MS-500 Risk Assessment & Management 5 — Questions and Answers
Question 1: Which Microsoft Purview tool helps organizations assess compliance risk specifically against frameworks like ISO 27001, NIST 800-53, and FedRAMP?
- Microsoft Defender for Cloud
- Compliance Manager (Correct answer)
- Microsoft Sentinel
- Secure Score
Correct answer: Compliance Manager
Compliance Manager provides pre-built assessments mapped to over 300 regulatory frameworks including ISO 27001, NIST 800-53, and FedRAMP, with scored improvement actions.
Question 2: A company's risk policy requires that any user flagged as 'High' risk by Entra ID Protection be blocked from accessing cloud apps until remediated. Which control enforces this automatically?
- Microsoft Sentinel alert rule
- Entra ID Conditional Access user risk policy (Correct answer)
- Defender for Cloud Apps session policy
- Microsoft Purview DLP policy
Correct answer: Entra ID Conditional Access user risk policy
A Conditional Access user risk policy set to block access for High-risk users automatically enforces this requirement without manual intervention each time a risk event is detected.
Question 3: In the context of MS-500, what is 'residual risk'?
- Risk that exists before any controls are applied
- Risk that remains after security controls have been implemented (Correct answer)
- Risk transferred to a third-party insurer
- Risk classified as low priority in the risk register
Correct answer: Risk that remains after security controls have been implemented
Residual risk is the remaining level of risk after all planned security controls have been applied — no control eliminates risk entirely, so residual risk must be accepted or further treated.
Question 4: Microsoft Defender for Cloud Apps allows administrators to set an app risk score threshold below which apps are automatically blocked. What governance framework concept does this implement?
- Continuous monitoring
- Risk-based access control (Correct answer)
- Data classification
- Least privilege
Correct answer: Risk-based access control
Risk-based access control denies or restricts access to resources (cloud apps in this case) based on computed risk scores rather than static allow/deny lists.
Question 5: An Insider Risk Management policy alert was generated for a user exfiltrating files. The risk analyst 'confirms' the alert and escalates to an eDiscovery case. What happens to the user's risk score?
- It resets to zero after case creation
- It increases as the confirmed alert adds to the user's risk history (Correct answer)
- It is frozen until the eDiscovery case is closed
- It is transferred to the manager's profile
Correct answer: It increases as the confirmed alert adds to the user's risk history
Confirming an Insider Risk Management alert validates the risk signal, which increases the user's cumulative risk score and raises their priority for future monitoring.
Question 6: Which feature in Microsoft 365 provides a centralized view of threat exposure across endpoints, identities, cloud apps, and email to support enterprise-wide risk assessment?
- Microsoft Defender XDR unified portal (Correct answer)
- Microsoft Entra ID admin center
- Microsoft Purview compliance portal
- Microsoft Intune endpoint analytics
Correct answer: Microsoft Defender XDR unified portal
The Microsoft Defender XDR unified portal consolidates signals from Defender for Endpoint, Identity, Office 365, and Cloud Apps into a single pane for cross-domain risk assessment and investigation.
Question 7: A risk assessment determines that sharing SharePoint sites externally without expiration dates creates unacceptable data risk. Which Microsoft 365 control directly mitigates this?
- Sensitivity labels with encryption
- SharePoint external sharing expiration policy (Correct answer)
- Microsoft Defender for Cloud Apps file policy
- Conditional Access location-based policy
Correct answer: SharePoint external sharing expiration policy
SharePoint's external sharing expiration policy automatically expires guest access links after a configurable number of days, ensuring time-limited access that reduces stale access risk.
Which Microsoft Purview tool helps organizations assess compliance risk specifically against frameworks like ISO 27001, NIST 800-53, and FedRAMP?