access?
Show answer details
Correct answer: C
In the Microsoft 365 admin center, go to Settings > Org settings > Organization profile > Release preferences, select Targeted release for selected users, and add the users (Standard release is the default). Targeted release applies to services such as new Outlook, OneDrive, SharePoint, Microsoft 365 for the web, the admin center, and some parts of Exchange Online and Teams. Copilot features use a newer audience-based model instead: Copilot > Settings > Copilot Frontier gives specific users pre-release Copilot features, and Copilot release preferences set Standard or Deferred release. Intune update rings, Exchange address book policies and Teams messaging policies don't control Microsoft 365 feature release timing.
- 7
A global administrator at Contoso Ltd. is configuring access for a new group of external consultants. The consultants need to access specific SharePoint sites and Teams channels but should not have access to any other Microsoft 365 resources. The administrator wants to ensure that every access request is verified explicitly, regardless of where the request originates. Which security model principle is the administrator applying?
Show answer details
Correct answer: D
The principle of 'Verify explicitly' requires that all access requests be fully authenticated, authorized, and encrypted before granting access. This matches the scenario where the administrator wants to verify every request regardless of origin. 'Assume breach' focuses on minimizing blast radius and segmenting access, while 'Use least privilege access' focuses on limiting user permissions to only what is necessary.
- 8
You are the Microsoft 365 Administrator for Litware, Inc. You need to assign licenses to a new department of 50 users. These users require access to Microsoft 365 Copilot but do not need the advanced eDiscovery and automated investigation capabilities found in the E5 license. They currently hold Microsoft 365 E3 licenses. What is the most cost-effective licensing strategy to enable Copilot for these users?
Show answer details
Correct answer: C
Microsoft 365 Copilot is available as an add-on license. Since the users already have a prerequisite license (Microsoft 365 E3) and do not need the other features of E5, purchasing the Copilot add-on is the most cost-effective and direct solution. Upgrading to E5 would incur unnecessary costs for features not required.
- 9
A security administrator needs to configure a policy that blocks sign-ins from countries where the organization has no presence, unless the user is utilizing a compliant device and multi-factor authentication (MFA). Which Microsoft Entra feature should be used to enforce this requirement logic?
Show answer details
Correct answer: C
Conditional Access policies in Microsoft Entra ID allow administrators to create if-then statements (signals to decisions) to enforce access controls. This scenario describes a classic Conditional Access policy: IF location is X AND device is Y, THEN Grant/Block access. Identity Protection focuses more on risk-based events like leaked credentials.
- 10
You are explaining to a client how Microsoft 365 Copilot processes user prompts securely. The client is concerned about their data training public models. Review the diagram below representing the Copilot architecture flow.
flowchart LR User[User Prompt] --> Graph[Microsoft Graph] Graph --> LLM[Large Language Model] LLM --> Process[Post-Processing] Process --> Response[Response to User]Based on Microsoft's data protection principles for Copilot, which statement is legally and technically accurate regarding the 'Large Language Model' step?
Show answer details
Correct answer: B
A core security principle of Microsoft 365 Copilot is that customer data (prompts and grounding data) is NOT used to train the foundation Large Language Models (LLMs). The data remains within the tenant boundary and is only used to generate the specific response for that user session.
- 11
Your organization uses Microsoft Purview to manage data governance. You need to ensure that credit card numbers shared in Teams chats are automatically detected and blocked before they can be sent. Which specific Purview solution should you configure?
Show answer details
Correct answer: D
Data Loss Prevention (DLP) is designed specifically to detect sensitive information types (like credit card numbers) and apply protective actions, such as blocking the transmission of that data in Teams chats. Communication Compliance is for detecting inappropriate conduct (harassment, threats), not necessarily structured sensitive data types like credit cards.
