Microsoft Certification 70-346 - O365 Identities/Requirements

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Bearxor
B
Bearxor
Community Contributor
Quizzes Created: 1 | Total Attempts: 376
| Attempts: 376
SettingsSettings
Please wait...
  • 1/96 Questions

    You are the Office 365 administrator for your company. You prepare to install Active Directory Federation Services (AD FS). You need to open the correct port between the AD FS proxy server and the AD FS federation server.Which port should you open?

    • TCP 80
    • TCP 135
    • TCP 389
    • TCP 443
    • TCP 636
    • TCP 1723
Please wait...
About This Quiz

This quiz assesses knowledge on managing Office 365 identities and requirements, focusing on hybrid configurations, single sign-on setups, and Active Directory Federation Services. It is designed for individuals preparing for the Microsoft Certification 70-346.

Microsoft Certification 70-346 - O365 Identities/Requirements - Quiz

Quiz Preview

  • 2. 

    You are the Office 365 administrator for your company. The company uses Active Directory Federation Services (AD FS) to provide single sign-on to cloud-based services. You enable multi-factor authentication. Users must NOT be required to use multi-factor authentication when they sign in from the company's main office location. However, users must be required to verify their identity with a password and token when they access resources from remote locations.You need to configure the environment. What should you do?

    • Disable AD FS multi-factor authentication

    • Configure an IP blacklist for the main office location

    • Disable the AD FS proxy

    • Configure an IP whitelist for the main office location

    Correct Answer
    A. Configure an IP whitelist for the main office location
    Explanation
    To meet the requirement of not requiring multi-factor authentication for users signing in from the main office location, the administrator should configure an IP whitelist for the main office location. By doing this, the system will allow access without multi-factor authentication only from the specified IP addresses associated with the main office location. This ensures that users accessing resources from remote locations will still be required to verify their identity with a password and token, while users within the main office location will not be prompted for multi-factor authentication.

    Rate this question:

  • 3. 

    You are the Office 365 administrator for your company. The environment must support single sign-on. You need to install the required certificates.Which two certificates should you install? Each correct answer presents part of the solution.

    • Secure Sockets Layer (SSL)

    • Privacy-enhanced mail (PEM)

    • Token signing

    • Personal

    • Software publisher

    Correct Answer(s)
    A. Secure Sockets Layer (SSL)
    A. Token signing
    Explanation
    To support single sign-on in Office 365, two certificates need to be installed: Secure Sockets Layer (SSL) and Token signing. The SSL certificate is necessary for encrypting the communication between the user's browser and the Office 365 services, ensuring a secure connection. The Token signing certificate is used to sign the security tokens issued by the identity provider, allowing Office 365 to trust the authentication information provided by the identity provider. By installing both certificates, the environment will be able to establish a secure and trusted single sign-on experience for users.

    Rate this question:

  • 4. 

    An organization deploys an Office 365 tenant. User accounts must be synchronized to Office 365 by using the Windows Azure Active Directory Sync Tool. You have the following password policies:
    • Passwords for the on-premises Active Directory DOmain Services (AD DS) user accounts are at least six characters long
    • Passwords for Office 365 user accounts are at least eight characters long.
    You need to ensure that the user accounts will be synchronized. Which user accounts will be synchronized?

    • All user accounts

    • No user accounts

    • User accounts with a password length of at least 8 characters

    • User accounts with a password length of at least 14 characters

    Correct Answer
    A. All user accounts
    Explanation
    All user accounts will be synchronized. The Windows Azure Active Directory Sync Tool will synchronize all user accounts, regardless of their password length. The password policies for on-premises Active Directory Domain Services (AD DS) and Office 365 user accounts are not relevant to the synchronization process.

    Rate this question:

  • 5. 

    You are the Office 365 administrator for your company. The company has a single office. You have the following requirements:
    • You must configure a redundant Active Directory Federation Services (AD FS) implementation
    • You must use a Windows Internal Database to store AD FS configuration data
    • The solution must use a custom login page for external users
    • The solution must use a single sign-on for internal users
    You need to deploy the minimum number of servers. How many servers should you deploy.

    • 2

    • 4

    • 6

    • 16

    Correct Answer
    A. 4
    Explanation
    To meet the requirements of a redundant AD FS implementation, a minimum of two AD FS servers is required. Each server would have a Windows Internal Database to store AD FS configuration data. Additionally, to achieve a custom login page for external users and single sign-on for internal users, a minimum of two Web Application Proxy (WAP) servers is needed. Therefore, a total of four servers should be deployed.

    Rate this question:

  • 6. 

    You manage a team of three administrators for an organization that uses Office 365. You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks. UserRequirementsAdmin1Reset user passwords for administratorsAdmin2Perform purchasing purchasing operationsAdmin3Create and manage user viewsWhat administrative role should you assign to Admin1?

    • Billing administrator

    • Global administrator

    • User management administrator

    Correct Answer
    A. Global administrator
    Explanation
    Admin1 should be assigned the role of a global administrator. A global administrator has the highest level of permissions in Office 365 and can perform all administrative tasks, including resetting user passwords for administrators. This role provides the necessary permissions to fulfill the requirement of resetting user passwords for administrators.

    Rate this question:

  • 7. 

    You are the Office 365 administrator for your company. The company has two administrators named User1 and User2. Users must be able to perform the activities as shown in the following table: AdministratorActivitiesUser1
    • Reset passwords for standard user accounts
    • Reset passwords for other members of the same role.
    • Must NOT reset passwords for other administrator accounts
    User2
    • Reset passwords for all administrator accounts
    What is the correct role to assign to User2?

