MS-500 Research & Evidence-Based Practice 2 — Questions and Answers
Question 1: Microsoft Secure Score is primarily designed to help organizations do what?
- Track the number of phishing emails blocked monthly
- Measure and improve their security posture based on recommended actions (Correct answer)
- Monitor user license compliance across Microsoft 365
- Audit administrator account sign-in history
Correct answer: Measure and improve their security posture based on recommended actions
Microsoft Secure Score quantifies an organization's security posture and provides actionable improvement recommendations.
Question 2: Which Microsoft 365 Defender feature allows security analysts to write custom KQL queries to hunt for threats across historical data?
- Threat analytics
- Incident queue
- Advanced hunting (Correct answer)
- Action center
Correct answer: Advanced hunting
Advanced hunting uses Kusto Query Language (KQL) to query up to 30 days of raw security event data.
Question 3: In Microsoft Sentinel, what is the primary container that groups related alerts, entities, and evidence for a single investigation?
- Incident (Correct answer)
- Workbook
- Analytics rule
- Watchlist
Correct answer: Incident
Incidents in Microsoft Sentinel aggregate correlated alerts and associated entities into a single investigation unit.
Question 4: A security team wants to understand the tactics and techniques used in an active threat campaign targeting their industry. Which Microsoft 365 Defender section provides this contextual intelligence?
- Secure Score
- Advanced hunting
- Threat analytics (Correct answer)
- Incidents queue
Correct answer: Threat analytics
Threat analytics provides curated reports authored by Microsoft researchers on active threat campaigns, including MITRE ATT&CK mappings.
Question 5: Which Microsoft feature allows an admin to simulate phishing attacks against employees and provide targeted security awareness training to those who were deceived?
- Microsoft Defender for Endpoint
- Attack simulation training (Correct answer)
- Microsoft Purview insider risk management
- Safe Links policies
Correct answer: Attack simulation training
Attack simulation training in Microsoft Defender for Office 365 runs simulated phishing campaigns and automatically assigns remediation training.
Question 6: An admin wants to compare their organization's Microsoft Secure Score with similar-sized organizations in the same industry. Which Secure Score tab enables this?
- Improvement actions tab
- History tab
- Comparison benchmark (Correct answer)
- Recommended actions
Correct answer: Comparison benchmark
The Comparison tab in Secure Score benchmarks your score against organizations of similar size and industry.
Question 7: Which Microsoft Defender for Office 365 report provides a combined trend view of email threats including malware, phishing, and spam detections over time?
- Threat protection status report (Correct answer)
- Mail flow summary
- Defender for Endpoint device report
- Secure Score history chart
Correct answer: Threat protection status report
The Threat protection status report in Defender for Office 365 shows aggregated detection trends across malware, phishing, and spam categories.
Microsoft Secure Score is primarily designed to help organizations do what?