dc dotCreds
Microsoft 365 Copilot and Agent Administration Fundamentals (AB-900)

AB-900 Practice Test

Start a free 30-question AB-900 daily set with source-backed explanations, local progress, and a fresh rotation every morning.

30 daily web questions Source-backed explanations 7-day score history Questions updated at Apr 14, 2026, 7:33 PM CDT
AB-900 icon

AB-900

Microsoft 365 Copilot and Agent Administration Fundamentals (AB-900)

Why this page works

  • Thirty focused questions every day
  • Source links on every explanation
  • Local progress saved automatically
  • Email sync path ready for later
  • Apps provide deeper drills when available
Today's 30 AB-900 questions

Use this AB-900 practice test to review Microsoft 365 Copilot Admin. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
30 questions
Daily set rotates at 10:00 AM local time
Progress
0/30
Answered on this page session
Accuracy
0%
Loading countdown…

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily AB-900 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

120 verified questions are currently in the live bank. Questions updated at Apr 14, 2026, 7:33 PM CDT. The daily set rotates at 10:00 AM local time, and each explanation links back to the source used to write it. Use the web set for quick practice, then switch to the app when available for larger banks and deeper review.

Official exam resources

Use these official Microsoft resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent Microsoft practice pages too? Microsoft practice hub.

Question 1 of 30
Objective 3.3 Perform basic administrative tasks for Copilot and agents

Which hosting option in Microsoft Foundry Agent Service is container-based, managed?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: Fully managed is incorrect because it refers to a different type of service management rather than specifically container-based hosting.

B. Incorrect: Multi-agent, branching is incorrect because it describes a configuration option for agents but does not relate to the hosting environment being container-based and managed.

C. Incorrect: Custom logic is incorrect because it pertains to agent behavior customization and is unrelated to the hosting infrastructure.

D. Correct: Container-based, managed is correct because it accurately identifies the container-based, managed hosting option in Microsoft Foundry Agent Service.

Why this matters: This matters because agent-administration questions test whether hosting, orchestration, and workflow terms match how Copilot agents are deployed.
Question 2 of 30
Objective 1.1 Identify the core features and objects of Microsoft 365 services

In the Microsoft 365 admin center, which section allows you to manage email settings?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Correct: Email and calendars is correct because it includes the section where you can manage email settings and other related configurations in Microsoft 365.

B. Incorrect: Manage users is incorrect because managing users involves setting up user accounts and licenses, not email settings.

C. Incorrect: Security settings is incorrect because they are for configuring policies to protect data and systems, not for managing email settings directly.

D. Incorrect: Subscription management is incorrect because it deals with purchasing and managing subscriptions, unrelated to email settings.

Why this matters: This matters because Microsoft 365 admin questions test which admin area changes mail, groups, users, or collaboration settings.
Question 3 of 30
Objective 2.3 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which feature of Microsoft Purview Data Security Posture Management (DSPM) helps in identifying sensitive information within AI applications like Copilots?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Compliance Manager risks is incorrect because it focus on compliance issues rather than identifying sensitive data within AI applications.

B. Incorrect: Insider Risk Management alerts is incorrect because they are designed to detect insider threats and do not specifically address the identification of sensitive information in AI contexts.

C. Correct: Data Explorer for sensitive information is tailored to identify and manage sensitive data, including within AI applications like Copilots.

D. Incorrect: Purview DLP and Communication Compliance violations is incorrect because they pertain more to policy enforcement rather than identifying sensitive data specifically.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 4 of 30
Objective 3.1 Perform basic administrative tasks for Copilot and agents

Which feature allows an Azure agent to analyze and upgrade Java applications?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: Copilot code completion is incorrect because it does not involve analyzing and upgrading Java applications.

B. Incorrect: Monthly license model is incorrect because it is a monthly license model relates to cost structure rather than application analysis or upgrade capabilities.

C. Incorrect: Researcher data migration is incorrect because it pertains to transferring research datasets, unrelated to Java application upgrades.

