MS-500 Risk Assessment & Management 4 — Questions and Answers
Question 1: A security team is prioritizing vulnerabilities found by Microsoft Defender Vulnerability Management. Which metric best quantifies exploitability risk for prioritization?
- CVSS base score only
- Asset criticality score
- Exposure score combined with device criticality (Correct answer)
- Number of affected devices
Correct answer: Exposure score combined with device criticality
Microsoft Defender Vulnerability Management's Exposure Score combines vulnerability severity with device criticality and exposure probability to prioritize which vulnerabilities pose the greatest organizational risk.
Question 2: What risk mitigation strategy is being applied when an organization accepts a known vulnerability because the cost of remediation exceeds the potential impact?
- Risk transfer
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk reduction
Correct answer: Risk acceptance
Risk acceptance is the deliberate decision to acknowledge a risk and take no further action because the remediation cost or operational impact outweighs the benefit of fixing it.
Question 3: In Microsoft Sentinel, which built-in feature automates risk scoring of incidents by correlating multiple low-severity alerts into a single high-priority incident?
- Playbooks
- Fusion detection (Correct answer)
- Workbooks
- Analytics rules
Correct answer: Fusion detection
Fusion detection in Microsoft Sentinel uses machine learning to correlate multiple low-fidelity signals across kill chain stages into a single high-severity incident with a unified risk score.
Question 4: An organization enables Microsoft Purview Communication Compliance to reduce legal risk. Which scenario does this policy primarily address?
- Preventing data exfiltration via USB drives
- Detecting regulatory violations in email and Teams communications (Correct answer)
- Blocking access to malicious URLs
- Monitoring privileged admin account activity
Correct answer: Detecting regulatory violations in email and Teams communications
Communication Compliance monitors Microsoft 365 communications for policy violations like harassment, sensitive data sharing, or financial regulatory non-compliance, reducing legal and reputational risk.
Question 5: Which Entra ID feature allows administrators to reduce risk by periodically verifying that guest users still require access to shared resources?
- Conditional Access policies
- Access reviews in Entra ID Governance (Correct answer)
- Privileged Identity Management (PIM)
- Cross-tenant access settings
Correct answer: Access reviews in Entra ID Governance
Entra ID Governance Access Reviews periodically prompt resource owners or users to confirm ongoing need for access, automatically revoking access when reviews are not completed or denied.
Question 6: A risk assessment identifies that admins are using permanent Global Administrator roles. Which Microsoft 365 control directly reduces this privileged identity risk?
- Multi-factor authentication (MFA)
- Privileged Identity Management (PIM) with just-in-time access (Correct answer)
- Microsoft Defender for Identity
- Security defaults
Correct answer: Privileged Identity Management (PIM) with just-in-time access
PIM provides just-in-time privileged access, requiring admins to activate elevated roles with approval and time limits, reducing the window of exposure from standing privileged accounts.
Question 7: When implementing a risk treatment plan in Microsoft 365, which document type formally records the decision to deploy Microsoft Entra ID Protection as a control for identity risk?
- Business Impact Analysis (BIA)
- Statement of Applicability (SoA)
- System Security Plan (SSP)
- Risk Treatment Plan (RTP) (Correct answer)
Correct answer: Risk Treatment Plan (RTP)
A Risk Treatment Plan documents the specific controls selected to address identified risks, the responsible parties, timelines, and residual risk after control implementation.
A security team is prioritizing vulnerabilities found by Microsoft Defender Vulnerability Management.
Which metric best quantifies exploitability risk for prioritization?