70-346.examcollection - Premium.exam.110q: Number: 70-346 Passing Score: 800 Time Limit: 120 Min File Version: 9.0
70-346.examcollection - Premium.exam.110q: Number: 70-346 Passing Score: 800 Time Limit: 120 Min File Version: 9.0
110q
Number: 70-346
Passing Score: 800
Time Limit: 120 min
File Version: 9.0
70-346
Version 9.0
Exam A
QUESTION 1
A company migrates to Office 365. 2,000 active users have valid Office 365 licenses assigned.
An additional 5,000 user accounts were created during the migration and testing processes.
These users do not have any licenses assigned.
You need to remove the Office 365 user accounts that do not have any licenses assigned by using the least amount of administrative effort.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/dn194133.aspx
QUESTION 2
DRAG DROP
Litware Inc. has an Office 365 Enterprise El plan. Employees have access to all Office 365 services.
Employees in the human resources (HR) department must continue to use the on-premises SharePoint 2013 deployment due to legal requirements.
You need to disable access to SharePoint Online for all HR department employees.
How should you complete the relevant Windows PowerShell commands? To answer, drag the appropriate Windows PowerShell segment to the correct location or
locations in the answer area. Each Windows PowerShell segment may be used once, more than once, or not at all. You may need to drag the split bar between panes
or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 3
HOTSPOT
A company deploys an Office 365 tenant.
You prepare to use the bulk add tool to add users to Office 365.
You need to prepare a file to use with the bulk add tool.
Which fields must you include in the file? To answer, drag the appropriate response to each field. Each response may be used once, more than once, or not at all. You
may need to drag the split bar between panes or scroll to view content.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 4
DRAG DROP
A company has 50 employees that use Office 365.
How should you complete the relevant Windows PowerShell command? To answer, drag the appropriate Windows PowerShell segment to the correct location or
locations. Each Windows PowerShell segment may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view
content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 5
DRAG DROP
You are the Office 365 administrator for your company. Your company uses Office 365 for collaboration.
You must reset the password for all of the employees in your company.
You need to ensure that all employees create a new password the next time they sign in to Office 365.
How should you complete the relevant Windows PowerShell command? To answer, drag the appropriate Windows PowerShell segment to the correct location or
locations. Each Windows PowerShell segment may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view
content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 6
You are the Office 365 administrator for your company.
You must use Windows PowerShell to manage cloud identities in Office 365. You must use a computer that runs Windows 8 to perform the management tasks.
You need to ensure that the Windows 8 computer has the necessary software installed.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/magazine/hh750396.aspx
QUESTION 7
DRAG DROP
You are the Office 365 administrator for your company. The company has two administrators named User1 and User2.
Users must be able to perform the activities as shown in the following table:
What should you do? To answer, drag the appropriate role to the correct user. Each role may be used once, more than once, or not at all. You may need to drag the
split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 8
DRAG DROP
A company deploys an Office 365 tenant.
You need to enable multi-factor authentication for Office 365.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/library/dn249466.aspx
QUESTION 9
DRAG DROP
Contoso Ltd. plans to use Office 365 services for collaboration between departments. Contoso has one Active Directory Domain Services domain named
contoso.local. You deploy the Windows Azure Active Directory Sync tool.
You need to synchronize only the user accounts that have valid routable domain names and are members of specified departments.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Section: (none)
Explanation
Explanation/Reference:
QUESTION 10
An organization plans to migrate to Office 365. You use the Windows Azure Active Directory (AD) Sync tool.
Several users will not migrate to Office 365. You must exclude these users from synchronization. All users must continue to authenticate against the on-premises
Active Directory.
Which three actions should you perform to ensure users excluded from migration are not synchronized? Each correct answer presents part of the solution.
Explanation/Reference:
QUESTION 11
You use a centralized identity management system as a source of authority for user account information. You export a list of new user accounts to a file on a daily
basis. Your company uses a local Active Directory for storing user accounts for on-premises solutions. You are configuring the Windows Azure Active Directory Sync
tool.
New user accounts must be created in both the local Active Directory and Office 365. You must import user account data into Office 365 daily.
You need to import the new users. What should you do?
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 12
DRAG DROP
An organization plans to deploy an Office 365 tenant. The company has two servers named SERVER1 and SERVER2. SERVER1 is a member server of the Active
Directory forest that you are synchronizing. SERVER2 is a standalone server. Both servers run Windows Server 2012.
You need to use the Windows Azure Active Directory Sync tool to provision users.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/jj151831.aspx
QUESTION 13
An organization deploys an Office 365 tenant.
User accounts must be synchronized to Office 365 by using the Windows Azure Active Directory Sync tool.
You need to ensure that the user accounts will be synchronized. Which user accounts will be synchronized?
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Explanation:
After deploying ADFS tenant password policies are handled by the local Active Directory Environment, and not Office 365 Azure. All users will be synchronized and will
utilize the AD DS six character long password policy.
Reference: http://howdouc.blogspot.ca/2011/04/active-directory-federation-services.html
QUESTION 14
Contoso, Ltd. plans to use Office 365 for email services and Lync Online. Contoso has four unique domain names.
Which two domain names should you exclude from the migration? Each correct answer presents part of the solution.
A. contoso.us
B. contoso
C. contoso.local
D. contoso.co
Correct Answer: BC
Section: (none)
Explanation
Explanation/Reference:
Explanation:
contoso.us - valid TLD Domain
contoso.co - valid TLD Domain
contoso - single labeled domain - not valid
contoso.local - internal labeled domain - not valid
QUESTION 15
HOTSPOT
An organization prepares to migrate to Office 365. The organization has one domain controller named NYC-DC1 and one server named NYC-DS that is designated as
the directory synchronization computer.
You must upgrade each server to meet only the minimum requirements by using the least amount of administrative effort.
You need to ensure that you can use the Windows Azure Active Directory Sync tool to synchronize the local Active Directory with Office 365.
What should you do? Select the correct action from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: http://msdn.microsoft.com/en-us/library/azure/jj151831.aspx#BKMK_ComputerRequirements
QUESTION 16
You are the Office 365 administrator for your company. The company synchronizes the local Active Directory objects with a central identity management system.
The environment has the following characteristics:
Each department has its own organizational unit (OU).
The company has OU hierarchies for partner user accounts. All user accounts are maintained by the identity management system.
