Microsoft Certification 70-346 - O365 Identities/Requirements

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Bearxor
B
Bearxor
Community Contributor
Quizzes Created: 1 | Total Attempts: 376
| Attempts: 376 | Questions: 96
Please wait...
Question 1 / 96
0 %
0/100
Score 0/100
1. You are the Office 365 administrator for your company. The company uses Active Directory Federation Services (AD FS) to provide single sign-on to cloud-based services. You enable multi-factor authentication. Users must NOT be required to use multi-factor authentication when they sign in from the company's main office location. However, users must be required to verify their identity with a password and token when they access resources from remote locations.You need to configure the environment. What should you do?

Explanation

To meet the requirement of not requiring multi-factor authentication for users signing in from the main office location, the administrator should configure an IP whitelist for the main office location. By doing this, the system will allow access without multi-factor authentication only from the specified IP addresses associated with the main office location. This ensures that users accessing resources from remote locations will still be required to verify their identity with a password and token, while users within the main office location will not be prompted for multi-factor authentication.

Submit
Please wait...
About This Quiz
Microsoft Certification 70-346 - O365 Identities/Requirements - Quiz

This quiz assesses knowledge on managing Office 365 identities and requirements, focusing on hybrid configurations, single sign-on setups, and Active Directory Federation Services. It is designed for individuals... see morepreparing for the Microsoft Certification 70-346. see less

2. You are the Office 365 administrator for your company. You prepare to install Active Directory Federation Services (AD FS). You need to open the correct port between the AD FS proxy server and the AD FS federation server.Which port should you open?

Explanation

The correct port to open between the AD FS proxy server and the AD FS federation server is TCP 443. This is because TCP port 443 is the default port for HTTPS communication, which is used for secure communication between web browsers and web servers. AD FS requires secure communication for authentication and authorization processes, and TCP 443 ensures that the communication is encrypted and secure.

Submit
3. An organization deploys an Office 365 tenant. User accounts must be synchronized to Office 365 by using the Windows Azure Active Directory Sync Tool. You have the following password policies:
  • Passwords for the on-premises Active Directory DOmain Services (AD DS) user accounts are at least six characters long
  • Passwords for Office 365 user accounts are at least eight characters long.
You need to ensure that the user accounts will be synchronized. Which user accounts will be synchronized?

Explanation

All user accounts will be synchronized. The Windows Azure Active Directory Sync Tool will synchronize all user accounts, regardless of their password length. The password policies for on-premises Active Directory Domain Services (AD DS) and Office 365 user accounts are not relevant to the synchronization process.

Submit
4. You are the Office 365 administrator for your company. The environment must support single sign-on. You need to install the required certificates.Which two certificates should you install? Each correct answer presents part of the solution.

Explanation

To support single sign-on in Office 365, two certificates need to be installed: Secure Sockets Layer (SSL) and Token signing. The SSL certificate is necessary for encrypting the communication between the user's browser and the Office 365 services, ensuring a secure connection. The Token signing certificate is used to sign the security tokens issued by the identity provider, allowing Office 365 to trust the authentication information provided by the identity provider. By installing both certificates, the environment will be able to establish a secure and trusted single sign-on experience for users.

Submit
5. You are the Office 365 administrator for your company. The company has a single office. You have the following requirements:
  • You must configure a redundant Active Directory Federation Services (AD FS) implementation
  • You must use a Windows Internal Database to store AD FS configuration data
  • The solution must use a custom login page for external users
  • The solution must use a single sign-on for internal users
You need to deploy the minimum number of servers. How many servers should you deploy.

Explanation

To meet the requirements of a redundant AD FS implementation, a minimum of two AD FS servers is required. Each server would have a Windows Internal Database to store AD FS configuration data. Additionally, to achieve a custom login page for external users and single sign-on for internal users, a minimum of two Web Application Proxy (WAP) servers is needed. Therefore, a total of four servers should be deployed.

Submit
6. You manage a team of three administrators for an organization that uses Office 365. You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks. 
UserRequirements
Admin1Reset user passwords for administrators
Admin2Perform purchasing purchasing operations
Admin3Create and manage user views
What administrative role should you assign to Admin1?

Explanation

Admin1 should be assigned the role of a global administrator. A global administrator has the highest level of permissions in Office 365 and can perform all administrative tasks, including resetting user passwords for administrators. This role provides the necessary permissions to fulfill the requirement of resetting user passwords for administrators.

Submit
7. You manage a team of three administrators for an organization that uses Office 365. You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks.
 
UserRequirements
Admin1Reset user passwords for administrators
Admin2Perform purchasing purchasing operations
Admin3Create and manage user views






What administrative role should you assign to Admin2?

Explanation

Admin2 should be assigned the role of a "billing administrator" because they need to perform purchasing operations. The billing administrator role allows them to manage billing, subscriptions, and purchases for the organization. This role does not have excessive permissions beyond what is required for their specific task.

Submit
8. You are the Office 365 administrator for your company. The company has two administrators named User1 and User2. Users must be able to perform the activities as shown in the following table:
 
AdministratorActivities
User1
  • Reset passwords for standard user accounts
  • Reset passwords for other members of the same role.
  • Must NOT reset passwords for other administrator accounts
User2
  • Reset passwords for all administrator accounts











What is the correct role to assign to User2?

Explanation

The correct role to assign to User2 is "global administrator" because User2 needs to be able to reset passwords for all administrator accounts, which includes User1. The other options (delegate administrator, billing administrator, password administrator) do not have the necessary permissions to reset passwords for all administrator accounts.

Submit
9. A company named Fabrikam, Inc. is deploying an Office 365 tenant. You install Active Directory Federation Services (AD FS) on a server that runs Windows Server 2012. The company's environment is described in the following table: 
DescriptionFully Qualified Domain Name
Cluster DNS Namefs.fabrikam.com
Server node in clusterserver1.fabrikam.com
Server node in clusterserver2.fabrikam.com
You must obtain a certificate from a certification authority and install it on the federation servers. You need to specify the subject name for the certificate. Which name should you specify? 

Explanation

The subject name for the certificate should be fs.fabrikam.com. This is because fs.fabrikam.com is the fully qualified domain name (FQDN) that represents the federation servers in the Fabrikam, Inc. environment. The certificate needs to match the FQDN of the server where AD FS is installed in order to establish secure communication between the federation servers and other components of the Office 365 tenant.

Submit
10. You administer the Office 365 environment for a company that has offices around the world. All of the offices use the same Office 365 tenant. You need to ensure that all users can access the services that are available in their regions.Which setting or service should you update?

Explanation

To ensure that all users can access the services available in their regions, you should update the user location settings. By configuring the user location settings, you can specify the region or country for each user in the Office 365 environment. This allows the services to be localized and tailored to the specific needs and regulations of each region, ensuring that users have access to the appropriate services based on their location.

Submit
11. You manage a team of three administrators for an organization that uses Office 365. You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks.
 
UserRequirements
Admin1Reset user passwords for administrators
Admin2Perform purchasing purchasing operations
Admin3Create and manage user views






What administrative role should you assign to Admin3?

Explanation

Admin3 should be assigned the role of "user management administrator". This role will provide the necessary permissions to create and manage user views, which is the assigned task for Admin3. The other roles, such as billing administrator and global administrator, do not align with the specific tasks mentioned in the requirements.

Submit
12. An organization plans to deploy Exchange Online. You must support all Exchange Online features. You need to create the required DNS entries.Which two DNS entries should you create?

Explanation

To support all Exchange Online features, you need to create two DNS entries: MX and CNAME. The MX (Mail Exchanger) record is used to specify the mail server responsible for accepting email messages on behalf of the domain. This record ensures that incoming emails are delivered to the correct server. The CNAME (Canonical Name) record is used to create an alias for a domain name. In this case, it is used to create an alias for the Autodiscover service, which is required for various Exchange Online features such as automatic configuration of email clients.

