Microsoft 365 Copilot and Agent Administration Fundamentals (AB-900)

Use this AB-900 practice test to prepare for the Microsoft 365 Copilot and Agent Administration Fundamentals exam. Original questions are grounded in verified Microsoft Learn content, with explanations and source links for focused revision.

Q001 - Question

A user in the marketing department asks Microsoft 365 Copilot in Word to summarize a finance report. The report is stored in a SharePoint site that the user doesn't have permission to access. How does Copilot handle the finance report content?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

B is correct.

Explanation: Copilot operates inside the organization's Microsoft 365 tenant and can only use data that the signed-in user already has permission to access. A user without access to the SharePoint site can't get that content through Copilot.

A is incorrect: Microsoft Graph provides data connectivity, but Copilot is still limited to content the signed-in user can access.

C is incorrect: The orchestration service manages prompts and rules. It doesn't grant access to content that the user can't already access.

D is incorrect: Work IQ provides contextual assistance within security and compliance boundaries. It doesn't expand user permissions.

Learn more in Microsoft Learn

Q002 - Question

A company wants to give users agent capabilities for a common scenario as soon as possible. The IT team has limited time for configuration and customization. Which type of agent should the company use first?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

D is correct.

Explanation: A prebuilt agent is created by Microsoft or a Microsoft-approved vendor. It can provide immediate value without extensive configuration or customization, which matches the limited IT time.

A is incorrect: An advanced agent requires the IT team to build and customize it, which conflicts with the limited time for configuration.

B is incorrect: Agents for everyday business users require each department to create and configure them, which adds effort before users get value.

C is incorrect: A SharePoint site agent works with site content. It doesn't address the need for a ready-made agent for a common scenario without configuration.

Learn more in Microsoft Learn

Q003 - Question

An organization currently uses the free Copilot chat experience. Managers want Copilot responses grounded in their emails, chats, and documents. Finance requires predictable monthly costs for these users. Which option should you recommend?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

C is correct.

Explanation: The Microsoft 365 Copilot paid plan grounds responses in Microsoft Graph data such as emails, chats, and documents. A monthly per-user license provides predictable costs.

A is incorrect: The free Copilot chat experience doesn't access organizational Microsoft 365 data, so it doesn't meet the grounding requirement.

B is incorrect: The free Copilot chat experience doesn't access organizational Microsoft 365 data, regardless of how the organization pays.

D is incorrect: The paid plan meets the grounding requirement, but pay-as-you-go aligns costs with usage. It doesn't meet the requirement for predictable monthly costs.

Learn more in Microsoft Learn

Q004 - Question

An administrator plans to introduce Microsoft 365 Copilot features. Leadership wants to validate business value and manage risk before a broad rollout. Which two actions should the administrator take? Each correct answer presents part of the solution.

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Multi-select

B and D are correct.

Explanation: Granular controls by app, feature, user, or group support phased rollouts and pilots. Feedback and escalation loops help you collect results and address issues before you expand access.

A is incorrect: A tenant-wide rollout to every user doesn't support a pilot, and training and adoption plans should be part of planning, not added after the rollout.

C is incorrect: Planning includes data access and sensitivity classification. Postponing it until all users have access increases risk.

Learn more in Microsoft Learn

Q005 - Question

An operations team runs the same multi-step process every week. The process collects data from a system outside Microsoft 365 through an API, updates records, and sends a standardized report. Which solution best fits this process?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

A is correct.

Explanation: Advanced custom agents can integrate APIs and automate complex, multi-step, cross-system processes. Agents fit repeatable and standardized processes that connect with systems outside Microsoft 365.

B is incorrect: Copilot fits one-off, user-driven tasks inside Microsoft 365 apps. It doesn't automate a repeatable process that connects to an external system.

C is incorrect: Lightweight agents from business users handle department-specific questions, guided processes, and simple data lookups, not complex cross-system automation.

D is incorrect: Researcher specializes in unstructured organizational content. It doesn't automate API integration and record updates.

