MS-500 Quality Control & Assurance 2 — Questions and Answers
Question 1: A security admin wants to ensure that Conditional Access policies are not misconfigured before enforcing them broadly. Which feature allows testing a policy without blocking users?
- Report-only mode (Correct answer)
- Policy exclusions
- Named locations
- Sign-in risk policy
Correct answer: Report-only mode
Report-only mode evaluates a Conditional Access policy and logs what would have happened without actually enforcing block or grant controls.
Question 2: When reviewing Microsoft Secure Score, an admin notices a recommendation to enable MFA for all admins. What does acting on this improvement action directly affect?
- The organization's Secure Score percentage (Correct answer)
- The Azure AD license tier
- The number of Conditional Access policies
- The tenant's compliance score only
Correct answer: The organization's Secure Score percentage
Completing improvement actions in Secure Score raises the organization's percentage score by the points assigned to that action.
Question 3: An admin is assessing the quality of DLP policies. Which Microsoft Purview feature provides a report showing how many DLP policy matches occurred and which policy triggered them?
- DLP policy reports in the compliance portal (Correct answer)
- Microsoft Defender for Cloud Apps activity log
- Microsoft 365 Message Trace
- Audit log search
Correct answer: DLP policy reports in the compliance portal
The Microsoft Purview compliance portal provides DLP reports that show policy match counts, rules triggered, and affected content.
Question 4: A compliance officer wants to verify that sensitivity labels are being applied consistently across SharePoint sites. Which tool provides visibility into labeled content across Microsoft 365?
- Content explorer in Microsoft Purview (Correct answer)
- Azure AD access reviews
- Microsoft Defender for Identity
- Exchange message trace
Correct answer: Content explorer in Microsoft Purview
Content explorer in Microsoft Purview shows all items that have sensitivity labels or sensitive information types applied across Microsoft 365 locations.
Question 5: During a QA review, an admin finds that several guest users have had their access for over 90 days without review. Which feature automates periodic guest access validation?
- Azure AD Access Reviews (Correct answer)
- Privileged Identity Management
- Entitlement Management
- Identity Protection
Correct answer: Azure AD Access Reviews
Azure AD Access Reviews can be configured to automatically review and expire guest user access on a recurring schedule.
Question 6: An admin wants to confirm that communication compliance policies are detecting potential violations accurately. What should they review to evaluate policy effectiveness?
- Pending review items and false-positive rates in the compliance portal (Correct answer)
- The number of eDiscovery holds placed
- Microsoft Defender for Office 365 safe links reports
- The Secure Score recommendation list
Correct answer: Pending review items and false-positive rates in the compliance portal
Reviewing pending items and tracking false positives in the communication compliance dashboard helps assess and tune policy accuracy.
Question 7: Which Microsoft 365 Defender feature provides a prioritized list of recommended actions to reduce attack surface across endpoints, email, and identity?
- Microsoft Secure Score (Correct answer)
- Threat Analytics
- Incident queue
- Advanced Hunting
Correct answer: Microsoft Secure Score
Microsoft Secure Score aggregates security posture across Microsoft 365 services and surfaces prioritized improvement actions to reduce risk.
A security admin wants to ensure that Conditional Access policies are not misconfigured before enforcing them broadly.
Which feature allows testing a policy without blocking users?