MS-500 Risk Assessment & Management 2 — Questions and Answers
Question 1: In Microsoft Secure Score, what does a 'Regression' status on a recommended action indicate?
- The action was never configured
- The score for that action decreased since last measurement (Correct answer)
- The action requires a license upgrade
- The action is not applicable to your tenant
Correct answer: The score for that action decreased since last measurement
A Regression status means the improvement action's score contribution has decreased, signaling a security control degraded since it was last evaluated.
Question 2: Which Microsoft 365 Defender feature provides an aggregated risk score based on device, identity, and app signals for a specific user?
- Secure Score
- Insider Risk Management
- User Risk in Identity Protection
- Investigation priority score (Correct answer)
Correct answer: Investigation priority score
Microsoft Defender for Office 365 and Defender XDR assign an Investigation priority score to users by combining behavioral anomalies, alert severity, and asset sensitivity.
Question 3: A company wants to assess risk from OAuth apps connected to Microsoft 365. Which tool surfaces app risk scores and permission scopes?
- Microsoft Purview Compliance Manager
- Microsoft Defender for Cloud Apps (Correct answer)
- Microsoft Entra ID Governance
- Microsoft Secure Score
Correct answer: Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) provides an app risk score for each OAuth app based on permissions, community use, and publisher verification.
Question 4: Under the NIST Cybersecurity Framework, which function maps most directly to Microsoft Compliance Manager's assessment capabilities?
- Protect
- Detect
- Identify (Correct answer)
- Recover
Correct answer: Identify
The NIST 'Identify' function covers asset management, risk assessment, and governance — which aligns with Compliance Manager's control assessments and risk scores.
Question 5: An admin notices a sign-in from an unfamiliar location immediately after a user's normal sign-in. Which Entra ID Protection risk detection type flags this pattern?
- Leaked credentials
- Impossible travel
- Atypical travel (Correct answer)
- Anonymous IP address
Correct answer: Atypical travel
Atypical travel detects sign-ins from locations that are unusual for the user based on their historical behavior, even if travel speed is plausible.
Question 6: Which Compliance Manager control category specifically tracks your organization's obligation to respond when a data breach affects regulated data?
- Data governance
- Incident response (Correct answer)
- Configuration management
- Identity management
Correct answer: Incident response
Incident response controls in Compliance Manager cover breach notification obligations, response planning, and post-incident analysis required by regulations like GDPR.
Question 7: A risk manager wants to quantify the potential financial loss from a successful phishing attack. Which component of quantitative risk analysis does this represent?
- Threat likelihood
- Single Loss Expectancy (SLE) (Correct answer)
- Annual Rate of Occurrence (ARO)
- Risk appetite
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) represents the monetary value expected to be lost in a single occurrence of a specific risk event.
In Microsoft Secure Score, what does a 'Regression' status on a recommended action indicate?