Submit
13. You are the Office 365 adminstrator for your company. You configure new user accounts for User1 and User2. User1 has an on-premises mailbox. User2 has an Office 365 mailbox. Each user must be able to view the availability of the other user. You need to ascertain whether users can share their free/busy information.What should you use?

Explanation

The Microsoft Remote Connectivity Analyzer Tool is used to test the connectivity and functionality of various Office 365 services, including Exchange Online. In this scenario, the tool can be used to check if User1 and User2 can share their free/busy information, ensuring that they can view each other's availability. By running the appropriate tests in the tool, the administrator can verify the configuration and troubleshoot any issues that may prevent the free/busy information from being shared.

Submit
14. An organization deploys an Office 365 tenant. The Service Health page displays the following information:What is the current status of Exchange Online and SharePoint Online?

Explanation

The current status of Exchange Online is available but the service is degraded. This means that while Exchange Online is still accessible, there may be some performance issues or limitations in its functionality. On the other hand, SharePoint Online is available without any reported issues.

Submit
15. Your company purchases an Office 365 plan. The company has an Active Directory Domain Services domain. User1 must manage Office 365 delegation for the company. You need to ensure that User1 can assign administrative roles to other users.What should you do?

Explanation

To ensure that User1 can assign administrative roles to other users, User1 needs to have the highest level of administrative privileges, which is the global administrator role. By creating an Office 365 tenant and assigning User1 the global administrator role, User1 will have the necessary permissions to manage Office 365 delegation for the company.

Submit
16. Contoso Ltd. uses Office 365 for collaboration. You are implementing Active Directory Federation Services (AD FS) for single sign-on (SSO) with Office 365 services. The environment contains an Active Directory domain and an AD FS federation server. You need to ensure that the environment is prepared for the AD FS setup.Which two actions should you preform? Each correct answer presents part of the solution.

Explanation

To prepare the environment for AD FS setup, the first action is to configure Active Directory to use the domain "contoso.com". This ensures that the AD FS server is integrated with the correct Active Directory domain.

The second action is to create a server authentication certificate for the federation server. This certificate should have "fs.contoso.com" as the subject name and subject alternative name. This certificate is necessary for secure communication between the AD FS server and Office 365 services, enabling SSO functionality.

Submit
17. Fabrikam, Inc employs 500 users and plans to migrate to Office 365. You must sign up for a trial plan from the Office 365 website. You have the following requirements:
  • Create the maximum number of trial users allowed
  • Convert the trial plan to a paid plan at the end of the trial that supports all of Fabrikam's users
You need to create an Office 365 trial plan. Which plan gives you the maximum amount of trail users?

Explanation

The Office 365 Enterprise E3 plan allows for a maximum of 25 trial users. This plan would be the best choice as it provides the highest number of trial users compared to the other options.

Submit
18. Your company has an Office 365 subscription. You create a new retention policy that contains several retention tags. A user named Test5 has a client computer that runs Microsoft Office Outlook 2007. You install Microsoft Outlook 2010 on the client computer of Test5. Test5 reports that the new retention tags are unavailable from Outlook 2010. You verify that other users can use the new retention tags.You need to ensure that the new retention tags are available to Test5 from Outlook 2010. What should you do?

Explanation

not-available-via-ai

Submit
19. Your company subscribes to an Office 365 Plan E3. A user named User1 installs Office Professional Plus for Office 365 on a client computer. From the Microsoft Online Services portal, you assign User1 an Office Professional Plus license. One month after installing Office, User1 can no longer save and edit Office documents on the client computer. User1 can open and view Office documents. You need to ensure that User1 can save and edit documents on the client computer by using office.What should you do?

Explanation

The Microsoft Online Services Sign-in Assistant is required for Office Professional Plus to authenticate and connect to the Office 365 services. By installing the Sign-in Assistant, User1 will be able to save and edit Office documents on the client computer again. Reinstalling Office Professional Plus or upgrading the subscription to Plan E4 would not address the issue, and installing the Office Customization Tool is not necessary for resolving this specific problem.

Submit
20. Your company uses Office 365. You need to identify which users do NOT have a Microsoft Exchange Online license assigned to their user account.Which PowerShell cmdlet should you use?

Explanation

The Get-MSOLUser cmdlet is used to retrieve information about users in Azure Active Directory, including their assigned licenses. By using this cmdlet, you can identify which users do not have a Microsoft Exchange Online license assigned to their user account.

Submit
21. A company plans to deploy an Office 365 tenant. You have two servers named FS1 and FS2 that have the Federation Service Proxy role service installed. You must deploy Active Directory Federation Services (AD FS) on Windows Server 2012. You need to configure name resolution for FS1 and FS2.What should you do?

Explanation

Adding the cluster DNS name and IP address of the federation server farm to the hosts file on both FS1 and FS2 ensures that name resolution is configured correctly for both servers. The hosts file is a local file on each server that maps hostnames to IP addresses, allowing the servers to resolve the DNS name of the federation server farm to the correct IP address. By adding the cluster DNS name and IP address to the hosts file on both servers, name resolution will be consistent and reliable for the deployment of Active Directory Federation Services (AD FS) on Windows Server 2012.

Submit
22. You are the Office 365 administrator for your company. The company has two administrators named User1 and User2. Users must be able to perform the activities as shown in the following table: 
AdministratorActivities
User1
  • Reset passwords for standard user accounts
  • Reset passwords for other members of the same role.
  • Must NOT reset passwords for other administrator accounts
User2
  • Reset passwords for all administrator accounts
What is the correct role to assign to User1?

Explanation

The correct role to assign to User1 is "password administrator" because User1 needs to be able to reset passwords for standard user accounts and other members of the same role, but must not reset passwords for other administrator accounts. This role allows User1 to manage passwords for specific user accounts without having the ability to access or modify other administrative settings.

Submit
23. A company uses Office 365 services. You implement the Windows Azure Active Directory Sync tool in the local environment. An employee moves to a new department. All Office 365 services must display the new department information for the employee. You need to update the employee's user account.Where should you change the value of the department attribute for the employee?

Explanation

The on-premises Active Directory is where the department attribute for the employee should be changed. The Windows Azure Active Directory Sync tool synchronizes the on-premises Active Directory with Office 365 services, so any changes made to the on-premises Active Directory will be reflected in Office 365. Therefore, updating the department attribute in the on-premises Active Directory will ensure that the new department information is displayed in all Office 365 services for the employee.

Submit
24. Contoso, Ltd. plans to use Office 365 for email services and Lync Online. Contoso has four unique domain names. You need to migrate domain names to Office 365.Which two domain names should you exclude from the migration?

Explanation

The domain names "contoso" and "contoso.local" should be excluded from the migration. "contoso" is likely the internal domain name used within the local network and does not need to be migrated to Office 365. "contoso.local" is also an internal domain name commonly used for Active Directory domains and does not need to be migrated either. The domain names "contoso.us" and "contoso.co" should be included in the migration as they are likely the public domain names that need to be configured for email and Lync Online services in Office 365.

Submit
25. An organization implements single sign-on (SSO) for use with Office 365 services. You install an Active Directory Federation Services (AD FS) proxy server. Users report that they are unable to authenticate. You launch the Event Viewer and view the event information shown in the following screen shot:You need to ensure that users can authenticate to Office 365. What should you do?

Explanation

not-available-via-ai

Submit
26. A company plans to use Office 365 to provide email services for users. You need to ensure that a custom domain name is used.What should you do first?

Explanation

To ensure that a custom domain name is used in Office 365 for email services, the first step should be to add the custom domain name to Office 365 and then verify it. This allows the company to establish ownership and control over the domain name. Once the domain is added and verified, the necessary DNS records can be created, such as MX records for email routing or CNAME records for domain aliasing. However, these DNS records can only be set up after the domain has been added and verified in Office 365.

