Summer Sale - Special Discounts Limited Time 55% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 63r59951

Note! The MS-500 Exam is no longer available.

MS-500 Microsoft 365 Security Administration Questions and Answers

Questions 4

Which user passwords will User2 be prevented from resetting?

Options:

A.

User6 and User7

B.

User4 and User6

C.

User4 only

D.

User7 and User8

E.

User8 only

Buy Now
Questions 5

You have a Microsoft 365 tenant that has modern authentication enabled.

You have Windows 10, MacOS. Android, and iOS devices that are managed by using Microsoft Endpoint Manager. Some users have older email client applications that use Basic authentication to connect to Microsoft Exchange Online. You need to implement a solution to meet the following security requirements-

• Allow users to connect to Exchange Online only by using email client applications that support modern authentication protocols based on OAuth 2.0.

• Block connections to Exchange Online by any email client applications that do NOT support modern authentication.

What should you implement?

Options:

A.

a conditional access policy in Azure Active Directory (Azure AD)

B.

an OAuth app policy m Microsoft Defender for Cloud Apps

C.

a compliance policy in Microsoft Endpoint Manager

D.

an application control profile in Microsoft Endpoint Manager

Buy Now
Questions 6

You have a Microsoft SharePoint Online site named Sitel that contains the files shown in the following table.

MS-500 Question 6

You have a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rules shown in the following table.

MS-500 Question 6

You apply DLP1 toSitel.

Which policy tips will appear for File2?

Options:

A.

Tip1 only

B.

Tip2only

C.

Tip3only

D.

Tip1 and Tip2 only

Buy Now
Questions 7

You have a Microsoft 365 subscription that uses a default domain name of contoso.com.

The multi-factor authentication (MFA) service settings are configured as shown in the exhibit. (Clock the Exhibit tab.)

MS-500 Question 7

In contoso.com, you create the users shown in the following table.

MS-500 Question 7

What is the effect of the configuration? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 7

Options:

Buy Now
Questions 8

Which users are members of ADGroup1 and ADGroup2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 8

Options:

Buy Now
Questions 9

You have a Microsoft Defender for Endpoint deployment that has custom network indicators turned on. Microsoft Defender for Endpoint protects two computers that run Windows 10 as shown in the following table.

MS-500 Question 9

Microsoft Defender foe Endpoint has the device groups shown in the following table.

MS-500 Question 9

MS-500 Question 9

Options:

Buy Now
Questions 10

You have a Microsoft 365 E5 subscription

You need to ensure that users who are assigned the Exchange administrator role have time-limited permissions and must use multi factor authentication (MFA) to request the permissions.

What should you use to achieve the goal?

Options:

A.

Microsoft 365 user management

B.

Microsoft Azure AD group management

C.

Security & Compliance permissions

D.

Microsoft Azure Active Directory (Azure AD} Privileged Identity Management

Buy Now
Questions 11

Which role should you assign to User1?

Options:

A.

Global administrator

B.

User administrator

C.

Privileged role administrator

D.

Security administrator

Buy Now
Questions 12

Which policies apply to which devices? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 12

Options:

Buy Now
Questions 13

You need to meet the technical requirements for User9. What should you do?

Options:

A.

Assign the Privileged administrator role to User9 and configure a mobile phone number for User9

B.

Assign the Compliance administrator role to User9 and configure a mobile phone number for User9

C.

Assign the Security administrator role to User9

D.

Assign the Global administrator role to User9

Buy Now
Questions 14

What should User6 use to meet the technical requirements?

Options:

A.

Supervision in the Security & Compliance admin center

B.

Service requests in the Microsoft 365 admin center

C.

Security & privacy in the Microsoft 365 admin center

D.

Data subject requests in the Security & Compliance admin center

Buy Now
Questions 15

You are evaluating which devices are compliant in Intune.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

MS-500 Question 15

Options:

Buy Now
Questions 16

You are evaluating which finance department users will be prompted for Azure MFA credentials.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

MS-500 Question 16

Options:

Buy Now
Questions 17

You have a Microsoft 365 subscription linked to an Azure Active Directory (Azure AD) tenant that contains a user named User1.