Learn more in Microsoft Learn

Q006 - Question

A company supports hybrid work. Employees access Microsoft 365 from office networks, home networks, and personal devices. The security lead wants the access strategy to align with the Zero Trust security model. Which approach should the security lead use?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

C is correct.

Explanation: Zero Trust operates on the principle that no user, device, or application is trusted by default, regardless of location. This matters in hybrid work because users access resources from many devices and locations, often outside the corporate firewall.

A is incorrect: Trusting users because they are inside the corporate firewall is the traditional perimeter-based model. Zero Trust does not treat internal networks as trustworthy.

B is incorrect: Zero Trust is not a single product. It is a strategy that spans identity, endpoints, data, applications, infrastructure, and networks.

D is incorrect: Zero Trust does not trust any device by default. Every access request must be verified.

Learn more in Microsoft Learn

Q007 - Question

A project manager drafts a plan to implement Zero Trust in Microsoft 365. The draft plan schedules one configuration sprint and then closes the project. You need to recommend a change so the plan aligns with how Zero Trust is implemented. What should you recommend?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

A is correct.

Explanation: Implementing Zero Trust in Microsoft 365 is a continuous process. You assess your current environment, apply layered controls, and refine policies over time. It also requires coordination across teams and continuous monitoring.

B is incorrect: Zero Trust is not a one-time configuration. A plan that ends after one sprint does not include continuous monitoring or iterative refinement.

C is incorrect: Zero Trust is not a single product or feature. It requires layered controls.

D is incorrect: Tailor the implementation strategy to your organization's risk profile, regulatory requirements, and operational needs.

Learn more in Microsoft Learn

Q008 - Question

A security team investigates a business email compromise attempt. Analysts review email, endpoint, and identity data separately, so each analyst sees only part of the attack. The team wants to understand the benefit of the integrated threat protection tools in Microsoft 365. Which benefit addresses this problem?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

D is correct.

Explanation: Microsoft 365 brings together tools that work together to detect, investigate, and respond to threats across email, endpoints, identities, and applications. This approach helps security teams see the full picture instead of isolated fragments.

A is incorrect: Threats are not limited to malware or spam. Attackers also use phishing, business email compromise, credential theft, and lateral movement.

B is incorrect: The threat protection tools cover email, endpoints, identities, and applications, not only email.

C is incorrect: The tools support security teams as they detect, investigate, and respond to threats. They do not remove the need for security teams.

Learn more in Microsoft Learn

Q009 - Question

A new employee signs in to Microsoft 365, and the sign-in is verified. The administrator now needs to make sure the employee can access only the email, files, and apps required for the job. Which process should the administrator configure?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

B is correct.

Explanation: Authorization governs what users are permitted to access and do within Microsoft 365. It grants or restricts access to resources such as email, files, apps, and administrative settings. Use it so users have access only to the tools and data they need to do their job.

A is incorrect: Authentication proves that users are who they say they are. In this scenario, the sign-in is already verified.

C is incorrect: Single sign-on (SSO) relates to how users sign in. It does not define which resources a user is permitted to access.

D is incorrect: Identity answers who is trying to access Microsoft 365. It does not determine what that user is allowed to do.

Learn more in Microsoft Learn

Q010 - Question

An organization plans to monitor its Microsoft 365 identity environment proactively with audit logs. The administrator needs visibility into user and admin activities. Which two outcomes does this monitoring support? Each correct answer presents a complete solution.

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Multiple choice

B and D are correct.

Explanation: Proactive monitoring through audit logs provides visibility into user and admin activities. This visibility helps organizations detect suspicious behavior and meet compliance requirements.

A is incorrect: Audit logs record activity. They do not verify who a user is, so authentication is still required.

C is incorrect: Audit logs provide visibility into activity. They do not grant just-in-time privileged access. That access is a function of Privileged Identity Management (PIM).

Learn more in Microsoft Learn

Q011 - Question

An IT team is writing a deployment plan. The plan must list the foundational service components of the Microsoft 365 ecosystem. Which two services should the team list as core service components? Each correct answer presents part of the solution.

