Microsoft Defender for Office 365 provides protection from phishing and malware attacks. Answer: Yes
Microsoft Defender for Identity monitors identities in Active Directory domains. Answer: Yes
Microsoft Defender Vulnerability Management provides protection for software as a service (SaaS) applications. Answer: No
The correct selections are Yes, Yes, No . Microsoft documents that Microsoft Defender for Office 365 protects email and collaboration workloads from threats such as phishing and malware , including zero-day malware and business email compromise scenarios. That makes statement 1 Yes .
Statement 2 is also Yes because Microsoft states that Microsoft Defender for Identity monitors identity signals from on-premises Active Directory and related identity infrastructure to detect suspicious activity and identity-based attacks. Microsoft further describes monitoring information generated from your organization’s Active Directory, network, and event activities.
Statement 3 is No because Microsoft Defender Vulnerability Management is focused on discovering and prioritizing vulnerabilities across devices and assets such as Windows, macOS, Linux, mobile platforms, and network devices. Microsoft’s SaaS application protection offering is Microsoft Defender for Cloud Apps , not Defender Vulnerability Management.
Question # 25
Select the answer that correctly completes the sentence.
The correct selections are No, No, Yes . Microsoft states that for Microsoft 365 Copilot , customer prompts, responses, and Microsoft Graph grounding data aren’t used to train foundation models . Microsoft also explains that Copilot processes organizational data within the service boundary and applies the same commitments that protect Microsoft 365 customer data. That makes statements 1 and 2 No . Microsoft further documents that Microsoft 365 Copilot grounds responses using Microsoft Graph and only surfaces data that the user is permitted to access , so it respects existing identity, access, and permission controls in the tenant. That makes statement 3 Yes .
This behavior is a core part of Copilot’s enterprise design. Microsoft describes Copilot as inheriting your organization’s existing Microsoft 365 permissions model, including access controls on content in SharePoint, OneDrive, Exchange, Teams, and other Microsoft 365 services. So Copilot does not grant new access; it works within the permissions already assigned to the signed-in user.