Free AB-900 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Microsoft AB 900
Q: 1
A SharePoint administrator notices that all project documents for the company are being
stored in a single Projects site and a single document library, using only folders to separate
projects. Project owners now want each new project to have its own home page, its own
permissions boundary, and the ability to host multiple document libraries and lists if
needed.
Which object should the admin create and manage in the SharePoint admin center to best
meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A financial services company wants to understand where highly regulated data (such as
credit card numbers and national ID numbers) is stored across SharePoint, OneDrive, and
Exchange. They want a near real-time snapshot of items that match prebuilt and custom
sensitive information types, the ability to filter by repository and label, and a way to export
the results for further analysis in another system. The solution must rely on Microsoft
Purview and should not require copying all content into a new system.
Which proposed solution best meets these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Your organization is rolling out Microsoft 365 Copilot to help people draft customer emails.
A product owner asks:
"What does it mean to use Copilot in a way that aligns with Microsoft's responsible AI
principles, especially for customer-facing content?"
Which practice best reflects those principles in this context?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
You are an administrator at Adventure Works. You need to explain the di[erence between
App registrations and Enterprise applications in Microsoft Entra ID.
Which explanation best describes the relationship between App registrations and
Enterprise apps?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Northwind Bank has deployed Microsoft Purview DLP policies that now include coverage
for Microsoft 365 Copilot interactions. After rollout, the security operations center (SOC)
notices a steady stream of alerts where Copilot content includes or references sensitive
information such as payment card numbers or customer IDs. They want to ensure that
these alerts are handled consistently and that serious incidents can be correlated with
other signals like endpoint activity and sign-in anomalies.
What is the most appropriate way for the SOC to operationalize DLP alerts that involve
Copilot?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
You plan to create an agent in the Microsoft 365 Copilot app to solve a business issue. What are two
reasons to create the agent? Each correct answer presents a complete solution. NOTE: Each correct
selection is worth one point.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
A security architect is summarizing why the organization is rolling out PIM.
Complete the sentence:
“In Microsoft Entra ID, Privileged Identity Management is primarily used to ________.”
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Your organization has purchased SharePoint Advanced Management to lock down a small
set of "high-risk" SharePoint sites that host merger and acquisition (M&A) documents.
Leadership wants only members of a specific Microsoft Entra security group to be able to
access those sites at all, regardless of other group memberships or sharing links, while
leaving the rest of the tenant unchanged and centrally governed by admins.
Which proposed solution best meets these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
You are investigating a suspected data theft incident and need to answer two separate
questions:
1. Who changed several Entra admin roles and consented a suspicious enterprise
application?
2. What potentially sensitive actions a specific user took across Exchange Online,
SharePoint, and Teams in the last 30 days?
Multiple engineers propose di[erent approaches to pull the necessary evidence while
maintaining a clear separation between directory-level configuration changes and cross-
workload user activity.
Which proposed approach best uses the appropriate tools for each part of this
investigation?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Your organization has deployed several production agents plus a few experimental ones.
The AI admin wants to understand which agents users are actually invoking inside
Microsoft 365 Copilot, while the Power Platform admin wants to track environment-level
health and troubleshoot issues with flows and connectors that support those agents. You
recommend that the AI admin start in the Microsoft 365 admin center under Reports >
Usage > Microsoft 365 Copilot, and then switch to the Power Platform admin center for
deeper environment diagnostics.
To see adoption and usage of specific agents in Microsoft 365, the AI admin should use the
Agents tab in the Microsoft 365 Copilot ______ report.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
An HR operations team wants an AI assistant that can watch a “New Hire” mailbox, look up
candidates in the HR system, generate personalized onboarding plans, create tasks for IT
and facilities, and post updates into a Teams channel. They need this experience to follow a
consistent, governed workflow and to keep using the same configuration over time instead
of relying on one-o[ prompts.
To meet this requirement, they should build a ______ in Copilot Studio that encapsulates
the workflow and connects to their HR and collaboration tools.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Fabrikam’s IP protection team notices an increase in risky activity after Copilot rollout:
users exporting files with AI-generated summaries to personal cloud storage and copying
design documents shortly before resigning. They want a solution that can correlate
multiple user signals over time (downloads, copies, unusual browsing, resignation
indicators) and raise cases to a dedicated team, with built-in privacy controls such as
pseudonymization.
Complete the architect’s recommendation:
“To proactively detect potential IP theft around our Copilot-related file activity and user
behavior, we should configure an ______ that uses built-in machine learning templates to
correlate risky signals into manageable cases.”
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
A manager tells the compliance team that once they enable Microsoft Purview retention
policies, they no longer need backup or recovery strategies, because retention “is our
backup” and can always restore any deleted item from any point in time.
Microsoft Purview retention is a full replacement for backup and recovery solutions; if
retention policies are configured, the organization no longer needs separate backup
strategies.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
A records manager explains that Microsoft Purview Data Lifecycle Management lets the
organization keep only what it needs and delete content that is no longer required. They use
retention labels and policies to manage records, prove compliance, and ensure that Teams
messages, SharePoint files, and emails follow defined retention schedules.
Microsoft Purview Data Lifecycle Management provides tools to retain content that must
be kept, delete content that should no longer be kept, and manage records and proof of
compliance across Microsoft 365.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Your organization has built several custom agents in Copilot Studio and now wants to roll
them out to di[erent business units. The admin wants to avoid editing each agent every
time someone joins or leaves a team and instead prefers to control access with Microsoft
Entra groups and standard role assignments. A colleague says: “That’s not possible; the
only way to control who can use an agent is to add or remove each user individually inside
the agent configuration. Groups and roles can’t be used to grant or deny access.”
Is this statement true or false?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
A security engineer explains Identity Secure Score to management as follows:
“Some improvement actions give partial credit if you roll them out to only part of the
organisation. For example, enabling MFA for all admins but not all users can still give you
some points, even though the action isn’t fully completed for the whole tenant.”
Is this statement True or False?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
On an existing Departments SharePoint site, all teams share a single Documents library.
HR wants a location where only HR sta[ can see documents, but they don’t want a new site
or a new library. An admin creates a folder named HR-Private inside the existing
Documents library, leaves the default inherited permissions in place, and instructs HR to
store confidential files there, assuming the folder name alone will keep non-HR users out.
Proposed solution: Use the HR-Private folder with inherited permissions unchanged and
rely on the folder name to ensure only HR users can access those documents.
Does this solution meet the goal?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
“The Researcher agent is mainly intended for simple, one-step edits like rephrasing a
sentence, and it does not draw on multiple sources or produce structured reports.”
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Tailwind Traders is redesigning its security architecture. A network engineer proposes that
once a user connects from a managed device on the corporate LAN or VPN, their tra[ic
should bypass conditional access checks and device compliance validation to “reduce
friction,” because the internal network is considered trusted. The security architect argues
this approach conflicts with the organization’s Zero Trust strategy.
In a Zero Trust model, it is acceptable to fully trust any user and device solely because they
are connected from an internal corporate network segment, and to skip further verification
for resource access.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
You need to prevent external senders from emailing an existing internal announcement list
[email protected] while keeping internal use unchanged. A colleague suggests:
“In Exchange Online, you should edit the distribution group object in the Exchange admin
center and configure its delivery management and address list options there, instead of
touching each member’s mailbox.”
Is this guidance correct?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20