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Multiple choice

A and C are correct.

Explanation: The foundational components of Microsoft 365 are Exchange Online, Microsoft Teams, SharePoint Online, OneDrive, and Microsoft Copilot. Exchange Online and OneDrive are both in this group.

B is incorrect: Microsoft Intune is a tool that admins use to configure baseline policies, such as device access. It isn't listed as a core service component.

D is incorrect: Microsoft Purview is a tool that admins use to configure baseline policies, such as content protection. It isn't listed as a core service component.

Learn more in Microsoft Learn

Q012 - Question

A new administrator needs one web-based portal to manage users, services, configurations, and health across the organization's Microsoft 365 tenant. Which tool should the administrator use?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

D is correct.

Explanation: The Microsoft 365 admin center is the central hub for managing users, services, configurations, and health in your Microsoft 365 environment. It's a web-based portal at https://admin.microsoft.com, and it provides a unified interface for managing your tenant.

A is incorrect: Microsoft Purview is a tool for configuring baseline policies, such as content protection. It isn't the unified interface for managing users and tenant health.

B is incorrect: Microsoft Intune is a tool for configuring baseline policies, such as device access. It isn't the central hub for managing users, services, and health.

C is incorrect: SharePoint Online is a collaboration and content management service. It isn't the portal for managing the tenant.

Learn more in Microsoft Learn

Q013 - Question

A company is planning the initial setup of the Microsoft 365 services that support workplace communication, collaboration, and content management. Which set of services should the plan include?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

B is correct.

Explanation: Exchange Online, Teams, and SharePoint Online form the backbone of workplace communication, collaboration, and content management. Their initial setup prepares the organization for secure, efficient, and scalable operations.

A is incorrect: Microsoft Entra, Microsoft Purview, and Microsoft Intune are tools for configuring baseline security and compliance policies. They aren't the core collaboration services.

C is incorrect: The Microsoft 365 admin center is a management portal, not a collaboration service. OneDrive and Microsoft Copilot aren't listed as the core collaboration services in this group.

D is incorrect: Microsoft Intune is a policy tool, not a collaboration service. This set also leaves out Exchange Online and SharePoint Online.

Learn more in Microsoft Learn

Q014 - Question

An administrator must configure baseline policies for device access, conditional access, and content protection across Exchange Online, SharePoint Online, and Microsoft Teams. Which set of tools should the administrator use?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

C is correct.

Explanation: Microsoft Entra, Microsoft Purview, and Microsoft Intune are the primary tools that Microsoft 365 admins use to configure baseline policies for device access, conditional access, and content protection.

A is incorrect: Exchange Online, SharePoint Online, and Microsoft Teams are the services that the policies apply to. They aren't the tools that you use to define the policies.

B is incorrect: These items aren't the primary tools for baseline security and compliance policies. OneDrive and Microsoft Copilot are core service components.

D is incorrect: This set includes Microsoft Purview, but it leaves out Microsoft Entra and Microsoft Intune. Microsoft Teams and OneDrive are collaboration services, not policy tools.

Learn more in Microsoft Learn

Q015 - Question

An organization uses Role-Based Access Control (RBAC) to delegate Microsoft 365 administration. A new administrator will manage one specific set of tasks. How should the organization assign permissions to this administrator?

Domain: Identify the core features and objects of Microsoft 365 services (30–35%) Type: Single choice

A is correct.

Explanation: RBAC in Microsoft 365 is built on the principle of least privilege. Grant each administrator only the permissions needed to perform their specific tasks.

B is incorrect: Broad permissions for every administrator don't follow least privilege. RBAC limits each administrator to the access their role requires.

C is incorrect: Starting with all permissions gives the administrator more access than needed. Least privilege grants only the necessary access from the start.

D is incorrect: Permissions for possible future tasks go beyond what the administrator needs now. This approach doesn't follow least privilege.

