MS-500 Communication & Stakeholder Relations 4 — Questions and Answers
Question 1: A security administrator needs to brief newly onboarded department managers about Microsoft 365 insider risk management policies. Which framing best addresses likely manager concerns about employee privacy?
- Explain that policies detect behavioral anomalies at aggregate level with strict access controls limiting who can view individual alerts (Correct answer)
- Assure managers that all employee activities are fully visible to HR and management on demand
- State that insider risk monitoring is legally required and privacy concerns are not relevant
- Describe the technical architecture of the Microsoft Graph API data collection
Correct answer: Explain that policies detect behavioral anomalies at aggregate level with strict access controls limiting who can view individual alerts
Addressing privacy concerns directly by explaining access controls, need-to-know limitations, and aggregate detection builds manager trust in the program.
Question 2: The legal team asks whether Microsoft 365 audit logs can be used in employee disciplinary proceedings. What should the security administrator communicate?
- Logs can support disciplinary proceedings but legal should confirm admissibility, chain of custody requirements, and relevant employment law before use (Correct answer)
- Microsoft 365 audit logs are never admissible in any proceedings
- Logs should be immediately shared with the employee under review before any legal review
- Security administrators should independently decide evidentiary use without legal input
Correct answer: Logs can support disciplinary proceedings but legal should confirm admissibility, chain of custody requirements, and relevant employment law before use
Security administrators should provide logs to legal with appropriate chain-of-custody documentation but defer to legal counsel on admissibility and employment law compliance.
Question 3: A Microsoft 365 security administrator is asked to explain why Safe Links re-writes URLs in emails to non-technical finance staff who are frustrated by the changed links. What is the best explanation?
- Safe Links checks the URL at click-time against threat intelligence to block malicious sites, even if a link looked safe when the email arrived (Correct answer)
- The re-written URLs are Microsoft's way of tracking employee email reading habits
- URL re-writing is a Microsoft bug that will be fixed in a future update
- Safe Links changes URLs to reduce email message size for faster delivery
Correct answer: Safe Links checks the URL at click-time against threat intelligence to block malicious sites, even if a link looked safe when the email arrived
Safe Links provides time-of-click protection against URLs that may become malicious after delivery, which requires re-writing URLs to route through Microsoft's scanning infrastructure.
Question 4: An organization's compliance officer asks the security team for evidence that Microsoft 365 retention policies are functioning correctly. Which report provides the most direct evidence?
- Microsoft Purview compliance portal retention policy activity and content match reports (Correct answer)
- Azure AD sign-in logs from the past 30 days
- Microsoft 365 admin center service health dashboard
- Intune device enrollment status report
Correct answer: Microsoft Purview compliance portal retention policy activity and content match reports
The Purview compliance portal provides retention policy activity reports showing which policies matched content, providing auditable evidence of policy operation.
Question 5: A project manager asks the Microsoft 365 security administrator to disable eDiscovery holds on a departed employee's mailbox to free up storage. What should the administrator communicate?
- Holds cannot be removed without legal counsel approval because active litigation or compliance requirements may mandate retention (Correct answer)
- Storage optimization is sufficient justification to remove eDiscovery holds immediately
- Only the departed employee can authorize removal of their mailbox hold
- eDiscovery holds automatically expire after 30 days and no action is needed
Correct answer: Holds cannot be removed without legal counsel approval because active litigation or compliance requirements may mandate retention
eDiscovery holds are placed for legal or compliance reasons, and removing them without legal counsel review risks spoliation of evidence or regulatory violations.
Question 6: A senior leader asks why a Microsoft 365 security alert about a risky sign-in did not result in automatic account lockout. Which explanation is most accurate?
- The risk policy may be configured to require MFA instead of block, or the user's risk level may not have met the block threshold defined in Conditional Access (Correct answer)
- Microsoft 365 never automatically blocks accounts based on risk alerts
- The alert was a false positive so no action was taken automatically
- Automatic lockout only applies to external users, not internal employees
Correct answer: The risk policy may be configured to require MFA instead of block, or the user's risk level may not have met the block threshold defined in Conditional Access
Azure AD Identity Protection Conditional Access risk policies can be configured to enforce MFA at medium risk and block only at high risk — the response depends on policy configuration.
Question 7: The security team wants to communicate the results of a Microsoft 365 Secure Score improvement initiative over a quarter. Which visualization best conveys progress to executive stakeholders?
- A trend line chart showing Secure Score percentage change over the quarter with milestone annotations (Correct answer)
- A raw table of all 150+ recommended actions and their completion status
- A technical firewall rule change log
- A list of all Azure AD conditional access policy JSON configurations
Correct answer: A trend line chart showing Secure Score percentage change over the quarter with milestone annotations
Executive stakeholders need high-level trend visualization with context, not raw technical data — a trend line with milestone annotations conveys progress clearly.
A security administrator needs to brief newly onboarded department managers about Microsoft 365 insider risk management policies.
Which framing best addresses likely manager concerns about employee privacy?