MS-100 Risk Assessment & Management 3 — Questions and Answers
Question 1: An organization uses Microsoft Defender for Identity. Which attack scenario does it specifically detect in an on-premises Active Directory environment?
- OAuth consent phishing in Microsoft 365 apps
- Pass-the-hash and pass-the-ticket lateral movement attacks (Correct answer)
- Malicious email attachments in Exchange Online
- Insider threats via SharePoint file downloads
Correct answer: Pass-the-hash and pass-the-ticket lateral movement attacks
Microsoft Defender for Identity monitors on-premises AD traffic to detect credential-based attacks like pass-the-hash, pass-the-ticket, and other lateral movement techniques.
Question 2: A company needs to assess their current Microsoft 365 security posture against industry benchmarks. Which tool provides a quantified score with prioritized improvement actions?
- Microsoft Compliance Manager
- Microsoft Secure Score (Correct answer)
- Service Trust Portal
- Azure Advisor
Correct answer: Microsoft Secure Score
Microsoft Secure Score provides a numerical security posture rating and lists prioritized improvement actions to help organizations increase their defenses.
Question 3: Which Azure AD Identity Protection risk detection fires when a user's sign-in location is geographically impossible given their previous sign-in location and timing?
- Unfamiliar sign-in properties
- Anonymous IP address
- Atypical travel (Correct answer)
- Password spray
Correct answer: Atypical travel
The 'Atypical travel' detection identifies sign-ins from two geographically distant locations within a time window too short for realistic travel.
Question 4: An admin wants to ensure that users can self-remediate risky sign-ins without admin intervention. Which combination enables this?
- User risk policy set to block + admin-only remediation
- Sign-in risk policy requiring MFA + users registered for SSPR and MFA (Correct answer)
- Conditional Access blocking all High risk sign-ins
- Disabling legacy authentication protocols
Correct answer: Sign-in risk policy requiring MFA + users registered for SSPR and MFA
When a sign-in risk policy requires MFA and users are already registered for MFA, they can self-remediate risky sign-ins by completing the MFA challenge without admin help.
Question 5: A global admin reviews the 'Users flagged for risk' report and sees a user with a 'High' risk level. The user's risk was triggered by 'Leaked credentials'. What is the recommended immediate action?
- Delete the user account immediately
- Require the user to reset their password and dismiss the risk after verification (Correct answer)
- Disable all Conditional Access policies temporarily
- Remove the user's MFA registration
Correct answer: Require the user to reset their password and dismiss the risk after verification
For leaked credentials, the best practice is to require an immediate password reset (to invalidate the compromised credential) and then dismiss the risk after confirming the account is secure.
Question 6: Which Microsoft 365 tool aggregates security alerts from Defender products, Identity Protection, and third-party solutions into a unified incident queue?
- Microsoft Compliance Center
- Microsoft 365 Defender portal (Correct answer)
- Azure Security Center
- Service Health Dashboard
Correct answer: Microsoft 365 Defender portal
The Microsoft 365 Defender portal correlates alerts from multiple security products into unified incidents, enabling comprehensive investigation and response.
Question 7: An organization's Identity Protection policy is configured with a sign-in risk threshold of 'Low and above' requiring MFA. Which scenario would NOT trigger this policy?
- A sign-in from a known anonymous proxy
- A sign-in from a named location marked as trusted (Correct answer)
- A sign-in with atypical travel detection
- A sign-in from a malware-linked IP
Correct answer: A sign-in from a named location marked as trusted
Conditional Access policies can be scoped to exclude named trusted locations, so sign-ins from trusted IPs bypass the risk-based MFA requirement even if risk signals are present.
An organization uses Microsoft Defender for Identity.
Which attack scenario does it specifically detect in an on-premises Active Directory environment?