MS-500 Endpoint Security & Device Management 1 — Questions and Answers
Question 1: Which Microsoft 365 service is the primary Mobile Device Management (MDM) and Mobile Application Management (MAM) solution for managing and securing endpoints?
- Microsoft Defender for Endpoint
- Microsoft Intune (Correct answer)
- Azure AD Join
- Microsoft Endpoint Configuration Manager
Correct answer: Microsoft Intune
Microsoft Intune is the cloud-based MDM/MAM solution in Microsoft 365 used to manage and secure devices and apps.
Question 2: What is the primary purpose of a Device Compliance Policy in Microsoft Intune?
- To push applications to enrolled devices
- To define rules that devices must satisfy to be considered compliant (Correct answer)
- To encrypt device storage automatically
- To configure Wi-Fi and VPN settings on devices
Correct answer: To define rules that devices must satisfy to be considered compliant
Device Compliance Policies define health and security rules (e.g., OS version, encryption, PIN) that devices must meet to be considered compliant.
Question 3: Which Microsoft Defender for Endpoint capability allows a security analyst to isolate a compromised device from the network while keeping the management channel active?
- Live Response
- Automated Investigation and Remediation
- Network Isolation (Contain Device) (Correct answer)
- Attack Surface Reduction
Correct answer: Network Isolation (Contain Device)
Network Isolation (Contain Device) cuts off all network connections except the Defender for Endpoint management channel, keeping investigative access intact.
Question 4: When an Intune-managed device is marked as non-compliant, what typically happens when Conditional Access policies are enforced?
- The device is immediately wiped remotely
- The user is blocked from accessing corporate resources (Correct answer)
- An SMS alert is sent to the device user
- The device is automatically remediated and marked compliant
Correct answer: The user is blocked from accessing corporate resources
Conditional Access evaluates compliance status and blocks non-compliant devices from accessing corporate resources such as Exchange Online and SharePoint.
Question 5: Which hardware security component does Microsoft Intune use for Windows device health attestation to verify the integrity of the boot process?
- BitLocker Encryption Chip
- Windows Hello for Business
- Trusted Platform Module (TPM) (Correct answer)
- Secure Boot UEFI Firmware
Correct answer: Trusted Platform Module (TPM)
The Trusted Platform Module (TPM) stores cryptographic measurements of the boot process, which Intune uses to attest that a device booted securely.
Question 6: Which Windows provisioning feature in Microsoft 365 automates the out-of-box experience to join devices to Azure AD and enroll them in Intune without IT imaging?
- Microsoft Endpoint Configuration Manager task sequences
- Windows Autopilot (Correct answer)
- Intune bulk enrollment
- Azure AD device registration
Correct answer: Windows Autopilot
Windows Autopilot uses pre-registered hardware IDs to automatically configure and enroll devices into Azure AD and Intune during first boot.
Question 7: Which Apple enrollment mechanism, integrated with Apple Business Manager, allows IT to automatically enroll corporate-owned iOS/iPadOS devices into Intune before they reach end users?
- Apple Configurator with user affinity
- BYOD Web Enrollment Portal
- Automated Device Enrollment (formerly DEP) (Correct answer)
- Apple Volume Purchase Program (VPP)
Correct answer: Automated Device Enrollment (formerly DEP)
Automated Device Enrollment (ADE), formerly Device Enrollment Program (DEP), allows zero-touch enrollment of Apple devices directly through Apple Business Manager.
Which Microsoft 365 service is the primary Mobile Device Management (MDM) and Mobile Application Management (MAM) solution for managing and securing endpoints?