MS-500 Case Studies & Practical Application 5 β Questions and Answers
Question 1: A financial services firm discovers that Microsoft Copilot for Microsoft 365 is surfacing confidential merger documents to employees who should not have access. What is the ROOT CAUSE and correct remediation?
- Copilot ignores permissions; disable Copilot for all users
- Overpermissioned SharePoint sites allowing broad access; remediate with SharePoint Advanced Management and sensitivity labels (Correct answer)
- DLP policies do not apply to Copilot; enable Copilot-specific DLP
- Copilot requires separate licensing to enforce permissions; upgrade licenses
Correct answer: Overpermissioned SharePoint sites allowing broad access; remediate with SharePoint Advanced Management and sensitivity labels
Copilot respects existing Microsoft 365 permissions, so surfaced content reflects underlying overpermissioning; the fix is to restrict site permissions and apply sensitivity labels using SharePoint Advanced Management.
Question 2: A company wants to automatically revoke access to all Microsoft 365 services within 5 minutes of an employee termination being processed in their HR system. Which integration achieves near-real-time deprovisioning?
- Microsoft Entra ID Lifecycle Workflows triggered by HR system via provisioning connector (Correct answer)
- Manual admin process of disabling accounts in Azure AD
- Conditional Access policy scheduled to check HR status daily
- Microsoft Identity Manager synchronizing AD accounts every 30 minutes
Correct answer: Microsoft Entra ID Lifecycle Workflows triggered by HR system via provisioning connector
Entra ID Lifecycle Workflows can trigger automated tasks (disable account, revoke sessions, remove group memberships) within minutes of a lifecycle event sourced from an HR connector.
Question 3: Security Operations at Tailspin Toys wants to use a SOAR playbook to automatically block a compromised user's sign-in and notify the manager when a high-severity Defender XDR incident is created. Which service hosts these playbooks?
- Microsoft Sentinel Logic App playbooks triggered by Sentinel analytics rules (Correct answer)
- Microsoft Defender XDR automated investigation response only
- Microsoft Purview Audit alerts with Power Automate flow
- Azure Automation runbooks triggered manually by SOC analyst
Correct answer: Microsoft Sentinel Logic App playbooks triggered by Sentinel analytics rules
Microsoft Sentinel Logic App playbooks can be triggered automatically by Sentinel analytics rules connected to Defender XDR incidents, enabling SOAR actions like blocking users and sending notifications.
Question 4: An admin applies a 'Highly Confidential' sensitivity label to a Teams meeting. What is the primary effect of this label on the meeting?
- The meeting recording is automatically deleted after 24 hours
- The label controls who can be invited, disables transcription, and applies watermarks to shared content
- The meeting is blocked from being recorded or transcribed, and only internal users can join (Correct answer)
- The meeting invitation is encrypted and cannot be forwarded
Correct answer: The meeting is blocked from being recorded or transcribed, and only internal users can join
Sensitivity labels applied to Teams meetings can restrict recording and transcription and limit attendees to internal users only, based on the label's configured meeting protection settings.
Question 5: Contoso's compliance team must demonstrate that their Microsoft 365 environment meets ISO 27001 controls. Which Microsoft tool provides pre-built assessments mapped to ISO 27001 with actionable improvement tasks?
- Microsoft Compliance Manager with ISO 27001 assessment template (Correct answer)
- Microsoft Secure Score with custom control mapping
- Azure Policy compliance dashboard for ISO 27001
- Microsoft Purview Audit log export for third-party GRC tools only
Correct answer: Microsoft Compliance Manager with ISO 27001 assessment template
Microsoft Purview Compliance Manager includes pre-built assessment templates for ISO 27001 that map Microsoft actions and customer actions to specific controls, tracking compliance posture with a score.
Question 6: A CISO wants to quantify the organization's exposure to Business Email Compromise (BEC) attacks. Which Microsoft 365 Defender report provides data on impersonation attempts, spoofed senders, and mailbox intelligence detections?
- Threat protection status report in Defender for Office 365 filtered by phish detections (Correct answer)
- Microsoft Secure Score identity improvement actions
- Entra ID sign-in risk report filtered by medium risk
- Exchange Online message trace report for external senders
Correct answer: Threat protection status report in Defender for Office 365 filtered by phish detections
The Threat Protection Status report in Defender for Office 365 shows detections by category including impersonation, spoofing, and mailbox intelligence, providing BEC exposure quantification.
Question 7: Woodgrove Bank wants to ensure that external guest users invited to SharePoint can only access specific shared sites and cannot discover other content or users in the tenant directory. Which settings achieve this?
- Set external sharing to 'Existing guests only' and enable Azure AD B2B collaboration restrictions with tenant-level directory access disabled (Correct answer)
- Block all external sharing in the SharePoint admin center
- Require guests to use MFA and comply with Intune device policy
- Apply sensitivity labels to all SharePoint sites and restrict guest access by label
Correct answer: Set external sharing to 'Existing guests only' and enable Azure AD B2B collaboration restrictions with tenant-level directory access disabled
Scoping external sharing to existing guests and configuring Azure AD cross-tenant access settings to restrict guest directory access limits guests to only their explicitly shared resources.
A financial services firm discovers that Microsoft Copilot for Microsoft 365 is surfacing confidential merger documents to employees who should not have access.
What is the ROOT CAUSE and correct remediation?