MS-500 Quality Control & Assurance 3 — Questions and Answers
Question 1: An admin reviews the Microsoft Purview Compliance Manager and sees a control marked as 'Failed'. What does this status indicate?
- The control's required actions have not been completed or evidence is missing (Correct answer)
- A compliance audit was initiated by a regulator
- The license has expired for that compliance feature
- A DLP policy has been disabled
Correct answer: The control's required actions have not been completed or evidence is missing
A 'Failed' status in Compliance Manager means the associated improvement actions have not been implemented or evidence has not been provided.
Question 2: A security team is performing quality assurance on their Microsoft Defender for Office 365 configuration. Which report shows the effectiveness of Safe Links over time?
- URL protection report in the Defender portal (Correct answer)
- Office 365 audit log
- Azure AD sign-in log
- DLP policy match report
Correct answer: URL protection report in the Defender portal
The URL protection report in Microsoft Defender for Office 365 shows click data, blocked URLs, and override activity for Safe Links.
Question 3: During a QA audit, an admin discovers that some high-risk sign-ins are not triggering Identity Protection alerts. What should the admin verify first?
- That the risk-based Conditional Access policy is enabled and targeting the correct users (Correct answer)
- That MFA is enabled for all users
- That Azure AD logs are exported to a SIEM
- That the tenant has a Microsoft 365 E3 license
Correct answer: That the risk-based Conditional Access policy is enabled and targeting the correct users
If risk-based alerts are not firing, the Conditional Access policy linked to sign-in risk may be misconfigured, disabled, or scoped to the wrong users.
Question 4: An admin wants to validate that eDiscovery searches are returning complete and accurate results for a legal hold. What action best supports result quality?
- Run keyword statistics and preview results before exporting (Correct answer)
- Export all mailboxes without filters
- Use the audit log exclusively
- Check message trace for the same time period
Correct answer: Run keyword statistics and preview results before exporting
Reviewing keyword statistics and previewing search results in eDiscovery ensures the query is correctly scoped before a full export.
Question 5: A compliance admin is configuring retention policies and wants to confirm the policy is working correctly. Which action verifies that content is being retained as expected?
- Check the Preservation Hold library in SharePoint or the Recoverable Items folder in Exchange (Correct answer)
- Review the DLP incident report
- Run an Advanced Hunting query in Defender
- Inspect the Azure AD audit log
Correct answer: Check the Preservation Hold library in SharePoint or the Recoverable Items folder in Exchange
Retained content is moved to the Preservation Hold library (SharePoint) or Recoverable Items (Exchange), confirming the policy is actively retaining data.
Question 6: Which Microsoft Purview tool helps QA teams identify sensitive data that is not yet protected by a DLP or sensitivity label policy?
- Data classification overview and content explorer (Correct answer)
- Microsoft Defender XDR advanced hunting
- Microsoft 365 admin center health dashboard
- Azure Monitor alerts
Correct answer: Data classification overview and content explorer
The data classification overview surfaces sensitive information type detections across the tenant, revealing unprotected sensitive content.
Question 7: An admin is reviewing audit logs to confirm quality of insider risk detection. Which Microsoft Purview feature should they use to review triggered insider risk alerts?
- Insider Risk Management alert queue in the compliance portal (Correct answer)
- Microsoft Defender for Endpoint alerts
- Azure Sentinel workbook
- Exchange admin center message trace
Correct answer: Insider Risk Management alert queue in the compliance portal
The Insider Risk Management alert queue in Microsoft Purview compliance portal shows all triggered alerts with risk scores and activity details for review.
An admin reviews the Microsoft Purview Compliance Manager and sees a control marked as 'Failed'.
What does this status indicate?