Submit
27. You deploy Lync Online for a company that has offices in San Francisco and New York. The two offices both connect to the internet. There is no private network link between the offices. Users in the New York office report that they cannot transfer files to the users in the San Francisco office by using Lync Online.What should you do?

Explanation

To resolve the issue of users in the New York office being unable to transfer files to users in the San Francisco office using Lync Online, the correct solution is to configure the firewall to open Transmission Control Protocol (TCP) ports 50040-50059. By opening these specific ports, it allows the necessary network traffic for file transfers between the two offices to pass through the firewall. This will enable the users to successfully transfer files using Lync Online without the need for a private network connection or upgrading the Lync Online clients.

Submit
28. You are the Office 365 administrator for your company. Users report that they cannot sign in to Lync from their mobile devices but they are able to send and receive Lync messages by using their laptop computers. You need to troubleshoot the issue.What should you do?

Explanation

The Microsoft Connectivity Analyzer tool is a useful tool for troubleshooting connectivity issues in Office 365. By using this tool, the administrator can test the Lync settings and determine if there are any issues with the configuration that may be preventing users from signing in to Lync on their mobile devices. This tool can help identify any network or configuration issues that may be causing the problem and provide recommendations for resolving them. Therefore, using the Microsoft Connectivity Analyzer tool to confirm settings is the appropriate action to take in this scenario.

Submit
29. Your company has 100 user mailboxes. The company purchases a subscription to Office 365 for professionals and small businesses. You need to enable the Litigation Hold feature for each mailbox. What should you do first?

Explanation

not-available-via-ai

Submit
30. Your company has a hybrid deployment of Office 365. All mailboxes are hosted on Office 365. All users access their Office 365 mailbox by using a user account that is hosted on-premises. You need to delete a user account and it's associated mailbox.Which tool should you use?

Explanation

You should use Active Directory Users and Computers to delete the user account and its associated mailbox. This tool allows you to manage user accounts and mailboxes in an on-premises Active Directory environment. Since the user accounts are hosted on-premises and not in Office 365, using this tool would be the appropriate choice for deleting the user account and mailbox.

Submit
31. A company migrates to Office 365. 2,000 active users have valid Office 365 licenses assigned. An additional 5,000 user accounts were created during the migration and testing processes.The additional users do not have any licenses assigned. You need to remove the Office 365 user accounts that do not have any licenses assigned by using the least amount of administrative effort. Which Windows PowerShell command should you run?

Explanation

The correct answer is "Get-MsolUser -All -UnlicensedUsersOnly | Remove-MsolUser -Force". This command will retrieve all user accounts in Office 365, including those without any licenses assigned, and then remove them using the "Remove-MsolUser" cmdlet. The "-Force" parameter is used to bypass any confirmation prompts and delete the user accounts without further intervention. This command ensures that only the unlicensed user accounts are removed, minimizing the administrative effort required.

Submit
32. An organization prepares to implement Office 365. You have the follow responsibilities:
  1. Gather information about the requirements for the Office 365 implementation
  2. Use a supported tool that provides the most comprehensive information about the current environment
You need to determine the organization's readiness for the Office 365 implementation. What should you do?

Explanation

To determine the organization's readiness for the Office 365 implementation, the best option is to run the OnRamp for Office 365 tool. This tool provides comprehensive information about the current environment and helps gather all the necessary requirements for the implementation. It is specifically designed for Office 365 deployments and will provide the most accurate assessment of the organization's readiness.

Submit
33. A company deploys an Office 365 tenant. You prepare to use the bulk add tool to add users to Office 365. You need to prepare a file to use with the bulk add tool.

Which fields must you include in the file?

Explanation

To use the bulk add tool to add users to Office 365, you need to include the User Name and Display Name fields in the file. The User Name field is necessary to uniquely identify each user, while the Display Name field is used to show the user's name in the Office 365 interface. Including these fields ensures that the users are properly identified and displayed within the Office 365 system. The other fields mentioned (First Name, Last Name, and Job Title) may be helpful for additional user information, but they are not specifically required for the bulk add process.

Submit
34. Your company has an Office 365 subscription. You need to add the label "external" to the subject line of each email message received by your organization from an external sender.What should you do?

Explanation

To add the label "external" to the subject line of each email message received from an external sender, you need to create a new rule in the Exchange Control Panel. The New Rule wizard allows you to set conditions and actions for incoming emails, including adding a label to the subject line. This can be done by selecting the option to add a condition for messages received from external senders and then selecting the action to add the label "external" to the subject line.

Submit
35. You need to enforce password complexity requirements for all accounts.What is the correct Windows PowerShell command?

Explanation

The correct Windows PowerShell command to enforce password complexity requirements for all accounts is "Get-MsolUser | Set-MsolUser -StrongPasswordRequired $true". This command retrieves all users using the Get-MsolUser cmdlet and then sets the StrongPasswordRequired property to true for each user using the Set-MsolUser cmdlet. This ensures that all users are required to have a strong password.

Submit
36. You are the Office 365 administrator for your company. Users report that their passwords expire too frequently, and they do not receive adequate notice of password expiration. Account passwords must remain active for the longest duration allowed. Users must receive password expiration notifications as early as possible. You need to configure the password expiration policy.

What is the maximum amount of days you can set before a password change is forced?

Explanation

The maximum amount of days that can be set before a password change is forced is 730. This means that users will have up to 2 years before they are required to change their passwords. This setting allows for longer periods of password validity, addressing the issue of passwords expiring too frequently. Additionally, users will receive password expiration notifications as early as possible, giving them ample time to change their passwords before they expire.

Submit
37. Your company has an Office 365 subscription. The network contains an Active Directory domain. You configure single sign-on for all users. You need to verify that single sign-on functions for the users who access Office 365 from the internet.What should you run?

Explanation

The Microsoft Remote Connectivity Analyzer is the correct answer because it is a tool that allows you to test and verify the functionality of various Office 365 services, including single sign-on. By running the analyzer, you can ensure that users are able to successfully authenticate and access Office 365 resources from the internet.

Submit
38. You are the Office 365 administrator for your company. A user named User1 from a partner organization is permitted to sign in and use the Office 365 services. User1 reports that the password expires in ten days. You must set the password to never expire.Changes must NOT impact any other accounts. You need to update the password policy for the user. Which Windows PowerShell cmdlet should you run?

Explanation

To update the password policy for a specific user in Office 365 without impacting any other accounts, the correct PowerShell cmdlet to run is "Set-MsolUser". This cmdlet allows the Office 365 administrator to modify user properties, including the password policy. By using this cmdlet, the administrator can set the password for User1 to never expire, as required in the scenario.

Submit
39. A company has a Windows Server 2008 domain controller and a SharePoint 2007 farm. All servers on the network run Windows Server 2008. You must provide single sign-on for Office 365 SharePoint sites from the company's network. You need to install the required software.What are the first three things you should install?NOTE: You will need to know the appropriate order for these installations on the exam.

Explanation

The first three things that should be installed are .NET Framework 3.5 with Service Pack 1, AD FS 2.0, and Rollup 3 for AD FS 2.0. Installing .NET Framework 3.5 with Service Pack 1 is necessary as it is a prerequisite for AD FS 2.0. AD FS 2.0 is required for single sign-on functionality. Rollup 3 for AD FS 2.0 is important to ensure that any necessary updates and fixes are applied to AD FS 2.0.

Submit
40. You are the Office 365 administrator for your company. You have a server that runs Windows Server 2012. You plan to install an Active Directory Federation Services (AD FS) proxy server. You need to install and configure all of the required roles.Which two roles should you install and configure?

Explanation

You should install and configure the Web Server (IIS) role and the AD FS role. The Web Server (IIS) role is required to host the AD FS proxy server. The AD FS role is necessary to set up and configure the AD FS service, which allows for single sign-on authentication and authorization across different applications and systems. The other roles listed are not directly related to the installation and configuration of an AD FS proxy server.