D. Correct: Agent application analysis allows for the examination and enhancement of Java applications in Azure.

Why this matters: This matters because agent-administration questions test whether hosting, orchestration, and workflow terms match how Copilot agents are deployed.
Question 5 of 30
Objective 1.2 Identify the core features and objects of Microsoft 365 services

Which pillar of Zero Trust is primarily concerned with securing identity and device access in Microsoft 365?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Correct: Identity is correct because it focuses on secure authentication and management of identities and devices in Microsoft 365.

B. Incorrect: Threat protection is incorrect because it deals with detecting and responding to security threats rather than managing identity access.

C. Incorrect: Intelligence is incorrect because it involves using data analytics for better decision-making, not securing identity and device access.

D. Incorrect: Authorization is incorrect because it is a part of the identity pillar but does not encompass all aspects of securing identities and devices.

Why this matters: This matters because Zero Trust questions test whether identity, device, and access risk are verified before Microsoft 365 resources are allowed.
Question 6 of 30
Objective 2.4 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which tool in SharePoint Advanced Management restricts access to sensitive sites?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: User Permissions Manager is incorrect because it does not specifically restrict access to sensitive sites in SharePoint.

B. Incorrect: Data Loss Prevention (DLP) policies is incorrect because they are used for protecting data from being shared outside the organization but do not directly manage site access restrictions.

C. Incorrect: SharePoint Alerts is incorrect because it notify users about updates or changes, but they do not control who can access sensitive sites.

D. Correct: Restricted Site Access Policies in SharePoint Advanced Management specifically restrict access to sensitive sites.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 7 of 30
Objective 3.2 Perform basic administrative tasks for Copilot and agents

Which feature in the Microsoft 365 admin center allows you to monitor and analyze the usage of Microsoft 365 Copilot?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: Billing Dashboard is incorrect because it is the Billing Dashboard focuses on financial information and does not provide insights into Copilot usage.

B. Incorrect: User Management Console is incorrect because it handles user accounts and permissions but does not offer analytics for Copilot usage.

C. Correct: Copilot Analytics specifically provides tools to monitor and analyze how Microsoft 365 Copilot is being used within your organization.

D. Incorrect: License Assignment Manager is incorrect because it deals with assigning licenses to users, which is unrelated to monitoring Copilot usage.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 8 of 30
Objective 1.3 Identify the core features and objects of Microsoft 365 services

Which service under Microsoft Purview offers both a Standard and Premium version for tenant-level auditing?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Microsoft Priva Privacy Risk Management is incorrect because it does not offer both Standard and Premium versions for tenant-level auditing.

B. Correct: Microsoft Purview Audit (Standard) offers both a Standard and Premium version for tenant-level auditing, aligning with the requirements of the question.

C. Incorrect: Microsoft Purview Collection Policies is incorrect because they are related to data governance but do not provide tenant-level auditing options in different versions.

D. Incorrect: Microsoft Purview Communications Compliance is incorrect because it focuses on monitoring communications for compliance issues rather than offering tenant-level auditing.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 9 of 30
Objective 2.1 Understand data protection and governance tasks for Microsoft 365 and Copilot

What does the classic version of Data Security Posture Management in Microsoft Purview provide for AI applications?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Automated threat detection and response is incorrect because it focuses on automated threat detection and response, which are important but not specifically highlighted as core features of Data Security Posture Management for AI applications in Microsoft Purview.

B. Incorrect: User behavior analytics and reporting is incorrect because they are valuable for understanding how users interact with data but do not directly address the security and compliance protections provided by Data Security Posture Management.

C. Correct: Data security and compliance protections is correct because it accurately describes that the classic version of Data Security Posture Management in Microsoft Purview offers essential safeguards to ensure AI applications adhere to data protection standards and regulatory requirements.

D. Incorrect: Real-time data encryption services is incorrect because they are crucial for protecting data but are not specifically mentioned as a primary feature of Data Security Posture Management for AI applications.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 10 of 30
Objective 3.1 Perform basic administrative tasks for Copilot and agents

Which licensing model allows you to pay only when using Azure's AI-powered agent services?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Correct: Pay-as-you-go is correct because it allows you to pay only when using Azure's AI-powered agent services, making it ideal for unpredictable usage patterns.