You have a Data Subject Request (DSR) case named Case1.

You need to allow User1 to export the results of Case1. The solution must use the principle of least privilege.

Which role should you assign to User1 for Case1?

Options:

A.

eDiscovery Manager

B.

Security Operator

C.

eDiscovery Administrator

D.

Global Reader

Buy Now
Questions 18

Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

You have a Microsoft 365 tenant. You create a label named CompanyConfidential in Microsoft Azure

Information Protection.

You add CompanyConfidential to a global policy.

A user protects an email message by using CompanyConfidential and sends the label to several external

recipients. The external recipients report that they cannot open the email message.

You need to ensure that the external recipients can open protected email messages sent to them.

Solution: You modify the content expiration settings of the label.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 19

You have a Microsoft 365 subscription that contains several Windows 10 devices. The devices are managed by using Microsoft Intune.

You need to enable Windows Defender Exploit Guard (Windows Defender EG) on the devices.

Which type of device configuration profile should you use?

Options:

A.

Endpoint protection

B.

Device restrictions

C.

Identity protection

D.

Windows Defender ATP

Buy Now
Questions 20

You have a Microsoft 365 subscription.

You enable auditing for the subscription.

You plan to provide a user named Auditor with the ability to review audit logs.

You add Auditor to the Global administrator role group.

Several days later, you discover that Auditor disabled auditing.

You remove Auditor from the Global administrator role group and enable auditing.

  • Be prevented from disabling auditing
  • Use the principle of least privilege
  • Be able to review the audit log

To which role group should you add Auditor?

Options:

A.

Security operator

B.

Security reader

C.

Security administrator

D.

Compliance administrator

Buy Now
Questions 21

You have several Conditional Access policies that block noncompliant devices from connecting to services.

You need to identify which devices are blocked by which policies.

What should you use?

Options:

A.

the Device compliance report in the Microsoft Endpoint Manager admin center

B.

the Device compliance trends report in the Microsoft Endpoint Manager admin center

C.

Activity log in the Cloud App Security admin center

D.

the Conditional Access Insights and Reporting workbook in the Azure Active Directory admin center

Buy Now
Questions 22

You have a Microsoft 365 that uses Microsoft ShareP0•int Online.

You need to ensure that users can only share files with users at specified partner companies. The solution must minimize administrative effort.

What should you do?

Options:

A.

Allow only in specific security groups to share externally.

B.

Set File and folder links to people.

C.

Limit external by domain

D.

Set External sharing to New and existing guest

Buy Now
Questions 23

You have a Microsoft 365 subscription.

You configure Microsoft Defender for Endpoint as shown in the following table.

MS-500 Question 23

You onboard devices to Microsoft Defender for Endpoint as shown in the following table.

MS-500 Question 23

Microsoft Defender for Endpoint contains the incidents shown in the following table.

MS-500 Question 23

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

MS-500 Question 23

Options:

Buy Now
Questions 24

You have a Microsoft 365 E5 subscription

You need to use Microsoft Cloud App Security to identify documents stored in Microsoft SharePomt Online that contain proprietary information.

What should you create in Cloud App Security?

Options:

A.

a data source and a file policy

B.

a data source and an app discovery policy

C.

an app connector and an app discovery policy

D.

an app connector and a We policy

Buy Now
Questions 25

Which IP address space should you include in the MFA configuration?

Options:

A.

131.107.83.0/28

B.

192.168.16.0/20

C.

172.16.0.0/24

D.

192.168.0.0/20

Buy Now
Questions 26

You need to create Group2.

What are two possible ways to create the group?

Options:

A.

an Office 365 group in the Microsoft 365 admin center

B.

a mail-enabled security group in the Microsoft 365 admin center

C.

a security group in the Microsoft 365 admin center

D.

a distribution list in the Microsoft 365 admin center

E.

a security group in the Azure AD admin center

Buy Now
Questions 27

How should you configure Azure AD Connect? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 27

Options:

Buy Now
Questions 28

You need to configure threat detection for Active Directory. The solution must meet the security requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

MS-500 Question 28

Options:

Buy Now
Questions 29

You need to implement Windows Defender ATP to meet the security requirements. What should you do?

