MS-500 Threat Protection & Security Operations 2 — Questions and Answers
Question 1: Which Microsoft Defender for Cloud Apps feature discovers unsanctioned cloud applications used by employees?
- App governance
- Cloud Discovery (Correct answer)
- Conditional Access App Control
- Activity policies
Correct answer: Cloud Discovery
Cloud Discovery analyzes network traffic logs to identify cloud apps being used by employees, revealing shadow IT in the organization.
Question 2: An admin wants to block downloads of sensitive files from unmanaged devices in real time. Which feature enables this?
- Microsoft Defender for Endpoint
- Conditional Access App Control in Defender for Cloud Apps (Correct answer)
- Safe Attachments policy
- Data Loss Prevention policy
Correct answer: Conditional Access App Control in Defender for Cloud Apps
Conditional Access App Control uses reverse proxy to monitor and control session activity in real time, including blocking downloads on unmanaged devices.
Question 3: What severity level should an organization assign when configuring Microsoft 365 Defender alert policies for high-impact events?
- Low
- Medium
- High (Correct answer)
- Informational
Correct answer: High
High-severity alerts should be assigned to events with significant business impact such as mass file deletion or ransomware activity.
Question 4: Which capability in Microsoft 365 Defender automates investigation and remediation of common threats?
- Threat Analytics
- Automated Investigation and Remediation (AIR) (Correct answer)
- Advanced Hunting
- Threat Intelligence
Correct answer: Automated Investigation and Remediation (AIR)
Automated Investigation and Remediation (AIR) automatically investigates alerts and takes remediation actions such as removing malicious emails or isolating devices.
Question 5: Which query language is used in Advanced Hunting within Microsoft 365 Defender?
- SQL
- Python
- Kusto Query Language (KQL) (Correct answer)
- PowerShell
Correct answer: Kusto Query Language (KQL)
Advanced Hunting uses Kusto Query Language (KQL) to search across 30 days of raw event data for threats and suspicious activity.
Question 6: What does the 'Threat Analytics' section of Microsoft 365 Defender provide?
- Real-time email filtering statistics
- Analyst reports on active threat campaigns and their impact on your organization (Correct answer)
- A list of all user sign-in activities
- Device compliance status across Intune
Correct answer: Analyst reports on active threat campaigns and their impact on your organization
Threat Analytics delivers Microsoft security researcher reports on active threat actors and campaigns, including their impact on and coverage across your environment.
Which Microsoft Defender for Cloud Apps feature discovers unsanctioned cloud applications used by employees?