MS-500 Communication & Stakeholder Relations 2 — Questions and Answers
Question 1: A CISO needs to present the organization's Microsoft 365 security posture to the board of directors. Which metric from the Microsoft Secure Score should be highlighted to convey overall security health?
- Current score vs. maximum achievable score as a percentage (Correct answer)
- Number of active conditional access policies
- Total number of licensed Microsoft 365 users
- Count of daily sign-in events in Azure AD
Correct answer: Current score vs. maximum achievable score as a percentage
Presenting Secure Score as a percentage of maximum achievable score gives the board a clear, normalized view of security health relative to potential.
Question 2: A security administrator must notify stakeholders about a planned Microsoft 365 tenant-wide multi-factor authentication enforcement. Which communication should go out FIRST?
- Executive leadership and department heads (Correct answer)
- All end users via email
- IT helpdesk staff
- External vendors with guest access
Correct answer: Executive leadership and department heads
Executive leadership and department heads must be informed first so they can cascade communications and address business impact concerns before broader rollout.
Question 3: During a security incident involving a compromised Microsoft 365 admin account, which stakeholder group requires immediate notification outside the security team?
- Legal and compliance teams (Correct answer)
- Marketing department
- External customers
- Hardware vendors
Correct answer: Legal and compliance teams
Legal and compliance teams must be notified immediately to assess regulatory obligations, breach notification requirements, and litigation holds.
Question 4: A security team wants to communicate the risk of disabling legacy authentication to non-technical managers. What is the most effective communication approach?
- Frame the risk in terms of business impact and data breach likelihood (Correct answer)
- Share technical SMTP authentication protocol documentation
- Send raw Azure AD sign-in logs showing legacy auth events
- Provide a list of affected RFC standards
Correct answer: Frame the risk in terms of business impact and data breach likelihood
Non-technical managers respond to business-impact framing — connecting technical risks to financial, reputational, or operational consequences drives decision-making.
Question 5: An organization has implemented Microsoft Defender for Office 365 anti-phishing policies. How should the security team communicate policy exceptions requested by a sales department head?
- Document the business justification, assess risk, escalate to CISO for approval, and record the exception formally (Correct answer)
- Implement the exception immediately to avoid business disruption
- Deny all exceptions without review to maintain security posture
- Have the sales department head submit a ServiceNow ticket only
Correct answer: Document the business justification, assess risk, escalate to CISO for approval, and record the exception formally
Security exceptions require documented business justification, risk assessment, appropriate authority approval, and formal tracking for audit purposes.
Question 6: After a phishing simulation campaign in Microsoft Defender for Office 365, the security team wants to share results with department managers. Which data presentation approach is most appropriate?
- Aggregate department-level click rates without identifying individual employees by name (Correct answer)
- Share a full list of every employee who clicked the phishing link
- Only report to the CEO without sharing with department managers
- Publish results on the company intranet for all employees to see
Correct answer: Aggregate department-level click rates without identifying individual employees by name
Aggregate department-level reporting protects individual privacy while giving managers actionable data to drive targeted training.
Question 7: A Microsoft 365 security administrator is asked to justify the cost of Microsoft Defender for Office 365 Plan 2 to finance leadership. Which argument is MOST compelling?
- Demonstrate the cost of a single ransomware incident versus the annual license cost (Correct answer)
- List all technical features included in the license tier
- Compare the number of API calls available vs. Plan 1
- Show the Microsoft product roadmap for future feature additions
Correct answer: Demonstrate the cost of a single ransomware incident versus the annual license cost
Finance stakeholders respond to ROI arguments — comparing potential breach costs against license fees directly frames security as a financial risk mitigation investment.
A CISO needs to present the organization's Microsoft 365 security posture to the board of directors.
Which metric from the Microsoft Secure Score should be highlighted to convey overall security health?