Microsoft 365 Security Administration (MS-500) — Questions and Answers
Question 1: A Microsoft 365 Security Administrator is asked to ensure all security configurations align with Microsoft's recommended security baselines. Where is the official source for these baselines?
- Microsoft Endpoint Manager Security Baselines (Correct answer)
- Microsoft Security Benchmark in Azure Policy
- Microsoft Compliance Manager
- Microsoft Secure Score recommendations
Correct answer: Microsoft Endpoint Manager Security Baselines
Microsoft Endpoint Manager (Intune) provides pre-configured Security Baselines that reflect Microsoft's best-practice security recommendations for Windows and Microsoft 365 apps.
Question 2: What role does peer review play in MS-500 - Microsoft 365 Security Administration practice?
- It provides quality assurance and professional development through collegial evaluation (Correct answer)
- It is only for beginners
- It replaces formal certification
- It creates unnecessary competition
Correct answer: It provides quality assurance and professional development through collegial evaluation
This is fundamental to MS-500 - Microsoft 365 Security Administration practice. It provides quality assurance and professional development through collegial evaluation represents the professional standard for professional standards in the MS-500 certification framework.
Question 3: In Microsoft Secure Score, what does a 'Regression' status on a recommended action indicate?
- The action was never configured
- The score for that action decreased since last measurement (Correct answer)
- The action requires a license upgrade
- The action is not applicable to your tenant
Correct answer: The score for that action decreased since last measurement
A Regression status means the improvement action's score contribution has decreased, signaling a security control degraded since it was last evaluated.
Question 4: When a security professional completes a forensic investigation in Microsoft 365, they must preserve the chain of custody for evidence. Which action best supports this requirement?
- Use eDiscovery holds and export via Microsoft Purview with a signed manifest (Correct answer)
- Copy audit logs to a SharePoint library
- Export audit logs to a CSV and store locally
- Archive mailboxes using Litigation Hold
Correct answer: Use eDiscovery holds and export via Microsoft Purview with a signed manifest
Microsoft Purview eDiscovery exports include a signed manifest that documents the integrity and source of collected evidence, supporting chain-of-custody requirements.
Question 5: A Microsoft 365 Security Administrator is responsible for maintaining a security operations playbook. What should the playbook include to meet professional standards?
- Step-by-step response procedures for common incident types, escalation paths, and tool references (Correct answer)
- Only the contact details of the security team
- Organizational charts and budget information
- A list of all security products in use
Correct answer: Step-by-step response procedures for common incident types, escalation paths, and tool references
A professional security playbook must include detailed procedural steps, decision trees for common incident types, escalation procedures, and references to the tools used in response.
Question 6: How do MS-500 professionals ensure compliance in daily practice?
- By memorizing all regulations
- Compliance is checked only annually
- By hiring a compliance officer
- By integrating compliance requirements into standard operating procedures and regular audits (Correct answer)
Correct answer: By integrating compliance requirements into standard operating procedures and regular audits
This is fundamental to MS-500 - Microsoft 365 Security Administration practice. By integrating compliance requirements into standard operating procedures and regular audits represents the professional standard for regulatory in the MS-500 certification framework.
Question 7: Which feature in Microsoft 365 provides a centralized view of threat exposure across endpoints, identities, cloud apps, and email to support enterprise-wide risk assessment?
- Microsoft Purview compliance portal
- Microsoft Intune endpoint analytics
- Microsoft Defender XDR unified portal (Correct answer)
- Microsoft Entra ID admin center
Correct answer: Microsoft Defender XDR unified portal
The Microsoft Defender XDR unified portal consolidates signals from Defender for Endpoint, Identity, Office 365, and Cloud Apps into a single pane for cross-domain risk assessment and investigation.
Question 8: A security admin wants to ensure that Conditional Access policies are not misconfigured before enforcing them broadly. Which feature allows testing a policy without blocking users?
- Policy exclusions
- Sign-in risk policy
- Report-only mode (Correct answer)
- Named locations
Correct answer: Report-only mode
Report-only mode evaluates a Conditional Access policy and logs what would have happened without actually enforcing block or grant controls.