B. Incorrect: Monthly license is incorrect because it is a monthly license would require payment regardless of the actual usage of the service during that month.

C. Incorrect: Annual subscription is incorrect because it is an annual subscription would obligate you to pay for a full year even if your use of the service varies or decreases over time.

D. Incorrect: Researcher use cases is incorrect because they are specific scenarios and do not represent a licensing model available to all users.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 11 of 30
Objective 1.1 Identify the core features and objects of Microsoft 365 services

Which section in the Microsoft 365 admin center would you use to manage distribution groups?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Manage users and licenses is incorrect because managing users and licenses does not include distribution group management.

B. Correct: Email and calendars settings is correct because they is the Email and calendars settings section includes tools to manage distribution groups.

C. Incorrect: SharePoint site libraries management is incorrect because it pertains to document storage and collaboration, not email-related features like distribution groups.

D. Incorrect: Security and compliance is incorrect because it focuses on policies and controls for data protection and governance, unrelated to managing distribution groups.

Why this matters: This matters because Microsoft 365 admin questions test which admin area changes mail, groups, users, or collaboration settings.
Question 12 of 30
Objective 2.2 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which service within Microsoft Purview is designed to ensure that generative AI applications like Copilots adhere to security standards?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Microsoft Graph API is incorrect because it provides access to data and services in Microsoft cloud environments but does not specifically manage security posture for AI applications.

B. Correct: Data Security Posture Management for AI (classic) in Microsoft Purview is designed to ensure that generative AI applications adhere to security standards and compliance requirements.

C. Incorrect: Azure Active Directory Permissions is incorrect because they are related to managing access control within an organization but do not specifically address the security of AI applications like Copilots.

D. Incorrect: Microsoft 365 Defender is incorrect because it focuses on threat protection, incident response, and compliance for Microsoft 365 services rather than specific security management for generative AI applications.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 13 of 30
Objective 3.3 Perform basic administrative tasks for Copilot and agents

Which hosting option in Microsoft Foundry Agent Service is container-based and managed?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: Fully managed is incorrect because it refers to a service where Microsoft handles all aspects of management and maintenance, but it does not specifically indicate container-based hosting.

B. Incorrect: Multi-agent, branching is incorrect because it describes a scenario involving multiple agents with branching logic, which is unrelated to the specific type of hosting environment.

C. Correct: Container-based, managed refers to an approach where Microsoft Foundry Agent Service uses containers for orchestration and management, providing a scalable and efficient solution.

D. Incorrect: Custom logic is incorrect because it pertains to user-defined rules or scripts that agents follow, rather than describing the hosting infrastructure.

Why this matters: This matters because agent-administration questions test whether hosting, orchestration, and workflow terms match how Copilot agents are deployed.
Question 14 of 30
Objective 1.1 Identify the core features and objects of Microsoft 365 services

Which feature in the Microsoft 365 admin center allows you to manage distribution groups?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Correct: Manage email settings is correct because managing email settings includes options to configure and oversee distribution groups.

B. Incorrect: Secure your users is incorrect because securing your users pertains to setting up security policies and compliance management rather than managing distribution groups directly.

C. Incorrect: Set up shared mailboxes is incorrect because setting up shared mailboxes involves creating accounts that multiple people can use, which is different from managing distribution groups.

D. Incorrect: Manage service plans is incorrect because managing service plans relates to assigning or removing services for users or groups, not specifically handling distribution group configurations.

Why this matters: This matters because Microsoft 365 admin questions test which admin area changes mail, groups, users, or collaboration settings.
Question 15 of 30
Objective 2.3 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which feature of Microsoft Purview Data Security Posture Management (DSPM) is used to identify potential compliance violations in AI applications like Copilots?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Purview DLP and Communication Compliance violations is incorrect because they are related to data loss prevention and communication policies rather than identifying compliance risks in AI applications.

B. Incorrect: Data Explorer for sensitive information is incorrect because it focuses on discovering and classifying sensitive data, not specifically on identifying compliance risks associated with AI applications like Copilots.

