MS-500 Research & Evidence-Based Practice 5 — Questions and Answers
Question 1: In Azure AD Identity Protection, which risk detection indicates that a user authenticated from an IP address associated with anonymous proxy or Tor exit node services?
- Leaked credentials
- Unfamiliar sign-in properties
- Anonymous IP address (Correct answer)
- Atypical travel
Correct answer: Anonymous IP address
The Anonymous IP address detection fires when a sign-in originates from a known anonymizing proxy, VPN, or Tor exit node.
Question 2: Which Azure AD Identity Protection policy should be configured to automatically require MFA or block access when the sign-in risk level is high?
- User risk policy
- Sign-in risk policy (Correct answer)
- Conditional Access named location policy
- Password protection policy
Correct answer: Sign-in risk policy
The sign-in risk policy evaluates risk at authentication time and can enforce MFA or block access based on the detected risk level.
Question 3: Microsoft recommends configuring the user risk policy remediation to which action so that high-risk users can self-remediate without admin intervention?
- Block access permanently
- Require MFA only
- Require password change (Correct answer)
- Send admin notification only
Correct answer: Require password change
Requiring a secure password change allows high-risk users to remediate their account themselves by resetting credentials, which clears the risk.
Question 4: An admin wants to review all Azure AD Identity Protection risk events detected over the past 30 days, including details on detection type and risk level. Which report provides this?
- Sign-in logs
- Risk detections report (Correct answer)
- Audit logs
- Risky users report
Correct answer: Risk detections report
The Risk detections report lists every individual risk event with detection type, risk level, and associated sign-in or user.
Question 5: Microsoft 365 Defender automatically correlates alerts from Defender for Endpoint, Defender for Office 365, and Defender for Identity into what unified investigation object?
- Incidents (Correct answer)
- Watchlists
- Workbooks
- Alert policies
Correct answer: Incidents
Microsoft 365 Defender correlates related cross-product alerts into incidents, providing a single pane for end-to-end attack investigation.
Question 6: Which Microsoft 365 security product uses machine learning to detect anomalous user behavior such as mass downloads, impossible travel, and unusual administrative activity in cloud apps?
- Microsoft Defender for Office 365
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud Apps (Correct answer)
- Azure AD Password Protection
Correct answer: Microsoft Defender for Cloud Apps
Defender for Cloud Apps (formerly MCAS) applies User and Entity Behavior Analytics (UEBA) to detect anomalous cloud application activity.
Question 7: When implementing an evidence-based security improvement program, which Microsoft 365 tool provides quantifiable metrics showing the point value impact of enabling specific security controls?
- Microsoft Purview audit logs
- Microsoft Secure Score improvement actions (Correct answer)
- Azure AD sign-in risk detections
- Microsoft Defender threat analytics
Correct answer: Microsoft Secure Score improvement actions
Each Secure Score improvement action displays the exact point gain achievable, enabling data-driven prioritization of security investments.
In Azure AD Identity Protection, which risk detection indicates that a user authenticated from an IP address associated with anonymous proxy or Tor exit node services?