Question 9: A financial services firm must comply with SEC Rule 17a-4 for immutable record retention. Which Microsoft 365 feature satisfies this requirement?
- SharePoint versioning
- Microsoft Teams channel archiving
- Azure AD Privileged Identity Management
- Microsoft Purview Retention Labels with Preservation Lock (Correct answer)
Correct answer: Microsoft Purview Retention Labels with Preservation Lock
Preservation Lock on Microsoft Purview retention policies ensures records cannot be deleted or modified before the retention period expires, satisfying SEC Rule 17a-4 WORM requirements.
Question 10: How should MS-500 professionals apply research findings to practice?
- Critically evaluate applicability, adapt to context, and monitor outcomes (Correct answer)
- Only follow systematic reviews
- Implement immediately without evaluation
- Ignore research that contradicts experience
Correct answer: Critically evaluate applicability, adapt to context, and monitor outcomes
This is fundamental to MS-500 - Microsoft 365 Security Administration practice. Critically evaluate applicability, adapt to context, and monitor outcomes represents the professional standard for research in the MS-500 certification framework.
Question 11: During a Microsoft 365 tenant migration, the security team discovers that guest users from an acquired company have excessive SharePoint permissions. Who should be the primary stakeholder to coordinate remediation?
- Business unit owners who sponsor the guest relationships (Correct answer)
- Microsoft support directly
- End users who shared the SharePoint sites
- The acquired company's IT administrator
Correct answer: Business unit owners who sponsor the guest relationships
Business unit owners who sponsor guest relationships are accountable for guest access decisions and must drive remediation to preserve business relationships while reducing risk.
Question 12: What is the value of written documentation in MS-500 professional communication?
- It is optional
- It creates permanent records, ensures clarity, and provides legal protection (Correct answer)
- It replaces verbal communication
- It is only for formal occasions
Correct answer: It creates permanent records, ensures clarity, and provides legal protection
This is fundamental to MS-500 - Microsoft 365 Security Administration practice. It creates permanent records, ensures clarity, and provides legal protection represents the professional standard for communication in the MS-500 certification framework.
Question 13: Your Microsoft 365 environment is a mix of the two. <br> Microsoft Office 365 ProPlus is installed on all machines, which runs Windows 10 Enterprise. Every one of <br> Active Directory is installed on PCs. <br> Server1 is a Windows Server 2016 server that you have. The telemetry database is stored on Server 1. You must prohibit Microsoft from receiving personal information from telemetry data. <br> What's your plan?
- On Server1, run readinessreportcreator.exe
- Configure a registry on the computers (Correct answer)
- On the computers, run tdadm.exe
- Configure a registry on Server1
Correct answer: Configure a registry on the computers
To prevent Microsoft from receiving personal information from telemetry data generated by Office 365 ProPlus, a registry setting needs to be configured directly on the client computers running Office. This setting allows administrators to control the level of diagnostic data sent to Microsoft. Modifying the registry on individual machines ensures that the policy is applied at the source of the telemetry data.
Question 14: When a Microsoft 365 Security Administrator leaves the organization, which professional standard practice must be immediately followed regarding their privileged access?
- Immediately remove all privileged role assignments and revoke active sessions (Correct answer)
- Transfer their admin roles to a colleague temporarily
- Archive their admin account for 30 days before deletion
- Reset their password and monitor the account for suspicious activity
Correct answer: Immediately remove all privileged role assignments and revoke active sessions
Immediate removal of all privileged role assignments and session revocation prevents unauthorized access by former employees, a core identity lifecycle management requirement.
Question 15: An organization is implementing Microsoft Purview Information Protection sensitivity labels. Which stakeholder group must be involved in defining label taxonomy before deployment?
- End users through a company-wide vote
- Only the IT security team
- Legal, compliance, and business unit data owners (Correct answer)
- External Microsoft consultants exclusively
Correct answer: Legal, compliance, and business unit data owners
Sensitivity label taxonomy reflects data classification policy, which must be co-owned by legal, compliance, and business units whose data is being labeled.
Question 16: What is the primary value of case study analysis in MS-500 - Microsoft 365 Security Administration training?