    • Global administrator

    • Delegate administrator

    • Billing administrator

    • Password administrator

    Correct Answer
    A. Global administrator
    Explanation
    The correct role to assign to User2 is "global administrator" because User2 needs to be able to reset passwords for all administrator accounts, which includes User1. The other options (delegate administrator, billing administrator, password administrator) do not have the necessary permissions to reset passwords for all administrator accounts.

    Rate this question:

  • 8. 

    A company named Fabrikam, Inc. is deploying an Office 365 tenant. You install Active Directory Federation Services (AD FS) on a server that runs Windows Server 2012. The company's environment is described in the following table: DescriptionFully Qualified Domain NameCluster DNS Namefs.fabrikam.comServer node in clusterserver1.fabrikam.comServer node in clusterserver2.fabrikam.comYou must obtain a certificate from a certification authority and install it on the federation servers. You need to specify the subject name for the certificate. Which name should you specify? 

    • Fs.fabrikam.com

    • Server1.fabrikam.com

    • Fabrikam.com

    • Server2.fabrikam.com

    Correct Answer
    A. Fs.fabrikam.com
    Explanation
    The subject name for the certificate should be fs.fabrikam.com. This is because fs.fabrikam.com is the fully qualified domain name (FQDN) that represents the federation servers in the Fabrikam, Inc. environment. The certificate needs to match the FQDN of the server where AD FS is installed in order to establish secure communication between the federation servers and other components of the Office 365 tenant.

    Rate this question:

  • 9. 

    You manage a team of three administrators for an organization that uses Office 365. You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks. UserRequirementsAdmin1Reset user passwords for administratorsAdmin2Perform purchasing purchasing operationsAdmin3Create and manage user viewsWhat administrative role should you assign to Admin2?

    • Billing administator

    • Global administrator

    • User management administrator

    Correct Answer
    A. Billing administator
    Explanation
    Admin2 should be assigned the role of a "billing administrator" because they need to perform purchasing operations. The billing administrator role allows them to manage billing, subscriptions, and purchases for the organization. This role does not have excessive permissions beyond what is required for their specific task.

    Rate this question:

  • 10. 

    You administer the Office 365 environment for a company that has offices around the world. All of the offices use the same Office 365 tenant. You need to ensure that all users can access the services that are available in their regions.Which setting or service should you update?

    • User location settings

    • User licenses

    • Service usage address

    • Rights management

    Correct Answer
    A. User location settings
    Explanation
    To ensure that all users can access the services available in their regions, you should update the user location settings. By configuring the user location settings, you can specify the region or country for each user in the Office 365 environment. This allows the services to be localized and tailored to the specific needs and regulations of each region, ensuring that users have access to the appropriate services based on their location.

    Rate this question:

  • 11. 

    You manage a team of three administrators for an organization that uses Office 365. You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks. UserRequirementsAdmin1Reset user passwords for administratorsAdmin2Perform purchasing purchasing operationsAdmin3Create and manage user viewsWhat administrative role should you assign to Admin3?

    • Billing administrator

    • Global administrator

    • User management administrator

    Correct Answer
    A. User management administrator
    Explanation
    Admin3 should be assigned the role of "user management administrator". This role will provide the necessary permissions to create and manage user views, which is the assigned task for Admin3. The other roles, such as billing administrator and global administrator, do not align with the specific tasks mentioned in the requirements.

    Rate this question:

  • 12. 

    An organization plans to deploy Exchange Online. You must support all Exchange Online features. You need to create the required DNS entries.Which two DNS entries should you create?

    • A

    • SRV

    • MX

    • CNAME

    Correct Answer(s)
    A. MX
    A. CNAME
    Explanation
    To support all Exchange Online features, you need to create two DNS entries: MX and CNAME. The MX (Mail Exchanger) record is used to specify the mail server responsible for accepting email messages on behalf of the domain. This record ensures that incoming emails are delivered to the correct server. The CNAME (Canonical Name) record is used to create an alias for a domain name. In this case, it is used to create an alias for the Autodiscover service, which is required for various Exchange Online features such as automatic configuration of email clients.

    Rate this question:

  • 13. 

    Your company purchases an Office 365 plan. The company has an Active Directory Domain Services domain. User1 must manage Office 365 delegation for the company. You need to ensure that User1 can assign administrative roles to other users.What should you do?

    • Create an Office 365 tenant and assign User1 the password administrator role.

    • Use a password administrator account to assign the role to User1.

    • Use a user management administrator account to assign the role to User1.

    • Create an Office 365 tenant and assign User1 the global administrator role.

    Correct Answer
    A. Create an Office 365 tenant and assign User1 the global administrator role.
    Explanation
    To ensure that User1 can assign administrative roles to other users, User1 needs to have the highest level of administrative privileges, which is the global administrator role. By creating an Office 365 tenant and assigning User1 the global administrator role, User1 will have the necessary permissions to manage Office 365 delegation for the company.

    Rate this question:

  • 14. 

    Contoso Ltd. uses Office 365 for collaboration. You are implementing Active Directory Federation Services (AD FS) for single sign-on (SSO) with Office 365 services. The environment contains an Active Directory domain and an AD FS federation server. You need to ensure that the environment is prepared for the AD FS setup.Which two actions should you preform? Each correct answer presents part of the solution.

    • Configure Active Directory to use the domain contoso.com

    • Configure Active Directory to use the domain contoso.local

    • Create a server authentication certificate for the federation server by using fs.contoso.com as the subject name and subject alternative name.

    • Create a server authentication certificate for the federation server by using fs.contoso.local as the subject name and subject alternative name.

