MS-500 Quality Control & Assurance 5 — Questions and Answers
Question 1: A security team is conducting quality assurance on Microsoft 365 audit logging. Which audit log retention period requires a Microsoft 365 E5 or Advanced Audit add-on license?
- 10-year audit log retention (Correct answer)
- 90-day audit log retention
- 30-day audit log retention
- 1-year audit log retention for all users
Correct answer: 10-year audit log retention
The 10-year audit log retention option requires a Microsoft 365 E5 license or the Microsoft 365 Advanced Audit add-on to be assigned to users.
Question 2: During a QA review, an admin wants to verify that Safe Attachments detonation is occurring before emails reach users. What setting must be enabled in the Safe Attachments policy?
- Dynamic Delivery (Correct answer)
- Standard protection
- Redirect attachments on detection
- Allow attachments if scanning can't complete
Correct answer: Dynamic Delivery
Dynamic Delivery detonates attachments in a sandbox and delivers the email body immediately while the attachment is being scanned, confirming pre-delivery inspection.
Question 3: An admin is reviewing the quality of Microsoft Defender for Endpoint onboarding. Which indicator confirms a device is successfully onboarded?
- The device appears in the Device inventory with an active sensor health status (Correct answer)
- The device shows in Azure AD as compliant
- The Intune compliance policy shows a green status
- The device receives a new Conditional Access policy
Correct answer: The device appears in the Device inventory with an active sensor health status
A successfully onboarded device appears in the Microsoft Defender for Endpoint Device inventory and shows an active or healthy sensor status.
Question 4: A QA analyst is checking whether Microsoft Purview Information Protection labels are enforced in third-party apps. Which feature extends label enforcement to non-Microsoft cloud apps?
- Microsoft Defender for Cloud Apps session policies with sensitivity label conditions (Correct answer)
- Azure AD Conditional Access app control
- Microsoft Intune app protection policies
- Exchange mail flow rules
Correct answer: Microsoft Defender for Cloud Apps session policies with sensitivity label conditions
Defender for Cloud Apps session policies can inspect and enforce sensitivity label conditions on content accessed through supported third-party SaaS applications.
Question 5: When performing quality assurance on Microsoft 365 Defender incidents, which triage step helps confirm an incident is genuine and not a false positive?
- Review the incident evidence, including related alerts, affected entities, and the attack story timeline (Correct answer)
- Immediately assign the incident to a tier-2 analyst
- Close the incident and review the audit log separately
- Run a DLP report for the same time period
Correct answer: Review the incident evidence, including related alerts, affected entities, and the attack story timeline
Reviewing the full incident evidence—related alerts, impacted users, devices, and the attack story—provides context to determine whether the incident is real.
Question 6: An admin wants to use Microsoft Purview to run a QA check confirming that records management labels are preventing deletion of regulated documents. What is the key indicator that a label is working correctly?
- Attempts to delete labeled items are blocked and logged as disposition review events (Correct answer)
- The item's sensitivity label changes automatically
- The document is moved to the archive mailbox
- An alert is sent to the compliance officer
Correct answer: Attempts to delete labeled items are blocked and logged as disposition review events
Records management labels block deletion and route items through disposition review at the end of the retention period, which is logged as a disposition event.
Question 7: Which Microsoft Defender for Office 365 feature enables security teams to proactively hunt for threats in email and collaboration data as part of ongoing quality assurance?
- Threat Explorer (Explorer) in the Microsoft Defender portal (Correct answer)
- Microsoft Purview content search
- Azure Sentinel email connector
- Office 365 message trace
Correct answer: Threat Explorer (Explorer) in the Microsoft Defender portal
Threat Explorer in the Microsoft Defender portal allows real-time and historical investigation of email threats, URLs, files, and sender patterns.
A security team is conducting quality assurance on Microsoft 365 audit logging.
Which audit log retention period requires a Microsoft 365 E5 or Advanced Audit add-on license?