- Memorizing specific outcomes
- Developing critical thinking by applying theory to realistic professional scenarios (Correct answer)
- Replacing hands-on experience
- Learning only from failures
Correct answer: Developing critical thinking by applying theory to realistic professional scenarios
This is fundamental to MS-500 - Microsoft 365 Security Administration practice. Developing critical thinking by applying theory to realistic professional scenarios represents the professional standard for practical in the MS-500 certification framework.
Question 17: A vendor partner requests that their service account be excluded from MFA Conditional Access policies for integration purposes. What governance step is required before granting this exception?
- Approve the exception verbally in a meeting to expedite the integration timeline
- Have the vendor submit the request directly to Microsoft for approval
- Add the exclusion immediately since service accounts typically don't need MFA
- Obtain written business justification, document the risk acceptance, use a service account with least-privilege permissions, and obtain CISO or equivalent approval (Correct answer)
Correct answer: Obtain written business justification, document the risk acceptance, use a service account with least-privilege permissions, and obtain CISO or equivalent approval
Service account MFA exclusions create risk and require formal risk acceptance documentation, least-privilege scoping, and leadership approval to maintain security governance.
Question 18: Which Microsoft 365 Defender feature allows security analysts to write custom KQL queries to hunt for threats across historical data?
- Advanced hunting (Correct answer)
- Threat analytics
- Action center
- Incident queue
Correct answer: Advanced hunting
Advanced hunting uses Kusto Query Language (KQL) to query up to 30 days of raw security event data.
Question 19: Which Microsoft Purview capability allows legal teams to search across Exchange, SharePoint, Teams, and OneDrive for litigation purposes?
- Content Search and eDiscovery (Correct answer)
- Microsoft Secure Score
- Azure AD audit logs
- Microsoft Defender for Office 365 Threat Explorer
Correct answer: Content Search and eDiscovery
Microsoft Purview Content Search and eDiscovery tools enable legal teams to locate and export content across multiple M365 workloads.
Question 20: What is the purpose of regular risk reviews in MS-500 - Microsoft 365 Security Administration practice?
- To reduce workload
- To satisfy auditors only
- To generate reports
- To identify new risks, evaluate control effectiveness, and update mitigation strategies (Correct answer)
Correct answer: To identify new risks, evaluate control effectiveness, and update mitigation strategies
This is fundamental to MS-500 - Microsoft 365 Security Administration practice. To identify new risks, evaluate control effectiveness, and update mitigation strategies represents the professional standard for risk management in the MS-500 certification framework.
Question 21: A security architect is implementing a Privileged Access Workstation (PAW) strategy. What is the primary security benefit of this approach?
- Enables multi-factor authentication for all admin accounts
- Centralizes all administrative tasks within Azure Virtual Desktop
- Reduces the attack surface by isolating privileged tasks to a dedicated, hardened device (Correct answer)
- Enforces Conditional Access policies for all users
Correct answer: Reduces the attack surface by isolating privileged tasks to a dedicated, hardened device
PAWs reduce the attack surface by ensuring that privileged credentials are only used on dedicated, hardened devices isolated from general internet browsing and email.
Question 22: A security administrator must notify stakeholders about a planned Microsoft 365 tenant-wide multi-factor authentication enforcement. Which communication should go out FIRST?
- All end users via email
- External vendors with guest access
- IT helpdesk staff
- Executive leadership and department heads (Correct answer)
Correct answer: Executive leadership and department heads
Executive leadership and department heads must be informed first so they can cascade communications and address business impact concerns before broader rollout.
Question 23: During an incident response exercise, the security team must contain a compromised user account. What is the correct sequence of initial containment steps in Microsoft 365?
- Reset password → enable MFA → review audit logs
- Disable the account → revoke all active sessions → reset credentials → investigate (Correct answer)
- Delete the account → revoke sessions → notify user
- Block sign-in → remove all licenses → open support ticket
Correct answer: Disable the account → revoke all active sessions → reset credentials → investigate
Best practice containment starts with disabling the account, then revoking active sessions to terminate access, followed by credential reset, and then investigation.