    Correct Answer(s)
    A. Configure Active Directory to use the domain contoso.com
    A. Create a server authentication certificate for the federation server by using fs.contoso.com as the subject name and subject alternative name.
    Explanation
    To prepare the environment for AD FS setup, the first action is to configure Active Directory to use the domain "contoso.com". This ensures that the AD FS server is integrated with the correct Active Directory domain.

    The second action is to create a server authentication certificate for the federation server. This certificate should have "fs.contoso.com" as the subject name and subject alternative name. This certificate is necessary for secure communication between the AD FS server and Office 365 services, enabling SSO functionality.

    Rate this question:

  • 15. 

    An organization deploys an Office 365 tenant. The Service Health page displays the following information:What is the current status of Exchange Online and SharePoint Online?

    • SharePoint Online is available. Exchange Online is available but service is degraded

    • SharePoint Online is available. Issues with the Exchange Online subscription are under investiagtion

    • The SharePoint Online subscription is expired. The Exchange Online subscription will expire soon.

    • The SharePoint Online subscription is expired. Issues with the Exchange Online service are under investigation.

    Correct Answer
    A. SharePoint Online is available. Exchange Online is available but service is degraded
    Explanation
    The current status of Exchange Online is available but the service is degraded. This means that while Exchange Online is still accessible, there may be some performance issues or limitations in its functionality. On the other hand, SharePoint Online is available without any reported issues.

    Rate this question:

  • 16. 

    Fabrikam, Inc employs 500 users and plans to migrate to Office 365. You must sign up for a trial plan from the Office 365 website. You have the following requirements:
    • Create the maximum number of trial users allowed
    • Convert the trial plan to a paid plan at the end of the trial that supports all of Fabrikam's users
    You need to create an Office 365 trial plan. Which plan gives you the maximum amount of trail users?

    • Office 365 Midsize Business - 100 Users

    • Office 365 Enterprise E1 - 10 Users

    • Office 365 Enterprise E3 - 25 Users

    • Office 365 Enterprise E4 - 250 users

    Correct Answer
    A. Office 365 Enterprise E3 - 25 Users
    Explanation
    The Office 365 Enterprise E3 plan allows for a maximum of 25 trial users. This plan would be the best choice as it provides the highest number of trial users compared to the other options.

    Rate this question:

  • 17. 

    You are the Office 365 adminstrator for your company. You configure new user accounts for User1 and User2. User1 has an on-premises mailbox. User2 has an Office 365 mailbox. Each user must be able to view the availability of the other user. You need to ascertain whether users can share their free/busy information.What should you use?

    • Transport Reliability IP Probe (TRIPP Tool)

    • Microsoft Remote Connectivity Analyzer Tool

    • Business Connectivity Services

    • Windows Azure Active Directory Rights Management

    Correct Answer
    A. Microsoft Remote Connectivity Analyzer Tool
    Explanation
    The Microsoft Remote Connectivity Analyzer Tool is used to test the connectivity and functionality of various Office 365 services, including Exchange Online. In this scenario, the tool can be used to check if User1 and User2 can share their free/busy information, ensuring that they can view each other's availability. By running the appropriate tests in the tool, the administrator can verify the configuration and troubleshoot any issues that may prevent the free/busy information from being shared.

    Rate this question:

  • 18. 

    Your company has an Office 365 subscription. You create a new retention policy that contains several retention tags. A user named Test5 has a client computer that runs Microsoft Office Outlook 2007. You install Microsoft Outlook 2010 on the client computer of Test5. Test5 reports that the new retention tags are unavailable from Outlook 2010. You verify that other users can use the new retention tags.You need to ensure that the new retention tags are available to Test5 from Outlook 2010. What should you do?

    • Instruct Test5 to repair the Outlook profile

    • Modify the retention policy tags

    • Run the Set-Mailbox cmdlet

    • Force directory synchronization

    Correct Answer
    A. Instruct Test5 to repair the Outlook profile
  • 19. 

    Your company uses Office 365. You need to identify which users do NOT have a Microsoft Exchange Online license assigned to their user account.Which PowerShell cmdlet should you use?

    • Get-ManagementRoleAssignment

    • Get-User

    • Get-RoleGroupMember

    • Get-LogonStatistics

    • Get-RemovedMailbox

    • Get-MSOLCOntact

    • Get-Recipient

    • Get-Mailbox

    • Get-Group

    • Get-MailboxStatistics

    • Get-MSOLUser

    • Get-MailContact

    Correct Answer
    A. Get-MSOLUser
    Explanation
    The Get-MSOLUser cmdlet is used to retrieve information about users in Azure Active Directory, including their assigned licenses. By using this cmdlet, you can identify which users do not have a Microsoft Exchange Online license assigned to their user account.

    Rate this question:

  • 20. 

    Your company subscribes to an Office 365 Plan E3. A user named User1 installs Office Professional Plus for Office 365 on a client computer. From the Microsoft Online Services portal, you assign User1 an Office Professional Plus license. One month after installing Office, User1 can no longer save and edit Office documents on the client computer. User1 can open and view Office documents. You need to ensure that User1 can save and edit documents on the client computer by using office.What should you do?

    • Install the Office Customization Tool

    • Reinstall Office Professional Plus

    • Install the Microsoft Online Services Sign-in Assistant

    • Upgrade the subscription to Plan E4

    Correct Answer
    A. Install the Microsoft Online Services Sign-in Assistant
    Explanation
    The Microsoft Online Services Sign-in Assistant is required for Office Professional Plus to authenticate and connect to the Office 365 services. By installing the Sign-in Assistant, User1 will be able to save and edit Office documents on the client computer again. Reinstalling Office Professional Plus or upgrading the subscription to Plan E4 would not address the issue, and installing the Office Customization Tool is not necessary for resolving this specific problem.

