Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You need to ensure that a user named User1 can review audit reports from the Microsoft 365 security center. User1 must be prevented from tracing messages from the Security admin center.
Solution: You assign the Reports reader role to User1.
Does this meet the goal?
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.

Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username: [email protected]
Microsoft 365 Password: xxxxxx
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only.
Lab Instance: XXXXXX
You need to ensure that all email messages in the mailbox of a user named Pradeep Gupta are retained for 90 days.
To complete this task, sign in to the Microsoft 365 admin center.
Explanation:
Go to the Microsoft 365 admin center and then click Users > Active users.
Select Pradeep Gupta.
On the properties flyout page, click the Mail tab, and then under More actions, click Manage litigation hold.

On the Manage litigation hold flyout page, select the Turn on litigation hold checkbox and then enter the following optional information:
Click Save changes on the Litigation hold flyout page to create the hold.
The system displays a banner saying it might take up to 240 minutes for the change to take effect.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-a-litigation-hold?view=o365-worldwide
You have a hybrid deployment between a Microsoft Exchange Online tenant and on-premises Exchange Server 2019 organization. The on-premises organization contains several Exchange Server 2019 servers.
You discover that delivery fails for all email messages sent from the on-premises organization to Microsoft 365.
You discover that the certificate for an on-premises Exchange server expired.
You need to resolve the issue as quickly possible. The solution must minimize administrative effort.
What should you do on the on-premises Exchange server?
Your company has a Microsoft Exchange Server 2019 hybrid deployment.
The company has a finance department.
You need to move all the on-premises mailboxes of the finance department to Exchange Online. The bulk of the move operation must occur during a weekend when the company's Internet traffic is lowest. The move must then be finalized the following Monday. The solution must minimize disruption to end users.
What should you do first?
You have a Microsoft 365 subscription that contains two users named User1 and User2.
User1 reports to have received a suspicious email message that appears to have come from User2.
You identify that the message was sent by an external user impersonating User2.
You need to block email that contains the email address of an impersonated sender.
What should you configure?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company has a Microsoft 365 subscription.
Several users in the finance department of the company recently accessed unsafe websites by clicking on links in email messages.
Users in the marketing department of the company report that they must be able to access all the links embedded in email messages.
You need to reduce the likelihood of the finance department users accessing unsafe websites. The solution must affect only the finance department users.
Solution: You create a new safe attachments policy.
Does this meet the goal?
Your company has a Microsoft Exchange Server 2019 hybrid deployment.
Users in the advertising department and the editorial department of the company have mailboxes in Exchange Online.
A company policy requires that the advertising department users and the editorial department users be segmented based on the following requirements:
The advertising department users must not see the editorial department users in the global address list (GAL).
The editorial department users must not see the advertising department users in the GAL.
The editorial department users must be treated as external recipients of the advertising department users.
The advertising department users must be treated as external recipients of the editorial department users.
You need to recommend a solution that meets the requirements and minimize costs and effort.
What should you recommend?
You need to configure a hybrid deployment between a Microsoft Exchange Online tenant and an on-premises Exchange Server 2019 organization that contains a server named Server! The solution must meet the following requirements:
* Support remote move migrations of mailboxes from Server! to Exchange Online.
* Enable free/busy lookups between Server 1 and Exchange Online.
What should you do for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company has a Microsoft Exchange Server 2019 hybrid deployment that contains two Mailbox servers named MBX1 and MBX2.
The company has the departments shown in the following table.

From the on-premises organization, outbound email is sent directly to the Internet by using DNS lookups.
You are informed that some sales department users send email messages that are identified as spam.
You need to automatically block the sales department users from repeatedly sending spam.
Solution: You modify the outbound spam filter policy in Exchange Online.
Does this meet the goal?
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.

Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username: [email protected]
Microsoft 365 Password: xxxxxx
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only.
Lab Instance: XXXXXX
Users report that email disclaimers are no longer being appended to email messages sent to external recipients.
You need to ensure that all email sent to external recipients contains your corporate disclaimer.
To complete this task, sign in to the Microsoft 365 admin center.
Explanation:
In the Microsoft 365 admin center, choose Admin centers > Exchange.
Open the EAC and go to Mail flow > Rules.
Click Add +, and then click Apply disclaimers.

In the New rule window that appears, enter a unique name the rule.
In the Apply this rule if box, select the conditions for displaying the disclaimer. For example, select The recipient is located condition, and then select Outside the organization. If you want this rule to apply to every message that enters or leaves your organization, select [Apply to all messages].
Next to the Do the following box, select Enter text to enter the text of your disclaimer.
Click Select one, and select one of the Fallback options if the disclaimer can't be added.
Specify the audit severity level to assign the severity level that appears in the message log.
Select the mode for the rule. Select Enforce to turn on the disclaimer immediately, or select Test without Policy Tips to put a message in the message tracking log instead of adding the disclaimer.
If you have additional conditions or exceptions that you want to add, select More options at the bottom of the page, which will show additional settings. For example, to add the exception that prevents multiple disclaimers being added in an email conversation, select Add exception and then select The subject or body > Subject or body matches these text patterns, and then specify the words or phrases in your disclaimer. Or, to put your disclaimer at the top of the email message instead of the bottom, in Do the following, select Apply a disclaimer to the message > prepend a disclaimer.
11. When you're finished, click Save.
Reference:
https://docs.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/disclaimers-signatures-footers-or-headers
You have a Microsoft Exchange Online tenant that contains a user named User1. User1 must perform the following tasks:
* Manage audit logs.
* Track email messages in the Exchange organization.
* Manage transport rules for the Exchange organization.
You need to recommend to which role group to add User1. The solution must follow the principle of least privilege. What should you recommend?
You have a Microsoft 365 subscription that has Microsoft Defender for Office 365 enabled and contains two groups named Group1 and Group 2. The members of the groups must meet the requirements shown in the following table.

You need to configure threat protection policies to meet the requirements.
Which threat protection policy should you configure for each group? To answer, drag the appropriate policies to the correct groups. Each policy may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each coned selection is worth one point.


You have a Microsoft Exchange Server 2019 hybrid deployment that contains the users shown in the following table.

You need to provide each user with an archive mailbox that is stored in Exchange Online.
Which admin center should you use to perform the configuration for each user? To answer, drag the appropriate admin centers to the correct users. Each admin center may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.


Reference:
https://docs.microsoft.com/en-us/office365/securitycompliance/enable-archive-mailboxes
https://docs.microsoft.com/en-us/exchange/hybrid-deployment/create-cloud-based-archive