MS-500 Case Studies & Practical Application 3 — Questions and Answers
Question 1: A company's CISO wants to enforce that only compliant, Intune-managed devices can access Exchange Online, regardless of user credentials. Which two components must be configured together?
- Intune device compliance policy AND Conditional Access policy requiring compliant device (Correct answer)
- Microsoft Defender for Endpoint AND Safe Attachments policy
- Azure AD Password Protection AND SSPR policy
- Entra ID Protection AND risk-based Conditional Access
Correct answer: Intune device compliance policy AND Conditional Access policy requiring compliant device
An Intune compliance policy defines what 'compliant' means, and a Conditional Access policy with the 'Require compliant device' grant control enforces that requirement at sign-in.
Question 2: An organization uses Microsoft 365 E5 and wants to detect when a user exports a large volume of records from SharePoint shortly before their termination date (loaded from HR). Which Insider Risk Management trigger should be configured?
- Departing employee data theft template with HR connector trigger (Correct answer)
- Data leaks policy triggered by DLP alert
- Security policy violation template with Defender for Endpoint signal
- Risky browser usage template with browsing signal
Correct answer: Departing employee data theft template with HR connector trigger
The departing employee data theft template uses an HR connector to import resignation dates and automatically elevates risk scoring when activity spikes near the termination date.
Question 3: Contoso detects that an attacker used a compromised service principal to exfiltrate data from SharePoint via Microsoft Graph API. Which Microsoft 365 Defender capability surfaces this type of OAuth app abuse?
- Microsoft Defender for Office 365 campaigns view
- Defender for Cloud Apps OAuth app governance policies (Correct answer)
- Microsoft Purview Audit (Premium) log search
- Microsoft Entra ID App registrations audit log only
Correct answer: Defender for Cloud Apps OAuth app governance policies
Defender for Cloud Apps OAuth app governance provides visibility into app permissions and can alert on abnormal data access patterns by service principals and OAuth apps.
Question 4: A global company must comply with GDPR and ensure EU employees' data is processed only in EU data centers. Which Microsoft 365 feature helps demonstrate this compliance?
- Microsoft Purview Data Residency commitments and Advanced Data Residency add-on (Correct answer)
- Sensitivity labels with geographic restrictions
- Conditional Access location-based policies blocking non-EU IPs
- Exchange Online mailbox region settings only
Correct answer: Microsoft Purview Data Residency commitments and Advanced Data Residency add-on
The Advanced Data Residency add-on provides contractual commitments and tooling to ensure specific Microsoft 365 workload data is stored and processed in the committed EU geo.
Question 5: A phishing simulation campaign reveals that 30% of employees clicked a malicious link. The security team wants to automate targeted training for those users. Which Microsoft 365 feature achieves this?
- Microsoft Defender for Office 365 Attack Simulator with assigned training (Correct answer)
- Microsoft Purview Communication Compliance training nudges
- Conditional Access blocking users who clicked phishing links
- Microsoft Secure Score improvement actions
Correct answer: Microsoft Defender for Office 365 Attack Simulator with assigned training
Attack Simulation Training in Defender for Office 365 can automatically assign remediation training to users who fail simulations, targeting those who clicked the link.
Question 6: An admin needs to investigate whether a specific file containing credit card numbers was accessed by unauthorized users across SharePoint and OneDrive in the past 90 days. What is the MOST efficient approach?
- Run a Content Search in Microsoft Purview scoped to credit card SIT with activity filters (Correct answer)
- Review each user's OneDrive access logs individually in the SharePoint admin center
- Use Defender for Cloud Apps file scan with manual review
- Enable Audit log search and filter by file name in Exchange admin center
Correct answer: Run a Content Search in Microsoft Purview scoped to credit card SIT with activity filters
Content Search with sensitive information type (SIT) scoping combined with Audit log activity filters provides the fastest cross-workload investigation for a specific file type.
Question 7: Fabrikam's security team wants to ensure that if Microsoft Defender for Endpoint detects malware on a device, the device is automatically removed from network access to Exchange Online within minutes. Which integration enables this automated response?
- Defender for Endpoint risk signal integrated with Intune compliance and Conditional Access (Correct answer)
- Microsoft Sentinel playbook triggering a manual admin workflow
- Exchange Online transport rule blocking the device's IP address
- Microsoft Defender XDR automated investigation and remediation only
Correct answer: Defender for Endpoint risk signal integrated with Intune compliance and Conditional Access
Defender for Endpoint device risk signals feed into Intune compliance policies, which then signal Conditional Access to block Exchange Online access for non-compliant (high-risk) devices automatically.
A company's CISO wants to enforce that only compliant, Intune-managed devices can access Exchange Online, regardless of user credentials.
Which two components must be configured together?