MS-500 Endpoint Security & Device Management 2 — Questions and Answers
Question 1: Which Microsoft Defender for Endpoint feature continuously discovers software vulnerabilities and misconfigurations on enrolled devices and prioritizes them by risk?
- Advanced Hunting
- Threat and Vulnerability Management (TVM) (Correct answer)
- Attack Surface Reduction rules
- Automated Investigation and Remediation
Correct answer: Threat and Vulnerability Management (TVM)
Threat and Vulnerability Management (TVM) scans enrolled endpoints for vulnerabilities and misconfigurations, then prioritizes them using a risk-based score.
Question 2: Which Attack Surface Reduction (ASR) rule helps prevent Office applications, such as Word and Excel, from spawning potentially malicious child processes?
- Block executable content from email client and webmail
- Block Office applications from creating child processes (Correct answer)
- Block credential stealing from Windows LSASS
- Block untrusted and unsigned processes that run from USB
Correct answer: Block Office applications from creating child processes
The ASR rule 'Block Office applications from creating child processes' prevents Office apps from launching child processes, a common technique used by macro-based malware.
Question 3: In Microsoft Intune, what is the purpose of a Configuration Profile?
- Managing user account passwords and MFA settings
- Applying device settings such as Wi-Fi, VPN, restrictions, and security baselines (Correct answer)
- Enrolling new devices into Intune management
- Monitoring real-time device compliance status
Correct answer: Applying device settings such as Wi-Fi, VPN, restrictions, and security baselines
Configuration Profiles push settings to devices, including Wi-Fi, VPN, email, restrictions, and security baselines, without requiring user interaction.
Question 4: Which Microsoft Defender for Endpoint feature uses AI to automatically investigate security alerts and take or recommend remediation actions to reduce the analyst workload?
- Threat and Vulnerability Management
- Advanced Hunting with KQL
- Automated Investigation and Remediation (AIR) (Correct answer)
- Attack Surface Reduction rules
Correct answer: Automated Investigation and Remediation (AIR)
Automated Investigation and Remediation (AIR) uses AI to automatically triage alerts, investigate the scope of a breach, and either auto-remediate or recommend actions.
Question 5: Which Android enrollment mode in Microsoft Intune creates a separate, encrypted work profile on a personally owned device to isolate corporate data from personal data?
- Android Enterprise Fully Managed
- Android Enterprise Dedicated Device
- Android Enterprise Work Profile (BYOD) (Correct answer)
- Android Device Administrator (legacy)
Correct answer: Android Enterprise Work Profile (BYOD)
Android Enterprise Work Profile creates an isolated, encrypted container for corporate apps and data, leaving personal data outside IT management scope.
Question 6: How does Microsoft Defender for Endpoint integrate with Microsoft Intune to enforce risk-based Conditional Access?
- By sending alerts directly to Azure Sentinel
- Through the Microsoft Defender for Endpoint connector in Intune, which feeds device risk scores into compliance policies (Correct answer)
- By writing compliance data to Azure Monitor Logs
- By pushing configuration profiles to non-compliant devices
Correct answer: Through the Microsoft Defender for Endpoint connector in Intune, which feeds device risk scores into compliance policies
The Microsoft Defender for Endpoint connector in Intune allows Defender's machine risk level to be evaluated as part of device compliance, blocking risky devices via Conditional Access.
Question 7: Which Microsoft 365 security portal serves as the unified console for investigating endpoint alerts, running advanced hunts, and managing Microsoft Defender for Endpoint policies?
- Microsoft Endpoint Manager admin center (endpoint.microsoft.com)
- Microsoft 365 Defender portal (security.microsoft.com) (Correct answer)
- Azure Security Center (portal.azure.com)
- Microsoft 365 compliance center (compliance.microsoft.com)
Correct answer: Microsoft 365 Defender portal (security.microsoft.com)
The Microsoft 365 Defender portal (security.microsoft.com) is the unified security operations center for Defender for Endpoint alerts, advanced hunting, and incident management.
Which Microsoft Defender for Endpoint feature continuously discovers software vulnerabilities and misconfigurations on enrolled devices and prioritizes them by risk?