C. Incorrect: Insider Risk Management alerts is incorrect because it focus on detecting insider threats and misuse of company resources, rather than compliance violations specific to AI applications.

D. Correct: Compliance Manager risks identify potential compliance issues in AI applications such as Copilots by assessing adherence to regulatory requirements.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 16 of 30
Objective 3.3 Perform basic administrative tasks for Copilot and agents

Which type of agent in Microsoft Foundry Agent Service is best suited for creating stable endpoints that can be shared through Microsoft Teams?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Correct: Workflow agents are designed to create stable endpoints that can be easily shared through Microsoft Teams.

B. Incorrect: Prompt agents is incorrect because they are used for generating responses based on user input and do not provide stable endpoints for sharing.

C. Incorrect: Hosted agents (preview) is incorrect because it offer a managed environment but are not specifically tailored for creating stable endpoints for Microsoft Teams integration.

D. Incorrect: Code-based agents is incorrect because it allow users to write custom scripts, which may lack the stability and ease of use required for consistent endpoint sharing in Teams.

Why this matters: This matters because agent-administration questions test whether hosting, orchestration, and workflow terms match how Copilot agents are deployed.
Question 17 of 30
Objective 1.1 Identify the core features and objects of Microsoft 365 services

In the Microsoft 365 admin center, which section would you use to manage SharePoint site libraries?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Secure your environment is incorrect because it pertains to security settings and does not relate to managing SharePoint site libraries.

B. Incorrect: Manage distribution groups is incorrect because distribution groups are related to email management rather than SharePoint site library administration.

C. Correct: Email and calendars is correct because they is the 'Email and calendars' section includes features for managing SharePoint site libraries, among other functionalities.

D. Incorrect: Set up shared mailboxes is incorrect because setting up shared mailboxes pertains to email functionality and does not involve SharePoint site library management.

Why this matters: This matters because Microsoft 365 admin questions test which admin area changes mail, groups, users, or collaboration settings.
Question 18 of 30
Objective 2.1 Understand data protection and governance tasks for Microsoft 365 and Copilot

What is the primary purpose of Data Security Posture Management in Microsoft Purview?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Correct: To ensure data security for AI applications is correct because data Security Posture Management in Microsoft Purview ensures data security specifically for AI applications.

B. Incorrect: To manage communication compliance is incorrect because managing communication compliance is a separate function and does not pertain to securing data for AI applications.

C. Incorrect: To prevent insider risks is incorrect because preventing insider risks, while important, is not the primary focus of Data Security Posture Management for AI applications.

D. Incorrect: To protect against data loss is incorrect because protecting against data loss is crucial but it's not the specific purpose of managing security posture for AI applications.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 19 of 30
Objective 3.1 Perform basic administrative tasks for Copilot and agents

What is a capability of Azure's AI-powered agents related to .NET applications?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: Code refactoring is incorrect because it involves restructuring existing code to improve readability and maintainability but does not directly relate to AI-powered agent capabilities.

B. Incorrect: Application migration is incorrect because it refers to moving applications from one environment to another, which is a manual process rather than an AI-driven analysis task.

C. Incorrect: Cost optimization is incorrect because it focuses on reducing expenses in cloud services through various strategies, unrelated to the specific capability of analyzing and upgrading .NET applications.

D. Correct: Upgrade analysis is correct because azure's AI-powered agents can analyze current application states and recommend or perform upgrades for .NET applications.

Why this matters: This matters because Microsoft 365 and Copilot questions test which control handles the specific data protection, compliance, or governance job in the scenario.
Question 20 of 30
Objective 1.1 Identify the core features and objects of Microsoft 365 services

In the Microsoft 365 admin center, which section would you use to manage Exchange Online mailboxes?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Manage users is incorrect because managing users in the Microsoft 365 admin center focuses on user accounts and licenses rather than mailbox settings.

B. Correct: Email and calendars is correct because they is the Email and calendars section includes tools to manage Exchange Online mailboxes, email policies, and other related features.

C. Incorrect: Security settings is incorrect because they are used for configuring protection measures like data loss prevention and compliance management, not directly managing mailboxes.

