Free AB-900 practice test: 20 questions
Twenty questions across the three AB-900 skill areas, weighted roughly as the real exam is: seven on core features, eight on data protection and governance, and five on Copilot and agents. These are original scenario questions. Read what the requirement actually asks before picking a tool.
Identify the core features and objects of Microsoft 365 services
Question 1. Your company has just bought the domain contoso-sales.com and wants users to receive email at it. Where do you add and verify the domain?
- A. The Microsoft 365 admin center
- B. The Teams admin center
- C. The SharePoint admin center
- D. The Microsoft Purview portal
Show answer
Answer: A
Custom domains are added and verified under org configuration in the Microsoft 365 admin center, by creating the DNS records it provides. The Exchange admin center manages mailboxes and mail flow once the domain exists, and the other admin centers do not manage domains.
Want more questions like this? Full AB-900 practice tests →
Question 2. A department wants an email address that delivers each message to all 40 of its members' own inboxes. No shared inbox is needed. What should you create?
- A. A shared mailbox
- B. A SharePoint communication site
- C. A distribution group
- D. A private Teams channel
Show answer
Answer: C
A distribution group delivers a copy of each message to every member’s own mailbox. A shared mailbox is one inbox several people open. A SharePoint site stores content, and a Teams channel is for conversation rather than email delivery.
Want more questions like this? Full AB-900 practice tests →
Question 3. A contractor must be able to read documents on a SharePoint project site but must not edit or delete anything. Which default site group should they be added to?
- A. Owners
- B. Members
- C. Site collection administrators
- D. Visitors
Show answer
Answer: D
The Visitors group has read permission by default. Members can edit and delete content, and Owners have full control. Site collection administrator is higher still.
Want more questions like this? Full AB-900 practice tests →
Question 4. Which statement best describes the Zero Trust principle 'assume breach'?
- A. Authenticate and authorise every request using all available signals
- B. Minimise the impact of an attacker who is already inside by segmenting, encrypting and monitoring
- C. Grant users only the access they need, for as long as they need it
- D. Trust devices on the corporate network and verify only external ones
Show answer
Answer: B
Assume breach means designing as if an attacker is already inside: segmenting access, encrypting data and monitoring continuously to limit the damage. Checking every request is verify explicitly. Minimal access is least privilege. Trusting the internal network is the opposite of Zero Trust.
Want more questions like this? Full AB-900 practice tests →
Question 5. Management wants MFA required for all users signing in from outside the company's trusted locations, but not from the office. What should you configure?
- A. A conditional access policy using named locations
- B. Privileged Identity Management for all users
- C. Identity Secure Score recommendations
- D. A Teams meeting policy
Show answer
Answer: A
A conditional access policy can use named locations as a condition and require MFA only when the sign-in comes from elsewhere. PIM manages role activation, Identity Secure Score only recommends improvements, and a Teams meeting policy governs meetings, not sign-ins.
Want more questions like this? Full AB-900 practice tests →
Question 6. The security team needs one place to investigate an attack that started with a phishing email, compromised an account and then reached a laptop. Which product correlates these signals into a single incident?
- A. Microsoft Purview Compliance Manager
- B. Microsoft Purview Communication Compliance
- C. Microsoft Defender XDR
- D. The Teams admin center
Show answer
Answer: C
Microsoft Defender XDR correlates signals across email, identities, endpoints and cloud apps into a single incident. Compliance Manager assesses regulatory controls, Communication Compliance reviews message content for policy breaches, and the Teams admin center manages Teams.
Want more questions like this? Full AB-900 practice tests →
Question 7. An auditor asks who added a user to the Global Administrator role last Tuesday. Where should you look?
- A. The Entra ID sign-in logs
- B. The Entra ID audit logs
- C. Identity Secure Score
- D. The Microsoft 365 Copilot usage report
Show answer
Answer: B
Audit logs record changes to users, groups and role assignments, including who made them and when. Sign-in logs record authentication attempts, Identity Secure Score measures posture, and a usage report shows service activity rather than administrative changes.