    Rate this question:

  • 21. 

    A company plans to deploy an Office 365 tenant. You have two servers named FS1 and FS2 that have the Federation Service Proxy role service installed. You must deploy Active Directory Federation Services (AD FS) on Windows Server 2012. You need to configure name resolution for FS1 and FS2.What should you do?

    • On FS1 and FS2, add the cluster DNS name and IP address of the federation server farm to the hosts file

    • On FS1 only, add the cluster DNS name and IP address of the federation server farm to the hosts file

    • On FS1 only, add the cluster NetBIOS name and IP address of the federation server farm to the LMHOSTS file

    • On FS1 and FS2, ad dthe cluster NetBIOS name and IP address of the federation server farm to the LMHOSTS file

    Correct Answer
    A. On FS1 and FS2, add the cluster DNS name and IP address of the federation server farm to the hosts file
    Explanation
    Adding the cluster DNS name and IP address of the federation server farm to the hosts file on both FS1 and FS2 ensures that name resolution is configured correctly for both servers. The hosts file is a local file on each server that maps hostnames to IP addresses, allowing the servers to resolve the DNS name of the federation server farm to the correct IP address. By adding the cluster DNS name and IP address to the hosts file on both servers, name resolution will be consistent and reliable for the deployment of Active Directory Federation Services (AD FS) on Windows Server 2012.

    Rate this question:

  • 22. 

    An organization implements single sign-on (SSO) for use with Office 365 services. You install an Active Directory Federation Services (AD FS) proxy server. Users report that they are unable to authenticate. You launch the Event Viewer and view the event information shown in the following screen shot:You need to ensure that users can authenticate to Office 365. What should you do?

    • Re-enter the credentials used to establish the trust.

    • Verify the federation server proxy is trusted by the federation service.

    • Re-install the Secure Sockets Layer certificate for the federation service.

    • Verify network connectivity between the Federation Service Proxy and federation server.

    Correct Answer
    A. Re-enter the credentials used to establish the trust.
  • 23. 

    You are the Office 365 administrator for your company. The company has two administrators named User1 and User2. Users must be able to perform the activities as shown in the following table: AdministratorActivitiesUser1
    • Reset passwords for standard user accounts
    • Reset passwords for other members of the same role.
    • Must NOT reset passwords for other administrator accounts
    User2
    • Reset passwords for all administrator accounts
    What is the correct role to assign to User1?

    • Global administrator

    • Delegate administrator

    • Billing administrator

    • Password administrator

    Correct Answer
    A. Password administrator
    Explanation
    The correct role to assign to User1 is "password administrator" because User1 needs to be able to reset passwords for standard user accounts and other members of the same role, but must not reset passwords for other administrator accounts. This role allows User1 to manage passwords for specific user accounts without having the ability to access or modify other administrative settings.

    Rate this question:

  • 24. 

    Contoso, Ltd. plans to use Office 365 for email services and Lync Online. Contoso has four unique domain names. You need to migrate domain names to Office 365.Which two domain names should you exclude from the migration?

    • Contoso.us

    • Contoso

    • Contoso.local

    • Contoso.co

    Correct Answer(s)
    A. Contoso
    A. Contoso.local
    Explanation
    The domain names "contoso" and "contoso.local" should be excluded from the migration. "contoso" is likely the internal domain name used within the local network and does not need to be migrated to Office 365. "contoso.local" is also an internal domain name commonly used for Active Directory domains and does not need to be migrated either. The domain names "contoso.us" and "contoso.co" should be included in the migration as they are likely the public domain names that need to be configured for email and Lync Online services in Office 365.

    Rate this question:

  • 25. 

    A company uses Office 365 services. You implement the Windows Azure Active Directory Sync tool in the local environment. An employee moves to a new department. All Office 365 services must display the new department information for the employee. You need to update the employee's user account.Where should you change the value of the department attribute for the employee?

    • The Active Directory management page in the Windows Azure Management Portal

    • The Users and groups page in the Office 365 admin center

    • The on-premises Active Directory

    • The Metaverse Designer

    Correct Answer
    A. The on-premises Active Directory
    Explanation
    The on-premises Active Directory is where the department attribute for the employee should be changed. The Windows Azure Active Directory Sync tool synchronizes the on-premises Active Directory with Office 365 services, so any changes made to the on-premises Active Directory will be reflected in Office 365. Therefore, updating the department attribute in the on-premises Active Directory will ensure that the new department information is displayed in all Office 365 services for the employee.

    Rate this question:

  • 26. 

    You deploy Lync Online for a company that has offices in San Francisco and New York. The two offices both connect to the internet. There is no private network link between the offices. Users in the New York office report that they cannot transfer files to the users in the San Francisco office by using Lync Online.What should you do?

    • Configure the firewall to open Transmission Control Protocol (TCP) ports 50060-50079

    • Configure the firewall to open Transmission Control Protocol (TCP) ports 50040-50059

    • Create a private network connection to share files

    • Upgrade all of the Lync Online clients to use Lync 2013

    Correct Answer
    A. Configure the firewall to open Transmission Control Protocol (TCP) ports 50040-50059
    Explanation
    To resolve the issue of users in the New York office being unable to transfer files to users in the San Francisco office using Lync Online, the correct solution is to configure the firewall to open Transmission Control Protocol (TCP) ports 50040-50059. By opening these specific ports, it allows the necessary network traffic for file transfers between the two offices to pass through the firewall. This will enable the users to successfully transfer files using Lync Online without the need for a private network connection or upgrading the Lync Online clients.