Submit
41. You are the Office 365 administrator for your company. Users report that their passwords expire too frequently, and they do not receive adequate notice of password expiration. Account passwords must remain active for the longest duration allowed. Users must receive password expiration notifications as early as possible. You need to configure the password expiration policy.

What is the earliest amount of time you can set or users to be notified of an upcoming password change?

Explanation

The earliest amount of time that can be set for users to be notified of an upcoming password change is 30 days. This means that users will receive a notification 30 days before their password is set to expire, giving them ample time to change their password before it becomes inactive. This setting allows for a longer duration for active passwords and ensures that users are adequately notified of the upcoming change.

Submit
42. You are the Office 365 administrator for your company. You must configure a trust between the on-premises Active Directory domain and the Office 365 envionment by using Active Directory Federation Services. You need to assign the correct certificate to the description of your on-premises server environment below.Which certificate secures the communication between federation servers, clients, and federation server proxy computers?

Explanation

The SSL certificate is used to secure the communication between federation servers, clients, and federation server proxy computers. SSL (Secure Sockets Layer) is a protocol that provides secure communication over a computer network. It encrypts the data transmitted between the client and the server, ensuring that it cannot be intercepted or tampered with by unauthorized parties. In the context of Active Directory Federation Services, the SSL certificate is necessary to establish a secure trust between the on-premises Active Directory domain and the Office 365 environment.

Submit
43. You are the administrator for a company named Contoso, Ltd. The company has an Office 365 subscription. Your need to prevent users from changing their user display name by using Outlook Web App. What should you do?

Explanation

To prevent users from changing their user display name using Outlook Web App, you should modify the default role assignment policy. By modifying the default role assignment policy, you can restrict the permissions for users to modify their display name. This will ensure that users do not have the ability to change their display name using Outlook Web App.

Submit
44. You use a centralized identity management system as a source of authority for user account information. You export a list of new user accounts to a file on a daily basis. Your company uses a local Active Directory for storing user accounts for on-premises solutions. You are configuring the Windows Azure Active Directory Sync tool.New user accounts must be created in both the local Active Directory and Office 365. You must import user account data into Office 365 daily. You need to import the new users. What should you do?

Explanation

To import the new user accounts into both the local Active Directory and Office 365, a Windows PowerShell script should be created to import account data from the file into Active Directory. This script will allow for the automation of the import process, ensuring that the new user accounts are created in both systems on a daily basis. Using the Office 365 admin center or the Windows Azure Management Portal would not provide the necessary functionality to import the data into Active Directory. Additionally, using the MSOnline module in the Windows PowerShell script will allow for the import of account data into Office 365 as well.

Submit
45. You are the Office 365 administrator for your company. Users report that they have received significantly more spam messages over the past month than they normally receive.You need to analyze trends for the email messages received over the past 60 days. From the Office 365 admin center, what should you view?

Explanation

To analyze trends for the email messages received over the past 60 days and determine the reason for the increase in spam messages, the Office 365 administrator should view the mail protection reports. These reports provide insights into the effectiveness of the mail protection features, including information on spam messages, malware detections, and other security-related metrics. By analyzing these reports, the administrator can identify patterns, trends, and potential issues that may be causing the increase in spam messages.

Submit
46. An organization purchases an Office 365 plan for 10,000 user accounts. You have a domain controller that runs Windows Server 2008 R2. The forest functional level is set to Windows Server 2000. The organization must be able to synchronize user attributes from the on-premises Active Directory Domain Services environment to Office 365.You need to prepare to install the Windows Azure Active Directory Sync tool. Which two actions should you preform?

Explanation

To prepare to install the Windows Azure Active Directory Sync tool, you need to perform two actions. First, you should install Microsoft .NET Framework 3.5 SP1 and Microsoft .NET Framework 4.0 on the domain controller. This is necessary because the Azure Active Directory Sync tool requires these frameworks to run properly. Second, you should raise the forest functional level to Windows Server 2008 R2. This is required because the Azure Active Directory Sync tool is not compatible with lower forest functional levels. By performing these two actions, you will ensure that the domain controller is ready for the installation of the Azure Active Directory Sync tool and that user attributes can be synchronized from the on-premises Active Directory Domain Services environment to Office 365.

Submit
47. You are the SharePoint Online administrator for Contoso, Ltd. The company purchases an Office 365 Enterprise E1 plan. The public-facing website must use SharePoint Online and the custom domain contoso.comYou need to configure the DNS settings for the public-facing SharePoint site. How should you configure the DNS settings?

Explanation

The correct answer is to configure a CNAME record with the hostname "www.contoso.com" and point it to "contoso-public.sharepoint.com". This is because a CNAME record is used to create an alias for a domain name, allowing multiple domain names to point to the same location. In this case, the custom domain "www.contoso.com" needs to point to the public-facing SharePoint site, which is hosted at "contoso-public.sharepoint.com".

Submit
48. A company plans to use Office 365 to provide email services to employees. The company obtains a custom domain name to use with Office 365. You need to add the domain name to Office 365.Which three actions should you preform?NOTE: On the exam, you will also need to know the correct sequence of the three actions.

Explanation

To add a custom domain name to Office 365, the first step is to connect to Windows Azure Active Directory. This allows you to manage the domain settings. Then, you need to run the Windows PowerShell cmdlet New-MsolDomain. This cmdlet is used to add the custom domain to Office 365. Finally, you should install the Windows Azure Active Directory module for Windows PowerShell. This module provides the necessary tools and commands to manage the Azure Active Directory.

Submit
49. A company deploys an Office 365 tenant. You need to enable multi-factor authentication for Office 365. Which three actions should you perform?NOTE: On the exam, you will need need to know the correct order of these actions.

Explanation

To enable multi-factor authentication for Office 365, the first action is to enable it for all user accounts. This ensures that all users will be required to go through the multi-factor authentication process. The second action is to instruct users to obtain a single-use password to complete the registration process. This ensures that users have a unique password that they can use during the registration process. The third action is to instruct users to use a mobile phone to complete the registration process. This ensures that users have a mobile device that they can use for the multi-factor authentication process.

Submit
50. You need to enable multi-factor authentication for Office 365. Which three actions should you preform?NOTE: On the exam, you will need to know the correct sequence for these actions.

Explanation

The correct answer is to enable multi-factor authentication for all user accounts, instruct users to obtain a single-use password to complete the registration process, and instruct users to use a mobile phone to complete the registration process. Enabling multi-factor authentication for all user accounts ensures that all users will have an additional layer of security when accessing Office 365. Instructing users to obtain a single-use password ensures that they go through a verification process during registration. Instructing users to use a mobile phone for registration process allows them to receive verification codes or use authentication apps for the second factor authentication.

Submit
51. Your company has a hybrid deployment of Office 365. You create a user in Office 365. The next day, you discover that the new user account fails to appear in the Microsoft Exchange Server on-premises global address list (GAL). You need to ensure that the user has a mailbox and appears in the Exchange on-premises GAL and the Office 365 GAL.What should you do?

Explanation

The correct answer is to delete the user account hosted on Office 365 and create a new remote mailbox from the Exchange Management Console. This is because the user account created in Office 365 is not appearing in the Exchange on-premises GAL, indicating a synchronization issue between the two environments. By deleting the user account and creating a new remote mailbox in the Exchange Management Console, it ensures that the user has a mailbox and appears in both the Exchange on-premises GAL and the Office 365 GAL.

Submit
52. A company deploys an Office 365 tenant in a hybrid configuration with Exchange Server 2013. Office 365 users cannot see the free/busy information that is published from the on-premises Exchange Server. In addition, Exchange Server users cannot see free/busy information that is published from Office 365.You need to troubleshoot why users cannot access free/busy information from both Office 365 and Exchange Server 2013. Which tool should you run?

Explanation

The correct answer is "The Remote Connectivity Analyzer with the Office 365 tab selected." This tool allows you to test the connectivity and configuration between Office 365 and the on-premises Exchange Server. By selecting the Office 365 tab, you can specifically troubleshoot the issue of users not being able to access free/busy information from both Office 365 and Exchange Server 2013.

Submit
53. User1 of Contoso, Ltd is unable to sign in. You need to change the password for User1 and ensure that the user is prompted to reset her password the next time she signs in.What is the correct Windows PowerShell command to accomplish the task?

Explanation

The correct Windows PowerShell command to change the password for User1 and ensure that the user is prompted to reset her password the next time she signs in is "Set-MsolUserPassword -UserPrincipalName [email protected]". This command specifies the user's UserPrincipalName (which is [email protected]) and sets a new password for the user. By using this command, the user will be prompted to reset her password the next time she signs in.

Submit
54. You audit the Windows Azure Active Directory Rights Management configuration for the company. You need to view a log of the recent administrative commands performed against the Microsoft Rights Management Service. Which three Windows PowerShell cmdlets should you run?NOTE: On the exam, you will need to know the correct sequence of these commands

Explanation

The correct answer is Import-Module AADRM, Connect-AadrmService, and Get-AadrmAdminLog.

To view a log of the recent administrative commands performed against the Microsoft Rights Management Service, you first need to import the AADRM module using the Import-Module AADRM cmdlet. Then, you need to connect to the AADRM service using the Connect-AadrmService cmdlet. Finally, you can use the Get-AadrmAdminLog cmdlet to retrieve the log of recent administrative commands.

Submit
55. All user accounts must be configured to use only a custom domain. You need to provision an Office 365 tenant for the company. Which three actions should you preform?NOTE: On the exam, you will need to know the correct sequence for the actions.

Explanation

The first action is to select the Office 365 plan, which is necessary to provision the tenant. The second action is to configure the global administrator account recovery information, which ensures that the account can be recovered in case of any issues. The third action is to configure the custom domain and DNS, which allows all user accounts to use only a custom domain. Removing the domain name onmicrosoft.com is not mentioned as a necessary action in the given scenario.

Submit
56. An organization prepares to migrate to Office 365. The organization has one domain controller named NYC-DC1 and one server named NYC-DS that is designated as the directory synchronization computer.NYC-DC1 is running Windows Server 2008 R2 and has a Forest Functional Level of Windows 2000. What is the minimum you must do to the server to allow Directory Synchronization to function?

Explanation

In order to allow Directory Synchronization to function, the forest functional level needs to be raised to at least Windows Server 2003. Since the current forest functional level is Windows 2000, it is necessary to raise it to Windows Server 2003 to meet the minimum requirement for Directory Synchronization.

Submit
57. The company obtains a custom domain name to use with Office 365. You need to add the domain name to Office 365.Which three actions should you perform?NOTE: On the exam, you will need to know the correct sequence of these actions

Explanation

To add a custom domain name to Office 365, the first step is to connect to Windows Azure Active Directory. This allows you to manage the domain in Office 365. Next, you need to run the Windows PowerShell cmdlet New-MsolDomain, which creates a new domain in Office 365. Finally, you should install the Windows Azure Active Directory module for Windows PowerShell, which provides the necessary tools for managing Azure Active Directory. By following these three actions in sequence, you can successfully add a custom domain name to Office 365.

Submit
58. Your company has a hybrid deployment of Office 365. You need to verify whether free/busy information sharing with external users is configured. Which Windows PowerShell cmdlet should you use?

Explanation

The correct answer is Get-OrganizationRelationship. This cmdlet is used to retrieve information about the organization relationships that have been configured in Office 365. By using this cmdlet, you can verify whether free/busy information sharing with external users is configured.

Submit
59. A company deploys an Office 365 tenant. You need to configure single sign-on (SSO) for all user accounts.Which two actions should you preform?

Explanation

To configure single sign-on (SSO) for all user accounts in an Office 365 tenant, you need to perform two actions. First, you need to run the Windows PowerShell cmdlet Convert-MsolDomainToFederated. This cmdlet converts the domain from standard authentication to federated authentication, enabling SSO for the users. Second, you need to deploy a federation server farm. The federation server farm acts as the authentication authority and allows users to authenticate once and access multiple applications without having to re-enter their credentials. By performing these two actions, you can successfully configure SSO for all user accounts in the Office 365 tenant.

Submit
60. An organization plans to migrate to Office 365. You use the Windows Azure Active Directory (AD) Sync tool. Several users will not migrate to Office 365. You must exclude these users from synchronization. All users must continue to authenticate against the on-premises Active Directory. You need to synchronize the remaining users.Which three actions should you preform?

Explanation

To exclude certain users from synchronization while migrating to Office 365, you need to perform the following three actions:

1. Populate an attribute for each user account: This involves adding a specific attribute to the user accounts that need to be excluded from synchronization.
2. Perform a full synchronization: This ensures that all the user accounts, including the ones with the newly added attribute, are synchronized with Office 365.
3. Configure the connection filter: By configuring the connection filter, you can specify criteria to exclude the users with the added attribute from being synchronized.

By performing these three actions, you can successfully exclude the specified users from synchronization while allowing all users to continue authenticating against the on-premises Active Directory.

Submit
61. Fabrikam has the Office 365 Enterprise E3 plan. You must add the domain name fabrikam.com to the Ofdfice 365 tenant. You need to confirm ownership of the domain.Which DNS records should you use?NOTE: On the exam, you will need to know the preferred and alternate method of verification.

Explanation

To confirm ownership of the domain fabrikam.com in Office 365, you should use the TXT and MX DNS records. The TXT record is commonly used for domain verification and allows you to add a specific text value provided by Office 365 to your domain's DNS settings. The MX record, on the other hand, is used to specify the mail server responsible for accepting email messages on behalf of the domain. By adding these DNS records, you can verify that you have control over the domain and proceed with configuring Office 365 for fabrikam.com.

Submit
62. A company is deploying an Office 365 tenant. You need to deploy a Windows Server 2012 R2 federation server farm. Which three actions should you perform?NOTE: On the exam, you will need to list the three actions in the correct sequence.

Explanation

To deploy a Windows Server 2012 R2 federation server farm, the first action is to install the Active Directory Federation Service (AD FS) server role. This will enable the server to function as a federation server. The second action is to use the AD FS Federation Server Configuration Wizard to configure the first federation server in the farm. This will set up the initial server with the necessary configurations. Finally, the third action is to use the same wizard to add the second federation server to the farm, expanding the server farm and increasing its capacity.

Submit
63. An organization deploys an Office 365 tenant. The Service Health page displays the following information:

What is the earliest date that a post-incident review will be available for SharePointOnline?

Explanation

The earliest date that a post-incident review will be available for SharePoint Online is November 13. This is because it is the first date mentioned in the list of options provided.

Submit
64. Your company has a hybrid deployment of Office 365. You need to create a group. The group must have the following characteristics:
  • Group properties are synchronized automatically
  • Group members have the ability to control which users can send email messages to the group
What should you do?

Explanation

Creating a distribution group and configuring the Mail Flow Settings allows for automatic synchronization of group properties. Additionally, it provides the ability for group members to control which users can send email messages to the group, fulfilling both requirements mentioned in the question.

Submit
65. A company deploys an Office 365 tenant. All employees use Lync Online. You need to configure the network firewall to support Lync Online.

Which port should you open for audio, video and application sharing sessions?

Explanation

To support Lync Online, the network firewall should have port 443 open. Port 443 is the default port for HTTPS traffic, which is used by Lync Online for audio, video, and application sharing sessions. By opening this port, the firewall allows the necessary communication to take place between Lync Online and the employees' devices, ensuring a seamless experience for audio, video, and application sharing sessions.

