Q: 12
HOTSPOT You have a Microsoft 365 E5 subscription linked to an Azure Active Directory (Azure AD) tenant. The tenant contains a group named Group1 and the users shown in the following table: 
Your Answer
Discussion
Makes sense, since both Conditional Access admin and Security admin have full CA policy rights. Only User admin gets blocked from changing CA assignments. So it should be YES, YES, NO here. Open to correction if I missed something.
Yep, looks right to me. YES, YES, NO
Be respectful. No spam.