    Rate this question:

  • 27. 

    You are the Office 365 administrator for your company. Users report that they cannot sign in to Lync from their mobile devices but they are able to send and receive Lync messages by using their laptop computers. You need to troubleshoot the issue.What should you do?

    • From the Office 365 message center, confirm Lync settings

    • Use the Microsoft Connectivity Analyzer tool to confirm settings

    • Confirm Lync user licenses for the affected users

    • From the Lync admin center, verify the external access settings

    Correct Answer
    A. Use the Microsoft Connectivity Analyzer tool to confirm settings
    Explanation
    The Microsoft Connectivity Analyzer tool is a useful tool for troubleshooting connectivity issues in Office 365. By using this tool, the administrator can test the Lync settings and determine if there are any issues with the configuration that may be preventing users from signing in to Lync on their mobile devices. This tool can help identify any network or configuration issues that may be causing the problem and provide recommendations for resolving them. Therefore, using the Microsoft Connectivity Analyzer tool to confirm settings is the appropriate action to take in this scenario.

    Rate this question:

  • 28. 

    A company plans to use Office 365 to provide email services for users. You need to ensure that a custom domain name is used.What should you do first?

    • Add the custom domain name to Office 365 and then verify it

    • Verify the Existing domain name

    • Create an MX record in DNS

    • Create a CNAME record in DNS

    Correct Answer
    A. Add the custom domain name to Office 365 and then verify it
    Explanation
    To ensure that a custom domain name is used in Office 365 for email services, the first step should be to add the custom domain name to Office 365 and then verify it. This allows the company to establish ownership and control over the domain name. Once the domain is added and verified, the necessary DNS records can be created, such as MX records for email routing or CNAME records for domain aliasing. However, these DNS records can only be set up after the domain has been added and verified in Office 365.

    Rate this question:

  • 29. 

    Your company has a hybrid deployment of Office 365. All mailboxes are hosted on Office 365. All users access their Office 365 mailbox by using a user account that is hosted on-premises. You need to delete a user account and it's associated mailbox.Which tool should you use?

    • The Remove-MSOLUser cmdlet

    • The Remove-Mailbox cmdlet

    • The Office 365 portal

    • Active Directory Users and Computers

    Correct Answer
    A. Active Directory Users and Computers
    Explanation
    You should use Active Directory Users and Computers to delete the user account and its associated mailbox. This tool allows you to manage user accounts and mailboxes in an on-premises Active Directory environment. Since the user accounts are hosted on-premises and not in Office 365, using this tool would be the appropriate choice for deleting the user account and mailbox.

    Rate this question:

  • 30. 

    Your company has 100 user mailboxes. The company purchases a subscription to Office 365 for professionals and small businesses. You need to enable the Litigation Hold feature for each mailbox. What should you do first?

    • Purchase a subscription to Office 365 for midsize business and enterprises

    • Enable audit logging for all of the mailboxes

    • Modify the default retention policy

    • Create a service request

    Correct Answer
    A. Purchase a subscription to Office 365 for midsize business and enterprises
  • 31. 

    An organization prepares to implement Office 365. You have the follow responsibilities:
    1. Gather information about the requirements for the Office 365 implementation
    2. Use a supported tool that provides the most comprehensive information about the current environment
    You need to determine the organization's readiness for the Office 365 implementation. What should you do?

    • Run the Windows PowerShell cmdlet Get-MsolCompanyInformation

    • Run the OnRamp for Office 365 tool

    • Install the Windows Azure Active Directory Sync tool

    • Run the Office 365 Deployment Readiness Tool

    Correct Answer
    A. Run the OnRamp for Office 365 tool
    Explanation
    To determine the organization's readiness for the Office 365 implementation, the best option is to run the OnRamp for Office 365 tool. This tool provides comprehensive information about the current environment and helps gather all the necessary requirements for the implementation. It is specifically designed for Office 365 deployments and will provide the most accurate assessment of the organization's readiness.

    Rate this question:

  • 32. 

    A company migrates to Office 365. 2,000 active users have valid Office 365 licenses assigned. An additional 5,000 user accounts were created during the migration and testing processes.The additional users do not have any licenses assigned. You need to remove the Office 365 user accounts that do not have any licenses assigned by using the least amount of administrative effort. Which Windows PowerShell command should you run?

    • Get-MsolUser -All EnabledFilter "DisabledOnly" | Remove-MsolUser -Force

    • Get-MsolUser-EnabledFilter "DisabledOnly" | Remove MsolUser -Force

    • Get-MsolUser -All -UnlicensedUsersOnly | Remove-MsolUser -Force

    • Get-MsolUser -UnlicensedUsersOnly | Remove-MsolUser - Force

    Correct Answer
    A. Get-MsolUser -All -UnlicensedUsersOnly | Remove-MsolUser -Force
    Explanation
    The correct answer is "Get-MsolUser -All -UnlicensedUsersOnly | Remove-MsolUser -Force". This command will retrieve all user accounts in Office 365, including those without any licenses assigned, and then remove them using the "Remove-MsolUser" cmdlet. The "-Force" parameter is used to bypass any confirmation prompts and delete the user accounts without further intervention. This command ensures that only the unlicensed user accounts are removed, minimizing the administrative effort required.

    Rate this question:

  • 33. 

    A company deploys an Office 365 tenant. You prepare to use the bulk add tool to add users to Office 365. You need to prepare a file to use with the bulk add tool.Which fields must you include in the file?