Submit
66. The company has Office 365 Enterprise E3 licenses for each of its 250 employees. The company does not allow email or Lync Online licenses to be assigned to external contractors. User1 is an external contractor who requires access to SharePoint and Office Web apps only. You need to add a license for User1's account.Choose the correct actions to fill in the blanks 
StepAction
1Sign in to the Office 365 admin center
2 
3Add an Office Web App with Sharepoint (Plan 1) plan
4 
5Assign licenses to User1
 

Explanation

To add a license for User1's account, the correct actions are to select the purchase services option and then select the users and groups option. This will allow you to choose the specific services and licenses that you want to assign to User1.

Submit
67. A company deploys an Office 365 tenant. All employees use Lync Online. You need to configure the network firewall to support Lync Online.Which port should you open for Lync Mobile push notifications?

Explanation

To support Lync Mobile push notifications, the network firewall should have port 5223 open. This port is specifically used for Apple Push Notification Service (APNS) traffic, which is required for Lync Mobile push notifications to work properly.

Submit
68. The legal department in your organization creates standardized disclaimers for all of their email messages. The disclaimers explain that any transmissions that are received in error should be reported back to the sender. You track any confidential documents that are attached to email messages. Your security team reports that an employee may have mistakenly sent an email message that contained confidential information. You need to identify whether the email message included the disclaimer and whether it contained confidential information.Which two options should you configure?

Explanation

To identify whether the email message included the disclaimer, you should configure "rule matches for sent mail". This rule will check if the email message contains the standardized disclaimer created by the legal department.

To identify whether the email message contained confidential information, you should configure "DLP policy matches for sent mail". This policy will scan the email message for any confidential documents attached to it, allowing you to track such documents and take appropriate actions if necessary.

Submit
69. Fabrikam, Inc plans to use the domain fabrikam.com for Office 365 user identities, email addresses, SIP addresses and a public-facing home page. Single Sign-on between Office 365 and the on-premises Active Directory is NOT required. You need to configure the Office 365 plan.Which four PowerShell cmdlets should you run?NOTE: On the exam, you will need to know the correct sequence of these commands.

Explanation

The given answer is correct because the first step is to create a new domain using the New-MsolDomain cmdlet. Then, the Get-MsolDomainVerificationDns cmdlet is used to retrieve the DNS records that need to be added to the DNS provider for domain verification. Once the DNS records are added, the Confirm-MsolDomain cmdlet is used to verify the domain. Finally, the Set-MsolDomain cmdlet is used to set the newly created domain as the default domain for Office 365.

Submit
70. An organization with an Active Directory Domain Services (AD DS) domain migrates to Office 365. You need to manage Office 365 from a domain-joined Windows Server 2012 Core server. Which three components should you install?

Explanation

To manage Office 365 from a domain-joined Windows Server 2012 Core server, you would need to install the Windows Azure Active Directory module for Windows PowerShell. This module allows you to manage user accounts and resources in Office 365 using PowerShell commands. Additionally, you would need to install the Microsoft .NET Framework 3.5, which is a prerequisite for the Azure Active Directory module. Lastly, you would need to install the Microsoft Online Services Sign-in Assistant, which enables single sign-on for Office 365 and allows you to manage user credentials.

Submit
71. You plan to deploy an Office 365 tenant to multiple office around the country. You need to modify the users and groups who are authorized to administer the Rights Management service.Which Windows PowerShell cmdlet should you run?

Explanation

To modify the users and groups who are authorized to administer the Rights Management service in an Office 365 tenant deployed across multiple offices, the appropriate Windows PowerShell cmdlet to run is "Add-MsolGroupMember". This cmdlet allows you to add users or groups as members of a specified group in the Microsoft Online Services Directory. By adding the desired users or groups as members of the appropriate group, you can grant them the necessary permissions to administer the Rights Management service.

Submit
72. You are the Office 365 administrator for your company. The company synchronizes the local Active Directory objects with a central identity management system. The environment has the following characteristics:
  • Each deployment has its own organizational unit (OU)
  • The company has OU hierarchies for partner user accounts
  • All user accounts are maintained by the identity management system
You need to ensure that partner accounts are NOT synchronized with Office 365. What should you do?

Explanation

To ensure that partner accounts are not synchronized with Office 365, you should configure user attribute-based filtering by using the Windows Azure Active Directory Sync tool. This means that you can set up specific attributes for the partner user accounts in the identity management system, and then configure the sync tool to filter out these accounts based on those attributes. This will prevent the synchronization of partner accounts with Office 365, ensuring that only the desired user accounts are synchronized.

Submit
73. An organization prepares to migrate to Office 365. The organization has one domain controller named NYC-DC1 and one server named NYC-DS that is designated as the directory synchronization computer.

NYC-DS is running Windows Server 2003. What is the minimum you must do to the server to allow Directory Synchronization to function?

Explanation

To allow Directory Synchronization to function, the minimum requirement is to install Windows Server 2008 R2 Standard edition. This version of the operating system is compatible with Office 365 and will enable the server to synchronize the directory with the cloud-based service. The other options mentioned, such as installing the 64-bit version of Windows Server 2008 Standard edition, Windows Server 2008 R2 Datacenter edition, or Windows Server 2012, do not meet the minimum requirement specified.

Submit
74. Contoso Ltd plans to use Office 365 services for collaboration between departments. Contoso has one Active Directory Domain Services domain named contoso.local. You deploy the Windows Azure Active Directory Sync tool.You plan to implement single sign-on for Office 365. You need to synchronize only the user accounts that have valid routable domain names and are members of specified departments. Which three actions should you preform?NOTE: On the exam, you will need to know the correct sequence of these commands.

Explanation

To synchronize only the user accounts that have valid routable domain names and are members of specified departments, three actions need to be performed. First, the user principal name (UPN) suffix contoso.com should be added to the domain contoso.local using the Active Directory Domains and Trusts MMC snap-in. Then, the UPN suffix should be changed to contoso.com for all users in the specified departments using the Active Directory Users and Computers MMC snap-in. Lastly, user attribute-based filtering should be used to exclude all users that have contoso.local in the userPrincipalName attribute. By following these steps, only the desired user accounts will be synchronized for single sign-on with Office 365.

Submit
75. Your company deploys an Office 365 tenant. You need to ensure that you can view service health and maintenance reports for the past seven days.What are two possible ways to achieve this goal? Each correct answer presents a complete solution.

Explanation

To view service health and maintenance reports for the past seven days in Office 365, there are two possible ways. Firstly, you can run the Microsoft Online Services Diagnostics and Logging (MOSDAL) Support Kit, which provides detailed diagnostic information and logs for troubleshooting purposes. Secondly, you can view the service health current status page of the Office 365 admin center, which displays real-time information about service health and any ongoing maintenance activities. These two methods together allow you to stay informed about the service health and maintenance activities in your Office 365 tenant.

Submit
76. An organization migrates to Office 365. The Office 365 administrator must be notified when Office 365 maintenance activities are planned. You need to configure the administrator's computer to receive the notifications.What should you configure?

Explanation

The Office 365 Management Pack for System Center Operations Manager should be configured to notify the administrator's computer when Office 365 maintenance activities are planned. This management pack integrates Office 365 with System Center Operations Manager, allowing administrators to monitor and manage their Office 365 environment. By configuring this, the administrator will receive notifications about planned maintenance activities, ensuring they are aware of any potential disruptions or downtime.

Submit
77. You must reset the password for all of the employees in your company. You need to ensure that all employees create a new password the next time the sign in to Office 365.What is the correct Windows PowerShell command to use?

Explanation

The correct answer is "Get-MsolUser -All | Set-MsolUser -NewPassword Pass#123#". This command retrieves all users in Office 365 and sets a new password for each user as "Pass#123#". This ensures that all employees will be prompted to create a new password the next time they sign in to Office 365.

Submit
78. You are the Office 365 administrator for your company. User1 leaves the company. You must delete the account for User1.When you delete the account, when will the Exchange Online mailbox be removed?

Explanation

When you delete the account for User1, the Exchange Online mailbox will be removed immediately. This means that all the emails, contacts, and other data associated with User1's mailbox will be permanently deleted without any grace period for recovery.

