MS-100 Risk Assessment & Management 4 — Questions and Answers
Question 1: A company must demonstrate compliance with GDPR. Which Microsoft 365 tool helps assess regulatory compliance posture and manage compliance activities with a built-in score?
- Microsoft Secure Score
- Microsoft Purview Compliance Manager (Correct answer)
- Azure Policy
- Microsoft Defender for Cloud
Correct answer: Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager provides a compliance score, pre-built regulatory templates (including GDPR), and action tracking to help organizations manage compliance obligations.
Question 2: Which risk management concept does Microsoft Secure Score's 'planned' status for an improvement action represent?
- The action has been completed and is providing score points
- The action has been noted as intentionally not implemented with a documented reason
- The action is scheduled for implementation and excluded from the score gap (Correct answer)
- The action is blocked by a third-party tool covering the same control
Correct answer: The action is scheduled for implementation and excluded from the score gap
Marking an improvement action as 'Planned' indicates it's on the roadmap for implementation but not yet complete; it doesn't increase the current score but tracks intent.
Question 3: An administrator wants to track when privileged roles are activated in Azure AD PIM. Which audit capability should they use?
- Azure AD sign-in logs
- PIM audit history (Correct answer)
- Microsoft Secure Score history
- Azure Activity Log
Correct answer: PIM audit history
Privileged Identity Management's audit history records all role activations, approvals, expirations, and assignment changes for privileged roles.
Question 4: An organization wants to reduce the attack surface by ensuring no user permanently holds the Global Administrator role. Which solution enforces just-in-time privileged access?
- Azure AD role-based access control (RBAC) with permanent assignments
- Azure AD Privileged Identity Management (PIM) with eligible assignments (Correct answer)
- Conditional Access policy requiring MFA for admins
- Azure AD Identity Protection user risk policy
Correct answer: Azure AD Privileged Identity Management (PIM) with eligible assignments
PIM with eligible assignments requires users to explicitly activate their role for a limited time window, ensuring Global Administrator is not permanently held.
Question 5: A security team wants to receive alerts when a user is assigned the Global Administrator role outside of PIM. Which tool should they configure?
- Microsoft Secure Score
- Azure AD Identity Protection
- Microsoft 365 Defender alert policies or PIM alerts (Correct answer)
- Service Health notifications
Correct answer: Microsoft 365 Defender alert policies or PIM alerts
PIM provides built-in alerts for direct role assignments that bypass the PIM workflow, and Microsoft 365 Defender alert policies can also trigger on suspicious admin role changes.
Question 6: Which Identity Protection feature allows admins to investigate the full sequence of events that contributed to a user being flagged as 'at risk'?
- Risky users report with drill-down to risk detections (Correct answer)
- Azure AD audit log export to SIEM
- Microsoft Secure Score recommendation details
- Conditional Access policy What If tool
Correct answer: Risky users report with drill-down to risk detections
The Risky users report lets admins click on a user to see all associated risk detections and their details, providing the full context behind the elevated risk level.
Question 7: A tenant has a 'High' user risk policy that blocks access. A user is permanently blocked because their password was previously compromised. What is the correct remediation flow?
- Disable the user risk policy globally to restore access
- Admin resets the user's password and dismisses the user risk in Identity Protection (Correct answer)
- The user completes MFA to unblock themselves
- Admin deletes the risky sign-in event from audit logs
Correct answer: Admin resets the user's password and dismisses the user risk in Identity Protection
When a user risk policy blocks a user, an admin must reset the password (remediating the compromised credential) and then dismiss the user risk to restore access.
A company must demonstrate compliance with GDPR.
Which Microsoft 365 tool helps assess regulatory compliance posture and manage compliance activities with a built-in score?