D. Incorrect: SharePoint sites is incorrect because it pertain to document management and collaboration within Microsoft 365, unrelated to mailbox administration.

Why this matters: This matters because Microsoft 365 admin questions test which admin area changes mail, groups, users, or collaboration settings.
Question 21 of 30
Objective 2.3 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which feature of Microsoft Purview Data Security Posture Management (DSPM) is used to detect sensitive information within AI applications such as Copilots?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Compliance Manager is incorrect because it focuses on tracking and managing compliance across an organization rather than detecting sensitive data within AI applications.

B. Correct: Data Explorer specifically scans for sensitive information in datasets used by AI applications like Copilots to ensure data security and privacy.

C. Incorrect: Insider Risk Management is incorrect because it monitors employee activities related to potential insider threats, not the detection of sensitive data within AI systems.

D. Incorrect: Communication Compliance is incorrect because it focuses on monitoring and managing communications to comply with regulatory requirements, unrelated to detecting sensitive information in AI applications.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 22 of 30
Objective 3.1 Perform basic administrative tasks for Copilot and agents

Which model is used to license Azure's AI-powered agents?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Correct: Pay-as-you-go is correct because azure's AI-powered agents are licensed under a pay-as-you-go model.

B. Incorrect: Monthly subscription is incorrect because it does not accurately describe the licensing model for Azure's AI-powered agents.

C. Incorrect: Annual commitment is incorrect because it is not the licensing model used for Azure's AI-powered agents.

D. Incorrect: Perpetual licensing is incorrect because it does not apply to Azure's AI-powered agents.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 23 of 30
Objective 1.2 Identify the core features and objects of Microsoft 365 services

Which principle is crucial for deploying Zero Trust in Microsoft 365 to ensure secure access to identities?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Network segmentation is incorrect because it focuses on dividing networks into smaller parts to enhance security but does not directly address identity verification.

B. Incorrect: Device encryption is incorrect because it protects data stored on devices but does not ensure secure access based on user identity and context.

C. Correct: Identity verification ensures that only authorized users gain access, a fundamental aspect of Zero Trust in Microsoft 365.

D. Incorrect: User behavior analytics is incorrect because it monitors actions to detect anomalies but does not directly control or verify the identity of accessing users.

Why this matters: This matters because Zero Trust questions test whether identity, device, and access risk are verified before Microsoft 365 resources are allowed.
Question 24 of 30
Objective 2.4 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which tool in the Microsoft Purview Data Security Posture Management (DSPM) can be used to identify oversharing of sensitive information within SharePoint sites?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Restricted Site Access is incorrect because it focuses on controlling who can access a site rather than identifying oversharing of sensitive information.

B. Incorrect: SharePoint Advanced Management is incorrect because it refers to general administrative tasks and does not specifically address data security or monitoring for oversharing issues.

C. Correct: Data Access Governance Reports help organizations identify and manage instances where sensitive information might be shared too widely, ensuring compliance with data protection policies.

D. Incorrect: AI Use Monitoring is incorrect because it pertains to tracking the usage of artificial intelligence tools rather than managing data access governance within SharePoint.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 25 of 30
Objective 3.2 Perform basic administrative tasks for Copilot and agents

Where in the Microsoft 365 admin center can you manage pay-as-you-go billing policies for Microsoft 365 Copilot?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: User management is incorrect because it focuses on managing users and their permissions rather than billing policies.

B. Correct: Billing and subscriptions is correct because it allows administrators to manage pay-as-you-go billing policies for Microsoft 365 Copilot.

C. Incorrect: Copilot settings is incorrect because they are used to configure the features and capabilities of Copilot, not its billing.

D. Incorrect: License management is incorrect because it deals with assigning and managing licenses for users, not billing policies.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 26 of 30
Objective 1.2 Identify the core features and objects of Microsoft 365 services

What is a key component in deploying Zero Trust principles within Microsoft 365 for securing identity?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Threat Protection is incorrect because alone does not address identity management and verification required by Zero Trust principles.