Submit
79. Your company has a subscription to Office 365 for midsize business and enterprises. The company uses Microsoft Lync Online. You need to open ports on the network firewall to enable all of the features of Lync Online.Which port ot ports should you open? Choose all that apply.

Explanation

To enable all the features of Lync Online, the company needs to open the following ports on the network firewall: outbound UDP 3478, outbound TCP 443, and outbound UDP 50000-59999. These ports are necessary for the proper functioning of Lync Online and allow for communication and data transfer between the Lync client and the Lync servers. Opening these ports will ensure that all the features of Lync Online can be utilized effectively.

Submit
80. A company deploys an Office 365 tenant. You must provide an administrator with the ability to manage company information in Office 365. You need to assign permissions to the administrator by following the principle of least privilege.Which role should you assign?

Explanation

The role that should be assigned in this scenario is the Service administrator. This role provides the administrator with the ability to manage company information in Office 365, while still following the principle of least privilege. The Global administrator role has more permissions than necessary for this specific task, while the Billing administrator role is focused on managing billing information. The User management administrator role is also not the correct choice as it is more focused on user management rather than company information management. Therefore, the Service administrator role is the most appropriate choice in this situation.

Submit
81. Your organization has over 10,000 users and uses a SQL-based Active Directory Federation Services (AD FS) server farm. You need to change the AD FS 2.0 service account password. Choose the correct action or utility for each step.
Submit
82. You are the Office 365 administrator for your company. Users report that they have received significantly more spam messages over the past month than they normally receive. You need to analyze trends for theemail messages received over the past 60 days.From the Office 365 admin center, what should you view?

Explanation

not-available-via-ai

Submit
83. A company plans to deploy an Office 365 tenant. You have the following requirements:
  1. Administrators must be able to access the Office 365 admin center
  2. Microsoft Exchange Online must be used as a Simple Mail Transfer Protocol (SMTP) relay for a line-of-business application that sends email messages to remote domains
  3. All users must be able to use the audio and video capabilities in Microsoft Lync 2013
You need to configure the ports for the firewall. Which port should you use for each application?
Submit
84. An organization plans to migrate to Office 365. You need to estimate the post-migration network traffic.Which tool should you use?

Explanation

The correct answer is Microsoft Online Services Diagnostics and Logging (MOSDAL) Support Kit. This tool is specifically designed to help organizations diagnose and troubleshoot issues related to Microsoft Online Services, including Office 365. It provides detailed information about network traffic, performance, and connectivity, allowing administrators to estimate the post-migration network traffic accurately. Microsoft Network Monitor is a general-purpose network protocol analyzer and may not provide the specific information required for Office 365 migration. Lync 2013 Bandwidth Calculator is used to estimate network bandwidth requirements for Lync Server 2013 deployments, not Office 365 migrations. Microsoft Remote Connectivity Analyzer is a web-based tool that helps diagnose and troubleshoot connectivity issues with various Microsoft services, but it may not provide the detailed network traffic estimation required for Office 365 migration.

Submit
85. You create an Office 365 tenant. You assign administrative roles to other users. You hire a new user named User2. User2 must NOT be able to change passwords for other users. You need to assign an administrative role to User2.Which role should you assign?

Explanation

The correct role to assign to User2 is Delegate administrator. This role allows the user to perform administrative tasks such as managing users and groups, but does not grant the ability to change passwords for other users. This ensures that User2 cannot make unauthorized changes to other users' accounts.

Submit
86. A company has an Active Directory Domain Service (AD DS) domain. All servers run Windows Server 2008. You have an on-premises Exchange 2010 server. The company plans to migrate to Office 365.When doing the pilot, which of these tasks are in the Planning Phase?

Explanation

In the planning phase of migrating to Office 365, the company needs to prepare the on-premises Active Directory for directory synchronization. This involves configuring the necessary settings and ensuring that the directory is ready for synchronization with Office 365. Additionally, raising the forest functional level to Windows Server 2008 is also a task in the planning phase, as it may be a requirement for the migration. Finally, upgrading the Exchange server to Exchange 2013 is also part of the planning phase, as it is necessary to ensure compatibility and a smooth transition to Office 365.

Submit
87. A company deploys an Office 365 tenant. You assign the roles to users as shown in the following table: 
UserRole Assigned
User1global administrator
User2user management administrator
User3no roles are assigned
User3 must be able to monitor the health of the Exchange Online Service. You must use the principle of least privlege to assign permissions to User3. You need to assign permissions to User3.Which three actions should you perform?

Explanation

not-available-via-ai

Submit
88. All employees in the Human Resources department must use multi-factor authentication. They must use only the Microsoft Outlook client to access their email messages. User1 joins the HR department. You need to help User1 configure his account.Which three actions should you preform?NOTE: On the exam you will need to know the correct sequence of these actions

Explanation

The correct answer is to enable multi-factor authentication for User1, instruct User1 to create an app password, and instruct User1 to use an app password to complete the registration process. This is because all employees in the HR department must use multi-factor authentication, and using an app password is a common method to securely access email messages through the Microsoft Outlook client. Using a one-time password or a mobile phone is not mentioned as a requirement in the given scenario.

Submit
89. You are the Office 365 administrator for your company. You must configure a trust between the on-premises Active Directory domain and the Office 365 envionment by using Active Directory Federation Services. You need to assign the correct certificate to the description of your on-premises server environment below.

Which certificate securely signs all tokens that the federation server issues for the cloud-based services.

Explanation

The correct answer is "Client". In an Active Directory Federation Services (ADFS) environment, the federation server issues security tokens to clients for accessing cloud-based services. These security tokens need to be securely signed to ensure the integrity and authenticity of the tokens. The client certificate is used to sign these tokens and verify their authenticity. Therefore, the client certificate is the correct certificate to securely sign all tokens issued by the federation server for cloud-based services.

Submit
90. You are the Office 365 administrator for your company. You need to ensure that trusted applications can decrypt rights-protected content. Which four PowerShell cmdlets should you run?NOTE: On the exam, you will have to know the correct order that these PowerShell cmdlets need to be run.

Explanation

not-available-via-ai

Submit
91. You need to ensure that trusted applications can decrypt rights-protected content. Which four PowerShell cmdlets should you run?NOTE: On the exam, you will be required to know the correct sequence of these cmdlets.

Explanation

The given correct answer suggests running four PowerShell cmdlets in a specific sequence to ensure that trusted applications can decrypt rights-protected content. The first cmdlet, Import-Module AADRM, imports the AADRM module, which is necessary for managing rights-protected content. The second cmdlet, Connect-AadrmService, establishes a connection to the AADRM service. The third cmdlet, Enable-AadrmSuperUserFeature, enables the super user feature, which allows trusted applications to access rights-protected content. The fourth cmdlet, Set-AadrmMigrationUrl, sets the URL for AADRM migration. These four cmdlets need to be run in the given sequence to ensure that trusted applications can decrypt rights-protected content.

Submit
92. You are the Office 365 administrator for your company. You must use Windows PowerShell to manage cloud identities in Office 365. You must use a computer that runs Windows 8 to perform the management tasks. You need to ensure that the Windows 8 computer has the necessary software installed.What should you install first?

Explanation

To manage cloud identities in Office 365 using Windows PowerShell on a Windows 8 computer, you need to install the Remote Server Administrator Tools for Windows first. These tools provide the necessary functionality to manage server roles and features remotely from a Windows client computer. Once installed, you can then use Windows PowerShell to perform the management tasks required for Office 365.

Submit
93. You are the Office 365 administrator for your company. You have a workstation that runs Windows 8. You need to install the prerequisite components so that you can view mail protection reports on the workstation.Which two items must you install? Each correct answer presents part of the solution.

Explanation

To view mail protection reports on the workstation, you need to install two items: SQL Server Analysis Services and the Microsoft Connectivity Analyzer Tool. SQL Server Analysis Services is required for data analysis and reporting, while the Microsoft Connectivity Analyzer Tool helps diagnose and troubleshoot connectivity issues. Installing these components will enable you to access and analyze the mail protection reports effectively.