Learn more in Microsoft Learn

Q016 - Question

A creator in Copilot Studio started a Copilot Chat agent from a template. The creator then customized the instructions and added several SharePoint knowledge sources. The creator now wants to switch to a different template to compare its structure. What should the creator know before switching templates?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

C is correct.

Explanation: A template provides a starting structure. If you switch templates, the configuration resets and your customizations are replaced. Record your instructions and knowledge sources before you switch.

A is incorrect: The template does not merge with your changes. Switching templates replaces your customizations.

B is incorrect: The Describe tab and the Configure tab are synchronized, so a change does not apply to only one tab.

D is incorrect: Switching templates resets the configuration. It does not keep your customizations and change only the icon.

Learn more in Microsoft Learn

Q017 - Question

A project manager has Read permissions on a SharePoint document library. The project manager wants to create a SharePoint agent that is scoped to that library. What should you verify first?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

A is correct.

Explanation: To create a SharePoint agent, you need Edit permissions or higher for the relevant site or document library. Read permissions are not enough.

B is incorrect: You use the Copilot agent tool in SharePoint to create SharePoint agents. You use Copilot Studio to create Copilot Chat agents.

C is incorrect: Use the fewest permissions needed. Reserve the Global Administrator role for emergencies.

D is incorrect: This option creates a Copilot Chat agent in Copilot Studio, not a SharePoint agent scoped to the library.

Learn more in Microsoft Learn

Q018 - Question

A department lead already uses Copilot Chat. The lead now needs to build, publish, and manage agents in Copilot Studio for the team. Which two items should you verify for this user? Each correct answer presents part of the solution.

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Multiple choice

B and D are correct.

Explanation: To create and manage agents in Copilot Studio, a user needs Copilot Studio licensing and the correct environment role in Power Platform. Verify both the license and a role such as Environment Maker.

A is incorrect: Copilot Chat access does not grant rights to build, publish, or manage agents.

C is incorrect: Edit permissions on a site are a requirement to create a SharePoint agent. They do not grant rights to build and manage agents in Copilot Studio.

Learn more in Microsoft Learn

Q019 - Question

Your organization is setting up an approval process for agent requests. A staff member will review submitted agents in the Microsoft 365 admin center and approve, reject, or request revisions. You must use the fewest permissions. Which role should you assign?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

D is correct.

Explanation: The AI Administrator role manages agents in the Microsoft 365 admin center. Use the fewest permissions needed for the review task.

A is incorrect: Reserve the Global Administrator role for emergencies. It grants more permissions than this task requires.

B is incorrect: Environment Maker is a Power Platform environment role that supports agent creation. It is not the role used to manage agents in the Microsoft 365 admin center.

C is incorrect: SharePoint Edit permissions let a user create a SharePoint agent. They do not let a user review agent requests in the Microsoft 365 admin center.

Learn more in Microsoft Learn

Q020 - Question

A seasonal sales agent is no longer needed for the rest of the year. Users must stop using the agent now. The business might reuse the agent next season, so it must stay in the agent inventory. What should you do?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

B is correct.

Explanation: Retirement can take two forms. You can block users from using the agent, or you can remove the agent from the agent inventory. Blocking stops use and keeps the agent in the inventory.

A is incorrect: Removing the agent deletes it from the agent inventory, so you cannot reuse it next season.

C is incorrect: Monitoring tracks adoption and performance, but it does not stop users from using the agent.

D is incorrect: Switching templates resets the configuration and replaces customizations. It does not block users, and it removes the setup you want to reuse.

Learn more in Microsoft Learn

Q021 - Question

Your organization wants the Marketing department to use Copilot with usage-based billing instead of full licenses. You create a billing policy that links an Azure subscription, scopes the policy to the Marketing group, and sets a budget with alerts. Consumption billing is still not active for Marketing users. What should you do next?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

C is correct.

Explanation: Pay-as-you-go billing requires two steps. First, create the billing policy. Second, connect that policy to a Copilot service on the Pay-as-you-go services tab. Connecting the policy activates consumption billing for the scoped users.