B. Incorrect: Device Access Policies is incorrect because it is important but does not encompass the full scope of securing identities under a Zero Trust model.

C. Correct: Identity Infrastructure is correct because deploying an identity infrastructure is essential for verifying user identities continuously, which is fundamental to implementing Zero Trust in Microsoft 365.

D. Incorrect: Intelligence is incorrect because while intelligence is valuable, it does not directly address the core requirement of managing and securing identities.

Why this matters: This matters because Zero Trust questions test whether identity, device, and access risk are verified before Microsoft 365 resources are allowed.
Question 27 of 30
Objective 2.4 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which feature in SharePoint Advanced Management helps monitor oversharing of sensitive information?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: SharePoint Alerts is incorrect because they are used to notify users of updates and changes but do not monitor oversharing.

B. Incorrect: Restricted Site Access is incorrect because it controls who can access certain sites but does not track oversharing activities.

C. Correct: Data Access Governance Reports help identify and monitor oversharing in SharePoint, ensuring sensitive information is protected.

D. Incorrect: User Activity Logs is incorrect because record user actions but do not specifically address or prevent oversharing of sensitive data.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Question 28 of 30
Objective 3.2 Perform basic administrative tasks for Copilot and agents

How can you monitor the usage and adoption of Microsoft 365 Copilot in your organization?

Concept tested: Perform basic administrative tasks for Copilot and agents

A. Incorrect: Reviewing billing statements is incorrect because it does not provide insights into how users are adopting and using Microsoft 365 Copilot.

B. Incorrect: Using the Security & Compliance Center is incorrect because it is the Security & Compliance Center focuses on security policies and compliance rather than usage analytics for Copilot.

C. Incorrect: By checking email logs is incorrect because checking email logs would not give comprehensive data about Copilot's adoption and user engagement across the organization.

D. Correct: Through the Copilot Analytics dashboard is correct because it is the Copilot Analytics dashboard provides specific insights into how users are adopting and using Microsoft 365 Copilot.

Why this matters: This matters because Copilot administration questions separate license assignment, billing policy, analytics, and security controls.
Question 29 of 30
Objective 1.1 Identify the core features and objects of Microsoft 365 services

In the Microsoft 365 admin center, which section would you use to manage distribution groups?

Concept tested: Identify the core features and objects of Microsoft 365 services

A. Incorrect: Manage users and devices is incorrect because managing users and devices does not include distribution groups.

B. Correct: Email and calendars includes the management of distribution groups.

C. Incorrect: SharePoint sites libraries is incorrect because they are unrelated to managing distribution groups.

D. Incorrect: Security settings is incorrect because it do not cover the administration of distribution groups.

Why this matters: This matters because Microsoft 365 admin questions test which admin area changes mail, groups, users, or collaboration settings.
Question 30 of 30
Objective 2.2 Understand data protection and governance tasks for Microsoft 365 and Copilot

Which service is responsible for ensuring that data security and compliance protections are in place when using generative AI applications like Copilots?

Concept tested: Understand data protection and governance tasks for Microsoft 365 and Copilot

A. Incorrect: Microsoft Defender for Cloud Apps is incorrect because it focuses on monitoring and managing cloud app risks rather than providing specific data security and compliance protections for generative AI applications.

B. Incorrect: Azure Information Protection is incorrect because primarily deals with classifying, labeling, and protecting sensitive information in documents and emails, not specifically for generative AI applications like Copilots.

C. Correct: Microsoft Purview Data Security Posture Management for AI is designed to provide data security and compliance protections tailored for generative AI applications such as Copilots.

D. Incorrect: Office 365 Advanced Threat Analytics is incorrect because it focuses on detecting advanced threats in email, collaboration apps, and file shares rather than providing specific data security and compliance protections for generative AI applications.

Why this matters: This matters because Copilot governance questions test which Purview control handles AI-specific data exposure, compliance risk, or posture.
Where to go after the daily web set

How are AB-900 questions generated?

dotCreds builds AB-900 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 30-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AB-900 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.

Why use the app when available?

The web page is the quick free sampler. If a dotCreds app is available for AB-900, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.