MS-500 Threat Protection & Security Operations 1 — Questions and Answers
Question 1: Which Microsoft 365 Defender service protects against malicious links and attachments in email?
- Microsoft Defender for Identity
- Microsoft Defender for Office 365 (Correct answer)
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud Apps
Correct answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 provides Safe Links and Safe Attachments to protect users from malicious URLs and email attachments.
Question 2: What does Microsoft Defender for Identity primarily monitor?
- Cloud app usage and shadow IT
- On-premises Active Directory signals for identity-based attacks (Correct answer)
- Endpoint behaviors for malware
- Email for phishing campaigns
Correct answer: On-premises Active Directory signals for identity-based attacks
Microsoft Defender for Identity monitors on-premises Active Directory activity to detect identity-based attacks like pass-the-hash and lateral movement.
Question 3: Which feature in Microsoft Defender for Office 365 detonates suspicious attachments in a sandbox before delivery?
- Safe Links
- Safe Attachments (Correct answer)
- Anti-phishing policies
- Mail flow rules
Correct answer: Safe Attachments
Safe Attachments detonates email attachments in a virtual sandbox environment to check for malicious behavior before delivering them to users.
Question 4: An alert fires in Microsoft 365 Defender indicating a compromised user account. What is the first recommended action?
- Delete the user account immediately
- Disable the account and reset the password (Correct answer)
- Increase the user's MFA requirements
- Review the user's OneDrive files
Correct answer: Disable the account and reset the password
When an account is suspected compromised, immediately disabling it and forcing a password reset stops the attacker while preserving the account for investigation.
Question 5: Which Microsoft 365 Defender portal provides a unified view of incidents across all Defender services?
- Microsoft Purview compliance portal
- Microsoft 365 Defender portal (security.microsoft.com) (Correct answer)
- Azure Security Center
- Microsoft Endpoint Manager
Correct answer: Microsoft 365 Defender portal (security.microsoft.com)
The Microsoft 365 Defender portal at security.microsoft.com aggregates incidents, alerts, and investigations from all Defender services into a single unified console.
Question 6: What is the purpose of Attack Simulation Training in Microsoft Defender for Office 365?
- Automatically block phishing emails before delivery
- Run simulated phishing campaigns to train users to recognize attacks (Correct answer)
- Scan email for malware signatures
- Test firewall rules against known attack patterns
Correct answer: Run simulated phishing campaigns to train users to recognize attacks
Attack Simulation Training allows security teams to launch simulated phishing and social engineering campaigns to measure and improve user security awareness.
Which Microsoft 365 Defender service protects against malicious links and attachments in email?