Question 24: Under ITAR (International Traffic in Arms Regulations), which Microsoft 365 environment is designed to restrict data to U.S. persons?
- Microsoft 365 Government GCC High (Correct answer)
- Microsoft 365 Business Premium
- Microsoft 365 Firstline Workers
- Microsoft 365 Enterprise E5
Correct answer: Microsoft 365 Government GCC High
Microsoft 365 GCC High restricts data handling to U.S. persons and is designed to support organizations subject to ITAR and other export control regulations.
Question 25: An organization must comply with FedRAMP requirements to use Microsoft 365 for federal government workloads. Which Microsoft 365 offering is FedRAMP High authorized?
- Microsoft 365 Enterprise E3
- Microsoft 365 Government (GCC High) (Correct answer)
- Microsoft 365 Frontline Worker
- Microsoft 365 Business Premium
Correct answer: Microsoft 365 Government (GCC High)
Microsoft 365 Government GCC High is FedRAMP High authorized and designed for U.S. federal agencies and contractors handling controlled unclassified information.
Question 26: Which regulation requires organizations to appoint a Data Protection Officer (DPO) when processing personal data at large scale, and how does Microsoft 365 support this role?
- PCI DSS; through the Qualified Security Assessor portal
- SOX; through the CFO sign-off workflow in Compliance Manager
- GDPR; through Compliance Manager role-based access allowing DPO review of assessments (Correct answer)
- HIPAA; through the Privacy Officer designation in the Admin Center
Correct answer: GDPR; through Compliance Manager role-based access allowing DPO review of assessments
GDPR requires a DPO for large-scale personal data processing; Compliance Manager supports this role by providing role-based access so DPOs can review compliance assessments without full admin rights.
Question 27: Which Microsoft 365 compliance feature allows legal holds to be placed on a former employee's mailbox to satisfy litigation preservation requirements under FRCP Rule 37(e)?
- Retention label with record declaration
- Microsoft 365 Archive mailbox
- Microsoft Purview eDiscovery Litigation Hold (Correct answer)
- Azure AD account disable
Correct answer: Microsoft Purview eDiscovery Litigation Hold
eDiscovery Litigation Hold preserves all mailbox content including deleted items, ensuring electronically stored information is available for litigation per FRCP Rule 37(e).
Question 28: When an Intune-managed device is marked as non-compliant, what typically happens when Conditional Access policies are enforced?
- The device is immediately wiped remotely
- An SMS alert is sent to the device user
- The user is blocked from accessing corporate resources (Correct answer)
- The device is automatically remediated and marked compliant
Correct answer: The user is blocked from accessing corporate resources
Conditional Access evaluates compliance status and blocks non-compliant devices from accessing corporate resources such as Exchange Online and SharePoint.
Question 29: Contoso's compliance team must demonstrate that their Microsoft 365 environment meets ISO 27001 controls. Which Microsoft tool provides pre-built assessments mapped to ISO 27001 with actionable improvement tasks?
- Microsoft Compliance Manager with ISO 27001 assessment template (Correct answer)
- Microsoft Purview Audit log export for third-party GRC tools only
- Azure Policy compliance dashboard for ISO 27001
- Microsoft Secure Score with custom control mapping
Correct answer: Microsoft Compliance Manager with ISO 27001 assessment template
Microsoft Purview Compliance Manager includes pre-built assessment templates for ISO 27001 that map Microsoft actions and customer actions to specific controls, tracking compliance posture with a score.
Question 30: An administrator must document all changes made to security policies in Microsoft 365 as part of a change management process. Which tool provides a unified audit log of administrative actions?
- Microsoft Purview Audit (Correct answer)
- Azure Security Center
- Microsoft Sentinel Workbooks
- Microsoft Defender for Cloud Apps
Correct answer: Microsoft Purview Audit
Microsoft Purview Audit (formerly Unified Audit Log) records administrative and user activity across Microsoft 365 services for compliance and investigation purposes.
Microsoft 365 Security Administration (MS-500)
The MS-500 exam validates skills in planning, implementing, managing, and monitoring security and compliance solutions for Microsoft 365 and hybrid environments, covering identity and access, threat protection, information protection, and compliance governance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds