MS-500 Case Studies & Practical Application 4 โ Questions and Answers
Question 1: A law firm needs to ensure that documents labeled 'Privileged โ Attorney Client' can never be printed or screen-captured, even by recipients inside the organization. Which capability enforces this?
- Sensitivity label with Rights Management protection restricting Print and Screen Copy permissions (Correct answer)
- DLP policy blocking document sharing
- Conditional Access policy requiring compliant device to open documents
- Retention policy applied to the document library
Correct answer: Sensitivity label with Rights Management protection restricting Print and Screen Copy permissions
Rights Management (Azure Information Protection) integrated with sensitivity labels can restrict specific usage rights such as Print and Copy (screen capture) at the encryption level.
Question 2: An administrator notices that Microsoft Secure Score dropped by 15 points overnight. After investigation, they find that the 'Require MFA for all users' Conditional Access policy was disabled. Which Microsoft 365 Defender feature would have alerted the team immediately?
- Microsoft Secure Score trend report
- Microsoft Defender XDR incident queue with configuration change alert (Correct answer)
- Entra ID audit logs reviewed weekly
- Microsoft Purview Audit log manual search
Correct answer: Microsoft Defender XDR incident queue with configuration change alert
Microsoft Defender XDR can generate incidents and alerts for configuration changes detected as anomalous, including disabling critical Conditional Access policies.
Question 3: Northwind Traders must implement Zero Trust network access for a legacy on-premises application accessed by remote workers. The app does not support modern authentication. Which Microsoft solution addresses this?
- Microsoft Entra application proxy with pre-authentication (Correct answer)
- Azure AD B2C with SAML federation
- Microsoft Tunnel VPN gateway for Intune-managed devices
- Always-on VPN with Conditional Access app control
Correct answer: Microsoft Entra application proxy with pre-authentication
Microsoft Entra Application Proxy publishes on-premises apps to the internet with Entra ID pre-authentication, enabling Zero Trust access without requiring the app to support modern auth natively.
Question 4: During a red team exercise, testers exfiltrated data by uploading files to a personal Google Drive account from a corporate browser session. Which Microsoft 365 control would prevent this going forward?
- Microsoft Defender for Cloud Apps session policy blocking uploads to unsanctioned cloud storage (Correct answer)
- DLP policy blocking all outbound HTTP traffic
- Conditional Access policy blocking Google.com domains
- Safe Links policy scanning all URLs in browser sessions
Correct answer: Microsoft Defender for Cloud Apps session policy blocking uploads to unsanctioned cloud storage
A Defender for Cloud Apps session policy with Conditional Access App Control can inspect and block real-time uploads to unsanctioned cloud storage apps like personal Google Drive.
Question 5: A company with 10,000 users wants to identify which users have NOT enrolled in MFA and are accessing cloud apps from outside the corporate network. Which toolset provides this visibility most efficiently?
- Microsoft Entra ID Authentication Methods Activity report combined with Conditional Access sign-in logs (Correct answer)
- Manual review of Azure AD audit logs filtered by MFA
- Microsoft Secure Score MFA action details only
- Intune enrollment status report and network location policy
Correct answer: Microsoft Entra ID Authentication Methods Activity report combined with Conditional Access sign-in logs
The Authentication Methods Activity report shows MFA enrollment status at scale, and Conditional Access sign-in logs can be filtered to identify successful non-MFA sign-ins from external networks.
Question 6: Contoso receives a legal hold notification requiring all email related to 'Project Helios' for the past three years to be preserved and produced. Which workflow is correct?
- Create an eDiscovery case, add a hold scoped to keyword 'Helios', then run a content search and export (Correct answer)
- Place all user mailboxes on Litigation Hold and manually search each mailbox
- Apply a retention label named 'Helios' to all mailboxes and export via PowerShell
- Use Microsoft Purview Audit to search for emails and download CSV
Correct answer: Create an eDiscovery case, add a hold scoped to keyword 'Helios', then run a content search and export
Creating a Microsoft Purview eDiscovery (Standard or Premium) case with a keyword-scoped hold preserves relevant content, then a content search with export produces the data for legal review.
Question 7: An organization wants to block users from sharing files externally in SharePoint unless the files have a sensitivity label of 'General' or lower, preventing accidental sharing of 'Confidential' labeled content. Which feature enforces this?
- Sensitivity label policies with SharePoint site-level external sharing restrictions based on label
- DLP policy with action to block external sharing for files with Confidential label (Correct answer)
- Conditional Access policy blocking SharePoint external access
- SharePoint admin center external sharing set to 'Existing guests only'
Correct answer: DLP policy with action to block external sharing for files with Confidential label
A DLP policy can detect files with a Confidential sensitivity label and apply a 'Block external sharing' action, preventing those specific files from being shared outside the organization.
A law firm needs to ensure that documents labeled 'Privileged โ Attorney Client' can never be printed or screen-captured, even by recipients inside the organization.
Which capability enforces this?