MS-500 Professional Standards & Competencies 2 — Questions and Answers
Question 1: An administrator must document all changes made to security policies in Microsoft 365 as part of a change management process. Which tool provides a unified audit log of administrative actions?
- Microsoft Defender for Cloud Apps
- Microsoft Purview Audit (Correct answer)
- Azure Security Center
- Microsoft Sentinel Workbooks
Correct answer: Microsoft Purview Audit
Microsoft Purview Audit (formerly Unified Audit Log) records administrative and user activity across Microsoft 365 services for compliance and investigation purposes.
Question 2: Under the Zero Trust model, which principle dictates that security should be applied regardless of whether a request originates inside or outside the corporate network?
- Verify explicitly
- Assume breach (Correct answer)
- Least privilege access
- Use just-in-time access
Correct answer: Assume breach
The 'Assume breach' principle of Zero Trust mandates designing security controls as if the network is already compromised, removing implicit trust based on network location.
Question 3: A security administrator is required to attest quarterly that all privileged roles in Azure AD are still necessary. Which feature enforces this requirement?
- Conditional Access Policies
- Access Reviews in Azure AD Identity Governance (Correct answer)
- Azure AD Entitlement Management
- Privileged Identity Management alerts
Correct answer: Access Reviews in Azure AD Identity Governance
Azure AD Identity Governance Access Reviews allow administrators or resource owners to periodically certify that privileged role assignments remain appropriate.
Question 4: Which NIST Cybersecurity Framework function is being applied when a security team classifies data, inventories assets, and maps data flows in Microsoft 365?
- Protect
- Respond
- Identify (Correct answer)
- Detect
Correct answer: Identify
The NIST CSF 'Identify' function covers asset management, business environment analysis, governance, risk assessment, and risk management strategy.
Question 5: A company's security policy requires that all service accounts in Microsoft 365 follow a naming convention and are documented in a central registry. What professional standard does this practice align with?
- ITIL Change Management
- ISO/IEC 27001 Asset Management
- COBIT DS5
- CIS Control 4 — Controlled Use of Administrative Privileges (Correct answer)
Correct answer: CIS Control 4 — Controlled Use of Administrative Privileges
CIS Control 4 focuses on the controlled use of administrative privileges, including inventorying and managing all admin/service accounts.
Question 6: A Microsoft 365 Security Administrator is asked to ensure all security configurations align with Microsoft's recommended security baselines. Where is the official source for these baselines?
- Microsoft Compliance Manager
- Microsoft Security Benchmark in Azure Policy
- Microsoft Secure Score recommendations
- Microsoft Endpoint Manager Security Baselines (Correct answer)
Correct answer: Microsoft Endpoint Manager Security Baselines
Microsoft Endpoint Manager (Intune) provides pre-configured Security Baselines that reflect Microsoft's best-practice security recommendations for Windows and Microsoft 365 apps.
Question 7: When a security professional completes a forensic investigation in Microsoft 365, they must preserve the chain of custody for evidence. Which action best supports this requirement?
- Export audit logs to a CSV and store locally
- Use eDiscovery holds and export via Microsoft Purview with a signed manifest (Correct answer)
- Archive mailboxes using Litigation Hold
- Copy audit logs to a SharePoint library
Correct answer: Use eDiscovery holds and export via Microsoft Purview with a signed manifest
Microsoft Purview eDiscovery exports include a signed manifest that documents the integrity and source of collected evidence, supporting chain-of-custody requirements.
An administrator must document all changes made to security policies in Microsoft 365 as part of a change management process.
Which tool provides a unified audit log of administrative actions?