Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft 365 Certified:Copilot and Agent Administration Fundamentals

Domain 2Objective 3

Identify Data Protection and Governance Risks for Microsoft 365 and Copilot AB-900 Practice Questions (Page 3)

Part of the Understand data protection and governance tasks for Microsoft 365 and Copilot domain, which accounts for 35–40% of the AB-900 exam. Microsoft does not publish an official question count, but from its 45-minute exam (~20–30 total, ~7–12 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
8concepts
35–40%of the exam

Questions 11–15

  1. 11application · medium

    Contoso's security team receives a DLP alert indicating that a user shared a document containing credit card numbers externally. The team needs to confirm whether the user actually sent the file and to whom, and then determine if the same user has shared other sensitive files recently. Which two Microsoft Purview tools should the team use together?

    Select an answer first
  2. 12foundation · easy

    A compliance officer wants to review a log of user activities such as viewing, downloading, and sharing sensitive files to investigate a potential data leak. Which Microsoft Purview tool provides this activity log?

    Select an answer first
  3. 13application · medium

    A legal team at Fabrikam needs to find all emails containing a specific project code and then place them on hold for litigation. Which Microsoft Purview tool should they use?

    Select an answer first
  4. 14expert · hard

    A technology company has an Insider Risk Management policy that flags users who download large volumes of data. The policy generates many alerts, but most are false positives from developers who legitimately download code repositories. The security team wants to reduce false positives while still detecting real data exfiltration. They also want to ensure that any DLP policies do not block legitimate developer workflows. Which approach should they take?

    Select an answer first
  5. 15application · medium

    A financial services company has a Communication Compliance policy that flags messages containing profanity or harassment. An HR investigator receives an alert for a message that contains a quote from a news article with profanity, but the employee was discussing the article in a professional context. The investigator wants to reduce false positives while still catching genuine harassment. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AB-900” is a trademark of its owner, used for identification only.