Want more questions like this? Full AB-900 practice tests →
Understand data protection and governance tasks for Microsoft 365 and Copilot
Question 8. Documents marked Confidential must show a footer reading 'Confidential' and must be blocked from being opened by anyone outside the company. What should you publish?
- A. A sensitivity label with content marking and encryption
- B. A retention label
- C. A Compliance Manager assessment
- D. An eDiscovery Content search
Show answer
Answer: A
A sensitivity label can apply both content marking, such as a footer, and encryption that restricts who can open the file. A retention label controls how long content is kept, Compliance Manager assesses controls, and Content search finds content.
Want more questions like this? Full AB-900 practice tests →
Question 9. Users regularly email spreadsheets containing credit card numbers to external addresses. You want Outlook to warn them and block the send. What should you configure?
- A. An Insider Risk Management policy
- B. A retention policy for Exchange
- C. A DLP policy using the credit card number sensitive information type
- D. A Communication Compliance policy
Show answer
Answer: C
A DLP policy detects the credit card sensitive information type in Exchange and can show a policy tip and block the message. Insider Risk Management looks at patterns of user behaviour, retention keeps content, and Communication Compliance reviews messages after the fact rather than blocking them at send.
Want more questions like this? Full AB-900 practice tests →
Question 10. Before labelling content, the compliance team wants to know which SharePoint sites and mailboxes contain items with passport numbers, and how many. Which tool shows this?
- A. Activity explorer
- B. Data Explorer
- C. Compliance Manager
- D. Identity Secure Score
Show answer
Answer: B
Data Explorer shows where classified and labelled items are stored and how many there are. Activity explorer shows what users did with such items. Compliance Manager scores regulatory posture, and Identity Secure Score is about identity.
Want more questions like this? Full AB-900 practice tests →
Question 11. An employee who has resigned starts downloading large numbers of confidential files and copying them to a USB drive. Which Purview solution is designed to detect this pattern?
- A. Communication Compliance
- B. Data Lifecycle Management
- C. eDiscovery Content search
- D. Insider Risk Management
Show answer
Answer: D
Insider Risk Management correlates activities such as mass downloads and copying to removable media, including around a resignation date, to identify risky users. Communication Compliance reviews message content, retention keeps content, and Content search is a manual investigation tool.
Want more questions like this? Full AB-900 practice tests →
Question 12. The HR department wants to detect harassment in Teams chats and email so reviewers can act on it. Which solution fits?
- A. Communication Compliance
- B. Insider Risk Management
- C. A DLP policy
- D. A sensitivity label
Show answer
Answer: A
Communication Compliance applies policies to message content in email and Teams and routes matches to reviewers. Insider Risk Management focuses on data-related activities rather than message tone, DLP protects sensitive data, and sensitivity labels classify content.
Want more questions like this? Full AB-900 practice tests →
Question 13. Your organisation must show auditors how well it meets a data protection regulation, with a score and recommended improvement actions. Which tool should you use?
- A. Identity Secure Score
- B. Activity explorer
- C. Compliance Manager
- D. DSPM for AI
Show answer
Answer: C
Compliance Manager provides assessments for regulations, a compliance score and improvement actions. Identity Secure Score only covers identity configuration, activity explorer shows user actions, and DSPM for AI focuses on AI activity.
Want more questions like this? Full AB-900 practice tests →
Question 14. A user with a Copilot licence asks Copilot to summarise a document they do not have permission to open. What happens?
- A. Copilot summarises it, because Copilot has tenant-wide read access
- B. Copilot cannot use the document, because it only accesses content the user is permitted to open
- C. Copilot automatically requests access from the document owner
- D. Copilot summarises it using an administrator’s permissions
Show answer
Answer: B
Copilot uses the signed-in user’s permissions through Microsoft Graph, so it cannot retrieve content the user cannot access. It does not escalate permissions, request access automatically or fall back to an administrator’s rights.