A is incorrect: Individual license assignment gives users full licenses. The requirement is usage-based billing, not permanent licenses.

B is incorrect: A larger budget doesn't activate billing. The existing policy still must be connected to a Copilot service.

D is incorrect: Group-based licensing assigns full licenses through Active groups. It doesn't complete the pay-as-you-go configuration.

Learn more in Microsoft Learn

Q022 - Question

Your pay-as-you-go Copilot charges increased sharply last week. Finance asks you to find which departments caused the increase and when it started, so you can decide whether to tighten restrictions. What should you use?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

D is correct.

Explanation: Azure Cost Management provides detailed cost analysis with filters, grouping, and time granularity. Use daily granularity to find when the spike started. Group by department to find which departments caused it. Then adjust your billing decisions.

A is incorrect: Invoices show billed amounts. They don't provide grouping by department or daily analysis to investigate an anomaly.

B is incorrect: Subscription information shows what the organization has purchased. It doesn't break down pay-as-you-go costs by department over time.

C is incorrect: License assignments show who has licenses. They don't show pay-as-you-go consumption costs.

Learn more in Microsoft Learn

Q023 - Question

You plan to publish the Viva Insights Copilot Dashboard so department managers can review Copilot adoption. You must protect individual privacy and control who can view the data. Which two settings should you configure before you publish the dashboard? Each correct answer presents part of the solution.

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Multiple choice

B and D are correct.

Explanation: Configure privacy and access settings before you publish dashboards. A minimum group size protects individual privacy in reported data. Insights roles control who can view the dashboard.

A is incorrect: CSV exports support reporting and long-term history. They don't set privacy thresholds or dashboard access.

C is incorrect: Use least privilege. Global Administrator grants far more access than managers need to view adoption data.

Learn more in Microsoft Learn

Q024 - Question

A sales team shares a scheduled Copilot prompt that contains customer account numbers typed directly into the prompt text. You need to reduce the risk of exposing this data while keeping the prompt reusable. What should you do?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

A is correct.

Explanation: Don't embed sensitive data directly in prompts. Have prompts refer to secure data sources where Microsoft 365 permissions enforce access. Train users on this practice so the prompt stays reusable without exposing data.

B is incorrect: Wider sharing increases exposure. Limit prompt sharing to trusted groups.

C is incorrect: Naming conventions and descriptions reduce duplication and inconsistent results. They don't remove the sensitive data from the prompt.

D is incorrect: Deleting all prompts removes reusable workflows that the organization uses. It doesn't address the specific data protection issue.

Learn more in Microsoft Learn

Q025 - Question

An IT staff member is responsible only for assigning and removing Microsoft 365 Copilot licenses. You must follow the principle of least privilege with Microsoft Entra role-based access control. Which role should you assign?

Domain: Perform basic administrative tasks for Copilot and agents (25–30%) Type: Single choice

B is correct.

Explanation: Assign roles that match responsibilities. The staff member manages licenses only, so License Administrator matches this responsibility and follows least privilege.

A is incorrect: Organizations shouldn't rely on the Global Administrator role. It grants more access than license management requires.

C is incorrect: Compliance Administrator matches compliance responsibilities, not license assignment.

D is incorrect: Helpdesk Administrator matches support responsibilities, not license management.

Learn more in Microsoft Learn

Q026 - Question

A healthcare organization stores large volumes of data in Microsoft 365. Leadership is concerned about data leaks, noncompliance with HIPAA and GDPR, and internal misuse of sensitive information. They want one unified solution for data governance, information protection, and compliance management across Microsoft 365 and beyond. Which solution should you recommend?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

B is correct.

Explanation: Microsoft Purview is Microsoft's unified solution for data governance, information protection, and compliance management across Microsoft 365 and beyond. It addresses risks such as data leaks, regulatory noncompliance, and internal misuse of sensitive information.

A is incorrect: Microsoft Graph is the centralized data-access layer for Microsoft 365. It enforces access-control checks on queries, but it isn't the governance and compliance solution.

