MS-500 Quality Control & Assurance 4 — Questions and Answers
Question 1: A security admin wants to assess whether anti-phishing policies are properly protecting users. Which Microsoft Defender for Office 365 report is most relevant?
- Threat protection status report filtered by phish (Correct answer)
- Security & compliance audit log
- Message trace results
- Azure AD risky users report
Correct answer: Threat protection status report filtered by phish
The Threat protection status report filtered to phish shows detection counts and the policies that blocked or allowed phishing messages.
Question 2: During quality assurance, an admin notices that a sensitivity label policy is not applying labels automatically to documents. What is the most likely first step to diagnose this?
- Verify that auto-labeling is enabled and the correct conditions are configured in the label policy (Correct answer)
- Disable and re-enable the sensitivity label
- Check the user's Azure AD group membership
- Review the eDiscovery case history
Correct answer: Verify that auto-labeling is enabled and the correct conditions are configured in the label policy
Auto-labeling requires specific conditions (e.g., sensitive info types) to be configured and the policy to be published and enabled for the targeted locations.
Question 3: An admin is performing QA on Microsoft Defender for Identity and wants to confirm sensors are correctly deployed. Where should they verify sensor health?
- The Sensors page in the Microsoft Defender for Identity portal settings (Correct answer)
- The Azure AD audit log
- The Microsoft 365 admin center health page
- The Microsoft Purview compliance portal
Correct answer: The Sensors page in the Microsoft Defender for Identity portal settings
The Sensors page in the Defender for Identity settings shows the status, version, and health of all deployed domain controller sensors.
Question 4: A compliance officer wants to validate that a communication compliance policy correctly detects financial regulatory language. What is the best QA approach?
- Send test messages containing the target keywords and verify they appear in the policy's review queue (Correct answer)
- Review the Secure Score improvement actions
- Check the DLP policy match report
- Run an eDiscovery content search
Correct answer: Send test messages containing the target keywords and verify they appear in the policy's review queue
Sending test messages with expected trigger phrases and confirming they appear in the communication compliance review queue validates policy accuracy.
Question 5: Which Microsoft 365 feature allows administrators to compare their security configuration against industry benchmarks like CIS or NIST as part of a QA review?
- Microsoft Compliance Manager with regulatory templates (Correct answer)
- Microsoft Secure Score improvement actions only
- Azure Security Center policy definitions
- Microsoft Defender for Endpoint baseline report
Correct answer: Microsoft Compliance Manager with regulatory templates
Compliance Manager includes pre-built assessment templates for frameworks like CIS, NIST, and ISO 27001 to benchmark organizational controls.
Question 6: An admin wants to ensure that Privileged Identity Management (PIM) activations are being properly reviewed. Which PIM feature generates a recurring review of active role assignments?
- PIM access reviews for Azure AD roles (Correct answer)
- Conditional Access sign-in risk policy
- Azure AD audit log export
- Microsoft Defender for Cloud alert rules
Correct answer: PIM access reviews for Azure AD roles
PIM access reviews allow administrators to schedule recurring reviews of eligible and active privileged role assignments to ensure least privilege.
Question 7: An admin is validating Microsoft Defender for Cloud Apps policies. Which report helps confirm that a file policy is correctly identifying and acting on sensitive cloud content?
- The Files page and Policy matches filter in Defender for Cloud Apps (Correct answer)
- The Microsoft Purview audit log
- The Secure Score dashboard
- The Exchange message trace
Correct answer: The Files page and Policy matches filter in Defender for Cloud Apps
Filtering the Files page by policy matches in Microsoft Defender for Cloud Apps shows which files triggered a file policy and what actions were taken.
A security admin wants to assess whether anti-phishing policies are properly protecting users.
Which Microsoft Defender for Office 365 report is most relevant?