Submit
94. You have an Office 365 environment. Synchronization between the on-premises Active Directory and Office 365 is enabled. You need to deactivate directory synchronization.Which Windows PowerShell cmdlet should you run?

Explanation

To deactivate directory synchronization in an Office 365 environment, you should run the "Set-MsolDirSyncEnabled" cmdlet. This cmdlet allows you to enable or disable directory synchronization. The "Update-MsolFederatedDomain" cmdlet is used to update settings for a federated domain. The "Remove-MsolDomain" cmdlet is used to remove a domain from Office 365. The "Remove-MsolFederatedDomain" cmdlet is used to remove a federated domain from Office 365.

Submit
95. An organization plans to deploy an Office 365 tenant. The company has two servers named SERVER1 and SERVER2. SERVER1 is a member server of the Active Directory forest that you are synchronizing. SERVER2 is a standalone server. Both servers are running Windows Server 2012.You need to use the Windows Azure Active Directory Sync tool to provision users. Which three actions should you perform?NOTE: On the exam, you will need to know the correct sequence for these three actions.

Explanation

not-available-via-ai

Submit
96. Contoso uses Office 365 for collaboration services. You implement single sign-on (SSO) with Office 365 by using Active Directory Federation Services (AD FS). You need to implement Windows Azure multi-factor authentication.Which three actions should you perform?

Explanation

To implement Windows Azure multi-factor authentication in Office 365 with AD FS, three actions should be performed. First, run PhoneFactor AgentSetup.exe on the AD FS federation server. This installs the necessary components for multi-factor authentication. Second, run WindowsAzureSDK-x64.exe on the AD FS Federation server. This installs the Windows Azure SDK, which is required for integrating with Azure multi-factor authentication. Finally, run the Windows PowerShell cmdlet Register-AdfsAuthenticationProvider on the AD FS Federation server. This registers the Azure multi-factor authentication as an authentication provider in AD FS.

Submit
View My Results

Quiz Review Timeline (Updated): Mar 20, 2023 +

Our quizzes are rigorously reviewed, monitored and continuously updated by our expert board to maintain accuracy, relevance, and timeliness.

  • Current Version
  • Mar 20, 2023
    Quiz Edited by
    ProProfs Editorial Team
  • Nov 11, 2014
    Quiz Created by
    Bearxor
Cancel
  • All
    All (96)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
You are the Office 365 administrator for your company. The company...
You are the Office 365 administrator for your company. You prepare to...
An organization deploys an Office 365 tenant. User accounts must be...
You are the Office 365 administrator for your company. The environment...
You are the Office 365 administrator for your company. The company has...
You manage a team of three administrators for an organization that...
You manage a team of three administrators for an organization that...
You are the Office 365 administrator for your company. The company has...
A company named Fabrikam, Inc. is deploying an Office 365 tenant. You...
You administer the Office 365 environment for a company that has...
You manage a team of three administrators for an organization that...
An organization plans to deploy Exchange Online. You must support all...
You are the Office 365 adminstrator for your company. You configure...
An organization deploys an Office 365 tenant. The Service Health page...
Your company purchases an Office 365 plan. The company has an Active...
Contoso Ltd. uses Office 365 for collaboration. You are implementing...
Fabrikam, Inc employs 500 users and plans to migrate to Office 365....
Your company has an Office 365 subscription. You create a new...
Your company subscribes to an Office 365 Plan E3. A user named User1...
Your company uses Office 365. You need to identify which users do NOT...
A company plans to deploy an Office 365 tenant. You have two servers...
You are the Office 365 administrator for your company. The company has...
A company uses Office 365 services. You implement the Windows Azure...
Contoso, Ltd. plans to use Office 365 for email services and Lync...
An organization implements single sign-on (SSO) for use with Office...
A company plans to use Office 365 to provide email services for users....
You deploy Lync Online for a company that has offices in San Francisco...
You are the Office 365 administrator for your company. Users report...
Your company has 100 user mailboxes. The company purchases a...
Your company has a hybrid deployment of Office 365. All mailboxes are...
A company migrates to Office 365. 2,000 active users have valid Office...
An organization prepares to implement Office 365. You have the follow...
A company deploys an Office 365 tenant. You prepare to use the bulk...
Your company has an Office 365 subscription. You need to add the label...
You need to enforce password complexity requirements for all...
You are the Office 365 administrator for your company. Users report...
Your company has an Office 365 subscription. The network contains an...
You are the Office 365 administrator for your company. A user named...
A company has a Windows Server 2008 domain controller and a SharePoint...
You are the Office 365 administrator for your company. You have a...
You are the Office 365 administrator for your company. Users report...
You are the Office 365 administrator for your company. You must...
You are the administrator for a company named Contoso, Ltd. The...
You use a centralized identity management system as a source of...
You are the Office 365 administrator for your company. Users report...
An organization purchases an Office 365 plan for 10,000 user accounts....
You are the SharePoint Online administrator for Contoso, Ltd. The...
A company plans to use Office 365 to provide email services to...
A company deploys an Office 365 tenant. You need to enable...
You need to enable multi-factor authentication for Office 365. Which...
Your company has a hybrid deployment of Office 365. You create a user...
A company deploys an Office 365 tenant in a hybrid configuration with...
User1 of Contoso, Ltd is unable to sign in. You need to change the...
You audit the Windows Azure Active Directory Rights Management...
All user accounts must be configured to use only a custom domain. You...
An organization prepares to migrate to Office 365. The organization...
The company obtains a custom domain name to use with Office 365. You...
Your company has a hybrid deployment of Office 365. You need to verify...
A company deploys an Office 365 tenant. You need to configure single...
An organization plans to migrate to Office 365. You use the Windows...
Fabrikam has the Office 365 Enterprise E3 plan. You must add the...
A company is deploying an Office 365 tenant. You need to deploy a...
An organization deploys an Office 365 tenant. The Service Health page...
Your company has a hybrid deployment of Office 365. You need to create...
A company deploys an Office 365 tenant. All employees use Lync Online....
The company has Office 365 Enterprise E3 licenses for each of its 250...
A company deploys an Office 365 tenant. All employees use Lync Online....
The legal department in your organization creates standardized...
Fabrikam, Inc plans to use the domain fabrikam.com for Office 365 user...
An organization with an Active Directory Domain Services (AD DS)...
You plan to deploy an Office 365 tenant to multiple office around the...
You are the Office 365 administrator for your company. The company...
An organization prepares to migrate to Office 365. The organization...
Contoso Ltd plans to use Office 365 services for collaboration between...
Your company deploys an Office 365 tenant. You need to ensure that you...
An organization migrates to Office 365. The Office 365 administrator...
You must reset the password for all of the employees in your company....
You are the Office 365 administrator for your company. User1 leaves...
Your company has a subscription to Office 365 for midsize business and...
A company deploys an Office 365 tenant. You must provide an...
Your organization has over 10,000 users and uses a SQL-based Active...
You are the Office 365 administrator for your company. Users report...
A company plans to deploy an Office 365 tenant. You have the following...
An organization plans to migrate to Office 365. You need to estimate...
You create an Office 365 tenant. You assign administrative roles to...
A company has an Active Directory Domain Service (AD DS) domain. All...
A company deploys an Office 365 tenant. You assign the roles to users...
All employees in the Human Resources department must use multi-factor...
You are the Office 365 administrator for your company. You must...
You are the Office 365 administrator for your company. You need to...
You need to ensure that trusted applications can decrypt...
You are the Office 365 administrator for your company. You must use...
You are the Office 365 administrator for your company. You have a...
You have an Office 365 environment. Synchronization between the...
An organization plans to deploy an Office 365 tenant. The company has...
Contoso uses Office 365 for collaboration services. You implement...
Alert!

Advertisement