You need to ensure that partner accounts are NOT synchronized with Office 365.
A. Configure OU-based filtering by using the Windows Azure Active Directory Sync tool.
B. In the Windows Azure Active Directory portal, configure OU-based filtering.
C. Configure user attribute-based filtering by using the Windows Azure Active Directory Sync tool.
D. In the Windows Azure Active Directory portal, configure user attribute-based filtering.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/jj710171.aspx
Company has OU hierarchies for partner user accounts so OU-based filtering should be fine.
QUESTION 17
An organization prepares to implement Office 365.
You need to determine the organization's readiness for the Office 365 implementation.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 18
DRAG DROP
A company plans to implement an Office 365 environment to manage email.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: http://office.microsoft.com/en-gb/office365-suite-help/add-your-domain-to-office-365-HA102818660.aspx
QUESTION 19
A company plans to use Office 365 to provide email services for users.
A. Add the custom domain name to Office 365 and then verify it.
B. Verify the existing domain name.
C. Create an MX record in DNS.
D. Create a CNAME record in DNS.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 20
You create an Office 365 tenant. You assign administrative roles to other users. You hire a new user named User2.
A. Service administrator
B. Global administrator
C. Delegate administrator
D. Password administrator
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Reference:
https://support.office.com/en-US/Article/Assigning-admin-roles-eac4d046-1afd-4f1a-85fc- 8219c79e1504?ui=en-US&rs=en-US&ad=US#__choose_an_admin
QUESTION 21
HOTSPOT
You are the Office 365 administrator for your company.
User1 leaves the company. You must delete the account for User1.
In the table below, identify when each type of data will be deleted. Make only one selection in each column. Each correct selection is worth one point.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 22
HOTSPOT
A company has an Active Directory Domain Service (AD OS) domain. All servers run Windows Server 2008. You have an on-premises Exchange 2010 server.
In the table below, identify the required action for each phase of the pilot. Make only one selection in each column. Each correct selection is worth one point.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 23
DRAG DROP
You are the Office 365 administrator for your company. The company has Office 365 Enterprise E3 licenses for each of its 250 employees. The company does not
allow email or Lync Online licenses to be assigned to external contractors.
User1 is an external contractor who requires access to SharePoint and Office Web Apps only.
You need to add a license for User1's account.
What should you do? To answer, drag the appropriate action to the correct location or locations. Each action may be used once, more than once, or not at all. You
may need to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 24
DRAG DROP
A company is deploying an Office 365 tenant.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/dn528856.aspx
QUESTION 25
You are the Office 365 administrator for your company. You have a server that runs Windows Server 2012. You plan to install an Active Directory Federation Services
(AD FS) proxy server.
Which two roles should you install and configure? Each correct answer presents part of the solution.
Correct Answer: AD
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/dd807096.aspx
QUESTION 26
Contoso Ltd. uses Office 365 for collaboration. You are implementing Active Directory Federation Services (AD FS) for single sign-on (SSO) with Office 365 services.
The environment contains an Active Directory domain and an AD FS federation server.
You need to ensure that the environment is prepared for the AD FS setup.
Which two actions should you perform? Each correct answer presents part of the solution.
Correct Answer: AC
Section: (none)
Explanation
Explanation/Reference:
QUESTION 27
You are the Office 365 administrator for your company. You prepare to install Active Directory Federation Services (AD FS).
You need to open the correct port between the AD FS proxy server and the AD FS federation server.
A. TCP 80
B. TCP 135
C. TCP 389
D. TCP 443
E. TCP 636
F. TCP 1723
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 28
You are the Office 365 administrator for your company. The company has a single office.
A. 2
B. 4
C. 6
D. 16
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 29
DRAG DROP
A company has a Windows Server 2008 domain controller and a SharePoint 2007 farm. All servers on the network run Windows Server 2008.
You must provide single sign-on for Office 365 SharePoint sites from the company's network.
What should you install? To answer, drag the appropriate action to the correct location. Each answer may be used once, more than once, or not at all. You may need
to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference:
http://technet.microsoft.com/en-us/library/cc771145.aspx
QUESTION 30
You are the Office 365 administrator for your company.
Which two certificates should you install? Each correct answer presents part of the solution.
Correct Answer: AC
Section: (none)
Explanation
Explanation/Reference:
QUESTION 31
A company deploys an Office 365 tenant.
You need to configure single sign-on (SSO) for all user accounts.
Which two actions should you perform? Each correct answer presents part of the solution.
Correct Answer: CF
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/dn194092.aspx
QUESTION 32
HOTSPOT
An organization deploys an Office 365 tenant.
You need to report the status of service interruptions for Exchange Online and SharePoint Online.
Use the drop-down menus to complete each statement based on the information presented in the screen shot. Each correct selection is worth one point.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
References: http://office.microsoft.com/en-in/office365-suite-help/view-the-status-of-your-services-HA102817837.aspx#_Status_icon_descriptions
http://technet.microsoft.com/en-us/library/office-365-service-continuity.aspx
QUESTION 33
You are the Office 365 administrator for your company.
Users report that they have received significantly more spam messages over the past month than they normally receive.
You need to analyze trends for the email messages received over the past 60 days.
From the Office 365 admin center, what should you view?
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 34
HOTSPOT
The legal department in your organization creates standardized disclaimers for all of their email messages. The disclaimers explain that any transmissions that are
received in error should be reported back to the sender. You track any confidential documents that are attached to email messages.
Your security team reports that an employee may have mistakenly sent an email message that contained confidential information.
You need to identify whether the email message included the disclaimer and whether it contained confidential information.
Which two options should you configure? To answer, select the appropriate objects in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 35
A company deploys an Office 365 tenant in a hybrid configuration with Exchange Server 2013.
Office 365 users cannot see free/busy information that is published from the on-premises Exchange Server. In addition, Exchange Server users cannot see free/busy
information that is published from Office 365.
You need to troubleshoot why users cannot access free/busy information from both Office 365 and Exchange Server 2013.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 36
You are the Office 365 administrator for your company.
Users report that they cannot sign in to Lync from their mobile devices, but they are able to send and receive Lync messages by using their laptop computers.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 37
An organization migrates to Office 365.
The Office 365 administrator must be notified when Office 365 maintenance activities are planned.