Want more questions like this? Full AB-900 practice tests →
Question 15. A highly sensitive M&A site is shared through old links with many people who have left the project. Until the owners clean up, only members of the M&A security group should be able to open the site. What should you use?
- A. A retention policy on the site
- B. A Compliance Manager assessment
- C. DSPM for AI
- D. Restricted access control in SharePoint Advanced Management
Show answer
Answer: D
Restricted access control, part of SharePoint Advanced Management, limits a site to members of a specified group regardless of existing sharing links or permissions. A retention policy keeps content, Compliance Manager assesses controls, and DSPM for AI reports on AI activity but does not restrict the site.
Want more questions like this? Full AB-900 practice tests →
Perform basic administrative tasks for Copilot and agents
Question 16. Fifty staff in finance need Microsoft 365 Copilot in Excel, Outlook and Teams every day. What is the most suitable licensing approach?
- A. Assign Microsoft 365 Copilot licences to a group containing the 50 users
- B. Use pay-as-you-go billing for all 50 users
- C. Give them only Copilot Chat without any licence change
- D. Create an Azure subscription for each user
Show answer
Answer: A
Heavy daily use across apps fits the per-user monthly Microsoft 365 Copilot licence, ideally assigned through a group. Pay-as-you-go suits occasional or agent-only use. Copilot Chat alone does not provide Copilot inside the apps grounded in work data, and an Azure subscription on its own grants nothing.
Want more questions like this? Full AB-900 practice tests →
Question 17. A sales manager needs to find out why regional revenue dropped last quarter by working through several large spreadsheets. Which built-in Copilot capability fits best?
- A. Researcher
- B. A scheduled prompt
- C. Analyst
- D. A DLP policy
Show answer
Answer: C
Analyst is designed to reason over data such as spreadsheets and explain trends. Researcher focuses on gathering and synthesising information from many sources into a report. A scheduled prompt runs a saved prompt at a set time, and a DLP policy protects data.
Want more questions like this? Full AB-900 practice tests →
Question 18. A team lead wants the same Copilot prompt to run every Monday morning and summarise last week's project emails. What should they use?
- A. Share the prompt with the team
- B. Schedule the saved prompt
- C. Build a custom agent in Copilot Studio
- D. Apply a retention label to the emails
Show answer
Answer: B
Prompts can be saved and scheduled to run at set times, which fits a weekly summary. Sharing a prompt makes it available to colleagues but does not run it. A custom agent is more than is needed, and a retention label is unrelated.
Want more questions like this? Full AB-900 practice tests →
Question 19. An agent built by the IT team should be available only to the service desk group, not to the whole organisation. Where should the admin configure this?
- A. The agent management settings in the Microsoft 365 admin center
- B. The Exchange admin center
- C. Identity Secure Score
- D. A retention policy
Show answer
Answer: A
Agent availability is managed in the agent settings of the Microsoft 365 admin center, where an agent can be made available to specific users or groups. The Exchange admin center manages mail, Identity Secure Score is posture reporting, and a retention policy governs content lifetime.
Want more questions like this? Full AB-900 practice tests →
Question 20. The platform team needs operational insights and governance for agents built in Copilot Studio, including the environments they run in. Which admin center should they use alongside the Microsoft 365 admin center?
- A. The Teams admin center
- B. The Exchange admin center
- C. The Microsoft Entra admin center
- D. The Power Platform admin center
Show answer
Answer: D
Copilot Studio agents live in Power Platform environments, so the Power Platform admin center provides environment-level governance and operational insights. The Teams, Exchange and Entra admin centers do not manage Copilot Studio environments.
Want more questions like this? Full AB-900 practice tests →
How did you do?
Sixteen or more correct suggests you are close. Below fourteen, the domain guides in this section are the fastest way to find the gaps. Questions 8–15 cover the largest domain: if you missed more than two of them, spend your next study week on data protection and governance, because the look-alike Purview tools are where AB-900 costs the most marks.