    • User Name

    • Display Name

    • First Name

    • Last Name

    • Job Title

    Correct Answer(s)
    A. User Name
    A. Display Name
    Explanation
    To use the bulk add tool to add users to Office 365, you need to include the User Name and Display Name fields in the file. The User Name field is necessary to uniquely identify each user, while the Display Name field is used to show the user's name in the Office 365 interface. Including these fields ensures that the users are properly identified and displayed within the Office 365 system. The other fields mentioned (First Name, Last Name, and Job Title) may be helpful for additional user information, but they are not specifically required for the bulk add process.

    Rate this question:

  • 34. 

    Your company has an Office 365 subscription. You need to add the label "external" to the subject line of each email message received by your organization from an external sender.What should you do?

    • From the Exchange Control Panel, add a MailTip

    • From the Forefront Online Protection Administration Center, set the footer for outbound email

    • Run the Enable-InboxRule cmdlet

    • From the Exchange Control Panel, run the New Rule wizard

    Correct Answer
    A. From the Exchange Control Panel, run the New Rule wizard
    Explanation
    To add the label "external" to the subject line of each email message received from an external sender, you need to create a new rule in the Exchange Control Panel. The New Rule wizard allows you to set conditions and actions for incoming emails, including adding a label to the subject line. This can be done by selecting the option to add a condition for messages received from external senders and then selecting the action to add the label "external" to the subject line.

    Rate this question:

  • 35. 

    You need to enforce password complexity requirements for all accounts.What is the correct Windows PowerShell command?

    • Get-MsolUser | Set-MsolUser -StrongPasswordRequired $true

    • Get-MsolUserPassword | Set-MsolUserPassword -StrongPasswordRequired $true

    • Get-MsolUserRole | Set-MsolUserPassword -StrongPasswordRequired $true

    • Get-MsolUserRole | Set-MsolUser -StrongPasswordRequired $true

    Correct Answer
    A. Get-MsolUser | Set-MsolUser -StrongPasswordRequired $true
    Explanation
    The correct Windows PowerShell command to enforce password complexity requirements for all accounts is "Get-MsolUser | Set-MsolUser -StrongPasswordRequired $true". This command retrieves all users using the Get-MsolUser cmdlet and then sets the StrongPasswordRequired property to true for each user using the Set-MsolUser cmdlet. This ensures that all users are required to have a strong password.

    Rate this question:

  • 36. 

    You are the Office 365 administrator for your company. Users report that their passwords expire too frequently, and they do not receive adequate notice of password expiration. Account passwords must remain active for the longest duration allowed. Users must receive password expiration notifications as early as possible. You need to configure the password expiration policy.What is the maximum amount of days you can set before a password change is forced?

    • 1

    • 13

    • 30

    • 72

    • 365

    • 730

    • 1095

    • 1460

    Correct Answer
    A. 730
    Explanation
    The maximum amount of days that can be set before a password change is forced is 730. This means that users will have up to 2 years before they are required to change their passwords. This setting allows for longer periods of password validity, addressing the issue of passwords expiring too frequently. Additionally, users will receive password expiration notifications as early as possible, giving them ample time to change their passwords before they expire.

    Rate this question:

  • 37. 

    Your company has an Office 365 subscription. The network contains an Active Directory domain. You configure single sign-on for all users. You need to verify that single sign-on functions for the users who access Office 365 from the internet.What should you run?

    • The get-MSOLFederationProperty cmdlet

    • The Test-OrganizationRelationship cmdlet

    • The Microsoft Remote Connectivity Analyzer

    • The Microsoft Exchange Server Deployment Assistant

    Correct Answer
    A. The Microsoft Remote Connectivity Analyzer
    Explanation
    The Microsoft Remote Connectivity Analyzer is the correct answer because it is a tool that allows you to test and verify the functionality of various Office 365 services, including single sign-on. By running the analyzer, you can ensure that users are able to successfully authenticate and access Office 365 resources from the internet.

    Rate this question:

  • 38. 

    You are the Office 365 administrator for your company. A user named User1 from a partner organization is permitted to sign in and use the Office 365 services. User1 reports that the password expires in ten days. You must set the password to never expire.Changes must NOT impact any other accounts. You need to update the password policy for the user. Which Windows PowerShell cmdlet should you run?

    • Set-MsolPasswordPolicy

    • Set-MsolPartnerInformation

    • Set-MsolUser

    • Set-MsolUserPassword

    Correct Answer
    A. Set-MsolUser
    Explanation
    To update the password policy for a specific user in Office 365 without impacting any other accounts, the correct PowerShell cmdlet to run is "Set-MsolUser". This cmdlet allows the Office 365 administrator to modify user properties, including the password policy. By using this cmdlet, the administrator can set the password for User1 to never expire, as required in the scenario.

    Rate this question:

  • 39. 

    A company has a Windows Server 2008 domain controller and a SharePoint 2007 farm. All servers on the network run Windows Server 2008. You must provide single sign-on for Office 365 SharePoint sites from the company's network. You need to install the required software.What are the first three things you should install?NOTE: You will need to know the appropriate order for these installations on the exam.

    • Install .NET Framework 3.5 with Service Pack 1

    • Install AD FS 2.0

    • Install Rollup 3 for AD FS 2.0

    • Install SharePoint Server 2013

    • Install SharePoint Server 2010 with Service Pack 1

    Correct Answer(s)
    A. Install .NET Framework 3.5 with Service Pack 1
    A. Install AD FS 2.0
    A. Install Rollup 3 for AD FS 2.0
    Explanation
    The first three things that should be installed are .NET Framework 3.5 with Service Pack 1, AD FS 2.0, and Rollup 3 for AD FS 2.0. Installing .NET Framework 3.5 with Service Pack 1 is necessary as it is a prerequisite for AD FS 2.0. AD FS 2.0 is required for single sign-on functionality. Rollup 3 for AD FS 2.0 is important to ensure that any necessary updates and fixes are applied to AD FS 2.0.