Options:

A.

Configure port mirroring

B.

Create the ForceDefenderPassiveMode registry setting

C.

Download and install the Microsoft Monitoring Agent

D.

Run WindowsDefenderATPOnboardingScript.cmd

Buy Now
Questions 30

How should you configure Group3? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 30

Options:

Buy Now
Questions 31

You have a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. OneDrive stores files that are shared with external users. The files are configured as shown in the following table.

MS-500 Question 31

You create a data loss prevention (DLP) policy that applies to the content stored in OneDrive accounts. The policy contains the following three rules:

• Rulel:

• Conditions: Label 1, Detect content that's shared with people outside my organization

• Actions: Restrict access to the content for external users

• User notifications: Notify the user who last modified the content

• User overrides: On

• Priority: 0

• Rule2:

• Conditions: Label 1 or Label2

• Actions: Restrict access to the content

• Priority: 1

• Rule3:

• Conditions: Label2, Detect content that's shared with people outside my organization

• Actions: Restrict access to the content for external users

• User notifications: Notify the user who last modified the content

• User overrides: On

• Priority: 2

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

MS-500 Question 31

Options:

Buy Now
Questions 32

You have a Microsoft 365 tenant.

You need to retain Azure Active Directory (Azure AD) audit logs for two years. Administrators must be able to query the audit log information by using the Azure Active Directory admin center.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 32

Options:

Buy Now
Questions 33

Your company uses Microsoft Azure Advanced Threat Protection (ATP).

You enable the delayed deployment of updates for an Azure ATP sensor named Sensor1.

How long after the Azure ATP cloud service is updated will Sensor1 be updated?

Options:

A.

7 days

B.

24 hours

C.

1 hour

D.

48 hours

E.

12 hours

Buy Now
Questions 34

You need to recommend a solution to protect the sign-ins of Admin1 and Admin2.

What should you include in the recommendation?

Options:

A.

a device compliance policy

B.

an access review

C.

a user risk policy

D.

a sign-in risk policy

Buy Now
Questions 35

An administrator configures Azure AD Privileged Identity Management as shown in the following exhibit.

MS-500 Question 35

What should you do to meet the security requirements?

Options:

A.

Change the Assignment Type for Admin2 to Permanent

B.

From the Azure Active Directory admin center, assign the Exchange administrator role to Admin2

C.

From the Azure Active Directory admin center, remove the Exchange administrator role to Admin1

D.

Change the Assignment Type for Admin1 to Eligible

Buy Now
Questions 36

You need to recommend a solution that meets the technical and security requirements for sharing data with the partners.

What should you include in the recommendation? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Create an access review.

B.

Assign the Global administrator role to User1.

C.

Assign the Guest inviter role to User1.

D.

Modify the External collaboration settings in the Azure Active Directory admin center.

Buy Now
Questions 37

You need to recommend a solution for the user administrators that meets the security requirements for auditing.

Which blade should you recommend using from the Azure Active Directory admin center?

Options:

A.

Sign-ins

B.

Azure AD Identity Protection

C.

Authentication methods

D.

Access review

Buy Now
Questions 38

You install Azure ATP sensors on domain controllers.

You add a member to the Domain Admins group. You view the timeline in Azure ATP and discover that information regarding the membership change is missing.

You need to meet the security requirements for Azure ATP reporting.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 38

Options:

Buy Now
Questions 39

You plan to configure an access review to meet the security requirements for the workload administrators. You create an access review policy and specify the scope and a group.

Which other settings should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 39

Options:

Buy Now
Questions 40

NO: 7

You need to resolve the issue that targets the automated email messages to the IT team.

Which tool should you run first?

Options:

A.

Synchronization Service Manager

B.

Azure AD Connect wizard

C.

Synchronization Rules Editor

D.

IdFix

Buy Now
Questions 41

You need to recommend an email malware solution that meets the security requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

MS-500 Question 41

Options:

Buy Now
Exam Code: MS-500
Exam Name: Microsoft 365 Security Administration
Last Update: Dec 11, 2023
Questions: 327