C is incorrect: SharePoint Admin Center provides sharing reports for SharePoint content. It doesn't provide unified governance and compliance management across Microsoft 365 and beyond.

D is incorrect: Microsoft 365 Copilot helps users work with content stored across Microsoft 365 services. It inherits the user's access controls and isn't a governance solution.

Learn more in Microsoft Learn

Q027 - Question

Your organization adopted hybrid work, cloud storage, and AI-enabled workplace tools. The security team wants to evaluate the Microsoft Purview capabilities that support compliance, data protection, and insider risk in Microsoft 365. Which set of capabilities should the team evaluate?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

C is correct.

Explanation: Within Microsoft 365, Microsoft Purview provides a unified platform for compliance, data protection, and insider risk. It includes Insider Risk Management, Data Loss Prevention (DLP), Communication Compliance, and Activity Explorer.

A is incorrect: Microsoft Graph, PowerShell, and SharePoint sharing reports help audit and report on access. They aren't the Purview capabilities for insider risk and data protection.

B is incorrect: Microsoft 365 Copilot is a productivity tool that inherits user permissions. Microsoft Graph is a data-access layer. Neither is a Purview insider risk capability.

D is incorrect: The admin centers and Microsoft Graph API support sharing reports and access audits. They don't make up the Purview set for compliance, data protection, and insider risk.

Learn more in Microsoft Learn

Q028 - Question

A compliance officer must report the organization's posture against a specific regulation. The officer needs a structured assessment that separates Microsoft-managed and customer-managed controls, lists improvement actions, and shows a score. Which Microsoft Purview tool should the officer use?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

D is correct.

Explanation: Compliance Manager provides structured assessments tailored to regulations. These assessments include Microsoft-managed and customer-managed controls, improvement actions, and a Compliance Score.

A is incorrect: Data Explorer helps you discover, visualize, filter, and analyze sensitive information across locations. It doesn't provide regulation-based assessments or a Compliance Score.

B is incorrect: eDiscovery Standard provides search, export, and legal holds for legal requests and investigations. It doesn't measure compliance posture against a regulation.

C is incorrect: Data Security Posture Management for AI provides visibility into AI interactions and shadow AI usage. It doesn't provide regulation-based assessments with improvement actions.

Learn more in Microsoft Learn

Q029 - Question

An admin needs to find where sensitive information is stored across SharePoint, Teams, and OneDrive. The admin wants to visualize the results, filter by location, and analyze the findings before planning protection controls. Which Microsoft Purview tool should the admin use?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

A is correct.

Explanation: Data Explorer helps admins discover, visualize, filter, and analyze sensitive information across locations such as SharePoint, Teams, and OneDrive.

B is incorrect: Compliance Manager assesses compliance posture with regulation-based controls, improvement actions, and a Compliance Score. It doesn't map sensitive information across locations.

C is incorrect: eDiscovery Premium adds case management, review sets, analytics, and redaction for legal investigations. Use it for legal matters, not for general sensitive data discovery.

D is incorrect: Content Search locates and preserves information for legal requests, audits, and investigations. It isn't the tool for visualizing and analyzing sensitive information across locations.

Learn more in Microsoft Learn

Q030 - Question

Employees use several AI tools at work, and some of these tools aren't approved by IT. The data security team needs visibility into AI interactions, a way to identify shadow AI usage, and controls that protect sensitive data in AI scenarios. Which Microsoft Purview capability should the team use?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

C is correct.

Explanation: Microsoft Purview Data Security Posture Management for AI provides visibility into AI interactions. It helps identify shadow AI usage and supports controls that protect sensitive data in AI scenarios.

A is incorrect: Compliance Manager provides regulation-based assessments and a Compliance Score. It doesn't identify shadow AI usage.

B is incorrect: eDiscovery Standard provides search, export, and legal holds for investigations. It doesn't provide visibility into AI interactions.

