MS-500 Case Studies & Practical Application 2 — Questions and Answers
Question 1: Contoso's SOC team discovers that a compromised admin account was used to create a new Global Admin and disable audit logging. Which Microsoft 365 Defender feature would have alerted the team to this lateral movement in near real-time?
- Microsoft Secure Score recommendations
- Identity Protection risky sign-in alerts
- Microsoft Sentinel UEBA anomaly detection
- Defender for Cloud Apps activity policies (Correct answer)
Correct answer: Defender for Cloud Apps activity policies
Defender for Cloud Apps activity policies can trigger real-time alerts on administrative actions such as creating privileged accounts or modifying audit settings.
Question 2: A healthcare organization must ensure that patient data (PHI) shared via Microsoft Teams is automatically classified and protected. Which solution combination achieves this without end-user intervention?
- Sensitivity labels with auto-labeling policies and Rights Management encryption (Correct answer)
- Manually applied retention labels and eDiscovery holds
- Communication compliance policies and DLP audit-only mode
- Azure AD Conditional Access and Intune device compliance
Correct answer: Sensitivity labels with auto-labeling policies and Rights Management encryption
Auto-labeling policies use trainable classifiers or sensitive information types to detect PHI and automatically apply sensitivity labels that enforce Rights Management encryption.
Question 3: An attacker performed a password spray attack and successfully authenticated as five users. Microsoft Entra ID Protection flagged the sign-ins as high-risk. What is the FASTEST remediation action an admin can take to block further access while preserving the accounts for investigation?
- Delete the five user accounts immediately
- Confirm compromise in Identity Protection and require MFA re-registration
- Enable a Conditional Access policy that blocks users with high user risk (Correct answer)
- Reset passwords and disable the accounts temporarily
Correct answer: Enable a Conditional Access policy that blocks users with high user risk
A Conditional Access policy scoped to high user risk immediately blocks sign-ins for all flagged users without requiring manual per-account action, preserving accounts for investigation.
Question 4: Fabrikam's IT team wants to prevent users from forwarding email to external domains using Outlook rules, while still allowing legitimate external email. Which policy type addresses this specific threat?
- Exchange Online mail flow rule blocking external auto-forward (Correct answer)
- Microsoft Defender for Office 365 Safe Links policy
- DLP policy with 'Block' action on all outbound email
- Outbound spam filter with high-confidence spam threshold
Correct answer: Exchange Online mail flow rule blocking external auto-forward
An Exchange Online mail flow (transport) rule can specifically block auto-forwarding to external recipients while allowing normal outbound email to flow.
Question 5: During an insider threat investigation, a legal team needs all email and Teams messages from a specific employee preserved immediately, even if the employee deletes them. What is the correct first step?
- Export a content search report from Compliance center
- Place the employee's mailbox on Litigation Hold (Correct answer)
- Apply a retention label to the employee's mailbox
- Enable Audit log search for the employee
Correct answer: Place the employee's mailbox on Litigation Hold
Litigation Hold immediately preserves all content in the mailbox—including deleted items—for as long as the hold is active, satisfying legal preservation requirements.
Question 6: A user reports receiving an email that passed SPF and DKIM checks but appears to be a phishing attempt impersonating Contoso's CEO. Which Defender for Office 365 feature is MOST likely to catch this scenario?
- Anti-spam policies with bulk complaint level filtering
- Anti-phishing impersonation protection for monitored users (Correct answer)
- Safe Attachments detonation sandbox
- DMARC enforcement with reject policy
Correct answer: Anti-phishing impersonation protection for monitored users
Anti-phishing impersonation protection in Defender for Office 365 monitors specified high-value users (like the CEO) and flags emails that impersonate their display name even when SPF/DKIM pass.
Question 7: Northwind Traders rolls out Microsoft Purview Insider Risk Management. The compliance officer sees an alert for 'Sequence of data theft activities' for a user who resigned last week. What does this sequence policy detect?
- A single large file download exceeding a threshold
- A series of risk activities that follow a defined pattern, such as downloading then emailing files externally (Correct answer)
- Multiple failed login attempts from an unmanaged device
- An email containing sensitive keywords sent to a competitor domain
Correct answer: A series of risk activities that follow a defined pattern, such as downloading then emailing files externally
Sequence policies in Insider Risk Management detect a defined chain of events (e.g., downloading files, then uploading to cloud storage, then emailing externally) that together indicate coordinated exfiltration.
Contoso's SOC team discovers that a compromised admin account was used to create a new Global Admin and disable audit logging.
Which Microsoft 365 Defender feature would have alerted the team to this lateral movement in near real-time?