You need to configure the administrator's computer to receive the notifications.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Reference:
https://support.office.com/en-us/article/View-the-status-of-your-services-932ad3ad-533c-418a- b938-6e44e8bc33b0
QUESTION 38
Your company deploys an Office 365 tenant.
You need to ensure that you can view service health and maintenance reports for the past seven days.
What are two possible ways to achieve this goal? Each correct answer presents a complete solution.
A. Run the Microsoft Online Services Diagnostics and Logging (MOSDAL) Support Kit.
B. View the service health current status page of the Office 365 admin center.
C. View the service settings page of the Office 365 admin center.
D. Subscribe to the Office 365 Service Health RSS Notifications feed.
Correct Answer: BD
Section: (none)
Explanation
Explanation/Reference:
QUESTION 39
DRAG DROP
You implement Office 365 for an organization.
You must create the correct DNS entries needed to configure Office 365.
Which DNS entries should you create? To answer, drag the appropriate DNS record type to the correct purpose. Each DNS record type may be used once, more than
once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 40
You deploy Lync Online for a company that has offices in San Francisco and New York. The two offices both connect to the Internet. There is no private network link
between the offices.
Users in the New York office report that they cannot transfer files to the users in the San Francisco office by using Lync Online.
You need to ensure that users in both offices can transfer files by using Lync Online.
A. Configure the firewall to open Transmission Control Protocol (TCP) ports 50060-50079.
B. Configure the firewall to open Transmission Control Protocol (TCP) ports 50040-50059.
C. Create a private network connection to share files.
D. Upgrade all of the Lync Online clients to use Lync 2013.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 41
A company deploys an Office 365 tenant. You assign the roles to users as shown in the following table:
User3 must be able to monitor the health of the Exchange Online service. You must use the principle of least privilege to assign permissions to User3.
Which three actions should you perform? Each correct answer presents part of the solution.
Explanation/Reference:
Explanation:
Only the global administrator can delegate service administrator role.
Reference: http://onlinehelp.microsoft.com/en-in/office365-enterprises/ff637584.asp
QUESTION 42
HOTSPOT
You are the SharePoint Online administrator for Contoso, Ltd. The company purchases an Office 365 Enterprise El plan.
The public-facing website must use SharePoint Online and the custom domain contoso.com.
You need to configure the DNS settings for the public-facing SharePoint site.
How should you configure the DNS settings? Select the appropriate options from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 43
A company deploys an Office 365 tenant.
You must provide an administrator with the ability to manage company information in Office 365.
You need to assign permissions to the administrator by following the principle of least privilege.
A. Global administrator
B. Service administrator
C. Billing administrator
D. User management administrator
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Explanation:
QUESTION 44
DRAG DROP
A company deploys an Office 365 tenant. All employees use Lync Online.
Which ports must you open? To answer, drag the appropriate port number to the correct feature or features. Each port number may be used once, more than once, or
not at all. You may need to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Explanation:
http://onlinehelp.microsoft.com/en-ca/office365-enterprises/hh416761.aspx
QUESTION 45
DRAG DROP
You are the Office 365 administrator for your company.
You need to ensure that trusted applications can decrypt rights-protected content.
Which four Windows PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and
arrange them in the correct order.
Section: (none)
Explanation
Explanation/Reference:
QUESTION 46
An organization plans to migrate to Office 365.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Explanation:
Reference: http://technet.microsoft.com/en-us/library/hh852542.aspx
QUESTION 47
DRAG DROP
You are the Office 365 administrator for Contoso, Ltd.
You need to change the password for User1 and ensure that the user is prompted to reset her password the next time she signs in.
How should you complete the relevant Windows PowerShell command? To answer, drag the appropriate Windows PowerShell segments to the correct location or
locations. Each Windows PowerShell segment may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view
content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 48
You are the Office 365 administrator for your company. A user named User1 from a partner organization is permitted to sign in and use the Office 365 services.
User1 reports that the password expires in ten days. You must set the password to never expire.
Changes must NOT impact any other accounts.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Reference:
http://onlinehelp.microsoft.com/en-ca/office365-enterprises/hh534387.aspx
QUESTION 49
DRAG DROP
You are the Office 365 administrator for your company.
Users report that their passwords expire too frequently, and they do not receive adequate notice of password expiration.
Account passwords must remain active for the longest duration allowed. Users must receive password expiration notifications as early as possible.
How should you set the policy on the password page of the Office 365 admin center? To answer, drag the appropriate duration to the correct location. Each duration
may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 50
DRAG DROP
A company has 50 employees that use Office 365.
How should you complete the relevant Windows PowerShell commands? To answer, drag the appropriate Windows PowerShell segment to the correct location in the
answer area. Each Windows PowerShell segment may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view
content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 51
DRAG DROP
A company deploys an Office 365 tenant.
All employees in the human resources (HR) department must use multi-factor authentication. They must use only the Microsoft Outlook client to access their email
messages. User1 joins the HR department.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Section: (none)
Explanation
Explanation/Reference:
QUESTION 52
DRAG DROP
You are the Office 365 administrator for your company. You audit the Windows Azure Active Directory Rights Management configuration for the company.
You need to view a log of the recent administrative commands performed against the Microsoft Rights Management Service.
Which three Windows PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of actions to the answer area and
arrange them in the correct order.
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/jj585027.aspx
QUESTION 53
You plan to deploy an Office 365 tenant to multiple offices around the country.
You need to modify the users and groups who are authorized to administer the Rights Management service.
A. Add-MsolGroupMember
B. Get-AadrmRoleBasedAdministrator
C. Remove-AadrmRoleBasedAdministrator
D. Enable-AadrmSuperUserFeature
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 54
An organization plans to deploy Exchange Online.
Which two DNS entries should you create? Each correct answer presents part of the solution.
A. A
B. SRV
C. MX
D. CNAME
Correct Answer: CD
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/hh852557.aspx
QUESTION 55
DRAG DROP
Fabrikam has the Office 365 Enterprise E3 plan.
You must add the domain name fabrikam.com to the Office 365 tenant. You need to confirm ownership of the domain.
Which DNS record types should you use? To answer, drag the appropriate DNS record type to the correct location or locations in the answer area. Each DNS record
type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 56
HOTSPOT
You manage a team of three administrators for an organization that uses Office 365.
You must assign roles for each of the administrators as shown in the table. You must assign the minimum permissions required to perform the assigned tasks.
You need to assign the correct role to each administrator.
Which administrative role should you configure for each user? Select the correct answer from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 57
Your company purchases an Office 365 plan. The company has an Active Directory Domain Services domain.
A. Create an Office 365 tenant and assign User1 the password administrator role.
B. Use a password administrator account to assign the role to User1.
C. Use a user management administrator account to assign the role to User1.
D. Create an Office 365 tenant and assign User1 the global administrator role.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 58
HOTSPOT
A company plans to deploy an Office 365 tenant.
Which port should you use for each application? Select the correct answer from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 59
HOTSPOT
Fabrikam, Inc. employs 500 users and plans to migrate to Office 365.
You must sign up for a trial plan from the Office 365 website. You have the following requirements:
Create the maximum number of trial users allowed.
Convert the trial plan to a paid plan at the end of the trial that supports all of Fabrikam's users.
How should you configure the trial plan? Select the correct answer from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 60
DRAG DROP
A company plans to use Office 365 to provide email services to employees. The company obtains a custom domain name to use with Office 365.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/jj151815.aspx
QUESTION 61
DRAG DROP
Fabrikam Inc. plans to use the domain fabrikam.com for Office 365 user identities, email addresses. Session Initiation Protocol (SIP) addresses, and a public-facing
home page.
Single sign-on (SSO) between Office 365 and the on-premises Active Directory is NOT required.
Which four Windows PowerShell cmdlets should you run in sequence? To answer, move the appropriate actions from the list of actions to the answer area and
arrange them in the correct order.
Section: (none)
Explanation
Explanation/Reference:
Explanation:
Box1. First we need to add the domain.
Box2. Next we need to check the DNS before the domain can be confirmed.
Box3. Now we can confirm the domain.
Box4. Next we can set fabrikam.com as the default domain.
QUESTION 62
You administer the Office 365 environment for a company that has offices around the world. All of the offices use the same Office 365tenant.
You need to ensure that all users can access the services that are available in their regions.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 63
You are the Office 365 administrator for your company. You have a workstation that runs Windows 8.
You need to install the prerequisite components so that you can view mail protection reports on the workstation.
Which two items must you install? Each correct answer presents part of the solution.
Correct Answer: DE
Section: (none)
Explanation
Explanation/Reference:
Reference: http://www.microsoft.com/en-gb/download/details.aspx?id=30716 Required Software:
2. Microsoft Online Services Sign-In Assistant (for Exchange Online Protection customers only)
3. An Office 365 subscription that contains Exchange Online or Exchange Online Protection
QUESTION 64
You are the Office 365 administrator for your company.
Users report that they have received significantly more spam messages over the past month than they normally receive.
You need to analyze trends for the email messages received over the past 60 days.
From the Office 365 admin center, what should you view?
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 65
You are the Office 365 administrator for your company. You configure new user accounts for User1 and User2. User1 has an on-premises mailbox. User2 has an
Office 365 mailbox.
Each user must be able to view the availability of the other user.
You need to ascertain whether users can share their free/busy information.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 66
HOTSPOT
You are the Exchange Online administrator for an organization. The organization migrates all users to Exchange Online. An employee works for a partner organization
named Contoso, Ltd. The employee uses the email alias employeel©contoso.com.
Users report that over the past week, they have not received email messages from [email protected].
You need to trace email messages that originate from [email protected] to users inside your organization.
In the message trace window, which two settings should you configure? To answer, select the appropriate objects in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 67
An organization with an Active Directory Domain Services (AD DS) domain migrates to Office 365. You need to manage Office 365 from a domain-joined Windows
Server 2012 Core server.
Which three components should you install? Each answer presents part of the solution.
Explanation/Reference:
QUESTION 68
An organization purchases an Office 365 plan for 10,000 user accounts. You have a domain controller that runs Windows Server 2008 R2. The forest functional level
is set to Windows Server 2000.
The organization must be able to synchronize user attributes from the on-premises Active Directory Domain Services environment to Office 365.
You need to prepare to install the Windows Azure Active Directory Sync tool.
Which two actions should you perform? Each correct answer presents part of the solution.
Correct Answer: BD
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/jj151831.aspx#BKMK_ComputerRequirements
QUESTION 69
A company uses Office 365 services. You implement the Windows Azure Active Directory Sync tool in the local environment.
An employee moves to a new department. All Office 365 services must display the new department information for the employee.
Where should you change the value of the department attribute for the employee?
A. The Active Directory management page in the Windows Azure Management Portal
B. The Users and groups page in the Office 365 admin center
C. The on-premises Active Directory
D. The Metaverse Designer
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
QUESTION 70
You have an Office 365 environment. Synchronization between the on-premises Active Directory and Office 365 is enabled.
A. Update-MsolFederatedDomain
B. Remove-MsolDomain
C. Remove-MsolFederatedDomain
D. Set-MsolDirSyncEnabled
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Explanation:
The complete command to disable directory Sync is Set-MsolDirSyncEnabled EnableDirSync $false
Reference: http://support.microsoft.com/kb/2619062
QUESTION 71
You are the Office 365 administrator for your company. The company uses Active Directory Federation Services (AD FS) to provide single sign-on to cloud-based
services. You enable multi-factor authentication.
Users must NOT be required to use multi-factor authentication when they sign in from the company's main office location. However, users must be required to verify
their identity with a password and token when they access resources from remote locations.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 72
HOTSPOT
An organization has over 10,000 users and uses a SQL-based Active Directory Federation Services (AD FS) server farm.
What should you do? Select the correct answer from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 73
DRAG DROP
A company deploys an Office 365 tenant. You install the Active Directory Federation Services (AD FS) server role on a server that runs Windows Server 2012. You
install and configure the Federation Service Proxy role service. Users sign in by using the Security Assertion Markup Language (SAML) protocol.
Which pages should you customize? To answer, drag the appropriate page to the correct customization. Each page may be used once, more than once, or not at all.
You may need to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference:
http://msdn.microsoft.com/en-us/library/ee895359.aspx
QUESTION 74
Contoso uses Office 365 for collaboration services. You implement single sign-on (SSO) with Office 365 by using Active Directory Federation Services (AD FS).
Which three actions should you perform? Each correct answer presents part of the solution.
Explanation/Reference:
QUESTION 75
DRAG DROP
You are the Office 365 administrator for your company.
You must configure a trust between the on-premises Active Directory domain and the Office 365 environment by using Active Directory Federation Services.
You need to assign the correct certificate to the description of your on-premises server environment below.
Which certificate types should you assign? To answer, drag the appropriate certificate type to the correct test description. Each certificate type may be used once,
more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Select and Place:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
QUESTION 76
A company plans to deploy an Office 365 tenant. You have two servers named FS1 and FS2 that have the Federation Service Proxy role service installed. You must
deploy Active Directory Federation Services (AD FS) on Windows Server 2012.
A. On FS1 and FS2, add the cluster DNS name and IP address of the federation server farm to the hosts file.
B. On FS1 only, add the cluster DNS name and IP address of the federation server farm to the hosts file.
C. On FS1 only, add the cluster NetBIOS name and IP address of the federation server farm to the LMHOSTS file.
D. On FS1 and FS2, add the cluster NetBIOS name and IP address of the federation server farm to the LMHOSTS file.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 77
A company named Fabrikam, Inc. is deploying an Office 365 tenant. You install Active Directory Federation Services (AD FS) on a server that runs Windows Server
2012.
You must obtain a certificate from a certification authority and install it on the federation servers.
A. fs.fabnkam.com
B. serverl.fabrikam.com
C. fabrikam.com
D. server2.fabrikam.com
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 78
An organization implements single sign-on (SSO) for use with Office 365 services. You install an Active Directory Federation Services (AD FS) proxy server.
Users report that they are unable to authenticate. You launch the Event Viewer and view the event information shown in the following screen shot:
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 79
Your company subscribes to an Office 365 Plan E3. A user named User1 installs Office Professional Plus for Office 365 on a client computer. From the Microsoft
Online Services portal, you assign User1 an Office Professional Plus license. One month after installing Office, User1 can no longer save and edit Office documents
on the client computer. User1 can open and view Office documents.
You need to ensure that User1 can save and edit documents on the client computer by using office.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Reference: http://technet.microsoft.com/en-us/library/gg702619(v=office.15).aspx
QUESTION 80
Your company uses Office 365. You need to identify which users do NOT have a Microsoft Exchange Online license assigned to their user account.
A. Get-ManagementRoleAssignment
B. Get-User
C. Get-RoleGroupMember
D. Get-LogonStatistics
E. Get-RemovedMailbox
F. Get-MSOLContact
G. Get-Recipient
H. Get-Mailbox
I. Get-Group
J. Get-MailboxStatistics
K. Get-MSOLUser
L. Get-MailContact
Correct Answer: K
Section: (none)
Explanation
Explanation/Reference:
QUESTION 81
Your company has an Office 365 subscription. You create a new retention policy that contains several retention tags. A user named Test5 has a client computer that
runs Microsoft Office Outlook 2007. You install Microsoft Outlook 2010 on the client computer of Test5. Test5 reports that the new retention tags are unavailable from
Outlook 2010.
You verify that other users can use the new retention tags. You need to ensure that the new retention tags are available to Test5 from Outlook 2010.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 82
You are the administrator for a company named Contoso, Ltd. The company has an Office 365 subscription.
Your need to prevent users from changing their user display name by using Outlook Web App.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Explanation:
Reference: http://help.outlook.com/en-us/140/ff852817.aspx
QUESTION 83
Your company has a hybrid deployment of Office 365. You need to create a group. The group must have the following characteristics:
Group properties are synchronized automatically.
Group members have the ability to control which users can send email messages to the group.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Explanation:
Message Approval
Use this section to set options for moderating the group. Moderators approve or reject messages sent to the group before they reach the group members.
Messages sent to this group have to be approved by a moderator This check box isn't selected by default. If you select this check box, incoming messages are
reviewed by the group moderators before delivery. Group moderators can approve or reject incoming messages.
Group moderators
To add group moderators, click Add. To remove a moderator, select the moderator, and then click Remove. If you have selected "Messages sent to this group have to
be approved by a moderator" and you don't select a moderator, messages to the group are sent to the group owners for approval.
Senders who don't require message approval
To add people or groups that can bypass moderation for this group, click Add. To remove a person or a group, select the item, and then click Remove.
Select moderation notifications
Use this section to set how users are notified about message approval. Notify all senders when their messages aren't approved. This is the default setting. Notify all
senders, inside and outside your organization, when their message isn't approved.
Notify senders in your organization only when their messages aren't approved. When you select this option, only people or groups in your organization are notified
when a message that they sent to the group isn't approved by a moderator.
Don't notify anyone when a message isn't approved. When you select this option, notifications aren't sent to message senders whose messages aren't approved by
the group moderators.
Reference: http://help.outlook.com/en-us/140/ms.exch.ecp.editdistributiongroup.aspx
QUESTION 84
Your company has a hybrid deployment of Office 365. You need to verify whether free/busy information sharing with external users is configured.
A. Test-OutlookConnectivity
B. Test-FederationTrust
C. Get-OrganizationRelationship
D. Get-MSOLDomainFederationSettings
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
QUESTION 85
Your company has 100 user mailboxes. The company purchases a subscription to Office 365 for professionals and small businesses. You need to enable the
Litigation Hold feature for each mailbox.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 86
Your company has a subscription to Office 365 for midsize business and enterprises. The company uses Microsoft Lync Online.
You need to open ports on the network firewall to enable all of the features of Lync Online.
Which port or ports should you open? (Each correct answer presents part of the solution. Choose all that apply.)
Explanation/Reference:
Reference: http://ahandyblog.wordpress.com/cloud-technologies/firewall-ports-for-office-365
QUESTION 87
Your company has an Office 365 subscription. You need to add the label "External" to the subject line of each email message received by your organization from an
external sender.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Explanation:
Option B also will do if that mentions "Inbound email". But here it says outbound email, so D is the current answer.
QUESTION 88
Your company has a hybrid deployment Office 365. You create a user in Office 365. The next day, you discover that the new user account fails to appear in the
Microsoft Exchange Server on- premises global address list (GAL).
You need to ensure that the user has a mailbox and appears in the Exchange on- premises GAL and the Office 365 GAL.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 89
Your company has an Office 365 subscription. The network contains an Active Directory domain. You configure single sign-on for all users.
You need to verify that single sign-on functions for the users who access Office 365 from the Internet.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
QUESTION 90
Your company has a hybrid deployment of Office 365. All mailboxes are hosted on Office 365. All users access their Office 365 mailbox by using a user account that is
hosted on-premises. You need to delete a user account and its associated mailbox.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Explanation:
When deleting accounts from Active Directory and directory synchronization runs the associated object will be deleted from Azure and also soft deleting the mailbox.
QUESTION 91
DRAG DROP
Contoso, Ltd. has an Office 365 tenant. The company has two servers named Server1 and Server2 that run Windows 2012 R2 Server. The servers are not joined to
the contoso.com domain. Server2 is deployed to the perimeter network. You install Secure Sockets Layer (SSL) certificates on both servers.
You deploy internal and external firewalls. All firewalls allow HTTPS traffic.
You must deploy single sign-on (SSO) and Active Directory Federation Services (AD FS).
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Section: (none)
Explanation
Explanation/Reference:
Note:
Prepare the Base Servers
Box 1, Box 2: AD FS Server
1. Base build the AD FS server with Windows Server 2012
2. Setup a connection to the internal network
3. Add the server to the local domain
4. Update the server with all Windows Updates
Box 3, Box 4: AD FS Proxy Server
Once the necessary WAP role services are installed, we are then able to launch the Web Application Proxy Wizard to configure WAP.
Note:
1. Base Build the AD FS Proxy server with Windows Server 2012
2. Setup a connection to the DMZ network (verify connectivity to the AD FS server on port 443)
3. DO NOT add the server to the local domain
4. Update the server with all Windows Updates
QUESTION 92
A company has an Office 365 tenant and uses Exchange Online and Skype for Business Online.
User1 is scheduling a Skype meeting with User2. User 1 is not able to see availability information for User2.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Centralized Logging Service (CLS) is a new feature in Lync Server 2013. It provides a mechanism to enable/disable logging across all Lync servers in a deployment
from a single interface and to search the resulting logs from the same interface.
You specify what should be logged based on the scenario you want to investigate. The scenarios supported are AlwaysOn, MediaConnectivity, ApplicationSharing,
AudioVideoConferencingIssue, HybridVoice, IncomingAndOutgoingCall, VoiceMail, IMAndPresence, AddressBook, DeviceUpdate, LYSSAndUCS, CLS, SP, WAC,
UserReplicator, HostedMigration, MonitoringAndArchiving, LILRLegacy, LILRLYSS, MeetingJoin, RGS, CPS, XMPP and CAA.
https://technet.microsoft.com/en-us/library/jj688145.aspx
QUESTION 93
You have an Exchange Online tenant. User1 reports that they are not able to check their email.
Other users can check their email.
You need to troubleshoot why the user cannot check his email.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Microsoft Remote Connectivity Analyzer (https://testconnectivity.microsoft.com/) can test incoming and outgoing e-mail.
Reference: https://testconnectivity.microsoft.com/
QUESTION 94
You have an Exchange Online tenant. You must identify mailboxes that are no longer in use.
A. Get-StaleMailboxReport-StartDate
B. Get-MailboxActivityReport-Organization
C. Get-MailboxActivityReport-Expression
D. Get-MailboxActivityReport-EndDate
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Use the Get-StaleMailboxDetailReport cmdlet to view mailboxes that haven't been accessed for at least 30 days.
The StartDate parameter specifies the start date of the date range.
Reference: Get-StaleMailboxDetailReport
https://technet.microsoft.com/en-us/library/jj200715(v=exchg.150).aspx
QUESTION 95
DRAG DROP
A graphic design agency has an Office 365 tenant. The agency uses only computers that run the Apple Macintosh operating system. Some users have Microsoft
Entourage 2008 for Mac, and some have Microsoft Outlook for Mac.
All users report that they cannot access Exchange Online to check their email.
You need to run test connectivity for all users to identify the problem. You need to use the Microsoft Remote Connectivity Analyzer and the credentials of the users.
What should you do? To answer, drag the appropriate test to run to the correct email client. Each test may be used once, more than once, or not at all. You may need
to drag the split bar between panes or scroll to view content.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Reference: https://testconnectivity.microsoft.com/
QUESTION 96
A company has an Office 365 tenant. You implement two-factor authentication for all users. You hire an employee named User1 to track service usage and status.
User1 must be able to monitor the status of the services over a period of time by using a report.
User1 does not have administrator access.
A. downloadable spreadsheet
B. REST reporting web service
C. reporting Windows PowerShell cmdlets
D. Office 365 admin center
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
The Office 365 Reporting web service enables developers to integrate information on email and spam, antivirus activity, compliance status, and Lync Online activities
into their custom service reporting applications and web portals.
All the reports available in the admin portal, within the downloadable Microsoft Excel spreadsheets, and those accessed through Windows PowerShell cmdlets, are
accessible using the Reporting web service.
QUESTION 97
A company has an Office 365 tenant that has an Enterprise E1 subscription.
You use single sign-on for all user accounts. You plan to migrate all services to Office 365.
A. Set-MsolUser
B. Redo-MsolProvisionUser
C. Set-MsolUserLicense
D. Set-MsolUserPrincipalName
E. Convert-MsolFederatedUser
F. Set-MailUser
G. Set-LinkedUser
H. New-MsolUser
Correct Answer: E
Section: (none)
Explanation
Explanation/Reference:
The Convert-MsolFederatedUser cmdlet is used to update a user in a domain that was recently converted from single sign-on (also known as identity federation) to
standard authentication type.
Incorrect answers:
Not A: The Set-MsolUser cmdlet is used to update a user object. This cmdlet should be used for basic properties only. The licenses, password, and User Principal
Name for a user can be updated through the Set-MsolUserLicense, Set-MsolUserPassword, and Set-MsolUserPrincipalName cmdlets respectively.
Not H: The New-MsolUser cmdlet is used to create a new user in the Microsoft Azure Active Directory (Microsoft Azure AD).
Reference: Convert-MsolFederatedUser
https://msdn.microsoft.com/sv-se/library/azure/dn194101.aspx
QUESTION 98
A company has an Office 365 tenant that has an Enterprise E1 subscription. You configure the policies required for self-service password reset.
You need to ensure that all existing users can perform self-service password resets.
Which Windows PowerShell cmdlet should you run?
A. Set-MsolUser
B. Redo-MsolProvisionUser
C. Set-MsolUserLicense
D. Set-MsolUserPrincipalName
E. Convert-MsolFederatedUser
F. Set-MailUser
G. Set-LinkedUser
H. New-MsolUser
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
Self-service password reset with on-premises write-back is a Premium-only feature.
Example:
The following command adds the Office 365 for enterprises license to the user.
Set-MsolUserLicense -UserPrincipalName [email protected] -AddLicenses "Contoso:ENTERPRISEPACK"
Note: The Set-MsolUserLicense cmdlet can be used to adjust the licenses for a user. This can include adding a new license, removing a license, updating the license
options, or any combination of these actions.
Incorrect answers:
Not A: The Set-MsolUser cmdlet is used to update a user object. This cmdlet should be used for basic properties only. The licenses, password, and User Principal
Name for a user can be updated through the Set-MsolUserLicense, Set-MsolUserPassword, and Set-MsolUserPrincipalName cmdlets respectively.
Not B: The Redo-MsolProvisionUser cmdlet can be used to retry the provisioning of a user object in Azure Active Directory when a previous attempt to create the user
object resulted in a validation error.
Not C: Not D: The Set-MsolUserPrincipalName cmdlet is used to change the User Principal Name (user ID) of a user. This cmdlet can be used to move a user
between a federated and standard domain, which will result in their authentication type changing to that of the target domain.
Not E: The Convert-MsolFederatedUser cmdlet is used to update a user in a domain that was recently converted from single sign-on (also known as identity
federation) to standard authentication type.
Not F: Use the Set-MailUser cmdlet to modify the mail-related attributes of an existing user in Active Directory.
This cmdlet is available in on-premises Exchange Server 2013 and in the cloud-based service.
Not G: Use the Set-LinkedUser cmdlet to modify the properties of a linked user account. A linked user is an account in one organization that is associated with an
account in a different organization.
Not H: The New-MsolUser cmdlet is used to create a new user in the Microsoft Azure Active Directory (Microsoft Azure AD).
Reference: Set-MsolUserLicense
https://msdn.microsoft.com/en-us/library/azure/dn194094.aspx
QUESTION 99
A company has an Office 365 tenant that has an Enterprise E1 subscription. The company has offices in several different countries.
You need to restrict Office 365 services for existing users by location.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
The Set-MsolUser cmdlet is used to update a user object.
Example: The following command sets the location (country) of this user. The country must be a two-letter ISO code. This can be set for synced users as well as
managed users.
Set-MsolUser -UserPrincipalName [email protected] -UsageLocation "CA"
Note:
Some organizations may want to create policies that limit access to Microsoft Office 365 services, depending on where the client resides.
Active Directory Federation Services (AD FS) 2.0 provides a way for organizations to configure these types of policies. Office 365 customers using Single Sign-On
(SSO) who require these policies can now use client access policy rules to restrict access based on the location of the computer or device that is making the request.
Customers using Microsoft Online Services cloud User IDs cannot implement these restrictions at this time.
Reference: Limiting Access to Office 365 Services Based on the Location of the Client
https://technet.microsoft.com/en-us/library/hh526961(v=ws.10).aspx
Reference: Set-MsolUser
https://msdn.microsoft.com/en-us/library/azure/dn194136.aspx
QUESTION 100
HOTSPOT
A company plans to synchronize users in an existing Active Directory organizational unit with Office 365.
You must configure the Azure Active Directory Synchronization (AAD Sync) tool with password sync.
You need to ensure that the service account has the minimum level of permissions required.
Which two permission levels should you assign to the account for each task? To answer, select the appropriate permission level from each list in the answer area.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Explanation:
* Password Write-Back
For each forest you have configured in Azure AD Sync, the account you have specified for a forest in the wizard must be given the “Reset-Password” and “Change
Password” extended rights on the root object of each domain in the forest.
If you want to enable password synchronization between your on-premises AD DS and your Azure Active Directory for your users, you need to grant the following
permissions to the account that is used by Azure AD Sync to connect to your AD DS:
Replicating Directory Changes
Replicating Directory Changes All
QUESTION 101
You have an Office 365 tenant that uses an Enterprise E3 subscription. You activate Azure Rights Management for the tenant.
You must test the service with the Development security group before you deploy Azure Rights Management for all users.
You need to enable Azure Rights Management for only the Development security group.
A. Enable-Aadrm
B. New-AadrmRightsDefinition
C. Enable-AadrmSuperUserFeature
D. Add-AadrmSuperUser
E. Set-AadrmOnboardingControlPolicy
Correct Answer: E
Section: (none)
Explanation
Explanation/Reference:
The Set-AadrmOnboardingControlPolicy cmdlet sets the policy that controls user on-boarding for Azure Rights Management. This cmdlet supports a gradual
deployment by controlling which users in your organization can protect content by using Azure Rights Management.
Example:
Restrict Azure RMS to users who are members of a specified group
This command allows only users that are members of the security group with the specified object ID to protect content by using Azure Rights Management. The
command applies to Windows clients and mobile devices.
Windows PowerShell
PS C:\> Set-AadrmOnboardingControlPolicy -UseRmsUserLicense $False -SecurityGroupObjectId "f
Incorrect answers:
Not A: The Enable-Aadrm cmdlet enables the capabilities of Azure Rights Management for your organization. When you activate Rights Management, you turn on this
feature for all rights-enabled services and applications. You must activate Rights Management before you can begin to use information rights management (IRM)
features with your applications.
Not B: The New-AadrmRightsDefinition cmdlet creates a Rights Definition object. A Rights Definition object expresses the rights of a user or group to content that
Azure Rights Management protects. Use Rights Definition objects to define rights in a rights policy template.
Not C: The Enable-AadrmSuperUserFeature cmdlet enables the super user feature. With this feature enabled, you can add or remove super users for Azure Rights
Management. By default, the super users feature is not enabled, and no users are assigned to this feature.
Not D: The Add-AadrmSuperUser cmdlet adds a super user for your organization.
Reference: Set-AadrmOnboardingControlPolicy
https://msdn.microsoft.com/en-us/library/dn857521.aspx
QUESTION 102
You have a legacy application that needs to send email to employees. The legacy application runs on a client computer.