D is incorrect: Data Explorer discovers and analyzes sensitive information across locations such as SharePoint, Teams, and OneDrive. It isn't focused on AI interactions or shadow AI.

Learn more in Microsoft Learn

Q031 - Question

A legal team responds to a complex litigation request. Search, export, and legal holds aren't enough. The team also needs case management, review sets, analytics, and redaction of sensitive content before production. Which option should you recommend?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

B is correct.

Explanation: eDiscovery Premium adds case management, review sets, analytics, and redaction to the search, export, and legal hold capabilities of eDiscovery Standard.

A is incorrect: eDiscovery Standard provides search, export, and legal holds. It doesn't include review sets, analytics, or redaction.

C is incorrect: Compliance Manager assesses compliance posture against regulations. It doesn't manage legal cases or redact content.

D is incorrect: Data Explorer discovers and analyzes sensitive information across locations. It doesn't provide case management or review sets for litigation.

Learn more in Microsoft Learn

Q032 - Question

A SharePoint Online admin reviews sharing activity for a finance site. Which two findings should the admin flag as oversharing? Each correct answer presents a complete solution.

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Multiple choice

B and D are correct.

Explanation: Oversharing occurs when users grant broader access to SharePoint content than is appropriate or intended. Examples include sharing with Anyone with the link and granting edit access when view-only access is sufficient.

A is incorrect: View-only access for the specific colleagues who need to read the file matches the intended access. It doesn't grant broader access than required.

C is incorrect: Restricting the site to finance team members who need edit access limits access to the intended audience. This isn't oversharing.

Learn more in Microsoft Learn

Q033 - Question

Your organization has thousands of SharePoint Online sites. The governance team wants to audit access programmatically across all sites to find risky sharing at scale. Which approach should you recommend?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

A is correct.

Explanation: PowerShell and the Microsoft Graph API can audit SharePoint access at scale. The Microsoft 365 Admin Center and SharePoint Admin Center also provide sharing reports.

B is incorrect: Compliance Manager assesses compliance posture against regulations. It doesn't audit sharing permissions across SharePoint sites.

C is incorrect: eDiscovery Standard legal holds preserve content for legal requests and investigations. A hold doesn't audit or remediate risky sharing.

D is incorrect: Copilot only sees what each signed-in user can already access. User prompts don't provide an organization-wide access audit.

Learn more in Microsoft Learn

Q034 - Question

A user asks Microsoft 365 Copilot to summarize a document stored in a SharePoint site. The user doesn't have permission to access that site. How does Copilot handle the document?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

D is correct.

Explanation: Copilot accesses data through Microsoft Graph by using the signed-in user's identity and permissions. It can only see information the user is already allowed to see and can't bypass existing file permissions.

A is incorrect: Copilot operates within Microsoft Purview compliance boundaries. These boundaries don't grant access to content the user can't already access.

B is incorrect: Copilot inherits the access controls of the authenticated user. It doesn't use a separate identity to bypass those controls.

C is incorrect: Microsoft Graph enforces access-control checks at every query. A user without permission to the document doesn't get access to it through Graph.

Learn more in Microsoft Learn

Q035 - Question

A security architect is reviewing a Microsoft 365 Copilot deployment. The architect needs to identify the layer that Copilot uses to retrieve Microsoft 365 data and that enforces access-control checks at every query. Which layer should the architect identify?

Domain: Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%) Type: Single choice

A is correct.

Explanation: Copilot's data retrieval operates through Microsoft Graph. Microsoft Graph is the centralized data-access layer for Microsoft 365 and enforces access-control checks at every query.

B is incorrect: Compliance Manager provides regulation-based assessments and a Compliance Score. It isn't the data-access layer that Copilot uses.

C is incorrect: Data Explorer helps admins discover and analyze sensitive information. It doesn't enforce access checks on Copilot queries.

D is incorrect: SharePoint Admin Center sharing reports help admins review sharing. They don't retrieve data for Copilot or enforce per-query access checks.

Learn more in Microsoft Learn

← Read the full AB-900 study guide