MS-500 Research & Evidence-Based Practice 4 — Questions and Answers
Question 1: What does the 'Improvement actions' section in Microsoft Secure Score provide to administrators?
- Historical score data showing trend over time
- A prioritized list of security tasks that will increase the score if implemented (Correct answer)
- Comparison data against organizations in the same industry
- Automated remediation scripts for immediate deployment
Correct answer: A prioritized list of security tasks that will increase the score if implemented
Improvement actions list specific configurations or policies an admin can implement, each with a point value showing its score impact.
Question 2: An organization needs to assess its Microsoft 365 compliance posture against the NIST Cybersecurity Framework. Which Microsoft tool provides this assessment?
- Microsoft Secure Score
- Microsoft Defender XDR
- Microsoft Purview Compliance Manager (Correct answer)
- Microsoft Sentinel
Correct answer: Microsoft Purview Compliance Manager
Compliance Manager provides assessments against regulatory frameworks including NIST CSF, ISO 27001, and GDPR with a scored action plan.
Question 3: Which Microsoft Intune feature provides pre-configured security setting recommendations for Windows devices based on Microsoft's research and best practices?
- Security baselines (Correct answer)
- Conditional Access policies
- Microsoft Sentinel analytics rules
- Purview data classification labels
Correct answer: Security baselines
Security baselines in Intune are pre-configured groups of Windows settings that reflect Microsoft's recommended security configurations.
Question 4: In Microsoft Defender Vulnerability Management, what information is provided for each identified vulnerability to guide remediation?
- User behavioral analytics scores
- CVE details, affected devices count, and remediation guidance (Correct answer)
- Email threat intelligence summaries
- Compliance assessment scores
Correct answer: CVE details, affected devices count, and remediation guidance
Defender Vulnerability Management surfaces CVE-specific details including severity, exposed devices, and actionable remediation steps prioritized by exposure.
Question 5: A security analyst notices the organization's Secure Score dropped significantly overnight. Which Secure Score feature should they use to identify what changed?
- Comparison tab
- Improvement actions tab
- History tab (Correct answer)
- Recommended score target
Correct answer: History tab
The History tab in Secure Score shows score changes over time with explanations for each point gain or loss.
Question 6: Which Microsoft 365 Defender section provides detailed written analysis of active threat campaigns, authored by Microsoft security researchers?
- Advanced hunting saved queries
- Incident summaries
- Threat analytics analyst reports (Correct answer)
- Secure Score recommendations
Correct answer: Threat analytics analyst reports
The Analyst report section within each Threat analytics entry contains in-depth research on threat actor techniques, indicators, and mitigations.
Question 7: Which Microsoft Purview data classification capability can automatically detect sensitive content like Social Security numbers or credit card numbers across Microsoft 365 services?
- Retention labels
- Sensitive information types (Correct answer)
- Trainable classifiers
- Communication compliance policies
Correct answer: Sensitive information types
Sensitive information types use pattern matching and keyword dictionaries to automatically identify regulated data in content across Microsoft 365.
What does the 'Improvement actions' section in Microsoft Secure Score provide to administrators?