The legacy application must send email by using IMAP through Exchange Online.
You need to identify the correct host name and port information.
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
For Office 365 for business, use the following settings.
IMAP4
outlook.office365.com
993 implicit
Reference: Use POP or IMAP to connect to Office 365 for business or Microsoft Exchange accounts
https://support.office.com/en-US/Article/Use-POP-or-IMAP-to-connect-to-Office-365-for- business-or-Microsoft-Exchange-accounts-44f951cc-2041-47ed-b674-
506889ca9d8b
QUESTION 103
A company has an Office 365 tenant. You plan to distribute the Office 365 ProPlus client to users.
You need to activate the Office 365 ProPlus installations and ensure that the licenses remain active.
A. Connect the client computer to the Internet once to activate the Office 365 ProPlus client, and once every 90 days after that.
B. Connect the client computer to the Internet once to activate the Office 365 ProPlus client, and once every 30 days after that.
C. Connect the client computer to the Internet only once to activate the Office 365 ProPlus client.
D. Connect the client computer to the Internet once to activate the Office 365 ProPlus client, and once every 180 days after that.
E. Connect the client computer to the Internet once to activate the Office 365 ProPlus client, and once every 365 days after that.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
After you've verified the user is assigned a license, you should check that Office 365 ProPlus is activated. Activation usually occurs during initial installation. The
computer has to connect to the Internet at least once every 30 days for Office 365 ProPlus to remain activated.
https://technet.microsoft.com/en-us/library/gg702620.aspx
QUESTION 104
HOTSPOT
You manage an Office 365 tenant. The subscription details for the tenant are displayed in the following screenshot.
Use the drop-down menus to select the answer choice that answers each question.
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Office 365 Business Premium
* Each user can install Office on 5 PCs or Macs, 5 tablets (Windows, iPad, and Android), and 5 phones.
* Online Services include:
Exchange, Sharepoint,Yammer, Skype for Business, etc.
* Office 365 Small Business Premium supports a maximum of 300 users
Reference: https://products.office.com/en-us/business/office-365-business-premium
QUESTION 105
A company has an Office 365 tenant. The company uses a third-party DNS provider that does not allow TXT records.
A. Create an MX record.
B. Create a CNAME record.
C. Create an A record.
D. Create an SRV record.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Add a TXT or MX record for DNS verification.
Reference: Change nameservers to set up Office 365 with any domain registrar
https://support.office.com/en-us/article/Change-nameservers-to-set-up-Office-365-with-any- domain-registrar-a8b487a9-2a45-4581-9dc4-5d28a47010a2
QUESTION 106
A company has an Office 365 tenant.
Which two passwords can you use? Each correct answer presents a complete solution.
A. Summer2015
B. May2015
C. User1User1
D. summer2015
E. May 2015
F. summer!@#$
G. M1crosoft
Correct Answer: AG
Section: (none)
Explanation
Explanation/Reference:
If the user is set to require a strong password, then all of the following rules must be met:
Incorrect:
Not E: no spaces
QUESTION 107
Your company deploys an Office 365 tenant.
You need to ensure that you can view service health and maintenance reports for the past seven days.
What are two possible ways to achieve this goal? Each correct answer presents a complete solution.
A. View the service health current status page of the Office 365 admin center.
B. Subscribe to the Office 365 Service Health RSS Notifications feed.
C. View the service settings page of the Office 365 admin center.
D. Run the Microsoft OnRamp Readiness Tool.
Correct Answer: AB
Section: (none)
Explanation
Explanation/Reference:
As an Office 365 admin, you can see whether there has been a service interruption or outage in your service on the Office 365 service health page. The Service health
page shows status information for today, the past six days, and 30 days of history.
https://support.office.com/en-us/article/View-the-status-of-your-services-932ad3ad-533c- 418a-b938-6e44e8bc33b0
QUESTION 108
You are the Office 365 administrator for your company.
Users report that they have received significantly more spam messages over the past month than they normally receive.
You need to analyze trends for the email messages received over the past 60 days.
From the Office 365 admin center, what should you view?
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Use mail protection reports in Office 365 to view data about malware, spam, and rule detections.
If you're an Exchange Online or Exchange Online Protection (EOP) admin, there's a good chance you'd like to monitor how much spam and malware is being
detected, or how often your transport rules are being matched. With the interactive mail protection reports in the Office 365 admin center, you can quickly get a visual
report of summary data, and drill-down into details about individual messages, for as far back as 90 days.
Reference: https://technet.microsoft.com/en-us/library/dn500744(v=exchg.150).aspx
QUESTION 109
An organization plans to migrate to Office 365.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
Office 365 includes Lync 2013.
With this latest version of the Microsoft Lync Server 2010 and 2013 Bandwidth Calculator, you can enter information about your users and the Lync Server features
that you want to deploy, and the Bandwidth Calculator will determine bandwidth requirements for the WAN that connects sites in your deployment. The accompanying
Bandwidth Calculator User Guide describes the recommended process for estimating your WAN bandwidth needs for Lync client real-time traffic.
Reference: Lync Server 2010 and 2013 Bandwidth Calculator Version 2.0
http://blogs.technet.com/b/nexthop/archive/2013/06/07/lync-server-2010-and-2013- bandwidth-calculator-version-2-0.aspx
QUESTION 110
HOTSPOT
You have an Office 365 tenant. A user named User1 has a mailbox. The user creates documents and saves the documents in a shared document library.
User1 leaves the company. You must delete the account for User1.
In the table below, identify when each type of data will be deleted.
NOTE: Make only one selection in each column. Each correct selection is worth one point.
Hot Area:
Correct Answer:
Section: (none)
Explanation
Explanation/Reference:
Explanation:
* When you delete an Office 365 user account, the corresponding Exchange Online mailbox is deleted and removed from the list of mailboxes in the EAC. After the
user account is deleted, it's listed on the Deleted Users page in the Office 365 admin center. It can be recovered within 30 days after being deleted. After 30 days, the
user account and mailbox are permanently deleted and not recoverable.
Reference: View, restore, or delete items in the Recycle Bin of a SharePoint site
https://support.office.com/en-sg/article/View-restore-or-delete-items-in-the-Recycle-Bin-of-a-SharePoint-site-6df466b6-55f2-4898-8d6e-c0dff851a0be