MS-500 Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: Which Microsoft 365 feature helps satisfy GDPR's requirement for Privacy by Design by classifying and protecting sensitive data at creation time?
- Microsoft Defender for Identity
- Sensitivity labels applied automatically via trainable classifiers (Correct answer)
- Azure AD Conditional Access
- Microsoft Purview Audit (Standard)
Correct answer: Sensitivity labels applied automatically via trainable classifiers
Auto-applying sensitivity labels at content creation via trainable classifiers embeds data protection from the start, supporting the GDPR Privacy by Design principle.
Question 2: A company must demonstrate that sensitive emails containing PII are encrypted in transit and at rest to satisfy GDPR Article 32. Which feature addresses this?
- Microsoft 365 Message Encryption (OME) with transport rules (Correct answer)
- Microsoft Defender for Office 365 Safe Attachments
- Azure AD Password Protection
- Microsoft Purview Insider Risk Management
Correct answer: Microsoft 365 Message Encryption (OME) with transport rules
Office 365 Message Encryption applied via mail flow rules encrypts sensitive emails automatically, addressing GDPR Article 32's requirement for appropriate technical security measures.
Question 3: Which Microsoft 365 compliance feature allows legal holds to be placed on a former employee's mailbox to satisfy litigation preservation requirements under FRCP Rule 37(e)?
- Microsoft Purview eDiscovery Litigation Hold (Correct answer)
- Azure AD account disable
- Microsoft 365 Archive mailbox
- Retention label with record declaration
Correct answer: Microsoft Purview eDiscovery Litigation Hold
eDiscovery Litigation Hold preserves all mailbox content including deleted items, ensuring electronically stored information is available for litigation per FRCP Rule 37(e).
Question 4: An organization subject to GLBA (Gramm-Leach-Bliley Act) must protect nonpublic personal financial information. Which Microsoft Purview feature is most directly applicable?
- Microsoft Defender for Cloud Apps
- Data Loss Prevention policies targeting financial information sensitive information types (Correct answer)
- Azure AD B2B collaboration
- Microsoft Teams external access policies
Correct answer: Data Loss Prevention policies targeting financial information sensitive information types
DLP policies using Microsoft's built-in financial sensitive information types detect and protect nonpublic personal financial information to satisfy GLBA Safeguards Rule requirements.
Question 5: Which Microsoft 365 audit log event type is most important for demonstrating compliance with HIPAA's Audit Controls standard (§164.312(b))?
- Azure AD sign-in logs showing successful logins only
- Unified audit log entries including access to mailboxes containing PHI (Correct answer)
- Microsoft Intune device enrollment logs
- Sensitivity label activity reports
Correct answer: Unified audit log entries including access to mailboxes containing PHI
HIPAA §164.312(b) requires audit controls to record and examine activity in information systems containing PHI; unified audit logs capturing mailbox and SharePoint access achieve this.
Question 6: A company's Compliance Score in Microsoft Purview Compliance Manager dropped after a Microsoft service update. What does this most likely indicate?
- A data breach was detected in the tenant
- A previously passing Microsoft-managed control no longer meets the assessment criteria (Correct answer)
- Admin MFA was disabled
- A retention policy was deleted
Correct answer: A previously passing Microsoft-managed control no longer meets the assessment criteria
Compliance Score can decrease if a Microsoft-managed action's status changes due to service updates that affect how controls are assessed against regulatory requirements.
Question 7: Which regulation requires organizations to appoint a Data Protection Officer (DPO) when processing personal data at large scale, and how does Microsoft 365 support this role?
- HIPAA; through the Privacy Officer designation in the Admin Center
- GDPR; through Compliance Manager role-based access allowing DPO review of assessments (Correct answer)
- PCI DSS; through the Qualified Security Assessor portal
- SOX; through the CFO sign-off workflow in Compliance Manager
Correct answer: GDPR; through Compliance Manager role-based access allowing DPO review of assessments
GDPR requires a DPO for large-scale personal data processing; Compliance Manager supports this role by providing role-based access so DPOs can review compliance assessments without full admin rights.
Which Microsoft 365 feature helps satisfy GDPR's requirement for Privacy by Design by classifying and protecting sensitive data at creation time?