MS-500 Professional Standards & Competencies 5 — Questions and Answers
Question 1: A Microsoft 365 Security Administrator is responsible for maintaining a security operations playbook. What should the playbook include to meet professional standards?
- Only the contact details of the security team
- Step-by-step response procedures for common incident types, escalation paths, and tool references (Correct answer)
- A list of all security products in use
- Organizational charts and budget information
Correct answer: Step-by-step response procedures for common incident types, escalation paths, and tool references
A professional security playbook must include detailed procedural steps, decision trees for common incident types, escalation procedures, and references to the tools used in response.
Question 2: What is the professional significance of maintaining a Configuration Management Database (CMDB) for Microsoft 365 security configurations?
- It automatically applies security patches
- It provides a baseline for detecting unauthorized configuration changes and supports change management (Correct answer)
- It replaces the need for audit logs
- It generates compliance reports automatically
Correct answer: It provides a baseline for detecting unauthorized configuration changes and supports change management
A CMDB documents the baseline configuration state, enabling detection of unauthorized drift and providing the documentation needed for structured change management processes.
Question 3: An organization is preparing for an ISO 27001 audit. The auditor asks for evidence that Microsoft 365 security controls are monitored continuously. Which Microsoft tool best provides this evidence?
- Microsoft Compliance Manager with continuous assessment (Correct answer)
- Microsoft Defender for Cloud Apps activity log
- Microsoft Purview Audit with log retention set to 90 days
- Azure AD sign-in reports
Correct answer: Microsoft Compliance Manager with continuous assessment
Microsoft Compliance Manager provides continuous compliance assessment with automated control testing evidence, directly supporting ISO 27001 audit requirements.
Question 4: A security team lead is mentoring a junior administrator on least privilege. The junior admin asks why Global Administrator should not be used for daily tasks. What is the best explanation?
- Global Admin accounts cost more licensing fees
- Using Global Admin for routine tasks exposes the highest-privilege account to greater risk; scoped roles limit blast radius if compromised (Correct answer)
- Global Admin cannot access certain features needed for daily tasks
- Regulations prohibit using Global Admin for daily operations
Correct answer: Using Global Admin for routine tasks exposes the highest-privilege account to greater risk; scoped roles limit blast radius if compromised
Using the least-privileged role for each task limits the damage if an account is compromised — a scoped role can only impact its specific area, unlike Global Admin which controls the entire tenant.
Question 5: When a Microsoft 365 Security Administrator leaves the organization, which professional standard practice must be immediately followed regarding their privileged access?
- Transfer their admin roles to a colleague temporarily
- Immediately remove all privileged role assignments and revoke active sessions (Correct answer)
- Archive their admin account for 30 days before deletion
- Reset their password and monitor the account for suspicious activity
Correct answer: Immediately remove all privileged role assignments and revoke active sessions
Immediate removal of all privileged role assignments and session revocation prevents unauthorized access by former employees, a core identity lifecycle management requirement.
Question 6: A company wants to demonstrate due diligence in its Microsoft 365 security program to its board of directors. Which report most effectively summarizes the overall security posture over time?
- Monthly Microsoft Secure Score trend report with improvement actions taken (Correct answer)
- Azure AD sign-in failure report
- List of all Conditional Access policies
- Microsoft Defender incident count by month
Correct answer: Monthly Microsoft Secure Score trend report with improvement actions taken
Microsoft Secure Score trend reports show measurable progress in security posture over time and contextualize specific improvement actions, making them effective for executive-level reporting.
Question 7: Which professional competency is demonstrated when a security administrator proactively reviews Microsoft's Threat Intelligence reports and adjusts Microsoft 365 security controls before a threat campaign reaches their organization?
- Reactive incident response
- Threat-informed defense and proactive security management (Correct answer)
- Compliance management
- Security awareness training
Correct answer: Threat-informed defense and proactive security management
Using threat intelligence to proactively update defenses before an attack materializes demonstrates a threat-informed defense competency, a hallmark of mature security operations.
A Microsoft 365 Security Administrator is responsible for maintaining a security operations playbook.
What should the playbook include to meet professional standards?