Microsoft certification preparation
AB-900 Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- AB-900
- Provider
- Microsoft
- Full set
- 417 questions
- Last Update Check
Woodgrove Bank has several custom agents in production and wants to understand how
often they are used and how adoption varies by agent. The AI admin prefers a built-in report
in the Microsoft 365 admin center that shows active users and usage for each agent
without exporting raw logs.
Which report should the admin use?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Tailwind Traders has started using the Microsoft 365 Copilot app with several built-in
agents visible in the left navigation. The Copilot admin wants to block a specific built-in
agent that isn’t relevant for their region so users don’t see it in the app, but they still want to
keep Copilot Chat and search available. They decide to manage this centrally from the
Microsoft 365 admin center.
What should the admin do?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Contoso's compliance o[icer needs to quickly find all email messages and documents
that mention a specific external vendor across many Exchange mailboxes and
SharePoint/OneDrive locations. They don't need case management or legal hold; they just
want to run a search, preview results, and export the matching items for further review.
Which tool should they use?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Complete the sentence:
"When governing agents built with Copilot Studio, the Power Platform admin center is
primarily used to ________."
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Your organisation stores customer records in SharePoint and plans to let users query them
through agents. You want to stop users from accidentally sending credit card numbers to
external destinations via Copilot Chat or agents, even if they are allowed to see that data
internally. You decide to use Microsoft Purview.
In Microsoft Purview, you configure _______ to detect and block this kind of data exfiltration
in Copilot interactions.
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
What does a retention policy in Exchange Online do?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Your tenant currently has over 30 users permanently assigned to high-privilege roles such
as Global Administrator and Privileged Role Administrator “to avoid delays.” A red team
exercise demonstrates that compromising any one of these accounts gives long-term
control of the environment with no time limits, approvals, or additional prompts.
Leadership asks for a solution that enforces just-in-time admin access, requires elevation
to be time-bound, and records every activation for audit.
Which feature should you implement first to address these requirements?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Contoso’s HR department has built a Copilot Studio agent that answers employees’ HR
policy questions. They want only the HR security group to use it in Microsoft 365 Copilot
Chat, and they also want to ensure it doesn’t quietly roll out to the whole tenant.
As the AI admin, you’ve confirmed the HR sta[ already have appropriate Copilot licenses.
You now need to configure who can access this specific agent.
What is the most appropriate way to scope user access?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A manager complains that Copilot isn’t appearing in Word for a new employee. What
should you check first?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A new CISO is reviewing an existing Microsoft 365 deployment where internal tra[ic is
implicitly trusted once users connect through a VPN. They want to move to a model that
treats every access attempt as potentially hostile, even from corporate networks or
managed devices, and that tightly scopes what each identity can do.
Which approach best aligns with Microsoft’s core Zero Trust principles in this scenario?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
