MS-500 Professional Standards & Competencies 3 — Questions and Answers
Question 1: An organization must demonstrate compliance with GDPR regarding data subject access requests. Which Microsoft 365 tool allows administrators to find and export personal data for a specific individual?
- Microsoft Compliance Manager
- Data Subject Request (DSR) tool in Microsoft Purview (Correct answer)
- Microsoft Defender for Identity
- Azure AD User Audit Logs
Correct answer: Data Subject Request (DSR) tool in Microsoft Purview
Microsoft Purview provides a Data Subject Request tool that allows administrators to search for and export personal data related to a specific individual across Microsoft 365 services.
Question 2: A security architect is implementing a Privileged Access Workstation (PAW) strategy. What is the primary security benefit of this approach?
- Reduces the attack surface by isolating privileged tasks to a dedicated, hardened device (Correct answer)
- Enables multi-factor authentication for all admin accounts
- Centralizes all administrative tasks within Azure Virtual Desktop
- Enforces Conditional Access policies for all users
Correct answer: Reduces the attack surface by isolating privileged tasks to a dedicated, hardened device
PAWs reduce the attack surface by ensuring that privileged credentials are only used on dedicated, hardened devices isolated from general internet browsing and email.
Question 3: According to Microsoft's recommended practices, how often should Global Administrator role assignments be reviewed in a production Microsoft 365 tenant?
- Annually
- Every six months
- Monthly or more frequently (Correct answer)
- Only when personnel changes occur
Correct answer: Monthly or more frequently
Microsoft recommends reviewing Global Administrator assignments monthly or more frequently because this role has the highest level of privilege in the tenant.
Question 4: A security team is building a RACI matrix for Microsoft 365 security responsibilities. What does the 'A' (Accountable) designation mean in this context?
- The person who performs the task
- The person who approves decisions and is answerable for the outcome (Correct answer)
- The person who provides input or expertise
- The person who receives status updates
Correct answer: The person who approves decisions and is answerable for the outcome
In a RACI matrix, 'Accountable' designates the single person who is ultimately answerable for the correct completion of the task and has decision-making authority.
Question 5: When conducting a Microsoft 365 security assessment, an administrator uses Microsoft Secure Score. What best describes what a Secure Score improvement action represents?
- A mandatory compliance regulation that must be met
- A recommended security configuration change with an associated score impact (Correct answer)
- An automated remediation that has already been applied
- A vulnerability that has been actively exploited
Correct answer: A recommended security configuration change with an associated score impact
Secure Score improvement actions are prioritized security recommendations; each has an associated point value reflecting its relative security impact if implemented.
Question 6: A company is implementing security awareness training. Which Microsoft 365 feature simulates phishing attacks to measure and train employees?
- Microsoft Defender for Office 365 Safe Links
- Attack Simulation Training in Microsoft Defender for Office 365 (Correct answer)
- Microsoft Purview Insider Risk Management
- Microsoft Secure Score phishing baseline
Correct answer: Attack Simulation Training in Microsoft Defender for Office 365
Attack Simulation Training in Microsoft Defender for Office 365 lets administrators launch simulated phishing campaigns and enroll employees in targeted training based on their results.
Question 7: Which professional responsibility does an MS-500 administrator have when they discover that a colleague has been granted excessive permissions to sensitive data without a documented business justification?
- Remove the permissions immediately without notifying anyone
- Document the finding and escalate through the defined security governance process (Correct answer)
- Monitor the colleague for 30 days before taking action
- Request a new audit of all permissions across the tenant
Correct answer: Document the finding and escalate through the defined security governance process
The professional standard is to document the finding and escalate through defined governance channels, ensuring accountability without unauthorized unilateral action.
An organization must demonstrate compliance with GDPR regarding data subject access requests.
Which Microsoft 365 tool allows administrators to find and export personal data for a specific individual?