MS-500 Risk Assessment & Management 3 — Questions and Answers
Question 1: What is the primary purpose of a Risk Register in a Microsoft 365 security program?
- Storing encryption keys for sensitive data
- Documenting identified risks, their likelihood, impact, and mitigation status (Correct answer)
- Tracking user license assignments
- Recording audit log retention policies
Correct answer: Documenting identified risks, their likelihood, impact, and mitigation status
A Risk Register is a centralized document that catalogs identified risks along with their assessed likelihood, potential impact, owner, and current mitigation or acceptance status.
Question 2: In Microsoft Entra ID Protection, when a user risk is set to 'High', what automated response can be enforced via Conditional Access?
- Block all access permanently
- Require password change via self-service password reset (Correct answer)
- Force device re-enrollment in Intune
- Revoke all OAuth tokens immediately
Correct answer: Require password change via self-service password reset
A high user risk Conditional Access policy can require users to perform a secure password change through SSPR before regaining access, remediating the risk.
Question 3: Which Microsoft 365 feature enables automated risk-based workflows such as notifying HR when an employee accesses unusual volumes of sensitive files before their resignation date?
- Microsoft Defender for Endpoint
- Microsoft Purview Insider Risk Management (Correct answer)
- Microsoft Entra ID Protection
- Microsoft Sentinel
Correct answer: Microsoft Purview Insider Risk Management
Microsoft Purview Insider Risk Management uses HR connector data and policy templates like 'Data theft by departing users' to trigger alerts based on risk indicators.
Question 4: A security analyst wants to evaluate third-party risk from a vendor with access to a shared SharePoint site. Which principle guides the least-privilege access review for this scenario?
- Defense in depth
- Need-to-know access control
- Zero Trust (Correct answer)
- Separation of duties
Correct answer: Zero Trust
Zero Trust's 'verify explicitly' and 'least privilege access' principles require continuously validating vendor permissions and limiting access to only what is necessary.
Question 5: In Compliance Manager, what does an 'improvement action' owned by Microsoft (as opposed to customer-owned) indicate?
- The customer must implement the control manually
- Microsoft manages and is responsible for that control on behalf of all tenants (Correct answer)
- The action is optional and can be skipped
- The action requires a Premium compliance license
Correct answer: Microsoft manages and is responsible for that control on behalf of all tenants
Microsoft-owned improvement actions are controls that Microsoft implements and manages in its infrastructure, contributing to your compliance score through the shared responsibility model.
Question 6: Which attack simulation technique in Microsoft Defender for Office 365 helps assess phishing susceptibility risk across an organization?
- Safe Links scanning
- Attack Simulation Training (Correct answer)
- Zero-hour auto purge (ZAP)
- Directory-based edge blocking
Correct answer: Attack Simulation Training
Attack Simulation Training lets admins send simulated phishing emails to users, measuring click rates and credential submission to identify high-risk employees for training.
Question 7: When using Microsoft Purview Compliance Manager, which score range indicates the highest compliance risk requiring immediate attention?
- 80-100
- 60-79
- 40-59
- 0-39 (Correct answer)
Correct answer: 0-39
A Compliance Manager score in the 0-39 range indicates significant gaps in implemented controls, representing the highest compliance risk that requires immediate remediation effort.
What is the primary purpose of a Risk Register in a Microsoft 365 security program?