MS-500 Communication & Stakeholder Relations 3 — Questions and Answers
Question 1: An organization is implementing Microsoft Purview Information Protection sensitivity labels. Which stakeholder group must be involved in defining label taxonomy before deployment?
- Legal, compliance, and business unit data owners (Correct answer)
- Only the IT security team
- External Microsoft consultants exclusively
- End users through a company-wide vote
Correct answer: Legal, compliance, and business unit data owners
Sensitivity label taxonomy reflects data classification policy, which must be co-owned by legal, compliance, and business units whose data is being labeled.
Question 2: A security team receives pushback from HR about Microsoft Purview communication compliance monitoring policies covering HR conversations. What is the best resolution approach?
- Engage HR leadership and legal to define scope, exclusions, and oversight procedures collaboratively (Correct answer)
- Override HR objections and enforce full monitoring without modification
- Exclude HR entirely from all compliance monitoring policies
- Escalate directly to the CEO without involving HR
Correct answer: Engage HR leadership and legal to define scope, exclusions, and oversight procedures collaboratively
Communication compliance policies affecting HR require collaborative scoping with HR and legal to balance regulatory requirements with employee relations and legal constraints.
Question 3: During a Microsoft 365 tenant migration, the security team discovers that guest users from an acquired company have excessive SharePoint permissions. Who should be the primary stakeholder to coordinate remediation?
- Business unit owners who sponsor the guest relationships (Correct answer)
- The acquired company's IT administrator
- Microsoft support directly
- End users who shared the SharePoint sites
Correct answer: Business unit owners who sponsor the guest relationships
Business unit owners who sponsor guest relationships are accountable for guest access decisions and must drive remediation to preserve business relationships while reducing risk.
Question 4: A Microsoft 365 security administrator needs to explain the purpose of Conditional Access named locations to a regional IT manager. Which explanation is clearest?
- Named locations define trusted IP ranges or countries so access policies can treat traffic from those locations differently (Correct answer)
- Named locations are SharePoint document libraries organized by office geography
- Named locations are Azure AD user attributes storing employees' physical office addresses
- Named locations are network segments managed through Microsoft Intune device compliance
Correct answer: Named locations define trusted IP ranges or countries so access policies can treat traffic from those locations differently
Named locations in Conditional Access represent trusted IP address ranges or geographic regions used to apply location-based access control rules.
Question 5: An executive requests a report on how many users are protected by Microsoft 365 Defender identity protection risk policies. Which tool provides the most accurate data for this stakeholder report?
- Azure AD Identity Protection risk detection and risky users dashboard (Correct answer)
- Microsoft 365 admin center active user count
- Microsoft Intune device compliance report
- Exchange Online mail flow statistics
Correct answer: Azure AD Identity Protection risk detection and risky users dashboard
Azure AD Identity Protection's risky users and risk detection dashboards show precisely which users are subject to identity risk policies and their current risk states.
Question 6: A helpdesk manager complains that users are frequently locked out after Microsoft 365 MFA enforcement. What is the most appropriate security team response?
- Analyze sign-in logs to identify failure patterns, provide user self-service MFA registration guidance, and coordinate a training campaign (Correct answer)
- Disable MFA for users who report lockouts
- Create a blanket MFA exclusion for all helpdesk-reported cases
- Redirect all lockout cases directly to Microsoft support
Correct answer: Analyze sign-in logs to identify failure patterns, provide user self-service MFA registration guidance, and coordinate a training campaign
Sign-in log analysis identifies root causes while proactive training and self-service registration reduce ongoing lockout friction without compromising security.
Question 7: When documenting a Microsoft 365 Data Loss Prevention policy for a regulatory audit, which element is MOST important to include?
- Business justification, regulatory requirement mapped, policy scope, exceptions, and approval chain (Correct answer)
- Only the technical DLP rule conditions and actions in JSON format
- A list of all users who triggered DLP policy matches
- The Microsoft product version the DLP policy was created in
Correct answer: Business justification, regulatory requirement mapped, policy scope, exceptions, and approval chain
Regulatory auditors need policy documentation that traces the rule back to a regulatory requirement with clear ownership, scope, and governance approval.
An organization is implementing Microsoft Purview Information Protection sensitivity labels.
Which stakeholder group must be involved in defining label taxonomy before deployment?