    Rate this question:

  • 40. 

    You are the Office 365 administrator for your company. You have a server that runs Windows Server 2012. You plan to install an Active Directory Federation Services (AD FS) proxy server. You need to install and configure all of the required roles.Which two roles should you install and configure?

    • Web Server (IIS)

    • AD FS

    • Application Server

    • Network Policy and Access Service

    • Active Directory Certificate Services (AD CS)

    • Remote Access

    Correct Answer(s)
    A. Web Server (IIS)
    A. AD FS
    Explanation
    You should install and configure the Web Server (IIS) role and the AD FS role. The Web Server (IIS) role is required to host the AD FS proxy server. The AD FS role is necessary to set up and configure the AD FS service, which allows for single sign-on authentication and authorization across different applications and systems. The other roles listed are not directly related to the installation and configuration of an AD FS proxy server.

    Rate this question:

  • 41. 

    You are the Office 365 administrator for your company. Users report that their passwords expire too frequently, and they do not receive adequate notice of password expiration. Account passwords must remain active for the longest duration allowed. Users must receive password expiration notifications as early as possible. You need to configure the password expiration policy.What is the earliest amount of time you can set or users to be notified of an upcoming password change?

    • 1

    • 13

    • 30

    • 72

    • 365

    • 730

    • 1095

    • 1460

    Correct Answer
    A. 30
    Explanation
    The earliest amount of time that can be set for users to be notified of an upcoming password change is 30 days. This means that users will receive a notification 30 days before their password is set to expire, giving them ample time to change their password before it becomes inactive. This setting allows for a longer duration for active passwords and ensures that users are adequately notified of the upcoming change.

    Rate this question:

  • 42. 

    You are the Office 365 administrator for your company. You must configure a trust between the on-premises Active Directory domain and the Office 365 envionment by using Active Directory Federation Services. You need to assign the correct certificate to the description of your on-premises server environment below.Which certificate secures the communication between federation servers, clients, and federation server proxy computers?

    • Client

    • Domain

    • X.509

    • SSL

    Correct Answer
    A. SSL
    Explanation
    The SSL certificate is used to secure the communication between federation servers, clients, and federation server proxy computers. SSL (Secure Sockets Layer) is a protocol that provides secure communication over a computer network. It encrypts the data transmitted between the client and the server, ensuring that it cannot be intercepted or tampered with by unauthorized parties. In the context of Active Directory Federation Services, the SSL certificate is necessary to establish a secure trust between the on-premises Active Directory domain and the Office 365 environment.

    Rate this question:

  • 43. 

    An organization purchases an Office 365 plan for 10,000 user accounts. You have a domain controller that runs Windows Server 2008 R2. The forest functional level is set to Windows Server 2000. The organization must be able to synchronize user attributes from the on-premises Active Directory Domain Services environment to Office 365.You need to prepare to install the Windows Azure Active Directory Sync tool. Which two actions should you preform?

    • Upgrade the domain controller to Windows Server 2012

    • Install Microsoft .NET Framework 3.5 SP1 and Microsoft .NET Framework 4.0

    • Install Windows Server 2012 Standard Edition

    • Raise the forest functional level to Windows Server 2008 R2

    • Join a workstation to an Active Directory domain

    Correct Answer(s)
    A. Install Microsoft .NET Framework 3.5 SP1 and Microsoft .NET Framework 4.0
    A. Raise the forest functional level to Windows Server 2008 R2
    Explanation
    To prepare to install the Windows Azure Active Directory Sync tool, you need to perform two actions. First, you should install Microsoft .NET Framework 3.5 SP1 and Microsoft .NET Framework 4.0 on the domain controller. This is necessary because the Azure Active Directory Sync tool requires these frameworks to run properly. Second, you should raise the forest functional level to Windows Server 2008 R2. This is required because the Azure Active Directory Sync tool is not compatible with lower forest functional levels. By performing these two actions, you will ensure that the domain controller is ready for the installation of the Azure Active Directory Sync tool and that user attributes can be synchronized from the on-premises Active Directory Domain Services environment to Office 365.

    Rate this question:

  • 44. 

    You are the administrator for a company named Contoso, Ltd. The company has an Office 365 subscription. Your need to prevent users from changing their user display name by using Outlook Web App. What should you do?

    • Run the Set-MsolCompanyContactInformation cmdlet

    • Modify the default email address policy

    • Run the Set-MsolUserPrincipalName cmdlet

    • Modify the default role assignment policy

    Correct Answer
    A. Modify the default role assignment policy
    Explanation
    To prevent users from changing their user display name using Outlook Web App, you should modify the default role assignment policy. By modifying the default role assignment policy, you can restrict the permissions for users to modify their display name. This will ensure that users do not have the ability to change their display name using Outlook Web App.

    Rate this question:

  • 45. 

    You are the Office 365 administrator for your company. Users report that they have received significantly more spam messages over the past month than they normally receive.You need to analyze trends for the email messages received over the past 60 days. From the Office 365 admin center, what should you view?

    • The mail protection reports

    • The mailbox content search and hold report

    • Messages on the message center page

    • The Office 365 Malware detections in sent mail report

    Correct Answer
    A. The mail protection reports
    Explanation
    To analyze trends for the email messages received over the past 60 days and determine the reason for the increase in spam messages, the Office 365 administrator should view the mail protection reports. These reports provide insights into the effectiveness of the mail protection features, including information on spam messages, malware detections, and other security-related metrics. By analyzing these reports, the administrator can identify patterns, trends, and potential issues that may be causing the increase in spam messages.

    Rate this question:

  • 46. 

    You use a centralized identity management system as a source of authority for user account information. You export a list of new user accounts to a file on a daily basis. Your company uses a local Active Directory for storing user accounts for on-premises solutions. You are configuring the Windows Azure Active Directory Sync tool.New user accounts must be created in both the local Active Directory and Office 365. You must import user account data into Office 365 daily. You need to import the new users. What should you do?

    • Use the Office 365 admin center to import the file

    • Create a Windows PowerShell script to import account data from the file into Active Directory

    • Use the Windows Azure Management Portal to import the file

    • Create a Windows PowerShell script that uses the MSOnline module to import account data from the file

    Correct Answer
    A. Create a Windows PowerShell script to import account data from the file into Active Directory
    Explanation
    To import the new user accounts into both the local Active Directory and Office 365, a Windows PowerShell script should be created to import account data from the file into Active Directory. This script will allow for the automation of the import process, ensuring that the new user accounts are created in both systems on a daily basis. Using the Office 365 admin center or the Windows Azure Management Portal would not provide the necessary functionality to import the data into Active Directory. Additionally, using the MSOnline module in the Windows PowerShell script will allow for the import of account data into Office 365 as well.

    Rate this question:

  • 47. 

    You are the SharePoint Online administrator for Contoso, Ltd. The company purchases an Office 365 Enterprise E1 plan. The public-facing website must use SharePoint Online and the custom domain contoso.comYou need to configure the DNS settings for the public-facing SharePoint site. How should you configure the DNS settings?

    • Record: A - Hostname: contoso-public.office.com - Points To Address: contoso-public.sharepoint.com

    • Record: CNAME - Hostname: www.contoso.com - Points To Address: contoso-public.sharepoint.com

    • Record: CNAME - Hostname: www.contoso.com - Points To Address: contoso-public.onmicrosoft.com

    • Record: A - Hostname: www.contoso.com - Points To Address: contoso-public.sharepoint.com

    Correct Answer
    A. Record: CNAME - Hostname: www.contoso.com - Points To Address: contoso-public.sharepoint.com
    Explanation
    The correct answer is to configure a CNAME record with the hostname "www.contoso.com" and point it to "contoso-public.sharepoint.com". This is because a CNAME record is used to create an alias for a domain name, allowing multiple domain names to point to the same location. In this case, the custom domain "www.contoso.com" needs to point to the public-facing SharePoint site, which is hosted at "contoso-public.sharepoint.com".

    Rate this question:

  • 48. 

    A company deploys an Office 365 tenant. You need to enable multi-factor authentication for Office 365. Which three actions should you perform?NOTE: On the exam, you will need need to know the correct order of these actions.

    • Enable multi-factor authentication for all user accounts

    • Instruct users to obtain a single-use password to complete the registration process

    • Instruct users to use a mobile phone to complete the registration process

    • Create a multi-factor authentication provider with the Per Enabled User usage model

    • Creat a multi-factor authentication provider with the Per Authentication usage model

    Correct Answer(s)
    A. Enable multi-factor authentication for all user accounts
    A. Instruct users to obtain a single-use password to complete the registration process
    A. Instruct users to use a mobile phone to complete the registration process
    Explanation
    To enable multi-factor authentication for Office 365, the first action is to enable it for all user accounts. This ensures that all users will be required to go through the multi-factor authentication process. The second action is to instruct users to obtain a single-use password to complete the registration process. This ensures that users have a unique password that they can use during the registration process. The third action is to instruct users to use a mobile phone to complete the registration process. This ensures that users have a mobile device that they can use for the multi-factor authentication process.

    Rate this question:

  • 49. 

    A company plans to use Office 365 to provide email services to employees. The company obtains a custom domain name to use with Office 365. You need to add the domain name to Office 365.Which three actions should you preform?NOTE: On the exam, you will also need to know the correct sequence of the three actions.

    • Connect to Windows Azure Active Directory

    • Run Remote PowerShell

    • Run the Windows PowerShell cmdlet New-MsolDomain

    • Run the Windows PowerShell cmdlet New-MsolFederatedDomain

    • Install the Windows Azure Active Directory module for Windows PowerShell

    Correct Answer(s)
    A. Connect to Windows Azure Active Directory
    A. Run the Windows PowerShell cmdlet New-MsolDomain
    A. Install the Windows Azure Active Directory module for Windows PowerShell
    Explanation
    To add a custom domain name to Office 365, the first step is to connect to Windows Azure Active Directory. This allows you to manage the domain settings. Then, you need to run the Windows PowerShell cmdlet New-MsolDomain. This cmdlet is used to add the custom domain to Office 365. Finally, you should install the Windows Azure Active Directory module for Windows PowerShell. This module provides the necessary tools and commands to manage the Azure Active Directory.

    Rate this question:

Quiz Review Timeline (Updated): Mar 20, 2023 +

Our quizzes are rigorously reviewed, monitored and continuously updated by our expert board to maintain accuracy, relevance, and timeliness.

  • Current Version
  • Mar 20, 2023
    Quiz Edited by
    ProProfs Editorial Team
  • Nov 11, 2014
    Quiz Created by
    Bearxor

Related Topics

Back to Top Back to top
Advertisement
×

Wait!
Here's an interesting quiz for you.

We have other quizzes matching your interest.